Trust & compliance
Compliance shouldn't have to be dug out of legal documents. Here is the full overview: where your data lives, how it is protected, and how the platform keeps you on the right side of both the GDPR and the AI Act.
GDPR in practice
Not promises in the air, but concrete mechanisms. The details are in the data processing agreement; here is the essence.
Hosted in the EU
The servers run at Contabo in Germany and the language model is Mistral AI in France. Full sub-processor overview in the DPA.
DPA included
The DPA is an annex to the Terms of Service and is entered into automatically at signup. No separate negotiation needed.
48-hour breach notice
In case of a personal data breach we notify you no later than 48 hours after becoming aware of it. The GDPR's own deadline to the supervisory authority is 72.
Concrete deletion deadlines
Knowledge base and conversation data are deleted no later than 30 days after termination, and backups rotate out no later than 21 days after that.
Encrypted all the way
TLS on all traffic and encryption at rest of the servers' data drives. Access keys are stored with AES-256-GCM.
Your data is yours
Tenant isolation at every layer, no training of general models on your content, and export in a standard format at any time.
Ready for AI Act Article 50
Since 2 August 2026, the EU's AI Act has required that users are clearly informed when they are talking to an AI. The requirement also applies to businesses that put a chatbot on their website, and the fines are substantial.
The fabrikken platform delivers the transparency out of the box: the chatbot presents itself as an AI, obtains explicit consent before the first message with timestamped documentation, and answers with source references, so nobody is in doubt about what they are talking to. In other words, Article 50 transparency is a built-in part of the product, not a project you have to run yourself.
The platform provides the tools; your specific setup and use remain your responsibility, cf. the Terms of Service.
Compliance FAQ
The questions your DPO asks first.
Where does our data live?
In the EU: hosting at Contabo in Germany and the language model at Mistral AI in France. Two transparent exceptions: speech-to-text is processed by Speechmatics in the UK (EU adequacy decision), and the network layer is currently provided by Cloudflare under the EU-US Data Privacy Framework. We are actively working to phase out the latter in favour of a purely European solution.
Who owns and controls the data?
You do. Your material and the knowledge base remain yours, the content is never used to train general language models, and you can have everything delivered in a commonly used format at any time.
What happens when we cancel?
Knowledge base, conversation data and configuration are deleted no later than 30 days after termination; backup copies rotate out no later than 21 days after that. Completed deletion is confirmed on request.
How do you handle security breaches?
We notify you without undue delay and no later than 48 hours after becoming aware of a breach, with the information you need for your own notification to the supervisory authority within 72 hours.
Can the chatbot be closed to the public?
Yes. Internal chatbots can be protected with IP gating, self-registration or named login, so only your own users have access.
Do we need to write our own data processing agreement?
No. Our DPA is entered into as an annex to the Terms of Service at signup and contains instructions, technical measures, the sub-processor list and deletion deadlines.