Skip to content

Compliance

GDPR compliance

How we meet our obligations under the EU and UK General Data Protection Regulation.

Last updated January 15, 2026

Our GDPR commitment

Bhogar is committed to compliance with the EU General Data Protection Regulation (Regulation 2016/679) and the UK GDPR. This page explains how we meet our obligations as both a data controller (for our marketing site) and a data processor (for customer data inside the platform).

Controller vs processor

We are the controller
For data we collect on bhogar.ai (marketing site analytics, sign-ups, support tickets, billing).
We are the processor
For data you and your end-users upload to your tenant - agent configurations, knowledge bases, conversation logs, evaluations, traces. You remain the controller.
Data Processing Agreement
Customers on Business and Enterprise plans may execute our standard Data Processing Agreement, which incorporates the latest EU Standard Contractual Clauses (2021/914) for international transfers.

Your rights as a data subject

Access
Request a copy of personal data we hold about you, in a portable JSON format.
Rectification
Correct inaccurate or incomplete personal data through the Profile settings page.
Erasure ("Right to be Forgotten")
Request deletion of your account and associated personal data, subject to retention required by law.
Restriction
Limit how we process your data while a complaint or correction is being investigated.
Portability
Export your data in a machine-readable format for transfer to another service.
Objection
Object to processing based on legitimate interests, including direct marketing.
Withdraw consent
Withdraw consent at any time without affecting the lawfulness of prior processing.
Complaint
Lodge a complaint with your local supervisory authority.

Lawful basis for processing

Contract
Necessary to deliver the platform services you subscribed to (Article 6(1)(b)).
Legitimate interests
Security monitoring, fraud prevention, service improvement, and aggregated analytics (Article 6(1)(f)).
Consent
Marketing emails, non-essential cookies, and optional product analytics (Article 6(1)(a)).
Legal obligation
Tax records, anti-money-laundering checks, lawful requests from authorities (Article 6(1)(c)).

International data transfers

EU hosting available
Enterprise customers can elect EU-only hosting (eu-west-1 / westeurope). Data and backups stay within the EEA.
Standard Contractual Clauses
For transfers outside the EEA we rely on the EU Commission's 2021/914 SCCs, plus supplementary measures (encryption, access controls, transparency reports).
Transfer impact assessments
We perform TIAs for each new sub-processor and re-evaluate annually. TIA summaries available on request for Enterprise customers.

Sub-processors

We use a small set of vetted sub-processors for hosting, observability, and email. The current list is published in your DPA and updated 30 days in advance of any addition. Customers may object to new sub-processors during that window.

Hosting (default)
AWS (us-east-1, eu-west-1) and Microsoft Azure (eastus2, westeurope, eastasia).
Email
Amazon SES for transactional email; SendGrid for marketing only.
Error tracking
Sentry, processed inside the customer's region.
Customer support
Front (helpdesk), processed in the EU.

Security and breach notification

Encryption
TLS 1.2+ in transit; AES-256 at rest. Per-tenant KMS keys available on Enterprise.
Access controls
Least-privilege RBAC, mandatory MFA for all employees, just-in-time access for production.
Breach notification
In the event of a personal data breach, we notify affected controllers without undue delay and within 72 hours of discovery.

Contact our data protection officer

Email privacy@bhogar.ai with any GDPR-related question, data subject request, or to receive our EU representative details. We respond within 30 days, as required by Article 12(3).

Questions for your security review?

Most GDPR answers are already in our Privacy Policy and DPA. Send us your questionnaire and we will fill in the rest.