Security and privacy, explained without jargon
What happens to your customers' data when they talk to your assistant: where it is processed, who is involved, how long it is kept and how it is deleted.
Where the data is processed
- The application and the database are in Germany, on netcup servers.
- Each reply is written by one of four AI models. Two process data in the EU; Groq and Cloudflare process it in the US, with the safeguards the GDPR requires.
- So when one of those two answers, the conversation leaves the EU.
- Groq's and Cloudflare's terms forbid them from using this data to train models.
| Provider | What for | Where |
|---|---|---|
| netcup | Application server and database | Germany |
| Mistral AI | AI model that writes replies | France |
| Our own model | AI model on our own server | Germany |
| Groq | AI model that writes replies and describes photos | US, with standard contractual clauses |
| Cloudflare | AI model that writes replies | US, under the EU-US Data Privacy Framework |
| Meta | WhatsApp messages, if you connect it | Ireland and, in part, the US |
Also involved: Netlify (hosts this website), Brevo (sends the emails), Stripe (payments), Shopify (only if you have a Shopify store) and, to read a website that blocks direct reading, Jina AI and the Internet Archive, which only receive that website's address. The full list, with each provider's safeguard, is in the privacy policy.
Who is responsible for what
For your customers' data, you are the controller and Atendyo processes it on your behalf. What we do with it, and what we don't, is written down in the data processing agreement, which is part of the terms of service.
Read the data processing agreement- We don't sell personal data or share it for advertising.
- If one of your customers asks us for their data or to delete it, we pass the request on to you without delay.
- The assistant replies automatically, but it doesn't decide anything about anyone: it makes no decisions with legal effects.
- On the website, the chat introduces itself as an “AI assistant” and, on WhatsApp, the first reply says so, as the EU AI Act requires.
How long it is kept and how it is deleted
Almost everything deletes itself, and we delete the rest when you ask.
How to request deletionHow we protect it
- All connections are encrypted (HTTPS).
- The Shopify or WhatsApp keys you connect are stored encrypted.
- Each business has its own isolated space: one business's data never mixes with another's.
- Each dashboard has its own access key.
- Order details are only given after checking that the person asking is the one who placed the order, and repeated attempts are blocked.
- We limit the number of requests to stop abuse.
- If there were a security breach, we would notify the Spanish Data Protection Agency (AEPD) within 72 hours when the law requires it, and the people affected if it poses a high risk to them.
About the AI
It is built to stick to your information, but an AI can get things wrong: give an incomplete, outdated or incorrect detail.
- You decide what information to give it, and you can read all its conversations in your dashboard.
- Before a reply goes out, a second check compares it with your information. If something isn't there, it says so and passes you the contact.
- You can tell it in its instructions not to ask for certain details, such as health information.
The legal texts
If anything on this page differs from them, they prevail. Any questions, at comercial@flexigobe.com.
- Privacy policyWhat data we process, what for, with whom and for how long.
- Data processing agreementThe GDPR Article 28 contract for your customers' data.
- Cookie policyWhat is stored in the browser, item by item.
- Data deletionHow to ask us to delete data, depending on who you are.
- Terms of servicePrice, trial, charges and cancellation.
- Legal noticeWho owns this website.