The Europe checklist.
Questions worth asking any chat-widget vendor, answered one by one: what runs where, who the sub-processors are, and where we’re upfront about limits.
Chat & your knowledge base: EU-hosted
Text conversations and retrieval over your pages/knowledge base run on European infrastructure with European models (Mistral). Your brand knowledge is tenant-isolated and never trains a shared model.
Voice: EU by default
Speech runs on European infrastructure by default (Mistral, EU). Other voice options are available only if you switch them on yourself, behind an explicit consent gate. Nothing leaves the EU unless you enable it.
Sub-processors
Mistral (EU) for language, embeddings and voice; EU hosting (Hetzner, Germany). The current list and the DPA are available on request and at /dpa.
Roles & GDPR rights
You are the data controller; OpenAlice is your processor under a signed DPA. Visitors can be exported or erased on request, and the widget shows an AI disclosure + consent before any voice capture.
Retention & memory
Conversation retention is configurable per widget: off, session, or persistent with a 7/30/90/365-day window (or forever). Visitor memory is opt-in and scoped to your tenant.
Visitor consent & transparency
Before voice, the widget asks for consent and discloses that Lily is an AI representing the brand, not a human. See our AI disclosure and Privacy policy.
Questions a reviewer needs answered? security@openalicelabs.eu · ← back to the overview