GDPR compliance
Last updated — July 7, 2026
How Asks approaches the GDPR — who controls what, how the AI uses your data, and the tools we build in so you can meet your own obligations.
Our commitment
Asks is built for teams that answer to their own customers — which means we answer to you. This page explains, in plain language, how Asks (asksdotapp, LLC) approaches the EU General Data Protection Regulation and equivalent laws (UK GDPR, Swiss FADP), and how we help you meet your own obligations when you use Asks to support your customers.
The binding commitments live in our Data Processing Addendum; this page is the readable map of them.
Who is responsible for what
Your customers' data — you control, we process
When your end users chat with your AI agent or message you through a connected channel, you are the controller of that data and Asks is your processor. We process it only to run your workspace, under the instructions in our DPA. You decide what channels to connect, what content to train on, and when data is deleted.
Your account data — we control
For the data about your own relationship with us — your team's logins, billing details, support emails, and product usage — Asks is the controller, as described in our Privacy Policy.
Lawful bases we rely on
- Contract— providing the platform you signed up for, including processing your end users' conversations on your instructions.
- Legitimate interests — securing the service, preventing abuse and fraud, and improving the product with usage telemetry.
- Consent — marketing emails and any non-essential cookies on our website (see the Cookie Policy).
- Legal obligation — tax, accounting, and lawful requests from authorities.
AI and your data
Asks generates answers with retrieval-augmented generation (RAG): the AI Agent retrieves relevant passages from your own knowledge base at answer time and grounds its response in them. This matters for GDPR because it means:
- We do not use your data — or your customers' data — to train models that serve other customers. Each workspace's knowledge lives in its own isolated index.
- Our large language model provider (OpenAI) processes conversation content via its API, and API data is not used to train OpenAI's models.
- Every AI response is checked for groundedness, and conversations can always be escalated to a human.
The subprocessors involved in AI processing, and where they run, are listed on our subprocessors page.
Data subject rights
GDPR gives individuals rights over their data — access, rectification, erasure, restriction, portability, and objection. How to exercise them depends on whose data it is:
- If you are an end user of one of our customers (you chatted with a business that uses Asks): contact that business — they control your data. If you contact us instead, we will refer your request to them promptly.
- If you are an Asks customer or team member: email privacy@asks.app. We respond within 30 days.
Built-in tools for controllers
We build the mechanics of compliance into the product:
- Delete individual customer records, conversations, or your entire workspace — deletion cascades through the database, file storage, search indexes, and AI vector indexes
- Export conversation and customer data
- Redaction flows for platform-initiated requests: Shopify customers/redact and shop/redact webhooks are honored automatically, as are Facebook and Instagram data-deletion callbacks
- Lead-capture and store-activity features are opt-in per workspace
Data minimization and retention
- We store the country your visitors chat from, not their raw IP address — IP addresses are used transiently for geolocation and discarded
- Store browsing events (Shopify store activity) are automatically purged after 30 days
- Error reports are scrubbed of email addresses and IP addresses before leaving our systems
- Customer Data is retained for as long as you use the service; when you delete your workspace, live data is deleted promptly and residual encrypted backups are overwritten in the ordinary backup cycle
- Account data is retained as long as your account is active, then deleted or anonymized except where law requires retention
International transfers
Asks processes data primarily in the United States, with certain subprocessors elsewhere (each is listed with its location on the subprocessors page). Transfers of EEA, UK, and Swiss personal data are protected by the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and Swiss FADP adaptations respectively — all incorporated in our DPA, together with our commitments on government access requests.
Security of processing
Article 32 requires security appropriate to the risk. Our measures — encryption in transit and at rest, application-layer encryption of integration credentials, role-based access control, per-workspace isolation of data and AI indexes, signed webhooks, rate limiting, and audit logging — are described in plain language on the Security page and contractually in Exhibit B of the DPA.
If something goes wrong
We will notify affected customers without undue delay after becoming aware of a personal data breach affecting their data, with the details controllers need for their own Article 33 notifications: what happened, whose data, likely consequences, and what we are doing about it. Our incident status is published at status.asks.app.
Subprocessor oversight
Every subprocessor signs a data processing agreement with us, is listed publicly with its purpose and location, and cannot start processing customer personal data until at least 10 days after we notify workspace owners — with a right to object. See subprocessors and DPA section 5.
Contact
For GDPR questions, data subject requests, or to reach our data protection contact: