Messaging Software Built for a GDPR Compliance Program

The General Data Protection Regulation puts real obligations on any business processing the personal data of people in the EU, and that includes the phone numbers, names, and conversation history that flow through SMS, WhatsApp, RCS, and AI agent messaging. No software product can make an organization compliant on its own. What it can do is give your compliance team the infrastructure and controls to build on: where data is processed, who can access it, and how personal data is handled inside an AI conversation.

What GDPR Asks of a Data Controller

GDPR Principle What It Means in Practice
Lawful basis & purpose limitation Personal data must be processed for a specific, lawful purpose, such as consent or legitimate interest, not repurposed silently.
Data minimization Collect and retain only the personal data actually needed for that purpose.
Security of processing Appropriate technical and organizational measures to protect personal data against breach or misuse.
Data subject rights Individuals can request access, correction, erasure, or portability of their personal data.
Breach notification Personal data breaches must generally be reported to the supervisory authority, and to affected individuals in higher-risk cases.
International transfers Transferring personal data outside the EU requires an approved safeguard, such as an adequacy decision or standard contractual clauses.

This is a plain-language summary for context, not legal advice. Your specific obligations depend on your business and should be confirmed with your own legal counsel or data protection officer.

Platform Controls That Support Your Program

Data Residency You Control

PII Controls on AI Conversations

  • AI Agent Builder supports PII redaction and topic guardrails per bot.
  • Bring your own model key for OpenAI, Anthropic, Azure OpenAI, or Gemini if you need to control which AI provider ever processes a query, with BYOK credentials encrypted at rest.

Restricted, Validated Data Exchange

  • Bulk SMS & RCS via SFTP runs over an IP-restricted connection instead of a public API, with every file validated before anything is sent.
  • The Website Chat Widget is locked to an allowlist of domains, with bot-traffic and scam-content detection.

No Vendor Lock-In on Infrastructure

  • Licensed software, not a platform tied to one cloud provider or region.
  • Move or add regions as your footprint or transfer requirements change.

Building out your GDPR compliance program?

Tell us your data residency and control requirements, and we will walk through which deployment model fits.

Talk to a Specialist

Not Legal Advice

This page describes platform capabilities that can support a GDPR compliance program, such as data residency choice, PII redaction, and access controls. It is not a compliance certification, and no vendor can guarantee your organization meets its GDPR obligations. Whether your specific processing activities are compliant depends on facts about your business, your lawful basis, and your data handling policies, which only your own legal team or data protection officer can assess.

FAQ

Frequently Asked Questions

No single product can make an organization GDPR compliant on its own. Compliance depends on your lawful basis for processing, your data retention policy, your data processing agreements, and your own legal review. The platform provides infrastructure and controls, such as data residency choice, PII redaction, and access restrictions, that a compliance program can build on.

Yes. Running the platform fully on-premise or in a private cloud account you control, in a region you choose, keeps that decision with you instead of a vendor. See On-Premise Messaging Software and Private Cloud Deployment for both models.

AI Agent Builder supports PII redaction and topic guardrails per bot, and lets you bring your own OpenAI, Anthropic, Azure OpenAI, or Gemini key if you need to control which AI provider processes a conversation, with BYOK credentials encrypted at rest.

Because the software runs on infrastructure you provision, you decide which region a deployment sits in, rather than depending on wherever a SaaS vendor happens to host their platform. Whether a specific transfer arrangement satisfies GDPR's cross-border transfer rules is a legal question for your own counsel.

Bulk file exchange through Bulk SMS & RCS via SFTP runs over an IP-restricted connection rather than a public endpoint, and the Website Chat Widget is locked to a domain allowlist.

Yes. This page describes platform capabilities, not legal advice. Whether your specific processing activities meet GDPR obligations depends on facts about your business that only your own legal and compliance team can assess.

Ready to talk through your requirements?

Talk to a Specialist

LET US SCOPE YOUR GDPR-READY DEPLOYMENT

Tell us about your data residency and processing requirements, and we will walk through which deployment model and controls fit your program.

TALK TO A SPECIALIST
Contact us