Skip to main content
Guide

GDPR-compliant AI sales tools: what to actually check before you buy.

An eight-point checklist for EU sales teams. Data residency, AI training, sub-processors, signed URLs, and the DPA you need to ask for.

Try a privacy-first option
Practical checks, not a legal compliance promise

The short answer

GDPR fit depends on the purpose, lawful basis, data flow, contracts, security, retention, deletion, and any international transfers. EU hosting can simplify one part of the review, but it does not settle the whole question. Ask for evidence and involve your privacy or legal team.

Why this checklist exists

AI sales tools can send personal data through storage, model, analytics, support, and communication providers. The marketing page rarely describes that full chain, so buyers need to map it before approving a use case.

The checks below are a procurement starting point, not legal advice or a substitute for a data-protection impact assessment where one is required.

Primary references: the European Commission on GDPR principles and the European Data Protection Board on international transfer safeguards.

The eight checks, in priority order

Run these against any AI sales tool before signing.

1. Where does the data physically sit?

Ask for the region of the database, file store, backups, logs, and any caching layer. Record international transfers and the mechanism used for each one. "Global" is not specific enough for a transfer assessment.

2. Which AI provider runs the inference?

Get the provider, product tier, processing region, retention terms, and training terms in writing. A provider name alone is not enough because products and contractual settings differ.

3. Is your data used for AI training?

Ask whether prompts, recordings, transcripts, and outputs are used for training or product improvement at every layer. Make sure the contract matches the technical setting.

4. Is there a GDPR Article 28 DPA on the website?

Where the vendor acts as a processor, review the Article 28 terms before production use. A public DPA is convenient, but availability by request is not itself evidence of weak compliance.

5. What is the sub-processor list?

You want a public, dated list. Each entry should name the service, the purpose, and the region. A typical AI sales tool can include a database, object store, model provider, email sender, analytics, and support tools. The relevant question is what each provider receives and why, not the raw count.

6. How is recorded media accessed?

Ask whether media is private, how playback is authorised, how links expire, and what appears in logs or caches. The suitable expiry depends on the workflow and threat model.

7. Does the receiver need an account?

Check whether account creation is necessary for the stated purpose. Avoid collecting identity data that the workflow does not need, but do not assume accountless collection contains no personal data.

8. How fast can you delete a record?

GDPR Article 17 gives data subjects a right to erasure. The tool should support deletion across the response, audio, transcript, derived summary, backups, and relevant processors according to its documented process.

Apply the checklist to HeySpeak

Use the current data-protection page and contractual documents for the live answers. Product architecture and subprocessors can change, so this guide should not be treated as the system of record.

  • Confirm the current database, object-storage, backup, and log regions.
  • Confirm the transcription and summarisation providers, product tiers, regions, retention, and training terms.
  • Review the DPA and complete subprocessor list before production use.
  • Verify how media playback, response access, retention, and deletion work.
  • Remember that an accountless response can still contain personal data in the recording, transcript, metadata, or written reply.

Your organisation remains responsible for the purpose, lawful basis, respondent information, access policy, and retention choice. Ask a qualified privacy professional when the use case is sensitive or the transfer analysis is unclear.

Three patterns that look fine and are not

First, "EU data center" without naming the provider. Many tools proxy through a US service for AI inference even if the database is in Frankfurt. Ask where the LLM call resolves, not just where the row is stored.

Second, training terms that depend on an undocumented setting. Check the contract, the vendor setting, and the model provider's terms for the exact product tier.

Third, playback protected only by an unguessable URL. Ask how access is authorised, how links expire, and whether media can appear in caches or logs.

Common questions

What makes an AI sales tool GDPR-compliant in practice?
No single feature makes a tool GDPR-compliant. Your organisation needs a lawful basis and a defined purpose, while the vendor needs appropriate processor terms, security, retention, deletion, subprocessor transparency, and lawful transfer safeguards where relevant. Evaluate the actual use case and data flow with your privacy or legal team.
Is a US-based AI tool ever GDPR-compliant if it has Standard Contractual Clauses?
It can be. Standard Contractual Clauses are one recognised transfer mechanism, but the exporter must assess the transfer and whether supplementary measures are needed. EU-only infrastructure can simplify that review, but it is not the same as automatic GDPR compliance.
Why does AI training on customer data matter for sales tools?
Sales conversations can contain confidential and personal information. Ask whether recordings, transcripts, prompts, or outputs are retained or used to improve models, and make sure the answer is covered by the contract and every relevant subprocessor term.
What should I ask about sub-processors before signing?
Ask for the current list, each provider's purpose, the data it receives, its processing region, and the transfer mechanism where applicable. Review database, storage, AI, email, analytics, support, and payment providers separately because they do not all receive the same data.
How long should recordings or transcripts be retained?
Keep personal data only as long as the stated purpose requires. Set a retention period for audio, transcripts, and summaries, document why it is needed, and verify that deletion covers copies held by relevant processors. There is no universal number of days that fits every sales workflow.
Do receivers of an AI sales tool need to consent?
They need clear information about who controls the data, the purpose, recipients, retention, and their rights. Consent is one possible lawful basis, not the only one. If you rely on consent, it must meet the GDPR conditions and be freely given, specific, informed, and withdrawable.
Where does HeySpeak fit in this checklist?
Use HeySpeak's current data-protection page and contractual documents as the source for subprocessors, regions, retention, access, and deletion. A receiver does not need a HeySpeak account, but the recording and its contents can still be personal data. Your own collection purpose and notice remain your responsibility.

Review the data flow before you collect.

No receiver account is required. Five free responses to start, no credit card.

Create your first link