Skip to content

Data Protection & GDPR in SmartReplyAssistant

Updated: August 11, 2026 119 views

This article explains, in plain language, how SmartReplyAssistant handles your data and how that maps to the GDPR. It is meant to help you understand and configure the product. It is not legal advice and does not replace your own data protection assessment.

What data is processed

SmartReplyAssistant is built to touch as little data as possible, and only when you ask it to. Two kinds of content are involved:

  • The email text you choose to assist. When you click to draft, summarize or translate, the relevant message text is sent to the AI model so it can produce a reply. Nothing is processed in the background and nothing is sent until you trigger an action.
  • Your knowledge base. The answers, policies, prices and phrasings you save are stored so drafts can be grounded in your real content instead of generic prose.

We do not scan your whole mailbox, and the assistant skips no-reply and automated senders by default, so it only engages where a human reply is actually needed.

Your knowledge is per-workspace and you control it

Knowledge entries belong to a single workspace. They are not shared across tenants and are never used to train a shared model. Within a workspace, roles (owner, manager, editor, member) decide who can read or change entries, so a team keeps one consistent, controlled source of truth.

You can add, edit and delete knowledge entries at any time. Deleting an entry removes it from future drafts immediately - there is no hidden copy kept to keep generating from.

Cache hits do not re-send your data

To keep things fast and inexpensive, SmartReplyAssistant can reuse a previously computed result when the same input appears again. A cache hit means the answer is served from that stored result - your email text is not sent to the AI provider a second time. Less data in transit means a smaller processing footprint, which is good for both speed and privacy.

Managed AI vs. your own AI

You choose where the AI runs.

  • Managed AI provider (default). Your selected message text is sent to a vetted AI provider to generate the draft. This is the simplest setup and requires no infrastructure from you.
  • Your own AI (add-on). With this option the model runs on self-hosted Ollama on EU servers. In this mode no data leaves your infrastructure - the email text and knowledge stay entirely within systems you control. This is the strongest option for data sovereignty and strict GDPR setups.

Where data lives and how to remove it

Use this table as a quick map of what is processed, where it lives, and how you remove it.

Data typeWhere it livesHow to remove it
Email text you assistSent transiently to the AI provider (or your own Ollama); not stored as a mailbox copyNothing to delete on your side; with your own AI it never leaves your servers
Knowledge base entriesWithin your workspaceDelete the entry, or delete the whole workspace
Cached resultsShort-lived cache keyed to the inputExpires automatically; cleared when entries change
API / access tokenYour account settingsRevoke or rotate the token in settings
Account & workspaceYour SmartReplyAssistant accountDelete the workspace or close the account

Deleting your data or your token

You stay in control of everything you put in:

  • Delete a knowledge entry to drop it from all future drafts at once.
  • Delete a workspace to remove its entire knowledge base in one step.
  • Revoke or rotate your token in account settings to cut off API access immediately - useful if a token was exposed or a team member leaves.
  • Close your account to remove your data end to end.

Because email text is only processed transiently, there is no separate archive of your messages to purge.

DPA / privacy policy

For business use under the GDPR you will typically need a data processing agreement (DPA / AVV) with us. The DPA and our privacy policy describe the legal roles, sub-processors, retention and your rights in full. They are linked in the app footer and on the website - read them alongside this article, which only covers the practical product behaviour.

This article is informational and not legal advice. Your own GDPR obligations depend on your business and use case; please consult your data protection officer or legal counsel where needed.

Ready to try it with privacy built in? Create your free SmartReplyAssistant account and keep your knowledge - and your data - under your control.

Support Chat
We usually reply instantly

Cookie Settings

We use cookies to provide you with the best possible experience. Some are technically necessary, while others help us improve our website and show you personalized content.