Security and data

Last updated: 26 July 2026

Where your data lives, what we encrypt, who we share it with, and what we never do. Written as it is — including the parts where the answer is not entirely tidy.

Who is who, legally

When you put the assistant on your website, you are the data controller for your visitors' information. We are the data processor and handle it only to deliver the service to you. That means we need a data processing agreement between us. It applies from the first customer — including on the free plan, because the requirement follows from personal data being processed, not from whether anyone pays. Write to hello@jyskhub.dk and we will send it.

Where the data lives

JyskHub is designed with European data protection requirements in mind. Primary service data is hosted on European infrastructure where possible. Managed AI defaults to Mistral AI. Customers may choose their own AI provider, which can process data in another region. CDN, email, push, messaging and integrations may process limited technical data outside the EU/EEA under appropriate safeguards. Firebase push contains only a neutral notice without a name or message text. A visitor's country is determined locally using a DB-IP Lite database. The IP address is not sent to DB-IP or an external geolocation API. JyskHub periodically downloads an updated database file containing IP allocation data.

What we encrypt

Passwords are stored as salted bcrypt hashes. We cannot read them, and we cannot send you your old password — only a link to choose a new one. If you use your own API key for an AI provider, it is encrypted at rest with AES-256-GCM and never shown in clear text again, not even to us. All traffic runs over HTTPS. Widget access requires a token that only works on the domains you have approved.

What we never do

We do not use your conversations to train AI models. We do not sell data on and do not use it for advertising. We do not use your data to improve other customers' assistants. Every workspace is separated, and the assistant answers only from the knowledge you put in yourself.

How long we keep things

Visit events are deleted automatically after 30 days. The warning and error log is deleted after 30 days. The administrative audit log is kept for 90 days. Conversations, messages and leads have a default retention period of 12 months after the latest activity. A workspace administrator can choose another period, export data, preview which records have expired and then confirm deletion. Individual conversations can also be deleted from the inbox.

Who we share with

Only the providers needed to deliver the service: hosting, the managed or customer-selected AI provider, Resend (email), GatewayAPI (SMS, if you switch it on), Telegram (if you connect it) and Google Firebase (neutral push to the mobile app). DB-IP supplies the database file used locally for country lookup; visitor IP addresses are not sent to DB-IP. The full list with purpose and location is in the appendix to the data processing agreement.

The EU AI Act

Article 50 AI transparency obligations generally apply from 2 August 2026. JyskHub designs the widget so visitors are informed about the AI interaction; customers must not hide that notice and must still assess their specific role and visitor information. The assistant always identifies itself as an AI — including when you give it a human name, and including after a human has taken over. When one of you replies manually, it is clearly marked as coming from a human. This supports the transparency requirement, but each customer must still assess its specific use and visitor information. Special use cases require legal review.

Responsible AI and intended use

JyskHub is intended for customer support and lead handling. It is not intended for legal or medical assessments or decisions about employment, credit, education admission, law enforcement or other high-risk purposes without a separate assessment. Owners and staff who configure or use the assistant should understand its limitations, verify important answers and know when a person must take over.

If something goes wrong

If we discover a personal data breach, we notify you without undue delay and with the information you need to report it to the Danish Data Protection Agency within 72 hours. Write to hello@jyskhub.dk if you spot something, or if you want data exported or deleted.
<- Back to the homepage