
Almost every first conversation we have about chatbots turns to data protection within ten minutes. Fair enough. A chatbot takes in whatever visitors type, stores the conversation and sends requests to an AI model. Personal data ends up in there, planned or not. The moment someone writes "hi it's Tom Fletcher, order 40817 never turned up", you've got a name and an order number in your chat history.
The reassuring part is that running a chatbot in line with the GDPR doesn't need a legal department. Below are the points we get asked about most in our projects. They should help you judge any provider, not only us.
Quick note first: this isn't legal advice. It describes what we pay attention to in practice. For your specific situation, please talk to your data protection officer or a lawyer.
Where the data lives
The first question for any provider: where are conversations, uploaded documents and contact details stored? Servers in Germany or the EU make life simpler, because you don't have to deal with transfers to third countries for storage.
Then ask a bit further. An AI chatbot has more than one moving part: the platform that stores conversations, and the language model that writes the replies. Those models often come from big providers such as OpenAI, Google or Anthropic. Ask which sub-processors are involved and on what basis data goes to them. A decent provider will answer that without squirming.
With My-Chatify, data is hosted on servers in Germany and the EU, connections are TLS-encrypted, and each assistant has its own separate database. Your content is never shared with other customers.
The data processing agreement (DPA)
When a service provider processes personal data on your behalf, you need a data processing agreement with them under Art. 28 GDPR. In Germany this is called an AVV. With a chatbot provider it's practically always required, since they store your customers' conversations.
Things worth checking in the DPA:
- Does one exist, and can you get it without chasing?
- Are the sub-processors listed, for hosting and for the AI model?
- Does it describe the technical and organisational measures in place?
- Does it say what happens to your data when you cancel?
To be honest, if a provider gets vague about the DPA, we'd take that as a reason to walk away. My-Chatify provides one.
No AI training on your data
This one gets missed a lot. Some services use what people type to improve their models. For a customer service bot that's a real problem: your customers' questions, order numbers and complaints would feed into someone else's model.
Get it in writing that conversations and uploaded documents won't be used to train AI models, neither by the chatbot provider nor by the AI company behind it. At My-Chatify that's the rule: your data and your customers' conversations are not used for training, including by providers such as OpenAI.
What goes in your privacy policy
Once the bot is live on your site, visitors need to be able to find out what happens to their data. The information duties under Art. 13 GDPR apply here as they do anywhere else. The usual approach is a separate "Chatbot" section in your privacy policy.
It typically covers:
- who runs the chatbot and where the data is processed
- why the input is processed, such as answering enquiries and passing them on to your team
- the legal basis for that
- who receives the data, including the AI model provider
- how long conversations are kept
- what rights visitors have: access, erasure, objection
Also check whether the chat widget stores anything in the browser, for instance a session ID so a conversation doesn't drop when someone clicks to another page. Whether and how that belongs in your cookie banner is a question for your data protection officer. Template wording from the internet is a starting point, not a substitute for that check.
Tell visitors in the chat itself
Hardly anyone reads a privacy policy before typing a question. That's why, in our projects, a short note right inside the chat has worked well. The welcome message is a good place:
"Hi, I'm the automated assistant for this website. I answer based on the information on our site. Please don't share sensitive personal details here. More in our privacy policy."
Two things in there matter to us. Visitors know they're talking to an AI, not a person. That's simply fair, and nobody feels misled later. And the line about sensitive details stops people who would otherwise type their entire medical history into a chat box.
If you collect contact details through the chat, for example with a short form before the conversation starts, say why. "We only need your email to send you the quote" usually does the job.
What to avoid
The most common mistake has little to do with technology. It happens when people build the conversation flows: the bot asks for things it doesn't need.
A few typical examples:
- A physiotherapy practice has the bot ask for the patient's diagnosis before booking. For an appointment you need a name, contact details and a preferred time. The diagnosis can wait for the treatment room.
- A shop asks for date of birth and home address to check delivery status. The order number is enough.
- A training provider asks for benefit paperwork in the very first chat message. That belongs in a proper consultation, not a website chat.
Health data, religious beliefs, financial details and ID documents have no place in a general website chat. If your line of work involves that kind of information, as a practice or a law firm might, use the bot for the organisational side (opening hours, document checklists, appointment requests) and handle anything sensitive through the channels you already use for it.
One more: don't upload internal documents containing personal data as knowledge sources. The staff list with direct dial numbers, a spreadsheet of customer records, old email threads. Anything in the sources can turn up in an answer.
A short checklist
| Item | What to ask or do |
|---|---|
| Hosting | Where are conversations and documents stored? Germany or the EU? |
| DPA | Is there a data processing agreement, with a list of sub-processors? |
| AI training | Is training on your data ruled out in writing? |
| Privacy policy | Is there a chatbot section covering purpose, recipients and retention? |
| Notice in the chat | Can visitors tell they're talking to an AI? |
| Data minimisation | Does the bot only ask for what it really needs? |
| Sources | Have you kept internal documents with personal data out? |
Wrapping up
Data protection for a chatbot is less daunting than most people expect. Most of the work lies in sensible choices during setup rather than in legal text. If you'd like to look at My-Chatify without any pressure, you can try it for free. For the DPA or any data protection questions, drop our team in Dortmund a line via the contact page.
All articles