Skip to content
For Membership Associations (opens in a new tab)

CustomGPT.ai is GDPR compliant

Your data is safe with CustomGPT.ai. We’re GDPR compliant, with a signed Data Processing Agreement for every customer and a clear process for handling data access, correction, and deletion requests

CustomGPT.ai GDPR compliance badge, with Data access, Data correction and Data deletion

Benefits

Benefits for our customers

  • GDPR compliance

    Ensure adherence to strict data protection standards in the EU, and foster trust among your users by demonstrating firm commitment to safeguarding their personal information.

  • Secure data handling

    Rigorous measures to safeguard both your organization’s data and the information of your end-users.

  • Enhanced transparency

    Our Trust Center provides clear visibility into how we manage and protect data—yours and your users.

  • Commitment to security

    We are committed to continually evolve to safeguard your data and your users’ data, staying ahead of regulatory changes, and setting new benchmarks in privacy protection.

Integrations

Securely ingest data from 100+ website and document sources

Resources

Everything you need to know

Testimonials

Trusted by security leaders

Jonas Walther
Jonas Walther AI Process Manager, GEMA
“By using CustomGPT.ai, we can provide our members and customers with even more targeted support and significantly optimize our internal processes. We value the partnership-based cooperation and the high level of professionalism that CustomGPT.ai brings to every project.”

Questions about GDPR compliance

Is CustomGPT.ai GDPR compliant?

Yes, CustomGPT.ai is fully GDPR compliant. We prioritize the protection of user data, adhere to strict data security standards, and ensure transparency in how personal data is collected, processed, and stored. Our GDPR compliance is audited by INTERCERT CPA LLC, assessed June 28, 2026, report issued August 12, 2026.

What is GDPR, and why does it matter?

The General Data Protection Regulation (GDPR) is a data privacy law enacted by the European Union to protect individuals’ personal data. It gives users more control over how their information is collected, used, and stored.

  • GDPR applies to any organization processing the personal data of EU residents, regardless of where the organization is based.
  • Compliance is essential for legal adherence, but it also builds trust by demonstrating a strong commitment to user privacy and data security.
How does CustomGPT.ai protect user data?

We employ robust measures to ensure your data is secure:

  • Encryption protocols: SSL encryption for data in transit and 256-bit AES encryption for data at rest.
  • Data minimization: We only collect the information necessary to deliver and improve our services.
  • Strict security measures: Data is safeguarded against unauthorized access or leaks.
What happens in case of a data breach?

CustomGPT.ai has systems in place to detect data breaches quickly. If a breach occurs:

  1. We will promptly notify you and provide guidance on securing your data.
  2. Relevant authorities will be informed as required under GDPR.
How can I access, modify, or delete my personal data?

You can submit a Data Subject Request (DSR) to access, modify, or request the deletion of your personal data. Simply fill out our Privacy Request Form and we will respond as soon as possible.

What types of personal data does CustomGPT.ai process?

We collect and process:

  • User data: Email addresses, usage data, and communications during service use.
  • Tracking data: Cookies and activity data collected automatically for platform functionality and improvement.

Our processing is based on legal grounds such as user consent, contractual necessity, legal obligations, and legitimate interests like fraud prevention. For more details, please consult our Privacy Policy.

Does CustomGPT.ai use third-party processors?

Yes, we work with trusted GDPR-compliant third-party providers for essential services, such as:

  • Hosting: Amazon Web Services (AWS)
  • Payments: Stripe
  • Productivity: Google Workspace
  • Platform services: Automattic (WordPress.com, Gravatar)

Data shared with these processors is limited to what is necessary for delivering their services, and they follow strict security protocols.

How long does CustomGPT.ai retain user data?

CustomGPT.ai keeps your data until you decide what to do with it. You can use CustomGPT.ai’s capabilities to delete your documents immediately after processing. If you choose to keep the documents to benefit from features like citations and links, they’ll stay with CustomGPT.ai until you choose to remove them.

Does CustomGPT.ai support data residency within the EU?

No, CustomGPT.ai does not currently support data residency within the EU. Data residency in the EU is not a requirement for GDPR compliance.

Why is data residency not required for GDPR compliance?

GDPR compliance focuses on how personal data is handled, processed, and secured, regardless of where the data is physically stored. Data residency within the EU is not a strict requirement under GDPR.

What should I do if I need data residency within the EU?

If your organization requires data to be stored within the EU, you may need to find a local hosting provider (if one exists) or set up your own hosting solution. Please note that building your own solution can be a complex and time-consuming process.

If data residency is mandatory for your use case, consider exploring external hosting options or consulting with CustomGPT.ai support for potential workarounds or recommendations.

How can CustomGPT.ai assure customers of GDPR compliance without EU data residency?

CustomGPT.ai adheres to GDPR regulations by implementing robust data protection practices, securing personal data, and providing transparency in how data is processed and stored.

How do I contact CustomGPT.ai’s Data Protection Officer (DPO)?

For GDPR-related inquiries or data requests, please fill out our contact form and we will respond as soon as possible.

Will the confidential data I share with CustomGPT.ai be used to learn for other people?

No, the data you share with CustomGPT.ai remains private and is not used to teach or provide insight for others. We have stringent data handling practices in place to ensure your data’s security and confidentiality. In fact, the data from one bot within your account has no effect on other bots within even your own account. Each bot is its own data silo.

Does data use on CustomGPT.ai end up on OpenAI servers and contribute to ChatGPT’s learning?

No, any data you interact with on CustomGPT.ai is not used to enhance the learning of ChatGPT. It’s confined to your specific bot, ensuring your content remains local and private. For further information, you can review OpenAI’s data usage policies at: https://openai.com/policies/api-data-usage-policies

How does CustomGPT.ai handle data privacy? Is our business data safe?

CustomGPT.ai prioritizes data privacy. We ensure that your business data stays safe by storing it in isolated environments per bot and not using it for any other purposes, including model training. You can find more about our data privacy policies on our Security and Trust page

Does CustomGPT.ai have a Data Processing Agreement (DPA), and what data is automatically collected from the user?

Yes, CustomGPT.ai operates under a DPA. As for data collection, CustomGPT.ai collects minimal user data required for service operation and improvement, in compliance with privacy laws and regulations. Detailed information can be found in our privacy policy: https://www.iubenda.com/privacy-policy/45263214

Can I delete the files immediately after processing?

Yes – there is an option to immediately delete the original files after processing. This gives you added protection.

How can we be assured our business data will be protected and there are no data breaches?

We take data protection seriously at CustomGPT.ai. Our security measures include strong encryption, access controls, and a robust system architecture designed to prevent unauthorized access or data breaches. For an in-depth understanding of how we ensure data protection, please refer to our security principles on our Security and Trust page. We are committed to regularly updating and improving our security practices to protect your business data effectively.

Is CustomGPT.ai SOC 2 Compliant?

Yes. CustomGPT.ai is SOC 2 Type 2 compliant. See our SOC 2 Type 2 Certification page for the current audit period and auditor, or request the report via our Trust Center.

Is my data used to train AI models?

No. Your content isn’t shared with other CustomGPT.ai customers and isn’t used to train our models or OpenAI’s.

Ready to start using custom AI the smart and secure way?