GDPR · DPA available EU data residency AI-transparent Audit-logged

Security & data posture

An AI on your storefront that can't go off-script.

Bespoke Seb is built so a luxury house can put an AI associate in front of customers without losing control — it can't invent a product, a price, or a promise, and every sensitive action is logged. Here is exactly what's in place, and what's on the way.

Straight to what we hold and what we don't ↓

Built secure by design

Trust earned by architecture, not by promise.

No hallucinated commerce

The associate can only surface pieces a live catalogue query returned in that conversation. Prices and policies come only from your systems — it cannot invent a product, a price, or a promise.

Human approval gate

Catalogue and knowledge changes are staged for review and reach shoppers only on your sign-off. Nothing goes live automatically.

Tamper-evident audit log

A hash-chained, per-tenant log of administrative, publish/approve, and SSO actions — visible to your Owners and verifiable end to end.

Role-based access & isolation

Owner, Marketing, Service desk, IT and Website-owner roles, each scoped server-side. Every record is keyed to one brand; no tenant can read another's data.

Single sign-on (SSO)

Per-tenant SSO with just-in-time provisioning and role mapping, behind a signed-assertion sign-in. Native SAML/OIDC connectors are next on the same seam.

Hosted in the EU

The platform and its database run in Frankfurt; your catalogue, knowledge and transcripts are stored there. Bespoke Seb acts as a GDPR data processor, with a DPA on request.

Not used to train models

Conversation content goes to Anthropic solely to generate the reply, under API terms that exclude training. Bespoke Seb builds no cross-brand shopper profiles and sells no data.

Encrypted, no card data

TLS for all shopper, API and dashboard traffic; storage on encrypted volumes. Checkout stays on your site, so no payment-card data ever touches Bespoke Seb (PCI out of scope).

AI transparency (EU AI Act)

Shoppers are told they're speaking with an AI associate. Per-brand blocked topics and a brand-anchored boundary keep it on your world.

Where your data goes

Four hops, and no others.

  1. On your storefront A shopper types into the widget — one script tag, served from your own page.
  2. Frankfurt, EU The message reaches our API, which reads your catalogue and brand knowledge from the EU database.
  3. Anthropic — inference only The conversation is sent to the model to draft one reply. It is not retained for training.
  4. Back to Frankfurt The turn and its funnel events are written to the EU database. Your team reads them through the authenticated dashboard.

Nothing else leaves. Shopper content is not sent to advertising, analytics, or data-broker destinations, and there is no cross-brand profile of any shopper. Checkout never touches us — payment-card data stays on your site, which is why PCI DSS is out of scope rather than “compliant”.

Sub-processors

Sub-processor Purpose Processing location
Render Application hosting, database, backups EU — Frankfurt
Anthropic Model inference — generating each reply USA, under Standard Contractual Clauses. No training on API data.
Stripe Merchant subscription payments (no shopper data) EU / USA
Transactional email provider Set-password and team-invite emails to your staff EU / USA

This is the complete list. We will give you advance notice of any addition, and the same list is maintained in our Privacy Policy and in the data-processing agreement.

Retention & erasure

You can have it back, and you can have it gone.

Every record is keyed to one brand, and the database is the single storage seam — which is what makes export and deletion a bounded operation rather than an archaeology project.

Data Kept for On request
Catalogue & brand knowledge Life of the account; replaced on each approved re-crawl Exported or deleted
Shopper conversations & transcripts Sessions expire automatically; stored transcripts are prunable Deleted; a fixed retention window can be agreed in the DPA
Funnel & conversion events Life of the account (pseudonymous; this is what measures the lift) Exported or deleted
Your team's accounts & audit log Life of the account, then as law requires Exported; deleted on termination
Payment-card data Never collected — checkout stays on your site

A configurable, self-serve retention policy in the dashboard is on the roadmap and is not built yet; today a retention window is set contractually and applied by us. Erasure requests reaching you as controller are handled by us as your processor within the DPA's timeframe.

Compliance status

What we hold, and what we do not.

Bespoke Seb is a young company, and we would rather your reviewer read this row-by-row than discover it in diligence. Nothing below is aspirational unless it says so.

Item Status Detail
GDPR — processor role & DPA In place Signed DPA with SCCs available before signature
EU data residency In place Application and database in Frankfurt; inference in the USA under SCCs
EU AI Act — transparency obligation In place Shoppers are told they are speaking with an AI. The associate is a limited-risk system: it recommends, it does not decide anything about a person.
Tamper-evident audit log In place Hash-chained, per tenant, chain-verifiable by your Owners
Single sign-on Partial Signed-assertion sign-in with just-in-time provisioning and role mapping is in place; a native SAML / OIDC connector is not built yet.
PCI DSS Out of scope No cardholder data ever reaches the platform
SOC 2 Type II Not held No report exists and no audit window has begun. We will commit to a window as part of a first enterprise engagement.
ISO/IEC 27001 Not held Not certified and not currently in certification. The controls above are the substance; the certificate is not yet the evidence.
Third-party penetration test Not yet conducted No independent test report exists. We will commission one against a pilot deployment, and will share the report and remediation.
Incident response & breach notification Being formalised We will notify you without undue delay and within GDPR's 72 hours, with a named escalation contact in the DPA. The written runbook is not finalised.
Cyber-insurance & MSA On engagement Master agreement with defined liability, mutual NDA, and cover put in place for an enterprise engagement

If a certification is a hard gate for your procurement, tell us at the first meeting rather than the last — the honest answer today is that we would be starting the audit for you, and that timeline belongs in the pilot plan.

Talk to us

Your security team's questions, answered.

We'll share the full security brief, a data-flow walkthrough, and a DPA.

Contact security