Skip to content

Data Protection & Compliance

MyGPTAssistants is committed to protecting your data and maintaining compliance with international data protection regulations.

CertificationStatus
GDPR✅ Implemented
CCPA/CPRA✅ Implemented
SOC2 Type II🔄 In Progress (Q2 2025)
HIPAA🔄 Partial - BAA available (Q3 2025)

Understanding how data responsibilities are shared:

  • MyGPTAssistants: Acts as Data Processor - we process data on your behalf according to your instructions
  • Your Business: Acts as Data Controller - you determine how and why personal data is processed
  • Your Customers: Are Data Subjects - individuals whose data is being processed
CategoryData ElementsPurpose
Contact DataName, email, phone, timezoneCustomer communication
Conversation DataChat messages, bot responsesService delivery
Appointment DataBooking details, form responsesScheduling services
  • Usage Data: Pages visited, features used, bot interactions
  • Device Information: Browser type, operating system, IP address
  • Cookies: Session cookies, preference cookies

We process personal data under the following legal bases (GDPR Article 6):

Legal BasisUse Case
ConsentMarketing communications - explicit opt-in required
ContractService delivery - required for platform functionality
Legitimate InterestsFraud prevention, analytics, service improvement
Legal ObligationTax records, audit logs, regulatory compliance

You can request a complete export of all personal data we hold about you.

  • Request via our portal or by contacting support
  • We respond within 30 days
  • Export available in JSON or CSV format
  • Includes all related records (appointments, conversations, etc.)

You can correct any inaccurate personal data.

  • Update your profile directly in the platform
  • Contact support for assistance with corrections
  • All modifications are logged for compliance

You can request deletion of your personal data.

  • Submit an erasure request via our portal
  • Data is anonymized to preserve statistical integrity
  • Related records are also anonymized
  • You’ll receive an erasure certificate as proof

You can receive your data in a machine-readable format.

  • Export formats: JSON (complete) or CSV (spreadsheet-compatible)
  • Includes integrity checksum for verification
  • Secure download link with expiration

You can withdraw consent for specific processing activities at any time.

Consent types you can control:

  • Marketing emails
  • Marketing SMS
  • Analytics tracking
  • Data sharing with third parties
  • Profiling

We retain data only as long as necessary for the purposes described.

Data TypeRetention PeriodReason
Contact Information3 yearsLegitimate business interests
Conversation History2 yearsService improvement
Appointments2 yearsContractual records
Support Tickets5 yearsLegal compliance
Audit Logs7 yearsRegulatory requirements
  • Retention policies run automatically
  • Data past retention period is either anonymized or deleted
  • All retention actions are logged for compliance

In Transit:

  • TLS 1.3 enforced for all connections
  • HSTS (HTTP Strict Transport Security) enabled
  • Certificate pinning for mobile applications

At Rest:

  • Database encryption via cloud provider
  • Sensitive fields encrypted at application layer (AES-256-GCM)
  • API keys and tokens are never stored in plain text

We implement Role-Based Access Control (RBAC):

RoleAccess Level
OwnerFull access including billing and team management
AdminFull access except ownership transfer
MemberStandard CRM and bot access
ViewerRead-only access

All data access and modifications are logged:

  • Cryptographic hash chain prevents tampering
  • Logs retained for 7 years
  • Includes before/after values for all changes

Your data is logically isolated from other customers:

  • All queries are scoped to your team
  • No cross-tenant data access possible
  • Enforced at API and database layers

We do not sell your personal data.

We share data only with:

Third PartyPurposeSafeguards
Cloud InfrastructureHosting and storageData Processing Agreement (DPA)
AI Model ProvidersProcessing chat queriesData anonymized/aggregated
Payment ProcessorsBilling (business customers)PCI-DSS compliant

When using MyGPTAssistants to process your customers’ data, you are responsible for:

  1. Obtaining valid consent from your end users
  2. Providing privacy notices to your customers
  3. Responding to data subject requests (we provide tools to assist)
  4. Configuring appropriate retention policies

We provide a Data Processing Agreement (DPA) that includes:

  • Technical and organizational security measures
  • Assistance with Data Subject Access Requests
  • Data breach notification within 72 hours
  • Data deletion upon contract termination

Contact [email protected] to request a DPA.

  • DSAR Management: Track and respond to data subject requests
  • Consent API: Programmatic consent management
  • Retention Policies: Configure automatic data cleanup
  • Export Tools: Generate compliance-ready data exports

We use the following cookies:

CookieTypePurposeDuration
sessionEssentialAuthenticationSession
team_contextEssentialMulti-tenant routingSession
csrf_tokenEssentialSecurity protectionSession

Analytics cookies (if enabled) require explicit consent.


For data protection inquiries: