← All posts
Compliance8 min read

[COMPLIANCE] · May 8, 2026 · 08:00

GDPR for chat tools in 2026: what compliance actually means

A founder-friendly walkthrough of the GDPR articles that touch live chat, what your tool needs to do, and how muro handles each one.

Tm

The muro team

muro.chat

#gdpr#privacy#compliance#eu#dpa
GDPR for chat tools in 2026: what compliance actually means

Live chat is a GDPR-rich product. Visitors send personal data ("my email is …", "my order number is …"); agents reply with more; the conversation lives in a database somewhere and gets emailed to a human inbox. Every step has an article that touches it. Here's the practical version, with what muro does for each.

Article 6, lawful basis

You need a legal reason to process visitor data. For live chat, that's legitimate interest (running the support service the visitor is asking for) for the conversation itself, plus consent if you set non-essential cookies. muro keeps essential cookies (session, CSRF) off the consent banner, you only ask consent for analytics, which we don't set by default anyway.

Article 7, proof of consent

"The user consented" is not enough, you need to prove it. muro stores every consent decision in cookie_consent with timestamp, IP, user-agent, and a fingerprint. If a regulator asks "did this user consent on March 4th?", we have the receipt.

Article 12-15, right of access

A visitor can ask: "what do you have on me?" You have one month to answer with all of it. muro's /api/account/export endpoint produces a JSON dump of everything, user record, accounts, sessions, organisations, websites the user belongs to, conversations, audit entries, in a single download. The dashboard exposes a button on /app/profile.

Article 17, right to erasure ("right to be forgotten")

A user (or visitor whose email we have) can ask for full erasure. Soft delete is not enough, the data must actually be gone. muro's /api/account/delete does cascade DELETE through every table (sessions, accounts, member rows, sole-owned orgs and their websites/conversations/messages). The audit log entry survives but only contains the action, no PII.

Article 20, data portability

Same export as Article 15 but in a structured, machine-readable format. JSON satisfies this. We were tempted to ship a "competitor migration ZIP" format too, but JSON is cleaner, anyone can write a 30-line script to import into anything else.

Article 25, privacy by design

You can't bolt privacy on at the end. In muro, every database query is WHERE organization_id = :orgId, there's literally no path in the codebase that would let one customer see another customer's data. We have unit tests that fail if a query forgets the predicate.

Article 28, processor agreements (DPA)

Your customers (controllers) have us (processor) handling personal data on their behalf. They need a signed DPA from us. We have a standard one at /legal/dpa; for enterprises we sign their custom one too. Includes the obligatory bits: technical safeguards, sub-processors list, breach notification clock (72 h to your team, you decide what to tell your users).

Article 30, records of processing

Every action that touches personal data should leave a trail. muro's audit_log records: sign-ins, password changes, API key creation/revoke, message sends, plan changes, billing events, GDPR requests. Retained 90 days, then automatically deleted by a cron job (you don't want infinite retention either, that's its own privacy problem).

Article 32, security

Vague but important. Means: encryption in transit (TLS 1.3), at rest (Postgres native), strong passwords (scrypt via better-auth), 2FA available, rate limiting on credentials endpoints, brute-force protection. We do all of these, it's in /security.

Article 44, international transfers

You can't ship EU citizen data outside the EU without specific safeguards. muro keeps your conversations in the EU, Hetzner Falkenstein for Postgres, eu-west-1 for AWS SES email. Payments go through Stripe under the EU Standard Contractual Clauses, the Article 46 safeguard for that one transfer. We don't merge data across regions.

What we explicitly don't do

  • →No Google Analytics, Mixpanel, Hotjar, Pendo, or other US analytics on the dashboard. Self-hosted Plausible for marketing pages, no fingerprinting.
  • →No advertising pixels (Facebook, Google Ads, LinkedIn).
  • →No cross-customer data joins. Even our own analytics queries respect organization_id.
  • →No "AI training on your data" clause. Your conversations are yours.
✦ ✦ ✦

GDPR isn't a checklist you finish, it's a posture. Build it into the architecture, document it in your DPA, surface it in the product (export buttons, consent records, audit log), and the compliance work mostly does itself. Anything in your stack that fights you on this is a candidate for replacement.

✦ Frequently asked

Questions people ask.

01Do I need a cookie consent banner for my live chat widget?+

The muro widget sets no cookies at all, so there is nothing for a cookie banner to gate. It writes three first party localStorage keys on your own domain (muro_vis, muro_conv, muro_fp) so a returning visitor keeps their thread instead of restarting. Local storage is still terminal equipment access under ePrivacy, so if your counsel wants it gated, the snippet is a plain async script tag any consent manager can inject after acceptance.

02Does muro store visitor IP addresses?+

Yes, but truncated. The last octet of the IPv4 is zeroed before it is written, so 203.0.113.47 lands in the database as 203.0.113.0. The visitor record also keeps country (from Cloudflare's CF-IPCountry header), device, browser and OS parsed from the user agent, plus the page URL and the referrer. Read the full record at /app/visitors/{id}, then list those fields in your privacy notice.

03A visitor asked me for a copy of their chat. How do I answer it?+

Open /app/visitors/{id} and click "Export visitor data (GDPR)". You get JSON with their identity record and every conversation they had, and the endpoint writes an audit_log row so the disclosure itself is traceable. Erasing one single visitor is not a one click action yet, so mail [email protected] for it. Deleting the workspace cascades every visitor, conversation and message it owned.

04If I turn on AI replies, do my visitors' messages leave the EU?+

They reach Anthropic's API, yes, which is why AI auto reply is a per site toggle that stays off until you switch it on in /app/sites/{id}. What leaves is the visitor's question plus keyword matched snippets from your own published docs and product context, not your conversation history, and none of it is used for training. Bring your own Anthropic key and that call runs under your contract instead of muro's.

05Is the DPA and EU hosting only available on an enterprise plan?+

No, they are standard. The signed DPA at /legal/dpa, EU hosting, the public sub-processor list, the REST API, webhooks and the hosted MCP server are identical on Solo ($19 a month, 2 projects) and Fleet ($59, unlimited projects), with unlimited agents on both and no per seat or per resolution charge. The 14 day trial takes a card, no charge today, one click cancels before it renews.

06What happens to a chat when nobody on my team is online?+

The message is emailed to your workspace after a delay you set in /app/settings/notifications (90 seconds by default), and you reply straight from your mail client. Two GDPR consequences follow. That transcript now also sits in your mailbox, so your own records of processing should name your mail provider, and muro sweeps its forwarded_email rows after 90 days while the conversation stays in the inbox.

✦ Try it

One support inbox for all your projects, one flat price.

muro is live chat, an AI that answers from your own docs, and a shared inbox for every site you run. See it both sides in the live demo, check the flat pricing, or see how muro compares.

Tm

✎ Written by

The muro team

muro.chat