At a glance: EUChat.ai is built for privacy-conscious organizations. We aim to collect what we need, use it for clear purposes, protect it with appropriate controls, and give you practical choices. This policy is a product-site draft and should be reviewed by qualified counsel before production use.
1. Scope and controller
This Privacy Policy explains how European Technology Services UG (“EUChat.ai”, “we”, “us”, or “our”) processes personal information through the EUChat.ai website, marketing communications, product trials, and the EUChat.ai AI workspace (together, the “Services”).
For website and direct account interactions, EUChat.ai is generally the controller of personal information. For an organization’s workspace, the organization may be the controller and EUChat.ai may act as a processor or service provider under the organization’s instructions. A customer’s data processing agreement, security addendum, or business associate agreement may provide more specific terms.
2. Information we collect
2.1 Information you provide
- Contact information: name, work email, organization, role, and the details you send when requesting a demo or support.
- Account information: login identifiers, authentication settings, workspace membership, roles, and preferences.
- Customer Content: prompts, messages, uploaded files, agent or workflow configurations, and other information you choose to process in a workspace.
- Communications: questions, feedback, support requests, and records of our correspondence.
2.2 Information collected automatically
We may collect device and usage information such as IP address, browser type, operating system, approximate location derived from IP, pages visited, referring page, timestamps, event logs, and basic performance or security telemetry. We use this information to operate, secure, troubleshoot, and improve the Services.
2.3 Information from organizations and providers
If your organization invites you to a workspace, we may receive your name, work email, role, and workspace permissions from that organization. If you connect a third-party provider, we may receive the information needed to authenticate and perform the action you request, subject to that provider’s terms and privacy policy.
3. How we use information
We use personal information for the following purposes:
- to provide, authenticate, personalize, and maintain the Services;
- to process prompts, files, and other Customer Content at your direction;
- to respond to support requests, demos, and other communications;
- to protect the Services, prevent abuse, investigate security events, and enforce our terms;
- to understand product performance and improve reliability, accessibility, and usability;
- to send service announcements and, where permitted, product or educational communications; and
- to comply with legal obligations and establish, exercise, or defend legal claims.
Depending on the context, our legal bases under the GDPR may include performance of a contract, legitimate interests, consent, and compliance with a legal obligation. Where we rely on consent, you can withdraw it at any time without affecting prior processing.
4. AI models, tools, and Customer Content
EUChat.ai is model agnostic and can connect to hosted providers, local models, custom endpoints, file search, web research, code execution, MCP servers, and other tools. When you use one of these capabilities, information may be sent to the selected provider or tool so it can perform the requested action.
Your organization controls which models and tools are available in its workspace. EUChat.ai does not use Customer Content from a private workspace to train a public model unless the organization or user has clearly opted in or a written agreement permits it. Customers should configure their providers and retention settings to match their data protection requirements.
If you use a self-hosted deployment, the organization operating that deployment controls its infrastructure, logs, storage, and provider connections. This policy applies to EUChat.ai’s own processing and may not describe the practices of an independent operator.
5. When we share information
We may share information with:
- Service providers: infrastructure, hosting, authentication, analytics, customer support, email, security, and other vendors that process information under our instructions;
- Connected providers: model providers, storage, search, code, and other tools that you or your organization choose to connect;
- Organization administrators: information about workspace membership, usage, content, and settings as permitted by the organization’s configuration and agreement;
- Authorities or advisors: when required by law or reasonably necessary to protect rights, safety, security, or the Services; and
- Business transaction parties: in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
6. International transfers and EU residency
EUChat.ai is designed around European data protection expectations and can support EU data residency and EU sovereign deployment options. The specific region, provider, and transfer path depend on the deployment and services selected by the customer.
If personal information is transferred outside the European Economic Area, we use a lawful transfer mechanism such as an adequacy decision, standard contractual clauses, or another mechanism recognized by applicable law, together with supplementary measures where appropriate.
7. Retention and deletion
We retain personal information for as long as reasonably necessary for the purpose collected, the applicable subscription, a documented customer instruction, or a legal obligation. Retention can vary by workspace settings, backups, security logs, support records, and connected services.
When a workspace or account is deleted, EUChat.ai will follow the applicable deletion process and agreement. Some information may remain in restricted backups or records for a limited period where needed for security, fraud prevention, legal compliance, or dispute resolution. Customers are responsible for requesting deletion from independent connected providers where the provider’s process requires it.
8. Security
We use administrative, technical, and organizational safeguards appropriate to the risk, which may include encryption in transit and at rest, least-privilege access, role-based permissions, authentication controls, audit events, environment separation, vulnerability management, and incident response processes.
No service can guarantee absolute security. Please use the deployment and workspace controls appropriate for the sensitivity of your information and notify us promptly if you suspect unauthorized access.
9. Your privacy rights
Depending on your location and the role of EUChat.ai, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of your personal information. You may also have the right to withdraw consent and to complain to your local data protection authority.
To exercise a right, contact us using the details below. We may need to verify your request and may route a workspace request to the relevant organization administrator. We will respond within the time required by applicable law.
10. Children
The Services are intended for organizations and professional users. They are not directed to children under the age at which they can consent to processing under applicable law. If you believe a child has provided personal information to us, contact us and we will take appropriate steps.
11. Cookies and similar technologies
We use essential cookies or local storage to remember basic preferences, keep the website functional, and protect forms. With your permission, we may use optional analytics technologies to understand page performance and improve the experience. We do not use optional analytics as a condition of accessing the basic website.
You can manage cookies through your browser settings. Blocking essential storage may affect navigation or preferences. If we add a non-essential provider, we will update this section and provide a choice mechanism where required.
12. Changes to this policy
We may update this Privacy Policy when our Services, legal obligations, or privacy practices change. We will post the updated version and revise the effective date. If a change is material, we will provide additional notice where required.
13. Contact us
European Technology Services UG
Privacy questions and rights requests: [email protected]
General contact: [email protected]