Skip to content
open·agent

Use case · EU Compliance

EU workspaces with GDPR + data residency: a chat platform that fits the audit, not the other way round

The Mittelstand procurement officer doesn't sign off on Intercom because the data goes to the US. The Italian bank can't use Zendesk because the audit trail isn't signed. OpenAgent ships in shapes that fit those constraints: EU-only hosting, a dedicated single-tenant deployment on the Business tier, signed conversation export, the audit log every regulator asks for.

Sujith Sasidharan· CTO & Technical Architect10 min read

Why EU buyers bounce off most US-built tools

Three constraints that come up in almost every EU procurement conversation:

  • Data residency. “Where, physically, does the customer message sit?” If the answer involves Frankfurt-via-Northern-Virginia (DPF mechanism), German finance and insurance buyers walk. The procurement memo says EU-only.
  • Sub-processor visibility. “Who else touches this data?” Most US chat tools list 12-20 sub-processors. The DPO has to evaluate each one. That's weeks of review for a single tool.
  • Audit signature. Regulated industries (insurance, banking, healthcare) need every conversation export to be tamper-evident. Most chat tools export a CSV. That's not an audit artifact.

OpenAgent addresses all three by design rather than by promise.

Three shapes for an EU deployment

1. EU-hosted SaaS (the default for most buyers)

Same OpenAgent product, infrastructure pinned to the EU. Postgres in Frankfurt or Dublin, MinIO for attachments in the same region, no US-region failover. The model provider you select (Gemini europe-west, Azure OpenAI West Europe, or a managed Mistral endpoint) keeps inference inside the EU as well. Sub-processor list is short and EU-anchored.

2. Dedicated single-tenant deployment (Business tier)

Your own OpenAgent instance, operated by us on dedicated EU infrastructure pinned to the region your DPO names. No shared compute, no shared database, an SLA, and audit log export. Model calls go through whichever endpoint you wire up (including a self-hosted Llama / Mistral if you don't want any third-party AI involved).

The Mittelstand profile usually picks this option. It costs more than shared SaaS, but it's dramatically cheaper than a comparable in-house helpdesk role (typically €120-180k/year fully loaded).

3. Hybrid: SaaS dashboard, model proxy in your VPN

For workspaces that want the SaaS convenience but need the model calls to go through their own audit point. The dashboard runs in the EU SaaS; the configured model endpoint points to a proxy you control; the proxy logs every request before forwarding. Two artifacts your DPO gets: the SaaS audit log and the proxy access log, which can be correlated by request id.

The audit trail in detail

Every mutation in OpenAgent writes a row to the audit log: authentication, user invite, agent prompt change, escalation policy edit, knowledge document upload, conversation state transition. Tenant-scoped, actor-attributed, immutable from the application layer.

For regulated buyers the on-roadmap signed export turns the log into a tamper-evident artifact: each conversation export carries a SHA-256 of the prior export, chain-anchored daily to a public timestamp service. The auditor verifies the chain; the workspace can't rewrite history without breaking the signature.

Multilingual support, properly

EU brands rarely sell into one language. Two pieces of OpenAgent make multilingual work without per-language KB rewrites:

  • Single KB, multi-language reply. Upload your knowledge base in your primary language (usually English or German). The widget passes the visitor's browser language as a hint to the agent. The AI retrieves the relevant chunk in the source language, then answers in the visitor's language. Quality on tier-1 questions is now near-human for the major EU languages.
  • Operator-language inbox. The dashboard renders the inbox in the operator's preferred language regardless of the conversation language, with optional auto-translate on the conversation thread for the operator's own reading.

Sample math: replacing an in-house tier-1 helpdesk role

EUR-denominated calculator below pre-loaded with DACH benchmark numbers. Adjust the loaded-cost field down for non-DACH markets; Italy and Spain run materially lower.

Live ROI calculator · DACH defaults

Override the assumptions, see your savings

Open full calculator →

DACH benchmark: €70-90k loaded. UK: £40-60k. US: $60-80k.

Estimated monthly savings

8.402 €

That is 100.829 € a year, roughly 60% cheaper than all-human at the same volume.

All-human today

14.011 €

1,800 × 7,7839 €/ticket

AI + humans on OpenAgent

5.609 €

1,080 AI + 720 human

Show the math
Human cost / ticket7,7839 €
All-human / month14.011 €
AI tickets (60%)1,080
Token cost (AI)1,188 €
Remaining human720 × 7,7839 € = 5.604 €
Platform fee3,00 €
Monthly savings8.402 €

Assumes 1,820 productive hours per agent per year. Token costs are mid-2026 list for the provider you selected; you pay the provider directly. Containment above 80% is achievable but usually means the escalation seam is too narrow, which hurts CSAT.

Typical Mittelstand support setup before:

Line itemAnnual cost
Tier-1 helpdesk role (fully loaded, DACH)€90,000
Helpdesk software (Zendesk Suite for 4 seats)€6,600
Tier-1 backup coverage (vacation, sickness)€12,000
Out-of-hours pager rotation€18,000
Total€126,600

With OpenAgent on a dedicated EU deployment:

Line itemAnnual cost
OpenAgent Business tier (indicative)€6,000
Dedicated EU infrastructure (indicative)€2,400
LLM provider (Gemini Flash, ~20k conversations/year)€220
Tier-2 specialist (existing engineer, 4hrs/week absorbed)€8,400
Total€17,020

Net annual saving: ~€110,000. Plus the out-of-hours coverage is no longer a person sitting on the phone.

For workspaces with stricter compliance (financial services, healthcare), pair the dedicated deployment with a model endpoint you control, or a model you host yourself; the math barely moves.

Quick FAQ

Where exactly is the data?

Three options. (1) EU-hosted SaaS: data stays in Frankfurt or Dublin, the model provider you pick determines where inference happens (Gemini and OpenAI both offer EU endpoints; Anthropic is US-only at the moment). (2) Dedicated single-tenant deployment on the Business tier: your own instance on dedicated EU infrastructure, no shared compute or storage. (3) Hybrid: SaaS for the dashboard, model calls go through your own proxy.

Does the AI process personal data?

The widget hashes the visitor's identifier before it reaches the AI, and the PII redactor strips email, card, SSN, IBAN, and phone patterns from message bodies before they go to the model. You can tighten the redactor list per tenant if your DPO wants more aggressive scrubbing.

What about the right to erasure?

Conversation deletion is a single API call: POST /api/visitors/:id/erase. It hard-deletes the visitor record, anonymises the conversation thread, and writes an audit log entry. We expose the same endpoint to the dashboard so an operator can handle a GDPR Article 17 request without engineering involvement.

Can you sign a DPA?

Yes, standard Article 28 DPA, ours uses the SCCs for any sub-processor outside the EU (today: only your model provider if you choose a non-EU one). The list of sub-processors lives on a sub-page so you can include it in your own ROPA.

Can the model calls stay inside the EU?

Yes. The model call goes from your OpenAgent workspace to whichever endpoint you choose. Gemini's europe-west endpoints, Azure OpenAI in West Europe, or a self-hosted Ollama running Mistral or Llama behind your own proxy. Each tenant picks per-workspace, so a German subsidiary can use europe-west while a UK subsidiary uses uksouth.

Try it on your own LLM keys from $3/mo.

$36 per site per year billed annually, or $5 per site per month billed monthly. No card on file, just paste your model key and your widget is live.