Data Protection Information
Last updated: 19 August 2026
1. Roles of the parties
| Party | Role under the GDPR |
| The Customer | Data controller: decides what data is provided to their assistant and for what purpose |
| Us | Data processor (Article 28), on the terms set out in section 2 |
| Infrastructure and model providers | Sub-processors (section 7) |
The Customer determines what information is entered into their assistant. We do not access that content except to provide the service or to resolve an incident at the Customer's request.
2. Service plans and scope of processing
The scope of this information depends on the plan contracted.
| Personal Plan | Professional Plan | |
| Intended use | Personal use by the account holder | Professional or business use |
| Our role | Only controller of account data | Processor acting on the Customer's behalf |
| Data processing agreement (Art. 28) | Not included | Included |
| Model catalogue | Standard models | Full catalogue, including EU-hosted models |
Personal Plan
This plan is designed for the personal use of its holder. Under it we act only as data controller for account data, in accordance with our Privacy Policy, and no data processing agreement is entered into.
The content you process with your agent is solely your responsibility: in the Personal plan hablo is neither controller nor processor of that data.
If you are going to process third-party personal data — that of customers, employees, suppliers or users — in a professional context, you must contract the Professional Plan, which includes the Article 28 data processing agreement and the list of sub-processors.
Professional Plan
This is the plan intended for the processing of personal data on behalf of the Customer. On contracting it we accept the data processing agreement under Article 28, which includes the list of sub-processors in section 7 and access to the full model catalogue, including frontier models.
Rule applicable to the Professional Plan: where the processing involves personal data of residents of the European Union, models identified with the (EU) label must be selected, as set out in section 6.
3. What data is processed
Customer content: conversations with the assistant, files provided to it, the assistant's memory and the contents of its workspace.
Usage metadata, required to operate and bill the service: customer identifier, model used, number of tokens consumed, cost, latency, response code and timestamp.
Metadata does not include the content of conversations. Our logging system stores only the fields listed above; technical logs record at most the size of the request in bytes, never its text.
4. Where data is processed
All of the service's infrastructure is located in the European Union:
| Location | Country | Use |
| Helsinki | Finland | Assistant servers and core services |
| Nuremberg | Germany | Assistant server |
| Falkenstein | Germany | Immutable backup |
Hosting provider: Hetzner Online GmbH (Germany). The location of processing carried out by model providers depends on the model selected by the Customer, as set out in section 6.
5. Retention and erasure
| Data | Retention |
| Conversations, memory and assistant files | For as long as the assistant exists. Deleted when the assistant or the account is removed |
| Usage and billing metadata | In accordance with applicable tax and accounting obligations |
| Daily backups | Automatic rotation, maximum 56 days |
| Immutable ransomware-protection backup | Up to 7 days |
| Server snapshots | Maximum 30 days |
How to request erasure. At the Customer's request we delete the active data of their assistant. Backups do not allow selective deletion by design, since that immutability is precisely the protection against ransomware attacks; they do, however, expire automatically within the periods indicated, after which erasure is complete.
6. Language models and Customer selection
The Customer decides which models are loaded into their assistant. From their customer area they can enable or disable the models available on their plan.
European models are identified by the (EU) label in their name. The specific data protection regime of each provider can be consulted in the documentation each one publishes; references for the European providers are set out at the end of this page.
On the Professional Plan, where the task involves processing personal data of residents of the European Union, models with the (EU) label must be selected. For tasks that do not involve personal data — programming, technical analysis, research or content writing — the Customer may use any model in the catalogue.
6.1 European models
| Provider | Registered office | Processing | Commitments |
| Mistral AI SAS | Paris, France | European regional endpoint; data centres in the EU and the EEA | Data processing agreement; zero data retention and model training disabled at organisation level |
| Scaleway SAS (Iliad group) | Paris, France | Paris, France, with a contractual guarantee that data remains in Europe | Contractually: does not retain requests or responses after processing them, does not log them and does not use them to train models or to improve the service |
Mistral AI. We have zero data retention enabled for our organisation: inputs and outputs are not retained beyond the time needed to generate the response and the abuse-monitoring window does not apply to them. The option to use our API calls to train their models is likewise disabled, as are the experimental models in their Labs programme, which are the only ones that would fall outside that exclusion. We access only their text generation and embedding services.
Scaleway. Their specific artificial intelligence terms provide that they do not retain requests or generated content after processing them, and that customer data is not used to train or retrain the models, is not accessible to the model providers or to third-party services, and is not used to improve the service. Their published exceptions are: content of requests with errors or abuse for a maximum of two weeks, batch processing inputs for twenty-four hours, and anonymised usage metrics for a maximum of six months.
Account administration. With both providers, the administration of our account — access keys, billing and usage statistics — may be processed outside the region where the models run. That information belongs to us as a customer of the provider and contains no Customer content or personal data of their users.
6.2 Frontier models and other non-European models
The catalogue also includes the most capable models available on the market, provided by companies established outside the European Union, as well as experimental models with no data processing agreement. They are available on the Professional Plan for tasks that do not involve personal data: programming, technical analysis, research or content writing.
These models must not be used to process personal data of residents of the European Union. Their use means that the relevant provider acts as a sub-processor and may involve international data transfers.
7. Sub-processors
The full list of sub-processors, together with their function and the location of processing, is published in section 7 of our Privacy Policy. We will notify the Customer of any addition or change of sub-processor sufficiently in advance for them to object.
8. Security measures
- Encrypted communications with model providers using TLS.
- Per-customer isolation: each assistant runs in its own container with independent storage.
- Administrative access restricted by firewall and named access keys.
- Verified daily backups, with an independent immutable copy as protection against ransomware attacks.
- Audit log of configuration changes.
9. Data subject rights
As data processor we assist the Customer in handling the rights of access, rectification, erasure, restriction, portability and objection over the data held in their assistant. Data subject requests must be addressed to the Customer in their capacity as data controller; we act on their instructions.
10. Personal data breaches
We will notify the Customer without undue delay once we become aware of a security breach affecting their personal data, providing the information available so that they can comply with their obligations under Articles 33 and 34 of the GDPR.
11. Termination
On termination of the contract, and at the Customer's choice, we will delete or return the personal data processed, without prejudice to the automatic expiry of backups within the periods set out in section 5.
References for European providers
- Mistral AI, data processing addendum: legal.mistral.ai
- Mistral AI, trust centre: trust.mistral.ai
- Scaleway, contracts and specific AI terms: scaleway.com/en/contracts
- Scaleway, sub-processor list: scaleway.com/en/subprocessorlist