AI Chatbot Compliance, Without the Vaporware Badges
Trusted by compliance-conscious teams in the EU
17,000+
Businesses use Boei
EU/EEA
Primary hosting (Hetzner, Nuremberg)
Free
DPA on every paid plan
30 days
Advance notice on subprocessor changes
Compliance is a buying signal, not a marketing badge
Most chatbot vendors bury their DPA behind an enterprise sales call, hide their subprocessor list, and slap a HIPAA logo on the homepage without signing a Business Associate Agreement. That may look reassuring, but it fails the first procurement review at any regulated buyer.
Boei takes the opposite approach: everything on this page is verifiable in one click, our DPA is free on every paid plan, and where we cannot honestly claim a certification (HIPAA is the big one), we say so in plain English.
The rest of this page walks through the five things procurement and privacy teams actually ask about: GDPR, our Data Processing Agreement, subprocessors, EU data residency, and our honest HIPAA stance.
What Boei Compliance Actually Covers
One card per topic. Every claim links back to its source-of-truth page.
GDPR by Design
Free DPA on Every Plan
Public Subprocessor List
EU Data Residency
HIPAA: Honest Scope
Auditability
How Boei Handles EU Personal Data
Boei is a GDPR data processor for the personal data your visitors submit through the chatbot widget (name, email, phone, message content). You (the site owner) are the controller. We invest continuously in maintaining GDPR compliance and helping you comply with the framework you owe your users.
What GDPR compliance means at Boei
- Lawful basis: we process Controller Personal Data solely to deliver the Service you subscribed to. No behavioral profiling, no ad targeting, no reselling to data brokers.
- EU/EEA hosting: primary application, database, and backups run on Hetzner Online GmbH in Nuremberg, Germany. Backups live on a separate Hetzner Storage Box in the same region and are retained up to 60 days.
- Data-subject rights: your admin dashboard lets you export a visitor's data (Article 15), erase a conversation on request (Article 17), or bulk-export the whole account. Configurable retention windows keep old chats from lingering.
- Sub-processor governance: every third party that touches personal data is listed publicly on our subprocessors page, with 30-day advance notice on additions.
- International transfers: where a US subprocessor is used (typically because you enabled a US-based AI model like OpenAI or Anthropic), we rely on Standard Contractual Clauses (SCCs) plus your explicit configuration choice.
- Encryption: 256-bit AES TLS in transit; AES full-disk encryption at rest on every server holding user data. Static assets in AWS S3 use server-side encryption and HTTPS-only access.
Full detail is on the Security page.
Free DPA on Every Plan, Including Starter
Boei's Data Processing Agreement is a public, standalone document. You do not need to be on a specific tier, hit a seat threshold, or talk to sales to get one. The DPA is live at /data-processing-agreement/ and by using the Service under a paid subscription you are already covered by it.
If your procurement needs a countersigned copy
- Download the DPA PDF from the DPA page.
- Sign your part.
- Email [email protected] and we send back a countersigned copy, usually within one business day.
- Custom red-line requests are welcome on the Scale plan ($229/mo annual) which includes a custom DPA signed by our legal team as part of the tier.
The DPA references our subprocessors page as Annex 1, so any new subprocessor is automatically covered by the same agreement (with the 30-day advance-notice mechanism preserving your right to object).
Every Third Party That Touches Your Data
The authoritative list lives at /legal/subprocessors/ and is versioned via our legal changelog. Here is a snapshot as of 2026-04-17 grouped by purpose so you can see the scope at a glance:
Core infrastructure (EU/EEA)
- Hetzner Online GmbH (Nuremberg, Germany) - primary servers, database, backups.
- Weaviate B.V. (registered in Amsterdam, processing in Frankfurt) - vector database for chatbot knowledge base.
- Amazon Web Services EMEA SARL (EU-West, Ireland) - static asset storage (S3).
- Plausible Insights OU (Tallinn, Estonia; processed in Germany) - cookie-less analytics for boei.help only, not Controller data.
AI model providers (configurable per customer)
- Mistral AI, SAS (Paris, France) - EU-hosted LLM option.
- OpenAI, Inc. (USA) - opt-in, requires customer configuration.
- Anthropic, Inc. (USA) - opt-in, requires customer configuration.
- Google LLC (Gemini) (USA) - opt-in, requires customer configuration.
The AI model your chatbot actually uses depends on your account settings. EU-only setups can pin Mistral and never touch a US-region provider for LLM inference.
Operational (US, SCCs in place)
- Cloudflare, Inc. - CDN, DDoS protection, WAF for public boei.help + widget traffic (EU-first routing where available).
- Mailgun Technologies - transactional email (chat transcripts, notifications).
- Firecrawl (Mendable, Inc.) - website crawling when you point Boei at your public content for knowledge-base training.
- Stripe, Inc. - payment processing and subscription billing.
If a subprocessor changes we post it to /legal/subprocessors/ at least 30 days in advance and notify DPA-holding customers per the agreement.
Where Your Data Physically Lives
Boei production services run on Hetzner Online GmbH infrastructure in Nuremberg, Germany. All Controller personal data processed by the Service is stored inside the EU/EEA. Backups sit on a separate Hetzner Storage Box, also in Nuremberg, and are retained up to 60 days.
Hetzner's data centers are ISO/IEC 27001 certified and operate with 24/7 on-site staff, video surveillance, biometric and multi-factor access control, redundant power and cooling, and fire suppression.
Static assets served alongside the widget (images uploaded through the admin) sit in the EU-West (Ireland) region of AWS S3 via Amazon Web Services EMEA SARL, with server-side encryption enabled.
Public-facing traffic to boei.help, app.boei.help, and the widget is served through Cloudflare's global edge (EU-first routing where available). Cloudflare processes minimal metadata (IP for routing, TLS termination) - it does not persist Controller personal data.
For teams that need to point to a specific procurement checklist item: this configuration satisfies the standard EU/EEA data-residency requirement most European public-sector and healthcare procurement bodies apply.
Our Honest Position on HIPAA
Boei is not currently HIPAA-certified and does not sign Business Associate Agreements at standard tiers. Some competitor sites display a HIPAA badge without ever signing a BAA, which is misleading. We prefer to be direct.
What this means in practice
- Non-PHI use cases work fine: appointment booking, hours, cost, prep instructions, insurance FAQ, general triage FAQ. None of these require the chatbot to touch protected health information.
- Symptom triage flows always include a non-medical-advice disclaimer so visitors are not misled into treating the chatbot output as clinical guidance.
- PHI-touching workflows: if your chatbot needs to intake symptoms tied to identifiable patients or coordinate care, and you need a signed BAA, contact us before onboarding to discuss the Scale plan and our current compliance roadmap.
See /for/healthcare/ for the vertical write-up aimed at clinics evaluating Boei.
Compliance at a glance
Boei vs Typical US-Hosted Chatbot Vendors
The compliance-posture questions procurement actually asks.
Compliance FAQ
Is Boei GDPR compliant?
Where can I download Boei's Data Processing Agreement?
Who are Boei's subprocessors?
Can I run Boei with only EU-based AI models?
Is Boei HIPAA compliant?
Where does my data physically live?
How do you handle right-to-erasure requests?
Do you sign custom DPAs with red-line changes?
What certifications does Boei's hosting provider have?
Explore More
Security Page
Data Processing Agreement
Subprocessor List
European AI Chatbot
For Healthcare Clinics
Ready to talk to a chatbot vendor that shows its compliance work?
Start the 7-day free trial (no credit card) or send our compliance stance to your privacy team first.