GDPR-Compliant Product Demo Software: What EU Buyers Should Check

GDPR-compliant product demo software is a demo tool you can use without losing control of your visitors’ personal data: you know where the data is stored, who processes it, on what legal basis, and how to delete it. For a demo tool this matters more than it seems, because an interactive or AI-guided demo can capture a visitor’s email, a voice or text conversation and behavioural data. This guide lists what to check before you buy, then shows openly how Sales Robots answers each point, including the certifications we do not hold. It is general information, not legal advice; check the details with your data protection officer (DPO).
What a demo tool actually processes
- The visitor. IP address, device and browser data, and (if analytics or advertising tags are used) cookie identifiers. These are governed by your cookie consent setup as much as by the demo vendor.
- The conversation. In an AI-guided demo the visitor types or speaks questions. A transcript can contain anything the visitor chooses to say, including personal or confidential details.
- Lead data. Name, email and phone number, when the visitor chooses to leave them.
- AI processing. If a language model generates answers, the question text is sent to an AI provider, which becomes another party in the chain.
A buyer checklist for demo software
- Hosting region. In which country or region are the database and file storage located? “EU” is better than “global”, and a named region is better than “EU”.
- Sub-processors. Which companies process data on the vendor’s behalf (hosting, AI model, email delivery, analytics)? Ask for the list and the region of each.
- Data processing agreement (DPA). Is there a signed or signable DPA that matches GDPR Article 28? A privacy policy is not a DPA.
- Transfers outside the EU. If any sub-processor is outside the EU/EEA, what transfer mechanism is used (for example Standard Contractual Clauses)?
- AI model provider. Which provider generates the answers, and is it an established vendor with published terms?
- Retention and deletion. How long are transcripts and leads kept, and can you delete a single person’s data on request?
- Consent. Is consent collected before the demo starts, and is contact data requested only with the visitor’s agreement?
- Email provider. If the tool sends emails (lead notifications, reports), which provider sends them and from which region?
- Certifications, stated honestly. Which audits does the vendor hold (SOC 2, ISO 27001), and which does it not? Vague wording such as “enterprise-grade security” is not an answer.
How Sales Robots answers: verified facts only
- Hosting and database: the Prezentér backend and database run on Supabase in the Frankfurt region (eu-central-1).
- Consent-first flow: the demo asks for consent before it starts, with a link to the privacy policy. Contact details are collected only with the visitor’s consent.
- Your data stays accessible to you: transcripts are available in your admin panel, and leads can be sent by webhook to your own CRM.
- AI model: answers are generated with Google Gemini, a solid, widely used LLM provider with published terms and a large enterprise customer base.
- Email delivery: notification and report emails are sent through Resend, in the EU region (Ireland).
- Privacy policy: our privacy policy lists the processors above and describes how we handle personal data.
EU hosting without a certificate vs a US vendor with SOC 2
| Approach | What it gives you | What to verify |
|---|---|---|
| US vendor with SOC 2 and Standard Contractual Clauses | An independent audit of security controls, usually a Trust Center and a ready DPA | Where data is stored, which sub-processors are outside the EU, and how transfers are covered |
| EU-hosted vendor without certification | A clear, short data path inside the EU and a direct line to the people who run the service | No independent audit exists: you rely on a questionnaire, a DPA and your own risk assessment |
When the missing certificate matters, and when it does not
FAQ
Is Sales Robots GDPR compliant?
We do not make a blanket compliance claim, because compliance depends on how you configure and use the tool. What we can state: the Prezentér database runs in Frankfurt (Supabase, eu-central-1), the demo asks for consent before it starts, and contact details are collected only with consent. We do not hold SOC 2 or ISO 27001 certification. This is not legal advice; check with your DPO.
Where is demo data stored?
The Prezentér backend and database run on Supabase in the Frankfurt region (eu-central-1). Transcripts are available in your admin panel, and leads can be sent by webhook to your own CRM.
Do you have SOC 2 or ISO 27001?
No. Sales Robots does not hold SOC 2 or ISO 27001 certification. If your procurement requires it, we are probably not the right fit yet; if a documented questionnaire is acceptable for a pilot, we will answer it in writing.
Do I need a DPA for a product demo tool?
If the vendor processes personal data on your behalf (visitor conversations, lead details), GDPR Article 28 requires a written processing agreement. Sales Robots has not yet published a standalone DPA page; our privacy policy is not a DPA. Ask for the agreement before launch, and check with your DPO.
Want a demo prospects run themselves?
Prezentér is an interactive product demo — it walks prospects through, answers questions by voice or text, and hands you a qualified lead. No waiting for a meeting.