European AI: GDPR and the EU AI Act
Last updated: March 2026
LastBot ONE is built for European operators. The platform runs on European infrastructure, is designed around GDPR controller and processor roles, and is structured to meet the obligations the EU AI Act places on providers and deployers of AI systems used in customer service. This page summarizes the posture; the Master Services Agreement and DPA contain the binding detail.
What the EU AI Act means for AI customer service
The EU AI Act (Regulation (EU) 2024/1689) classifies AI systems by risk. Most customer service AI agents fall outside the high-risk categories listed in Annex III, but they still trigger transparency, human-oversight, and risk-management duties. Operators must inform customers they are interacting with an AI, keep humans in the loop for material decisions, and document the system's intended purpose and limits.
LastBot ONE supports these duties out of the box: every channel includes an AI disclosure, the management portal exposes live oversight controls, and the agent specification doubles as the deployer's documentation of intended purpose.
GDPR posture
- Roles. Your business is the controller. LastBot Europe Oy is the processor under Article 28 and signs a DPA.
- Data residency. Conversation data and knowledge content are processed on European infrastructure.
- Sub-processors. Authorized sub-processors are listed in the MSA. Changes are notified in advance with an objection window.
- Transfers. Where any transfer outside the EEA is required for a specific feature, it is governed by Standard Contractual Clauses and a transfer impact assessment.
- Data subject rights. The platform supports access, rectification, deletion, and export requests through the management portal.
- Security. Encryption in transit and at rest, role-based access control, audit logs, and regular penetration testing.
Sovereign architecture
LastBot ONE is designed for digital sovereignty: European hosting, European-headquartered operator, and a model layer that can run on European-controlled compute. This matters when your customers, your regulators, or your procurement office require that personal data stays inside European jurisdiction end-to-end.
Sovereignty does not stop at hosting. The closed-loop AI coach learns from your tenant's data inside your tenant boundary; conversation content is not pooled across customers and is not used to train external foundation models.
Frequently asked questions
Is LastBot ONE subject to the EU AI Act?▾
Yes. LastBot ONE is an AI system placed on the EU market and used by EU-established operators, so it is subject to the EU AI Act. Customer service AI agents fall under the Act's general rules on transparency, human oversight, and risk management; LastBot ONE is designed to meet these obligations and to support operators in their own compliance.
Where is customer data stored?▾
LastBot ONE runs on European infrastructure. Conversation data, knowledge base content, and operational telemetry are processed within the EU. Sub-processors are documented in the Master Services Agreement and reviewed for adequacy under GDPR.
Who is the data controller, and who is the processor?▾
Your business is the controller of the personal data flowing through customer conversations. LastBot Europe Oy is the processor and signs a Data Processing Agreement (DPA) describing the scope, purpose, and safeguards. LastBot Europe Oy can act as joint controller only for limited platform-level telemetry, which is documented separately.
How does the platform support human oversight?▾
Every conversation can be reviewed in real time in the management portal. Human-in-the-loop rules let operators approve, override, or escalate AI responses. Decision logs are retained so reviewers can audit individual conversations and the model's behavior over time.
Does LastBot use customer conversations to train external models?▾
No. Customer conversation data is not used to train third-party models without explicit, documented consent. The closed-loop AI coach learns from your tenant's data inside your tenant boundary to improve answer quality for you.
References
Need a compliance walkthrough?
We can walk your DPO or procurement team through the architecture, sub-processor list, and DPA in a single session.