SiteGPT · Compliance
HIPAA and GDPR Compliance at SiteGPT
Two questions decide whether a chatbot clears your review: will the vendor sign a BAA, and will it sign a DPA. Both answers are on this page, with the plan each one requires, the documents your counsel can read today, and the parts SiteGPT does not claim.
SOC 2 Type II examination completed with zero exceptions noted. GDPR certified and HIPAA assessed by DPLMC International.
HIPAA
Will you sign a BAA?
Yes
Enterprise plan only
Business Associate Agreements are executed as part of enterprise onboarding, and they are not available on Starter, Growth, or Scale. The standard agreement is published in full, so your counsel can review it before the first call.
Read the standard BAA →GDPR
Will you sign a DPA?
Yes
Executed for Enterprise
A DPA prefilled with your company details can be generated and downloaded today, and it binds once both parties sign. SiteGPT executes DPAs for Enterprise customers at onboarding; baseline processing terms for other plans sit in the Terms and Conditions.
Generate your DPA →What each regime requires, what it costs on the plan sheet, and what you can read before talking to anyone.
HIPAA needs a BAA
Enterprise plan. Published in full at sitegpt.ai/legal/baa, and tailored during onboarding on retention windows, breach notice timelines, notice contacts, and scoping.
GDPR needs a DPA
Generated from sitegpt.ai/legal/dpa with your company details, executed for Enterprise customers at onboarding, binding only when both parties sign.
Both need the vendor chain
Every subprocessor is published with its purpose and location, and a new one gets ten days notice before it starts processing your data.
Both need proof
A completed SOC 2 Type II examination with zero exceptions noted, plus GDPR certification and a HIPAA assessment by DPLMC International.
SOC 2
Type II examination completed, zero exceptions noted
3
Subprocessors in the PHI path under a BAA
10 days
Notice before a new subprocessor starts processing
HIPAA: what is covered, and what is gated
A few terms first, because the rest of this section depends on them. HIPAA is the Health Insurance Portability and Accountability Act, the US law governing health information. PHI is protected health information, meaning health data that can be tied to a person. A business associate is a vendor that handles PHI on behalf of a covered entity, and a BAA (Business Associate Agreement) is the contract that makes that relationship lawful. HHS is the Department of Health and Human Services, which enforces all of it.
SiteGPT signs BAAs on the Enterprise plan only. They are not available on Starter, Growth, or Scale today, and a self-serve HIPAA tier is planned rather than shipped. That gating is the first thing to check against your budget, because everything else in this section depends on it.
The standard BAA is published in full, which is rarer than it sounds: most vendors send the document only after a sales call. It commits to Security Rule safeguards, defined breach notification timelines, automatic redaction of conversation content seven days after last activity (configurable on the order form), full subcontractor flow-down, and a commitment that PHI is never used to train AI models. It is also the standard document rather than a final one. Reasonable amendments to retention windows, breach notice timelines, notice contacts, and scoping are worked in during onboarding.
Before a BAA is executed
No PHI may be submitted through SiteGPT at all. That covers training content, end-user conversations, uploaded files, and lead capture, and it is a condition of the Terms. A healthcare organization can still use SiteGPT today for content that carries no PHI, such as public FAQs, scheduling guidance, and service information.
What a covered workspace changes
This is the part worth reading before you buy, because it narrows the product in ways that cut against its other strengths. The HIPAA docs cover the day-to-day behavior in full.
| What changes | And what you do instead |
|---|---|
| Cloud storage sources (Google Drive, Notion, Dropbox, OneDrive, Box, GitHub) are off by default, and sources already connected are switched off when HIPAA is enabled | Upload the files directly, one at a time, which is also where a PHI-free check actually happens. Each vendor can be turned back on when you hold your own BAA with that vendor. |
| Chat tool integrations (Zendesk, Slack, Crisp) are off by default | Use the native chat widget and the built-in escalation flow. Same rule applies: your own BAA with that vendor is the gate, not the vendor's general compliance posture. |
| PHI is scoped to end-user conversations | Keep training content PHI-free. This is a contract term rather than a statutory one, and the practical reason is simple: anyone who can chat with the bot can reach what it was trained on. |
| Conversation content is redacted seven days after last activity | Configurable on the order form. Leads are treated differently: they persist until you delete them, because a lead is a contact record your team may be required to retain. |
| The AI-generated disclosure stays pinned, even on white-label | Brand everything else. The disclosure is the one element that does not come off in a covered workspace. |
One thing SiteGPT does not do: scan your content for PHI. No automated check reads customer-supplied training content, instructions, or lead fields. Keeping PHI out of them is your own review step, and a lead that turns out to contain PHI is something you delete rather than something the platform catches.
GDPR: the DPA, subprocessors, and transfers
The vocabulary again, briefly. GDPR is the General Data Protection Regulation. A controller decides why personal data is processed and a processor handles it on the controller's instructions, which is the relationship a DPA (Data Processing Agreement) documents. A DSAR is a data subject access request, the mechanism a person uses to see or delete their data. SCCs are the European Commission's standard contractual clauses, the legal instrument that covers personal data leaving the EU.
In a chatbot deployment you are the controller and SiteGPT is the processor. The DPA generator produces a document prefilled with your company details, and it binds when both parties sign. DPAs are executed for Enterprise customers as part of enterprise onboarding; baseline processing terms for every plan sit in the Terms and Conditions.
Transfers, without a residency claim
There is no EU data residency option, and none is planned. Saying so plainly matters more than the feature would, because the real transfer mechanism is contractual rather than geographic. Per the privacy policy, transfers of EU, EEA, and UK personal data rely on the European Commission's Standard Contractual Clauses and, where a given provider is certified, the EU-U.S. Data Privacy Framework. Certification is per provider, so it is not blanket coverage.
SiteGPT has also appointed Article 27 representatives in both regions, which many small vendors skip entirely: Prighter EU Rep GmbH in Vienna for the EU, and Prighter Ltd in London for the UK. If your DPO checks one thing beyond the DPA, that is the checkable one.
SOC 2 Type II and the trust portal
SiteGPT has completed a SOC 2 Type II examination covering the security, availability, and confidentiality trust service criteria, audited by an independent CPA firm, with zero exceptions noted across all tested controls. The report itself is available to Enterprise customers and is requested through the trust portal at trust.sitegpt.ai, alongside the security documentation and the standard security questionnaire answers your procurement team will ask for.
The wording is worth keeping precise, because vendors blur it constantly. SiteGPT is GDPR certified by DPLMC International and HIPAA assessed by the same firm. Assessed is not certified, and the security page states it that way.
Where your data actually goes
The full list, reproduced here so a reviewer does not have to leave this page. It is maintained at sitegpt.ai/legal/subprocessors, last updated July 2026, and a new subprocessor gets at least ten days notice on that page before it starts processing personal data.
| Subprocessor | Purpose | Location |
|---|---|---|
| Infrastructure and hosting | ||
| Cloudflare, Inc. | Hosting, content delivery, file storage | Global |
| Data storage and processing | ||
| Convex, Inc. | Backend database and application platform | United States (AWS) |
| Pinecone Systems, Inc. | Vector database for AI embeddings | United States (AWS) |
| AI and machine learning | ||
| OpenAI, L.L.C. | AI language model processing | United States |
| Cohere Inc. | AI embeddings and language processing | United States |
| Content processing | ||
| Context.dev | Document and file parsing for uploaded sources | United States |
| Observability and analytics | ||
| Portkey AI | AI observability and logging | United States |
| PostHog | Product analytics | United States |
| DataFast | Marketing analytics | United States |
| Google LLC | Website analytics | United States |
| Dub Technologies, Inc. | Referral and affiliate link analytics | United States |
| Email and communications | ||
| Bento | Email marketing and communications | United States |
| AutoSend | Transactional email, account emails only | United States |
| Payments | ||
| Paddle | Merchant of Record, independent controller for payment data | United Kingdom |
The PHI path is narrower than the full list
Under an executed BAA, protected health information reaches three subprocessors only: Convex as the application database, OpenAI for AI responses and embeddings through zero-data-retention endpoints, and Pinecone for vector search. PHI does not flow to any other subprocessor on the list. Those boundaries are preconditions of enablement rather than best-effort promises, which is why keeping training content PHI-free matters: it is what keeps the ingestion and analytics vendors out of scope entirely.
What SiteGPT does not claim
A compliance page that only lists strengths is a page you have to verify twice. These are the limits, stated once, in the same place as the claims.
- No EU data residency, and none is planned. Transfers are covered contractually through SCCs and Article 27 representatives, not by hosting location.
- A HIPAA BAA is Enterprise only. It is not available on Starter, Growth, or Scale, and a self-serve HIPAA tier is planned rather than shipped.
- HIPAA status is assessed, not certified. The SOC 2 Type II examination and the GDPR certification are the two independently certified items.
- The DPA text is generated rather than published in advance, so counsel reviews it after generating a copy. The BAA is the stronger document here: its full text is public.
- There is no automated PHI detection. Nothing scans your training content, instructions, or lead fields for protected health information.
- A covered workspace turns cloud storage sources and chat integrations off by default. They come back per vendor, and only when you hold your own BAA with that vendor.
The document library
Business Associate Agreement
The standard BAA, published in full for your counsel to read before any call. Enterprise plan.
Read the BAA →Data Processing Agreement
A generator that produces a DPA prefilled with your company details. Executed for Enterprise customers at onboarding.
Generate a DPA →Subprocessor list
Every third party that processes data, what it does, and where it sits. Ten days notice before a new one starts processing.
View the list →Security overview
Encryption, access controls, infrastructure, and the certification detail behind the badges.
Read the overview →HIPAA program page
The authoritative status of HIPAA availability, BAA scope, and the onboarding sequence.
Open the program page →Trust portal
Request the SOC 2 Type II report and the rest of the security documentation.
Open the trust portal →Read the detail
Eight guides go deeper than a hub page can, four on each regime.
Frequently asked questions
Is SiteGPT HIPAA compliant?
SiteGPT has been assessed for HIPAA security and privacy safeguards by DPLMC International, and signs Business Associate Agreements on the Enterprise plan only. BAAs are not available on Starter, Growth, or Scale. Until a BAA is executed for an account, no protected health information may be submitted through SiteGPT at all, including training content, conversations, uploads, and lead capture.
Will SiteGPT sign a DPA?
Yes. A Data Processing Agreement can be generated at sitegpt.ai/legal/dpa, prefilled with your company details, and it becomes binding when both parties sign. SiteGPT executes DPAs for Enterprise customers as part of enterprise onboarding. Baseline data processing terms for every other plan are set out in the Terms and Conditions.
Where is SiteGPT data stored, and is there EU residency?
There is no EU data residency option and none is planned. Subprocessors are primarily located in the United States, with Cloudflare operating globally and Paddle in the United Kingdom. Transfers of EU, EEA, and UK personal data rely on the European Commission's Standard Contractual Clauses, and where a given provider is certified, the EU-U.S. Data Privacy Framework. SiteGPT has also appointed Article 27 representatives in both the EU and the UK.
Does SiteGPT have a SOC 2 report?
SiteGPT has completed a SOC 2 Type II examination covering the security, availability, and confidentiality trust service criteria, audited by an independent CPA firm with zero exceptions noted across all tested controls. The report is available to Enterprise customers through the trust portal at trust.sitegpt.ai.
Is customer data used to train AI models?
No. Conversations, training data, and customer interactions are never used to train or fine-tune AI models, and messages sent to OpenAI for processing run through zero-data-retention endpoints. That commitment is written into the BAA as well as the security policy.
What changes in a HIPAA-covered workspace?
Cloud storage sources and chat tool integrations are off by default and can be enabled per vendor only when you hold your own BAA with that vendor. Sources already connected are switched off when HIPAA processing is enabled. PHI is scoped to end-user conversations, so training content must stay PHI-free. Conversation content is redacted seven days after last activity by default, configurable on the order form. Leads persist until you delete them. The AI-generated disclosure stays pinned even on white-labeled widgets, and no analytics or session recording runs on chat surfaces or in the dashboards of covered workspaces.
Send this page to your reviewer, then talk to us
Both agreements are Enterprise, and both are scoped with you rather than handed over. Bring the deployment you have in mind and the provisions your counsel needs, and the first call can start there.