GDPR, in practical terms
If you run a website in — or serving — the EU, adding a chat widget makes you responsible for whatever your visitors type into it. Here is how the roles split, what you can ask us for, and how to get a signed DPA.
Last updated: August 7, 2026
Who is responsible for what
The single most common misunderstanding about support software. GDPR splits responsibility in two, and the heavier half stays with you.
You are the controller
You decide what to ask your visitors, what to store and how long to keep it. The conversations, contacts and tickets in your workspace are yours.
We are the processor
EasyChatDesk processes that data on your documented instructions in order to run the chat widget, AI chatbot and help desk — and for nothing else.
Article 28 in writing
A Data Processing Agreement covering the processor obligations under Art. 28 GDPR is available for every plan, at no extra cost.
Getting a Data Processing Agreement
A DPA is the contract that makes the processor relationship legally binding. If you process EU personal data through EasyChatDesk you are required to have one, and it is not an enterprise upsell here — it is free on every plan, including the free tier.
Email [email protected] with the subject DPA request and the legal name and address of your company. We will send a copy for signature. The agreement covers the Art. 28(3) obligations: processing only on your instructions, confidentiality of personnel, security measures, sub-processor terms, assistance with data subject requests, deletion or return at the end of the contract, and audit rights.
Data subject rights we help you honour
When one of your customers exercises a right, the request lands with you as controller. We give you the tools to act on it, and we will help directly if the data is not reachable from your dashboard.
| Right | What it means | GDPR |
|---|---|---|
| Access | Get a copy of the personal data we hold about you. | Art. 15 |
| Rectification | Correct data that is inaccurate or incomplete. | Art. 16 |
| Erasure | Have your personal data deleted (“right to be forgotten”). | Art. 17 |
| Restriction | Limit how we process your data while a dispute is resolved. | Art. 18 |
| Portability | Receive your data in a structured, machine-readable format. | Art. 20 |
| Objection | Object to processing based on legitimate interests, including direct marketing. | Art. 21 |
To raise a request with us directly, email [email protected]. We respond within 30 days, as required by Art. 12(3).
Sub-processors
Third parties that may process personal data in the course of delivering the service. We give notice before adding a new one.
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Stripe | Subscription billing and payment processing | Billing name, email, address, card data (entered directly into Stripe — never stored by us) |
| PrettyInsights | Website analytics on easychatdesk.com | Page views, referrer, coarse device and country information |
| Let's Encrypt | TLS certificate issuance for encrypted connections | Domain names only — no personal data |
Where data is stored, and for how long
EasyChatDesk runs on dedicated infrastructure rather than a shared multi-tenant cloud console, with the database and cache on a private network that is not reachable from the internet. For the current hosting provider and data centre location — which you will need for your own Records of Processing Activities — email [email protected] and we will confirm in writing.
Retention. Chat history retention depends on your plan, and you can delete individual conversations and tickets from the dashboard whenever you like. If you close your workspace and ask for deletion, we remove the associated data within 30 days, except where we are legally required to keep billing records.
Data minimisation. The most effective GDPR control is not collecting the data in the first place. Configure your pre-chat forms to ask only for what you genuinely need — an email address to reply to is usually enough, and every extra field is another thing you have to protect, justify and delete on request.
Related reading: our privacy policy covers personal data we collect as a controller, and security covers the technical measures behind all of this.
Not legal advice. This page describes how EasyChatDesk is built and what we will sign. It is not a legal opinion, and no software vendor can make your business GDPR compliant on its own — that depends on what you collect, why, and what you tell people about it. If you process sensitive categories of data or operate at scale, talk to a data protection specialist.
Chat software that does not create a compliance problem
Free DPA on every plan, data you can delete yourself, and a security page written in plain English.
- Guided onboarding
- Scale-as-you-grow pricing
- 55+ languages
- 15-day free trial
- Cancel anytime