Start free
Data protection

GDPR, in plain English

An honest, jargon-light rundown of how we handle your data, where it lives, and which providers help us run Kisnip.

The short version

We comply with the EU GDPR and the Swiss FADP. We don't sell your data, we don't use your conversations to train AI models, everything is encrypted, and you can export or delete your data whenever you want.

What we do

A few principles we don't compromise on, no matter which plan you're on.

We never sell your data

Not to advertisers, brokers, or anyone. Only ever to run the service you pay for.

No AI training on your content

Sent to our AI provider only to generate a live reply, never to train models.

Encrypted end to end

Encrypted in transit (TLS) and at rest, with access locked to systems that need it.

No voice recordings kept

Processed live to reply. We keep the text transcript, but never store the audio.

You're in control

Access, export, correct or delete it any time, from your dashboard or by email.

Built for Europe

When data leaves the EU, we rely on the EU's Standard Contractual Clauses (SCCs).

FAQ

A few common questions

Are you the controller or the processor?

Both, depending on the data. For your account details we're the controller. For the conversation data your visitors generate through the widget on your site, you're the controller and we act as your processor, which is why our Data Processing Agreement is built into our Terms.

Do I need to sign a separate DPA?

No separate signing needed. Our GDPR-compliant Data Processing Agreement is incorporated into our Terms of Service, so when you create an account and accept the Terms, you automatically enter into the DPA with us. If your organisation needs a counter-signed copy, contact us.

How long do you keep conversation data?

Transcripts stay available while your account is active so you can review them in your dashboard. When you delete your account, associated personal data is removed or anonymised within 30 days, except where the law requires us to keep certain records (for example, accounting records kept for up to 10 years under Swiss law).

Is data transferred outside the EU?

Some of our providers operate globally, so data may be processed outside the EU. Whenever that happens we rely on the European Commission's Standard Contractual Clauses and each provider's own safeguards to keep your data protected to EU standards.

What happens if there's a data breach?

If a breach is likely to put your rights at risk, we notify the competent supervisory authority without undue delay (within 72 hours where required) and inform affected users as soon as we reasonably can.

Still have questions?

We're happy to walk you through how we handle your data.

Privacy-first AI for your website

Kisnip handles every conversation under EU GDPR and Swiss FADP. Start free and see it in minutes, no credit card required.