Everything you want to know about data processing, hosting, and security at chat9.
Default in Switzerland. New chatbots run on Swiss infrastructure with a sovereign language model — Swiss data centers, Swiss law, not affected by the US CLOUD Act. This sets us apart from most chatbot platforms (Chatbase, Intercom, Drift, etc.) that only run on US cloud infrastructure — you don't have this choice there. If you explicitly want to choose an OpenAI model (e.g., GPT-4o-mini), you can do so — then the chat content goes to OpenAI servers (EU or USA). For sensitive or regulated applications, we recommend the Swiss default.
No. With the standard model (Swiss hosting), your prompts are neither stored nor used for training — contractually assured by our Swiss hosting partner. When explicitly choosing an OpenAI model, the OpenAI API Data Usage Policy: applies: “OpenAI does not use data submitted to and generated by our API to train OpenAI models.” Important: This differs from consumer apps like ChatGPT.com — there, training is partially done. We exclusively use the API tier. You can find details about our partners in the Datenschutzerklärung.
Application, database, stored chat conversations, and document uploads run on servers in Switzerland. By default, a language model with a Swiss hosting partner is used — chat content does not leave Switzerland. Only if you explicitly select an OpenAI model, chat content is sent to OpenAI servers (EU or USA). Named mention of our API partners in the Datenschutzerklärung.
At Chat9 itself: No. We are a Swiss AG, operated in Switzerland, under Swiss law — not affected by the US CLOUD Act. With the standard model (Swiss API partner), no byte leaves Switzerland. When explicitly choosing an OpenAI model: OpenAI is a US provider, theoretically CLOUD Act-affected. For customers who must exclude this: Stay with the standard configuration.
Swiss API partner (default): Requests are neither recorded nor used for training according to the partner's policy. OpenAI API (only if explicitly chosen): Up to 30 days for abuse monitoring, then deletion. No use for training. In our own database: as long as you do not delete the conversation or cancel your account. Details about the partners in the Datenschutzerklärung.
Yes. As a chatbot owner, you can view all conversations in the admin and delete individual messages or entire conversations at any time. Upon account termination, all data can be completely removed upon request (not just soft-deleted).
You (as the owner) see all conversations of your chatbots in the admin dashboard. chat9 employees only have access in support cases — and only with your explicit consent. No automated monitoring, no reading for marketing purposes.
Yes. We comply with the requirements of the EU GDPR and the revised Swiss Data Protection Act (nDSG). A data processing agreement (DPA) can be concluded upon request — standard for Business/Pro plans.
HTTPS/TLS for all connections. Passwords are stored hashed (bcrypt). CSRF protection, rate limiting against abuse, domain whitelisting per widget. Backups daily, encrypted. Access to production systems only via 2FA.
The platform (admin, customer data, website) continues to run — only the response generation is affected. In this case, the chatbot displays a friendly notice and refers to the stored contact details so that the visitor can reach you directly. As the owner, you can switch between different AI models in the admin at any time if a provider has prolonged issues.
No — on the contrary. The bot uses your website content as context for answering (RAG — Retrieval-Augmented Generation), but the underlying language model is NOT further trained on your data. Your content remains private and exclusively assigned to you.
Further questions? Write to us at info@chat9.ch.