Last updated: 23 March 2026
Recepte is built with privacy by design. Here's exactly how we handle data under GDPR.
| Scenario | Recepte's Role |
|---|---|
| Processing your business data | Data Controller |
| Processing your clients' data on your behalf | Data Processor |
| Data Type | Legal Basis |
|---|---|
| Business owner account data | Contract performance (Art. 6(1)(b)) |
| Client call/WhatsApp data | Legitimate interest (Art. 6(1)(f)) |
| Marketing to your clients | Your instruction as data controller |
| Analytics & cookies | Legitimate interest (Art. 6(1)(f)) |
All personal data is stored in the EU.
No personal data is transferred to the US or any non-EEA country without Standard Contractual Clauses (SCCs) in place.
| Service | Purpose | Location | DPA |
|---|---|---|---|
| Google Cloud / Firebase | Storage, compute | EU | Yes |
| Anthropic (Claude) | AI language model | US (SCCs) | Yes |
| Meta / WhatsApp | Messaging | EU/US (SCCs) | Yes |
| Stripe | Payments | EU | Yes |
| Deepgram | Speech-to-text | US (SCCs) | Yes |
| Cartesia | Text-to-speech | US (SCCs) | Yes |
| Cloudflare | CDN, hosting | EU edge | Yes |
We support all GDPR rights. Response time: within 30 days.
In the event of a personal data breach:
For any GDPR-related queries:
Email: privacy@recepte.co
As the data controller for your clients' data, you should:
A DPA is included in our Terms of Service and applies automatically to all accounts. For a standalone DPA, email privacy@recepte.co.