Back to blog
5 October 2026Petr Kubíček 8 min

GDPR-Compliant Product Demo Software: What EU Buyers Should Check

GDPR-Compliant Product Demo Software: What EU Buyers Should Check

GDPR-compliant product demo software is a demo tool you can use without losing control of your visitors’ personal data: you know where the data is stored, who processes it, on what legal basis, and how to delete it. For a demo tool this matters more than it seems, because an interactive or AI-guided demo can capture a visitor’s email, a voice or text conversation and behavioural data. This guide lists what to check before you buy, then shows openly how Sales Robots answers each point, including the certifications we do not hold. It is general information, not legal advice; check the details with your data protection officer (DPO).

What a demo tool actually processes

Before you ask a vendor about compliance, map the data. A self-serve demo usually touches four categories, and each one has a different risk profile.
  • The visitor. IP address, device and browser data, and (if analytics or advertising tags are used) cookie identifiers. These are governed by your cookie consent setup as much as by the demo vendor.
  • The conversation. In an AI-guided demo the visitor types or speaks questions. A transcript can contain anything the visitor chooses to say, including personal or confidential details.
  • Lead data. Name, email and phone number, when the visitor chooses to leave them.
  • AI processing. If a language model generates answers, the question text is sent to an AI provider, which becomes another party in the chain.
Static click-through tours mostly handle the first and third category. Conversational demos add the second and fourth, so they deserve a closer look at sub-processors and retention.

A buyer checklist for demo software

Use these questions in a security questionnaire. A good vendor can answer each in writing.
  1. Hosting region. In which country or region are the database and file storage located? “EU” is better than “global”, and a named region is better than “EU”.
  2. Sub-processors. Which companies process data on the vendor’s behalf (hosting, AI model, email delivery, analytics)? Ask for the list and the region of each.
  3. Data processing agreement (DPA). Is there a signed or signable DPA that matches GDPR Article 28? A privacy policy is not a DPA.
  4. Transfers outside the EU. If any sub-processor is outside the EU/EEA, what transfer mechanism is used (for example Standard Contractual Clauses)?
  5. AI model provider. Which provider generates the answers, and is it an established vendor with published terms?
  6. Retention and deletion. How long are transcripts and leads kept, and can you delete a single person’s data on request?
  7. Consent. Is consent collected before the demo starts, and is contact data requested only with the visitor’s agreement?
  8. Email provider. If the tool sends emails (lead notifications, reports), which provider sends them and from which region?
  9. Certifications, stated honestly. Which audits does the vendor hold (SOC 2, ISO 27001), and which does it not? Vague wording such as “enterprise-grade security” is not an answer.

How Sales Robots answers: verified facts only

Sales Robots (Prezentér) is built by Sales Robots s.r.o., a company based in Prague, Czech Republic. Here is what we can state today, point by point.
  • Hosting and database: the Prezentér backend and database run on Supabase in the Frankfurt region (eu-central-1).
  • Consent-first flow: the demo asks for consent before it starts, with a link to the privacy policy. Contact details are collected only with the visitor’s consent.
  • Your data stays accessible to you: transcripts are available in your admin panel, and leads can be sent by webhook to your own CRM.
  • AI model: answers are generated with Google Gemini, a solid, widely used LLM provider with published terms and a large enterprise customer base.
  • Email delivery: notification and report emails are sent through Resend, in the EU region (Ireland).
  • Privacy policy: our privacy policy lists the processors above and describes how we handle personal data.
What we do not have. Sales Robots does not hold SOC 2 or ISO 27001 certification. We also have not yet published a standalone data processing agreement (DPA) page; the privacy policy is a privacy policy, not a DPA. If either is a hard requirement for your procurement process, ask us before you start a pilot: contact us.

EU hosting without a certificate vs a US vendor with SOC 2

These two approaches answer different questions, and neither is automatically “more compliant”.
ApproachWhat it gives youWhat to verify
US vendor with SOC 2 and Standard Contractual ClausesAn independent audit of security controls, usually a Trust Center and a ready DPAWhere data is stored, which sub-processors are outside the EU, and how transfers are covered
EU-hosted vendor without certificationA clear, short data path inside the EU and a direct line to the people who run the serviceNo independent audit exists: you rely on a questionnaire, a DPA and your own risk assessment
A SOC 2 report says that security controls were audited; it does not by itself say that data stays in the EU. EU hosting says where the database is; it does not by itself say that controls were audited. Many procurement teams require the certificate, and some accept a documented questionnaire for a low-risk pilot. Decide which case you are in before you shortlist.

When the missing certificate matters, and when it does not

It matters when your company policy or customer contracts require SOC 2 or ISO 27001 from every vendor, when the demo will handle sensitive categories of data, or when the buying process goes through a formal security review.
It matters less for a limited pilot on public marketing pages, where the demo shows only product content you already publish, contact data is optional and consent-based, and your DPO accepts a questionnaire-based assessment. Even then, keep the checklist above and record the answers.
If you are still choosing between formats, see our overview of demo automation software, the comparison in best demo automation software 2026, and how interactive demo software works.

FAQ

Is Sales Robots GDPR compliant?

We do not make a blanket compliance claim, because compliance depends on how you configure and use the tool. What we can state: the Prezentér database runs in Frankfurt (Supabase, eu-central-1), the demo asks for consent before it starts, and contact details are collected only with consent. We do not hold SOC 2 or ISO 27001 certification. This is not legal advice; check with your DPO.

Where is demo data stored?

The Prezentér backend and database run on Supabase in the Frankfurt region (eu-central-1). Transcripts are available in your admin panel, and leads can be sent by webhook to your own CRM.

Do you have SOC 2 or ISO 27001?

No. Sales Robots does not hold SOC 2 or ISO 27001 certification. If your procurement requires it, we are probably not the right fit yet; if a documented questionnaire is acceptable for a pilot, we will answer it in writing.

Do I need a DPA for a product demo tool?

If the vendor processes personal data on your behalf (visitor conversations, lead details), GDPR Article 28 requires a written processing agreement. Sales Robots has not yet published a standalone DPA page; our privacy policy is not a DPA. Ask for the agreement before launch, and check with your DPO.

Want a demo prospects run themselves?

Prezentér is an interactive product demo — it walks prospects through, answers questions by voice or text, and hands you a qualified lead. No waiting for a meeting.

Read next