Security · GDPR
Committed to GDPR, 100% strict
Ultimo Bots treats GDPR as a design principle, not a checkbox. Our controls, contracts, and infrastructure are built for European privacy expectations.
Controller / Processor Commitments
How we handle data processing and privacy responsibilities.
Clear Lawful Basis
We operate as a processor under Art. 28 GDPR. Customers remain controllers of their data, and our Data Processing Agreement reflects that.
Data Minimization
Ultimo ingests only the content you upload or connect. Telemetry is pseudonymized, and retention policies default to the bare minimum.
Privacy by Design
Every new feature undergoes GDPR impact review, ensuring roles, retention, and transparency are baked in from day one.
EU Hosting & Transfers
All EU customers can pin workloads to EU data centers. When transfers occur, we use SCCs plus supplementary measures.
Data Subject Rights
Workflows that support individual privacy rights under GDPR.
Right of Access & Portability
Admins can export bot content, leads, and chat history per workspace. JSON/CSV outputs include metadata for regulators.
Right to Rectification
Knowledge base entries, behaviors, and leads can be updated or deleted instantly, changes propagate across all bots.
Right to be Forgotten
Ultimo deletes user content within 30 days of a request (often faster). Backups honor the same purge schedule.
Objection & Restriction
We provide controls to pause processing, disable analytics, or scrub conversations via retention policies.
Evidence & Transparency
How we demonstrate compliance and maintain transparency.
- Comprehensive audit logs show who accessed what, when, and from where-exportable for DPIAs.
- A dedicated Trust Portal shares DPA copies, SCCs, subprocessor list, and penetration-test summaries.
- Data breach notification SLA guarantees a maximum 24-hour initial update with remediation steps.
- We only work with subprocessors that uphold ISO 27001/SOC 2 or equivalent certifications.
Need a signed DPA?
Email privacy@ultimo-bots.com or use the in-app support widget. We respond with a countersigned DPA/SCC bundle within one business day.