CustomGPT.ai is GDPR compliant
Your data is safe with CustomGPT.ai. We’re GDPR compliant, with a signed Data Processing Agreement for every customer and a clear process for handling data access, correction, and deletion requests
Benefits
Benefits for our customers
-
GDPR compliance
Ensure adherence to strict data protection standards in the EU, and foster trust among your users by demonstrating firm commitment to safeguarding their personal information.
-
Secure data handling
Rigorous measures to safeguard both your organization’s data and the information of your end-users.
-
Enhanced transparency
Our Trust Center provides clear visibility into how we manage and protect data—yours and your users.
-
Commitment to security
We are committed to continually evolve to safeguard your data and your users’ data, staying ahead of regulatory changes, and setting new benchmarks in privacy protection.
Resources
Everything you need to know
-
What is GDPR?
A law governing data collection, processing, storage, and use.
-
SOC 2 Type 2
In addition to being GDPR compliant, we are also SOC 2 Type 2 compliant. See our SOC 2 Type 2 Certification page for the current audit period and auditor, or request the report via our Trust Center.
Testimonials
Trusted by security leaders
Questions about GDPR compliance
Is CustomGPT.ai GDPR compliant?
Yes, CustomGPT.ai is fully GDPR compliant. We prioritize the protection of user data, adhere to strict data security standards, and ensure transparency in how personal data is collected, processed, and stored. Our GDPR compliance is audited by INTERCERT CPA LLC, assessed June 28, 2026, report issued August 12, 2026.
What is GDPR, and why does it matter?
The General Data Protection Regulation (GDPR) is a data privacy law enacted by the European Union to protect individuals’ personal data. It gives users more control over how their information is collected, used, and stored.
- GDPR applies to any organization processing the personal data of EU residents, regardless of where the organization is based.
- Compliance is essential for legal adherence, but it also builds trust by demonstrating a strong commitment to user privacy and data security.
How does CustomGPT.ai ensure user consent for data collection?
From the moment you interact with CustomGPT.ai, we seek your explicit consent for data collection. We provide clear and straightforward information about what data is collected and why, ensuring you can make fully informed decisions.
How does CustomGPT.ai protect user data?
We employ robust measures to ensure your data is secure:
- Encryption protocols: SSL encryption for data in transit and 256-bit AES encryption for data at rest.
- Data minimization: We only collect the information necessary to deliver and improve our services.
- Strict security measures: Data is safeguarded against unauthorized access or leaks.
What happens in case of a data breach?
CustomGPT.ai has systems in place to detect data breaches quickly. If a breach occurs:
- We will promptly notify you and provide guidance on securing your data.
- Relevant authorities will be informed as required under GDPR.
How can I access, modify, or delete my personal data?
You can submit a Data Subject Request (DSR) to access, modify, or request the deletion of your personal data. Simply fill out our Privacy Request Form and we will respond as soon as possible.
What types of personal data does CustomGPT.ai process?
We collect and process:
- User data: Email addresses, usage data, and communications during service use.
- Tracking data: Cookies and activity data collected automatically for platform functionality and improvement.
Our processing is based on legal grounds such as user consent, contractual necessity, legal obligations, and legitimate interests like fraud prevention. For more details, please consult our Privacy Policy.
Does CustomGPT.ai use third-party processors?
Yes, we work with trusted GDPR-compliant third-party providers for essential services, such as:
- Hosting: Amazon Web Services (AWS)
- Payments: Stripe
- Productivity: Google Workspace
- Platform services: Automattic (WordPress.com, Gravatar)
Data shared with these processors is limited to what is necessary for delivering their services, and they follow strict security protocols.
How long does CustomGPT.ai retain user data?
CustomGPT.ai keeps your data until you decide what to do with it. You can use CustomGPT.ai’s capabilities to delete your documents immediately after processing. If you choose to keep the documents to benefit from features like citations and links, they’ll stay with CustomGPT.ai until you choose to remove them.
What is CustomGPT.ai’s Cookie Policy?
We use cookies and similar tracking technologies to enhance user experience and provide essential services. These include:
- First-party cookies: Managed by us.
- Third-party cookies: Used by providers like Stripe and Google Tag Manager.
Users can manage cookie preferences through the platform’s privacy settings or browser settings. Disabling cookies may impact platform functionality. For more details, consult our Cookie Policy.
Does CustomGPT.ai support data residency within the EU?
No, CustomGPT.ai does not currently support data residency within the EU. Data residency in the EU is not a requirement for GDPR compliance.
Why is data residency not required for GDPR compliance?
GDPR compliance focuses on how personal data is handled, processed, and secured, regardless of where the data is physically stored. Data residency within the EU is not a strict requirement under GDPR.
What should I do if I need data residency within the EU?
If your organization requires data to be stored within the EU, you may need to find a local hosting provider (if one exists) or set up your own hosting solution. Please note that building your own solution can be a complex and time-consuming process.
If data residency is mandatory for your use case, consider exploring external hosting options or consulting with CustomGPT.ai support for potential workarounds or recommendations.
How can CustomGPT.ai assure customers of GDPR compliance without EU data residency?
CustomGPT.ai adheres to GDPR regulations by implementing robust data protection practices, securing personal data, and providing transparency in how data is processed and stored.
How do I contact CustomGPT.ai’s Data Protection Officer (DPO)?
For GDPR-related inquiries or data requests, please fill out our contact form and we will respond as soon as possible.
Does data use on CustomGPT.ai end up on OpenAI servers and contribute to ChatGPT’s learning?
No, any data you interact with on CustomGPT.ai is not used to enhance the learning of ChatGPT. It’s confined to your specific bot, ensuring your content remains local and private. For further information, you can review OpenAI’s data usage policies at: https://openai.com/policies/api-data-usage-policies
How does CustomGPT.ai handle data privacy? Is our business data safe?
CustomGPT.ai prioritizes data privacy. We ensure that your business data stays safe by storing it in isolated environments per bot and not using it for any other purposes, including model training. You can find more about our data privacy policies on our Security and Trust page
Does CustomGPT.ai have a Data Processing Agreement (DPA), and what data is automatically collected from the user?
Yes, CustomGPT.ai operates under a DPA. As for data collection, CustomGPT.ai collects minimal user data required for service operation and improvement, in compliance with privacy laws and regulations. Detailed information can be found in our privacy policy: https://www.iubenda.com/privacy-policy/45263214
Can I delete the files immediately after processing?
Yes – there is an option to immediately delete the original files after processing. This gives you added protection.
How can we be assured our business data will be protected and there are no data breaches?
We take data protection seriously at CustomGPT.ai. Our security measures include strong encryption, access controls, and a robust system architecture designed to prevent unauthorized access or data breaches. For an in-depth understanding of how we ensure data protection, please refer to our security principles on our Security and Trust page. We are committed to regularly updating and improving our security practices to protect your business data effectively.
Is CustomGPT.ai SOC 2 Compliant?
Yes. CustomGPT.ai is SOC 2 Type 2 compliant. See our SOC 2 Type 2 Certification page for the current audit period and auditor, or request the report via our Trust Center.
Is my data used to train AI models?
No. Your content isn’t shared with other CustomGPT.ai customers and isn’t used to train our models or OpenAI’s.