Privacy Policy
Last updated: 21 September 2026
This policy explains how suppp handles personal data. We are based in the Netherlands and follow the EU General Data Protection Regulation (GDPR / AVG). In short: your data is hosted in the EU, we only use it to run the service, we never sell it, and you can export or delete it at any time.
1. Who we are
Wurkspace Studios, trading as suppp, registered with the Dutch Chamber of Commerce (KvK) under number 42083570, established in the Netherlands. Privacy questions: hello@suppp.chat.
2. Two roles: controller and processor
- Controller — for data about our own customers and their team members: account details, billing, and how the service is used. This policy covers that data.
- Processor — for data our customers collect through suppp about their customers (chat visitors, email contacts, conversation content, attachments). We process it only on our customer's instructions under our Data Processing Agreement. If you chatted with or emailed a company that uses suppp, that company is responsible for your data — please contact them first; we will help them handle your request.
3. What we collect and why
- Account data (name, email, profile photo, workspace name, role) — to create and secure your account and provide the service. Legal basis: contract (art. 6(1)(b) GDPR).
- Billing data (billing contact, invoices, subscription status; card details are handled only by Stripe) — to charge for paid plans and meet Dutch tax law. Legal basis: contract and legal obligation (art. 6(1)(b) and (c)).
- Service data (conversations, contacts, attachments, settings) — stored and processed to deliver the service on behalf of our customers (see section 2).
- Security and technical data (IP address, browser, request logs, sign-in events) — to keep the service secure, prevent abuse and fix errors. Legal basis: legitimate interest (art. 6(1)(f)).
- Website analytics — cookieless, aggregated page-view statistics (Vercel Web Analytics) to improve our website. No cookies, no cross-site tracking, no advertising profiles. Legal basis: legitimate interest.
- Transactional email — sign-in links, invitations and notifications you need to use the service. We only send marketing email if you opted in, and every such email has an unsubscribe link.
We do not sell personal data and do not use it for advertising.
4. AI features
AI summaries and suggested replies are off by default and only run when a workspace admin turns them on. When an agent analyses a conversation, its last 20 messages and the customer's name and email are sent to Anthropic (USA) to generate the result. Anthropic does not use this data to train its models. AI-suggested replies are never sent to customers without a person reviewing them.
5. Google and Microsoft inbox data
When a workspace connects a Gmail or Outlook inbox, suppp reads the messages in that inbox to show them in the shared support inbox, and sends the replies agents write from it. For Gmail we request only read and send access. Inbox data is used solely to provide these user-facing features: it is never sold, never used for advertising, never used to train AI models, and never read by people at suppp except with the workspace's permission for support, for security purposes, or where the law requires it. Disconnecting an inbox revokes our access immediately.
suppp's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Where your data is stored
Our database, file storage and application servers run in the EU (Frankfurt, Germany). Some of our providers are based in the USA; transfers to them are protected by the EU-US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses. The full list is on our subprocessors page.
7. How long we keep data
- Account data — while your account exists. Deleting your account removes it right away.
- Workspace data — until the workspace deletes it, an optional automatic retention period set by the workspace admin removes it, or the workspace is deleted (which deletes all its conversations, contacts and files immediately and disconnects linked inboxes).
- Chat widget sessions — expire after 30 days and are then deleted.
- Invoices and billing records — 7 years, as required by Dutch tax law.
- Backups and logs — encrypted database backups and server logs roll over automatically and are kept for at most 30 days.
8. How we protect data
Encryption in transit (TLS) and at rest, extra application-level encryption of email-account access tokens, strict per-workspace data isolation in the database, EU hosting, optional two-factor authentication, least-privilege access for our own staff, and a documented data-breach procedure. More on our security page.
9. Cookies
We only use strictly necessary cookies to keep you signed in and secure your session. The suppp chat widget stores a session token in the visitor's browser only after they open the chat, so their conversation continues across pages. No tracking or advertising cookies are used, so no cookie banner is needed for suppp.
10. Your rights
You have the right to access, correct, delete, restrict or port your personal data, and to object to processing based on legitimate interest. Most of this you can do yourself in the app (profile settings, account deletion, data export). Otherwise email hello@suppp.chat — we respond within one month.
You can also file a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens.
11. Changes
We'll announce material changes to this policy by email or in the product at least 30 days before they take effect.