Compliance and data questions

GDPR roles, DPAs, subprocessors, where Panelbot data lives, retention windows, and whether we train AI models on your data. We do not.

If you are the person who has to sign off on a new vendor, this page is for you. It answers the questions that usually arrive as a spreadsheet, without making you dig through the Terms first.

Do you train AI models on our data?

No. Conversations, customer data, and anything the assistant reads on your servers are never used to train AI models, ours or anyone else’s. The language model providers we use are under API terms that prohibit training on the data we send them.

This is the question we get asked most, and it is the one where a vague answer should worry you. Ours is in writing in our Terms and Privacy Policy, not just on this page.

Which AI providers see our data?

We use commercial language model providers as subprocessors, under written terms that prohibit training on your data. Chat text passes through them so the assistant can understand and answer. Your panel credentials and billing portal credentials do not.

We keep a current named list of subprocessors and share it with any customer who asks, which is the same list that accompanies a DPA.

Who are your subprocessors?

By category: cloud infrastructure in the United States, language model providers, a payment processor, and a transactional email service. Each is under written terms at least as protective as our own privacy commitments. Card numbers never touch our servers; the payment processor handles them.

The named list is available on request and as part of a DPA.

Will you sign a DPA?

Yes. Ask and we will send one.

What are the GDPR roles?

Two relationships, and they are not the same.

For your own account data, and for visitors to our website, we are the controller.

For your customers’ chat data, you decide what happens and we act on your instructions, which makes you the controller and us the processor. That distinction matters when your customer exercises a right: the request comes to you, and we support you in answering it.

Where is data stored?

United States datacenters.

How long do you keep things, and what happens if we leave?

If you close your account you have 30 days to export everything, including transcripts, audit logs, and your knowledge base. We delete your tenant data within 60 days after that, backups included.

While your account is open, chat transcripts and audit records are retained so you can search and report on them. The audit trail is append-only, so a record of an action cannot be quietly edited later.

Are you SOC 2 or ISO 27001 certified?

Not today, and we would rather say so plainly than imply otherwise. We can answer detailed security questionnaires, provide a DPA, name our subprocessors, and walk you through the permission model in as much depth as you want.

If a certification is a hard requirement for your procurement process, tell us during the sales conversation rather than after, so nobody wastes a month.

Is there an SLA?

Standard plans do not carry a contractual SLA. If your business needs one, that is an Enterprise conversation. See Reliability.

What is the liability position?

Our total liability for all claims is capped at what you paid us in the 12 months before the claim. That cap does not apply to liability the law does not allow to be limited, and it does not excuse willful misconduct. The full text is in the Terms.

The practical counterpart to that cap is the permission model: you decide what the assistant may do, deletions require a typed confirmation from the customer, and the operations you consider critical always route to a human. What you configure is what you have authorized.

How do we report a security issue?

Email security@panelbot.io. If you have found something, we want to hear about it before your customers do.