This is not legal advice
This page explains what LATYNEX does technically. Whether a given setup is GDPR-compliant for your specific business depends on facts only your own lawyer can confirm — lawful basis for processing, your specific retention obligations, and your data processing agreements with your own customers.
What data is actually collected
Name, contact detail (email/WhatsApp/phone), and whatever the visitor types about their inquiry — no more than that by default. See What Data Should an AI Intake Collect for the specific fields we recommend and why we don't recommend collecting more.
Data minimisation and consent
Forms ask for what's needed at that stage, not everything upfront. Consent for analytics tracking is handled via an explicit accept/decline banner, defaulting to denied — see how that's implemented in practice on this very site's cookie banner.
Where lead data actually goes
Today, submitted leads are delivered via the Telegram Bot API to a private chat, with server logs as a fallback if delivery fails. There is currently no separate database storing lead submissions — Telegram plus server logs are the only two places a lead is captured. If your business needs longer-term structured storage or a formal Data Processing Agreement with a database vendor, that's a separate scoping conversation, not something assumed by default.
Third-party processors
Telegram (message delivery) and Google Analytics (if consent is granted) are the only third-party processors in a standard setup. CRM platforms you already use (HubSpot, Pipedrive, etc.) become processors once connected — see Integrations.
Human handoff, audit logs and failure handling
Every AI intake is built with a defined point where a human takes over — see When Should AI Hand a Lead to a Human. Delivery failures are logged server-side without full personal data in the log line; there is no dedicated audit-log product today (see limits below).
Deletion requests
Because Telegram is the primary store, a deletion request today means deleting the message in the destination chat and any matching server log line — a manual process, not an automated "right to be forgotten" API. For higher-volume, higher-sensitivity use cases, ask about adding a proper data store with deletion tooling before launch.
Limits — what we don't provide today
No formal audit-log product, no automated data-subject-request tooling, and no dedicated database by default. These are real, current limits, not hidden ones — if your use case needs them, they're a scoping conversation, not an assumed default.
Questions
Is this a substitute for legal advice?+
No. Confirm lawful basis, retention policy and DPA requirements with your own counsel — this page explains the technical setup only.
Where is lead data stored?+
Delivered via Telegram to a private chat, with server logs as a failure fallback. No separate database by default.
Can data be deleted on request?+
Yes, but manually today — deleting the Telegram message and matching log line, not an automated tool.
Do you sign a formal DPA?+
That depends on your specific requirements and processors involved — raised and confirmed during scoping, not assumed by default.