GDPR Compliance Statement
Last updated: 1 May 2026
engagelayer.io is built around European data privacy principles. Here is how we support your GDPR obligations.
1. Lawful basis
You determine the lawful basis for processing your visitors' data — typically legitimate interest (qualifying inbound enquiries) or consent (explicit opt-in to receive sales contact). We provide consent collection tools you can configure.
2. Data minimization
The assistant asks for the minimum information needed: name, work email, company. Optional fields (phone, country, message) are off by default. You can disable any field you don't need.
3. Purpose limitation
Visitor data is used only for the conversation, the lead summary, and routing to your configured sales tool. We do not use it for marketing, model training, or any other purpose.
4. Transparency
The assistant displays a privacy notice you configure, explaining who receives the data and for what purpose. Visitors must explicitly consent before any contact details are saved.
5. Right to be forgotten
Visitors can request deletion of their conversation and contact data via the email address you provide. We process those requests within 30 days, with a 14-day standard target.
6. Data portability
You can export all your data — conversations, leads, content — as CSV or JSON, anytime, from your admin panel.
7. EU hosting
Default storage is in EU data centres (Frankfurt). Backups are also in the EU.
8. Sub-processors
Stripe (billing), AWS/OVH (hosting), and the managed AI provider that powers the assistant — each tenant’s conversations are processed in isolation, never in a shared pool. Full list on request.
9. Records of processing
We maintain Article 30 records of processing activities. We provide our portion to you on request to support your own Article 30 obligations.
10. Designated representative
We have a designated EU representative and a Data Protection Officer (DPO). Contact: dpo@engagelayer.io.
The English version of these documents is the legally authoritative reference.