GDPR-compliant AI sales tools: what to actually check before you buy.
An eight-point checklist for EU sales teams. Data residency, AI training, sub-processors, signed URLs, and the DPA you need to ask for.
The short answer
Why this checklist exists
AI sales tools can send personal data through storage, model, analytics, support, and communication providers. The marketing page rarely describes that full chain, so buyers need to map it before approving a use case.
The checks below are a procurement starting point, not legal advice or a substitute for a data-protection impact assessment where one is required.
Primary references: the European Commission on GDPR principles and the European Data Protection Board on international transfer safeguards.
The eight checks, in priority order
Run these against any AI sales tool before signing.
1. Where does the data physically sit?
Ask for the region of the database, file store, backups, logs, and any caching layer. Record international transfers and the mechanism used for each one. "Global" is not specific enough for a transfer assessment.
2. Which AI provider runs the inference?
Get the provider, product tier, processing region, retention terms, and training terms in writing. A provider name alone is not enough because products and contractual settings differ.
3. Is your data used for AI training?
Ask whether prompts, recordings, transcripts, and outputs are used for training or product improvement at every layer. Make sure the contract matches the technical setting.
4. Is there a GDPR Article 28 DPA on the website?
Where the vendor acts as a processor, review the Article 28 terms before production use. A public DPA is convenient, but availability by request is not itself evidence of weak compliance.
5. What is the sub-processor list?
You want a public, dated list. Each entry should name the service, the purpose, and the region. A typical AI sales tool can include a database, object store, model provider, email sender, analytics, and support tools. The relevant question is what each provider receives and why, not the raw count.
6. How is recorded media accessed?
Ask whether media is private, how playback is authorised, how links expire, and what appears in logs or caches. The suitable expiry depends on the workflow and threat model.
7. Does the receiver need an account?
Check whether account creation is necessary for the stated purpose. Avoid collecting identity data that the workflow does not need, but do not assume accountless collection contains no personal data.
8. How fast can you delete a record?
GDPR Article 17 gives data subjects a right to erasure. The tool should support deletion across the response, audio, transcript, derived summary, backups, and relevant processors according to its documented process.
Apply the checklist to HeySpeak
Use the current data-protection page and contractual documents for the live answers. Product architecture and subprocessors can change, so this guide should not be treated as the system of record.
- Confirm the current database, object-storage, backup, and log regions.
- Confirm the transcription and summarisation providers, product tiers, regions, retention, and training terms.
- Review the DPA and complete subprocessor list before production use.
- Verify how media playback, response access, retention, and deletion work.
- Remember that an accountless response can still contain personal data in the recording, transcript, metadata, or written reply.
Your organisation remains responsible for the purpose, lawful basis, respondent information, access policy, and retention choice. Ask a qualified privacy professional when the use case is sensitive or the transfer analysis is unclear.
Three patterns that look fine and are not
First, "EU data center" without naming the provider. Many tools proxy through a US service for AI inference even if the database is in Frankfurt. Ask where the LLM call resolves, not just where the row is stored.
Second, training terms that depend on an undocumented setting. Check the contract, the vendor setting, and the model provider's terms for the exact product tier.
Third, playback protected only by an unguessable URL. Ask how access is authorised, how links expire, and whether media can appear in caches or logs.
Keep going
Two related pages on running customer conversations without the meeting and without the privacy headache.
Common questions
What makes an AI sales tool GDPR-compliant in practice?
Is a US-based AI tool ever GDPR-compliant if it has Standard Contractual Clauses?
Why does AI training on customer data matter for sales tools?
What should I ask about sub-processors before signing?
How long should recordings or transcripts be retained?
Do receivers of an AI sales tool need to consent?
Where does HeySpeak fit in this checklist?
Review the data flow before you collect.
No receiver account is required. Five free responses to start, no credit card.
Create your first link