← Back to Recepte

GDPR Compliance

Last updated: 23 March 2026

Recepte is built with privacy by design. Here's exactly how we handle data under GDPR.

Our Role

ScenarioRecepte's Role
Processing your business dataData Controller
Processing your clients' data on your behalfData Processor

Legal Basis for Processing

Data TypeLegal Basis
Business owner account dataContract performance (Art. 6(1)(b))
Client call/WhatsApp dataLegitimate interest (Art. 6(1)(f))
Marketing to your clientsYour instruction as data controller
Analytics & cookiesLegitimate interest (Art. 6(1)(f))

Data Location

All personal data is stored in the EU.

No personal data is transferred to the US or any non-EEA country without Standard Contractual Clauses (SCCs) in place.

Sub-Processors

ServicePurposeLocationDPA
Google Cloud / FirebaseStorage, computeEUYes
Anthropic (Claude)AI language modelUS (SCCs)Yes
Meta / WhatsAppMessagingEU/US (SCCs)Yes
StripePaymentsEUYes
DeepgramSpeech-to-textUS (SCCs)Yes
CartesiaText-to-speechUS (SCCs)Yes
CloudflareCDN, hostingEU edgeYes

Data Subject Rights

We support all GDPR rights. Response time: within 30 days.

Data Breach Notification

In the event of a personal data breach:

Data Protection Officer

For any GDPR-related queries:

Email: [email protected]

Your Obligations as a Business Owner

As the data controller for your clients' data, you should:

Data Processing Agreement

A DPA is included in our Terms of Service and applies automatically to all accounts. For a standalone DPA, email [email protected].