Security & data residency

The Europe checklist.

Questions worth asking any chat-widget vendor, answered one by one: what runs where, who the sub-processors are, and where we’re upfront about limits.

Chat & your knowledge base: EU-hosted

Text conversations and retrieval over your pages/knowledge base run on European infrastructure with European models (Mistral). Your brand knowledge is tenant-isolated and never trains a shared model.

Voice: EU by default

Speech runs on European infrastructure by default (Mistral, EU). Other voice options are available only if you switch them on yourself, behind an explicit consent gate. Nothing leaves the EU unless you enable it.

Sub-processors

Mistral (EU) for language, embeddings and voice; EU hosting (Hetzner, Germany). The current list and the DPA are available on request and at /dpa.

Roles & GDPR rights

You are the data controller; OpenAlice is your processor under a signed DPA. Visitors can be exported or erased on request, and the widget shows an AI disclosure + consent before any voice capture.

Retention & memory

Conversation retention is configurable per widget: off, session, or persistent with a 7/30/90/365-day window (or forever). Visitor memory is opt-in and scoped to your tenant.

Visitor consent & transparency

Before voice, the widget asks for consent and discloses that Lily is an AI representing the brand, not a human. See our AI disclosure and Privacy policy.

Questions a reviewer needs answered? security@openalicelabs.eu · ← back to the overview