Security and privacy
Trust, by design.
Supporting customers means handling sensitive data. Hablari was built from day one with company isolation, regulatory compliance and transparency at its core —not as an afterthought.

Company isolation
Every company is separated at the database level with Row-Level Security (RLS): access policies stop one company from seeing another's data.
Encryption and credentials
All traffic goes over HTTPS/TLS. Your connector credentials are stored encrypted and never exposed to the browser; webhooks are verified with an HMAC signature.
Data in the European Union
The main database is hosted in the EU-Central region (Frankfurt). Transfers outside the EEA are covered by Standard Contractual Clauses.
GDPR, LOPDGDD and LSSI-CE
We are the processor of your customers' data: you are the controller and you decide. The terms are in the DPA built into the Terms.
Transparent AI (EU AI Act)
The chatbot always identifies itself as AI from the very first message. The OpenAI API is used in no-training mode: your data does not train its models.
Least privilege and auditing
Distinct roles (agent, manager, owner), rate limiting on public endpoints and an audit log of staff actions on customer accounts.
The full detail is in the Privacy Policy and in the Terms (with the DPA).
Need a signed DPA or want to report a vulnerability? Write to us at contacto@hablari.com with the subject “Security”.
Every company, isolated. Your data, in the European Union.
Per-company isolation (RLS) and EU hosting aren't an extra: they're the foundation Hablari was built on.
Frequently asked questions
Can one company see another's data?
No. Every company is isolated with Row-Level Security (RLS) in the database: access policies filter by organization on every table, so one company's data is never accessible from another.
Where is my data hosted?
The main database is in the European Union (Frankfurt, Germany). Some providers (payments, AI, email) may process data outside the EEA under Standard Contractual Clauses approved by the European Commission.
Who is the controller of my customers' data?
You are. Hablari acts as the processor (Art. 28 GDPR) for your customers' data and processes it only to provide you the service, following your instructions. The terms are in the Data Processing Agreement (DPA) within the Terms.
Does Hablari use my data to train AI?
No. The OpenAI API the chatbot uses runs in no-training mode: data sent via API is not used to train its models. And the chatbot always identifies itself as AI, in line with the EU AI Act.
Do you store my card details?
No. Payments are processed by Stripe (PCI DSS certified); Hablari only stores subscription identifiers, never the card number or the CVV.

