Data Protection & AI

GDPR-Compliant AI Chatbot — Data Protection and AI United

Zentor App AI Chatbot with EU hosting, local On-Premises option, and no third-party data sharing — fully GDPR-compliant.

The Compliance Challenge

Many AI chatbot solutions send conversation data to US-based cloud services — without businesses having full control over the processing. This creates significant compliance risks under the GDPR.

Article 46 GDPR governs the transfer of personal data to third countries. For businesses using AI services with US servers, a structural tension arises that cannot be resolved without technical measures.

GDPR and AI: What Businesses Need to Consider

AI chatbots process personal data: names, contact details, conversation content. This processing must be based on a legal foundation, be transparent, and comply with the principle of data minimization.

GDPR also requires technical and organizational measures (TOMs) to protect data from unauthorized access. An AI chatbot must be embedded within this compliance framework — not operate outside it.

EU Hosting: Infrastructure in Europe, AI Connections Legally Safeguarded

Zentor App operates its infrastructure in the European Union: hosting, databases, and application logic run on EU servers. Certain AI features may optionally use an external AI provider.

Any use of an external AI provider outside the EU takes place exclusively under EU Standard Contractual Clauses (Art. 46 GDPR). You receive a Data Processing Agreement (DPA) under Art. 28 GDPR; the full, current list of all processors used, with country and transfer basis, is available in our Privacy Policy.

On-Premises with local AI runtime: Maximum Data Sovereignty

In the Individual (Individuell) plan, Zentor App enables a complete On-Premises installation on your own server infrastructure. No cloud provider, no external data transfer — the entire platform runs in your data center.

Combined with a local AI runtime, you also run the AI models on your own hardware. Local AI models enable language model operation without external dependencies — conversation data never leaves the company.

The result: maximum data sovereignty. No data transfer, no external AI processing, complete control over models and infrastructure.

No Third-Party Data Sharing

Zentor App does not share your customer data with third parties — neither for AI model training nor for analytics or advertising purposes. Your data is exclusively yours.

When using external AI provider models via Zentor App, external AI provider's privacy terms apply. For businesses requiring complete isolation, we recommend the On-Premises option with local AI runtime.

Data Processing Agreement (DPA) under Art. 28 GDPR

As soon as an AI chatbot processes your customers' personal data — which is the case with every conversation — data processing according to Art. 28 GDPR applies...

Zentor App provides the DPA on request...

For on-premises operation, the DPA is not required as no data processing by Zentor App as an external service provider takes place...

Data Flows in the AI Chatbot: What Happens to Conversation Data?

For EU cloud operation: incoming messages are received by Zentor App, processed by the AI chatbot and stored as conversations in the database...

For on-premises operation: no data leaves your network...

Both variants support configurable retention periods...

Roles, Rights and Audit Trail

Zentor App implements role-based access control (RBAC)...

The audit trail logs all security-relevant actions: logins, configuration changes, data accesses, handover events...

RBAC, audit trail, SSO integration, and extended audit export functions are available as add-on modules in the Individual (Individuell) plan.

Technical Safeguards at a Glance

Zentor App implements multiple layers of technical protection to ensure GDPR compliance.

Encryption

All data transmissions are TLS-encrypted. Stored data is encrypted at rest.

RBAC

Role-based access control ensures agents can only access the data they are authorized for.

Audit-Trail

Complete, tamper-proof log of all security-relevant actions — for demonstrability and compliance documentation.

Data Deletion

Conversation data can be automatically deleted after defined retention periods.

Local AI Runtime vs. External AI Provider: Comparison from a Data Protection Perspective

Both options have their strengths. The choice depends on your data protection requirements and technical resources.

externer KI-Anbieter
  • Easy integration, fast start
  • High model quality without own hardware
  • Regular model updates without effort
  • Data transfer to external AI provider servers (US)
lokale KI-Ausführung
  • Complete data sovereignty
  • No data leaves your own infrastructure
  • GDPR-compliant without third-country risk
  • Requires own hardware and technical operation

Frequently Asked Questions About GDPR and AI Chatbots

Is Zentor App GDPR-compliant?+

Yes. Zentor App is designed as a European platform for GDPR compliance. You can choose between EU hosting and an On-Premises installation. In both scenarios, your customer data remains under your control; any use of an external AI provider outside the EU takes place exclusively under EU Standard Contractual Clauses (Art. 46 GDPR) — never uncontrolled. The full list of all processors, with country and transfer basis, is available in our Privacy Policy.

Where is my customer data stored?+

With EU hosting, hosting, databases, and application logic run on servers within the European Union; certain AI features may optionally use an external AI provider, safeguarded through EU Standard Contractual Clauses. With On-Premises operation, data remains completely on your own infrastructure — no data transfer, no external processing.

What is a local AI runtime and why is it privacy-friendly?+

A local AI runtime enables running AI language models on your own hardware. Since AI processing takes place on your own servers, no conversation data is transmitted to external AI services — the model and data remain entirely within your infrastructure.

Can I run Zentor App On-Premises?+

Yes. The Individual (Individuell) plan enables a complete On-Premises installation of Zentor App on your own server infrastructure. Combined with a local AI runtime, you operate both the platform and the AI models completely on your own hardware — without any data transfer to external clouds.

Which AI models can I use?+

Zentor App supports two model approaches: external AI provider models (for teams wanting to use cloud AI) and local AI models (for maximum data sovereignty). The Individual (Individuell) plan with optional Vector-RAG offers extended options for your own model configuration. The choice is entirely yours.

What is an Audit-Trail and from which plan is it available?+

An Audit-Trail is a complete, immutable log of all security-relevant actions in the platform — e.g., user logins, configuration changes, and data access. In Zentor App, the Audit-Trail is available as an add-on module in the Individual (Individuell) plan and is an important tool for demonstrating GDPR-compliant processes.

Do I need a Data Processing Agreement (DPA) for the chatbot?+

As a rule, yes. If your AI chatbot processes your customers' personal data...

How can conversation data from the chatbot be deleted?+

Zentor App enables the configuration of retention periods for conversation data...

Ready for a GDPR-Compliant AI Chatbot?

Test Zentor App in demo mode or speak with us about EU hosting and On-Premises options.

Related Content

Eine praxisnahe Übersicht finden Sie in der Chatbot Datenschutz Checkliste. Wer tiefer einsteigen möchte, findet die DSGVO-Anforderungen an KI-Chatbots im Detail im Ratgeber.

More in the Help Center