GDPR and data requests
Get a Data Processing Agreement, handle a customer's access or deletion request, and configure the widget so you collect less in the first place.
Updated August 7, 2026
If you operate in or sell to the EU, running a chat widget makes you responsible for whatever visitors type into it. This page is the practical version; GDPR & data protection has the fuller explanation.
Who is responsible for what
You are the data controller — you decide what to ask and why. EasyChatDesk is the data processor, acting on your instructions. That split matters because most obligations land on the controller, which is you.
Getting a DPA
A Data Processing Agreement is free on every plan, including the trial. Email [email protected] with the subject DPA request and your company’s legal name and address.
Do this before you go live, not after somebody’s procurement team asks.
Handling a data subject request
When one of your customers asks for their data, or asks you to delete it:
- Verify who they are. Do not action a deletion request from an unverified email address.
- Find the data. Conversations and tickets are searchable from your dashboard by email address.
- Export or delete. You can delete individual conversations and tickets yourself.
- If it is not reachable from the dashboard, email us and we will action it. We respond within 30 days, as Art. 12(3) requires — but tell us early rather than on day 28.
Collect less
The most effective control is not collecting the data at all. Two things worth doing today:
- Trim your pre-chat form. Every field is data you must justify, protect, and delete on request. Email plus “what do you need” is usually enough. Phone numbers and job titles collected “just in case” are pure liability.
- Configure the AI chatbot to decline special-category topics — health, finances, anything about a named third party. See guardrails.
Retention
Chat history retention depends on your plan. Do not treat the maximum as a target — if you do not need three years of chat transcripts, delete them. Shorter retention is both a compliance improvement and one less thing to worry about in a breach.
What we do not offer
Stated plainly so it does not surprise you in procurement: EasyChatDesk is not SOC 2 or ISO 27001 certified and does not sign HIPAA Business Associate Agreements. See security for the full list of what we do and do not claim.
Next: troubleshooting.
Still stuck? Message us from the widget in the corner of this page, or get in touch. A person answers.