AI Act & Trust
Chatmerce is built for European e-commerce. This page explains how we approach the EU AI Act — whose transparency obligations for AI chat interfaces (Article 50) apply from 2 August 2026 — and the controls that back our commitments up. It answers the questions procurement and security teams ask during due diligence. It is information about our product, not legal advice.
Transparency — you always know it’s AI
Every Chatmerce chat surface — the embeddable widget and our hosted demo — always shows an AI-disclosure line; it cannot be removed. By default it tells visitors, up front, that they are talking to an AI assistant. Pro and Enterprise customers may customise the wording, but the disclosure itself is never optional. This is the heart of the AI Act’s Article 50 transparency requirement, and we meet it by default.
A note on the dates. The duty to tell a person they are talking to an AI (Article 50(1)) applies from 2 August 2026 — with no transition period, including for chatbots deployed earlier. The 2 December 2026 date that sometimes comes up covers something else: machine-readable marking of AI-generated content (Article 50(2)), and only for generative systems already placed on the market before 2 August 2026.
What about your own shop? Check your chatbot in 2 minutes → — 5 questions and you’ll know whether you meet Article 50, and what to fix.
Human oversight — nothing changes without a person
When our setup assistant proposes a change to your configuration or a new integration, that change is staged for approval and applied only after a human approves it. The AI cannot silently alter your agent, your settings, or your connected tools.
Data protection & residency
All conversations, knowledge bases, and secrets are processed in the European Union — Google Cloud region europe-west4 (Netherlands). Passwords and API keys are stored in Google Secret Manager, never in our database or logs. We honour the GDPR right to erasure, and a Data Processing Agreement (DPA) is available. Personal data is redacted before any conversation is used to improve models.
An honest note on “sovereignty”: Chatmerce runs on Google Cloud, a US-headquartered provider. Processing takes place in the EU, and any international transfer relies on Standard Contractual Clauses and the safeguards in Chapter V of the GDPR. We do not claim “digital sovereignty” — we tell you exactly where your data is processed and on what legal basis. A detailed sub-processor list is available to Enterprise customers on request.
Credentials never reach the AI
API keys and other secrets you connect stay in Google Secret Manager and are attached server-side only at the moment of an outbound call. They never pass through the language model and are never written to logs.
Accountability & audit trail
Administrative and agent-configuration actions — creating and deploying agents, editing tools, updating settings and branding — are recorded with who did it, what changed, and when, and retained for compliance and review.
Defence against prompt injection
Inbound visitor messages are scanned for prompt-injection and jailbreak attempts using Google Cloud Model Armor.
What we’re still improving
We are candid about what is in progress: an external penetration test, formal DPAs with every sub-processor, an OWASP ASVS Level 2 self-assessment, and a STRIDE threat model.
Reviewing Chatmerce for procurement or security? Email hello@chatmerce.eu. See also our Data Processing Agreement and Privacy Policy.