When you run customer conversations through Smartsupp, you're trusting us with your visitors' data — so here is a plain overview of how we protect it. Everything on this page comes from our public legal documents, the Privacy Policy and the Data Processing Agreement (DPA), where each measure is described in full detail.
We've split this article into a few sections:
Encryption & infrastructure
All data transmission is encrypted using SSL/TLS, and the platform only allows secure channels and protocols for inbound network connections.
Physical and online access to the servers hosting personal data is restricted.
Our staff are prohibited from downloading or processing personal data locally on their workstations or any other network location.
We regularly test, assess, and evaluate the effectiveness of the technical and organizational security measures in place.
Where your data is stored
Your data is stored primarily in the EU. Some data is also stored in the US and other countries, where we ensure that our processors maintain a similar level of data security as in the EU.
Sub-processors (such as server hosting providers) are carefully selected with regard to their guarantees of security and data protection.
📋 The full, up-to-date list is in the List of Sub-processors.
Backups
We maintain established backup processes, mechanisms, and tools. The restoration procedure, data readability, and integrity of backups are periodically tested — a backup only counts if it can actually be restored.
Security controls you can configure
Beyond what we do on our side, you can tighten security for your own account under Settings → Security and privacy:
Allowed domains — restrict which websites may load your chat widget.
IP blocking — block unwanted visitors from the chat.
Cookie consent — let the widget respect your cookie banner before storing anything beyond the necessary.
IP address storage is off by default — when you create your account, Smartsupp turns off the storage of visitors' IP addresses and some other sensitive data.
GDPR, DPA & audits
Smartsupp is GDPR compliant, and a Data Processing Agreement (DPA) is concluded with every customer as part of the service.
Incident notification — if we discover a personal data breach, we report it to you without undue delay, no later than 48 hours after becoming aware of it.
Data deletion — after your contract ends, personal data stored for the service is deleted within 3 months (you can request a data return within that period).
Audit rights — as a customer you can audit the documentation and processes related to your use of the service, under the conditions described in the DPA.
💼 Filling in a security questionnaire or planning an audit? The DPA describes the exact scope and process — and our support team is happy to help with specific questions.
What's next?
DPA (Data Processing Terms) — the complete technical and organizational measures.
Privacy Policy — what we process, why, and for how long.
List of Sub-processors — who helps us run the service.
Cookie consent — how the widget handles cookies on your site.
💡 Need more help? Contact our support team — we're happy to assist!
