---
title: "Legal and Security FAQ | Quickchat AI - AI Agents"
description: "Answers to common questions about data privacy, security, compliance, and enterprise contracts."
source: https://quickchat.ai/legal-faq
---

# Legal and Security FAQ

Answers to common questions about data privacy, security, compliance, and enterprise contracts.

On this page

* [ Data Ownership & AI Training ](#section1)
* [ Third-Party AI Providers ](#section2)
* [ Infrastructure & Storage ](#section3)
* [ Privacy & Compliance ](#section4)
* [ Data Retention & Deletion ](#section5)
* [ Security Certifications ](#section6)
* [ Access Control ](#section7)
* [ Enterprise Contracts ](#section8)
* [ Deployment Options ](#section9)
* [ Incident Response ](#section10)
* [ AI Safety ](#section11)

### On this page

* [ Data Ownership & AI Training ](#section1)
* [ Third-Party AI Providers ](#section2)
* [ Infrastructure & Storage ](#section3)
* [ Privacy & Compliance ](#section4)
* [ Data Retention & Deletion ](#section5)
* [ Security Certifications ](#section6)
* [ Access Control ](#section7)
* [ Enterprise Contracts ](#section8)
* [ Deployment Options ](#section9)
* [ Incident Response ](#section10)
* [ AI Safety ](#section11)

## Data Ownership & AI Training

### Does Quickchat AI use customer data to train AI models?

No. Quickchat AI does not use customer knowledge base content, chat logs, or proprietary data to train any Large Language Models (LLMs). All customer content remains private and isolated per tenant and is never reused for model training.

### Who owns the uploaded data and knowledge base content?

Customers retain full ownership and intellectual property (IP) rights to all uploaded content, data, documents, and knowledge bases. Quickchat AI acts only as a data processor where applicable.

### Is customer data shared with other Quickchat AI customers?

No. Each customer environment is logically isolated. Data is never shared across tenants or made accessible to other customers.

## Third-Party AI Providers & Subprocessors

### Does Quickchat AI use third-party LLM providers such as OpenAI?

Yes. Quickchat AI may use third-party APIs (such as OpenAI, Anthropic, Gemini, Groq) strictly for inference and standard processing. Data sent to these providers is not used to train or improve their underlying models.

### Can enterprises avoid third-party LLMs entirely?

Yes. Enterprise customers can deploy self-hosted open-source LLMs (such as Llama, DeepSeek, gpt-oss or any open source model available on platforms such as Hugging Face) on their own cloud infrastructure for full data isolation and control. Typical infrastructure costs range from $5,000-$10,000/month depending on model size and compute requirements.

### Which third-party services are used for monitoring and analytics?

Quickchat AI uses: (i) Google Analytics - web analytics, (ii) Google Cloud Platform - cloud computing, (iii) Datadog - infrastructure monitoring and security telemetry, (iv) PostHog - product analytics, (v) HubSpot - customer relationship management. All subprocessors comply with enterprise security standards and contractual obligations.

## Infrastructure & Data Storage

### Where is customer data stored?

All customer data is securely stored on Google Cloud Platform (GCP) infrastructure located in Belgium, Europe. Knowledge bases are logically separated per customer and protected with enterprise-grade cloud security controls.

### Is customer data encrypted?

Yes. Data is encrypted: (i) in transit, using TLS encryption, and (ii) at rest, using cloud provider encryption standards. This applies to stored content, API communications, and internal services.

### Is customer data logically isolated?

Yes. Each customer environment is tenant-isolated to prevent cross-access and unauthorized exposure.

## Privacy & Regulatory Compliance

### Is Quickchat AI GDPR compliant?

Yes. Quickchat AI complies with GDPR requirements. Personal data handling, processing limitations, and data subject rights are governed by the Privacy Policy and Data Processing Agreement (DPA).

### Can we sign a Data Processing Agreement (DPA)?

Yes. A [DPA](https://quickchat.ai/dpa) is available and required when Quickchat AI may process personal data on behalf of customers - including theoretical access scenarios. Personal data processing is also governed by the [Privacy Policy](https://quickchat.ai/privacy), [GDPR Statement](https://quickchat.ai/gdpr) and the Data Security Policy (on request).

### How does Quickchat AI handle international data transfers?

Quickchat AI is actively aligning with the EU-US Data Privacy Framework (DPF) to simplify lawful cross-border data transfers.

### Does Quickchat AI store Personally Identifiable Information (PII)?

Quickchat AI only processes PII when explicitly provided by customers for business use cases. PII protection is governed by GDPR compliance policies and contractual safeguards. Conversations can be scrubbed of Personally Identifiable Information (PII) before any LLM processing on client's request.

## Data Retention & Deletion

### How long is customer data retained?

Data is retained only for the duration necessary to provide services or meet legal obligations. Retention does not exceed: (i) Customer consent period, (ii) Contract duration, and (iii) Applicable limitation periods for claims.

### Can customers request full data deletion?

Yes. Customers may request account and content deletion at any time by contacting Quickchat AI support. Deletions follow secure data erasure procedures.

## Security Certifications & Programs

### Is Quickchat AI SOC 2 certified?

Quickchat AI is actively pursuing SOC 2 compliance to strengthen enterprise security posture and meet procurement requirements.

### Does Quickchat AI conduct third-party security assessments?

Yes. Quickchat AI conducts periodic third-party security assessments and penetration tests. We also provide standardized security documentation on client's request.

### What security documentation is available?

Available documents include: (i) Data Security Policy (on request), (ii) [Privacy Policy](https://quickchat.ai/privacy), (iii) [GDPR Statement](https://quickchat.ai/gdpr), (iv) [Data Processing Agreement (DPA)](https://quickchat.ai/dpa), (v) Penetration Test Report (on request).

## Access Control & Operational Security

### Who can access customer data internally?

Access is strictly limited to authorized personnel on a need-to-know basis and governed by role-based access control (RBAC) and audit logging.

### Is customer production data accessed for support purposes?

Only when explicitly authorized by the customer and strictly for troubleshooting or support activities.

## Enterprise Contracts & Legal Protections

### Does Quickchat AI provide enterprise SLAs?

Yes. Enterprise agreements may include: (i) Service Level Agreements (SLAs), (ii) availability commitments, and (iii) support response time guarantees.

### How are Intellectual Property rights handled?

Contracts explicitly state that: (i) customers retain ownership of all input content and proprietary knowledge, (ii) Quickchat AI does not claim ownership over customer data.

### Can contracts be customized for enterprise compliance needs?

Yes. Enterprise agreements can be negotiated to include customized legal, security, compliance, and data protection clauses.

### Can customers allow third parties to use Quickchat AI under their account?

Yes, but only with prior written consent from Quickchat AI. This is commonly approved when required for contractors, partners, or service providers performing contractual obligations.

## Deployment Options

### Is on-premise or private cloud deployment supported?

Quickchat AI supports multiple deployment models to meet enterprise infrastructure and compliance requirements.

* Standard Cloud Deployment - Quickchat AI manages infrastructure and hosting with enterprise security standards.
* Private Cloud Deployment - Enterprises can request dedicated environments with isolated compute resources.
* Self-Hosted LLM Deployment - Organizations can run open-source LLMs on a selected cloud platform. This provides full control over data flows, no dependency on third-party AI providers, and maximum regulatory compliance.
* On‑Premises Deployment - Organizations can deploy Quickchat AI on their own infrastructure, ensuring full control over data flows and regulatory compliance.
* Hybrid Architecture - Some customers choose hybrid setups - using Quickchat's orchestration layer while hosting LLM inference privately.

## Incident Response & Reliability

### Does Quickchat AI monitor system availability and security incidents?

Yes. Continuous monitoring via Datadog and GCP infrastructure ensures uptime, performance, and anomaly detection. Our users can monitor the system status on our status page: <https://status.quickchat.ai>.

### Is there an incident response process?

Yes. Quickchat AI maintains internal procedures for detecting, responding to, mitigating, and communicating security incidents in line with industry best practices. All incidents are communicated to our customers on our status page: <https://status.quickchat.ai>.

## AI Safety

### How does Quickchat AI ensure high answer accuracy and reduce AI hallucinations?

Quickchat AI is designed with an enterprise-first architecture focused on grounded responses and controlled knowledge retrieval rather than open-ended generative output. Key mechanisms include:

* Retrieval-Augmented Generation (RAG) - Our proprietary RAG and reranking systems use advanced data modelling to ensure your AI stays grounded in your knowledge base. AI responses directly connected to your approved knowledge sources (documents, help centers, internal wikis, databases).
* Source-Constrained Answering - Administrators can restrict agents to only respond using connected data sources. If no verified answer exists in the knowledge base, the assistant can be configured to: (i) ask clarifying questions, (ii) escalate to a human agent, or (iii) return a "no answer found" response. This significantly reduces hallucinations and misinformation risks.
* Continuous Knowledge Updates - Quickchat AI automatically syncs with connected sources, ensuring AI answers remain up-to-date without manual retraining.
* Prompt Governance & Behavior Controls - Enterprises can define system instructions, tone constraints, and response rules to ensure consistent, compliant output across teams and channels.

### What audit and observability tools are available?

Quickchat AI provides enterprise-grade observability and traceability features that support compliance, quality assurance, and operational oversight.

* Conversation Logs & History - All AI interactions can be logged and reviewed by authorized administrators for: (i) quality assurance, (ii) compliance auditing, (iii) agent training optimization, and (iv) dispute resolution.
* Source Attribution (Explainability) - Quickchat AI can display which internal documents or knowledge sources were used to generate responses. This allows teams to: (i) validate AI outputs, (ii) identify outdated content, and (iii) improve documentation quality.
* Analytics Dashboard - Administrators can monitor: (i) usage volume, (ii) resolution rates, (iii) escalation frequency, (iv) top user questions, and (v) knowledge gaps. This enables continuous performance optimization.
* Human-in-the-Loop Review - Teams can review flagged conversations and refine AI behavior based on real usage patterns.

### Have more questions?

Our team is ready to help you understand how Quickchat AI can meet your compliance and security requirements.

[ Contact us ](https://quickchat.ai/contact "Contact us") [  View all legal documents ](https://quickchat.ai/legal)
