Heyloha
Back to blog

Privacy in AI customer service: how you protect personal data and where your data lives

Using AI in your customer contact raises two questions: what happens to your customers' personal data, and where does your data live? Here is how Heyloha masks data before it leaves the platform, and why your data stays in Europe.

Author: Heyloha Team

Two questions every GDPR-conscious business owner asks

The moment you put an AI Agent to work on your customer contact, two questions land on the table. What happens to the personal data that customers share? And where does your data actually live, if the AI model comes from an American company?

These are fair questions. Without thinking twice, customers type their name, address, phone number and sometimes even their IBAN or national ID number into a chat. And the best-known AI models run at large American tech companies. In this article we explain how Heyloha handles that: personal data is masked before it leaves the platform, and your data stays in Europe.

The problem: customers share more than you think

In a conversation, a customer shares sensitive data before you know it. An address for a viewing, a phone number for a callback request, an IBAN when there is a payment question. That is part of good customer contact, but it does mean personal data is flowing through your system.

The reflex is then to not use AI for customer contact at all. That is not necessary. What matters is that this data does not end up in the wrong place, and that you know where it lives.

Personal data does not go to the AI model

Before a conversation goes to the AI model, Heyloha strips out the personal data and replaces it with placeholders. So the model sees a code instead of the real name, and simply carries on working with it. In the reply the customer gets back, the real data is put back in its place. So the model works with the codes, not the real data.

Among other things, we mask: names, email addresses, phone numbers, addresses, cities, postal codes, IBAN, national ID numbers, IP addresses and license plates.

Important: this happens automatically on your chat channels, so your web chat, WhatsApp, Instagram, LinkedIn and email. You do not need to set anything up and there is no button to turn it off.

Your data lives in Europe, in the Netherlands

The real data does not leave your European environment. Heyloha stores your data within the EU, at our hosting partner in the Netherlands. Your conversations, your knowledge base and the real personal data are on European servers and fall under the GDPR.

Because the personal data is already masked before a conversation leaves the platform, the only thing that goes to the AI model is an anonymized version of the conversation. The traceable data stays within your European environment.

So what does go to the AI model?

Only the text of the conversation, with placeholders in the spots where the personal data was. With that, the model composes a good answer, without knowing the real data.

On top of that, two more agreements apply. Your conversations are not used to train AI models. And the conversation data at the AI model is deleted after seven days. The processing falls under a data processing agreement.

Your archive stays yours

In your own Heyloha inbox, the conversations simply stay put, including the real data, so you can read them back and follow up. They live within your European environment. The masking applies to the trip to the AI model, not to your own archive.

What does this mean for the GDPR?

It comes down to this: your customers can share data with your agent without that data ending up at the AI model. If someone pastes an address or a national ID number into the chat unprompted, that gets masked too, because the masking happens on everything that comes in.

You also stay in control yourself. You set per brand what the agent may and may not say, and per channel which functions are active. A colleague can always take over a conversation manually.

A full explanation of exactly what we mask and how long we keep data is on our security page.

Privacy does not have to stand in the way of AI

You do not have to choose between good AI customer service and your customers' privacy. With masking of personal data and storage within the EU, you can have both.

Want to see how this works for your customer contact? Try Heyloha for free, no credit card needed.

Frequently asked questions

Where does our data live? On servers within the European Union, at our hosting partner in the Netherlands. The processing falls under the GDPR and we work with a data processing agreement.

Does OpenAI train on our conversations? No. Your conversations are not used to train models, and the personal data has already been replaced by placeholders before the conversation leaves the platform.

Does the masking also apply to phone calls? The masking of personal data works on your chat channels: web chat, WhatsApp, Instagram, LinkedIn and email. Voice on the phone channel works differently on a technical level and does not go through the same masking.

Can I turn off the masking? No. On your chat channels it is always on, so you never accidentally get it wrong.