GDPR considerations for AI customer support
Using AI to draft support replies is processing personal data, because customer emails contain names, addresses, order details and sometimes much more. Under GDPR that means you need to know what's processed, by whom, on what basis, and how a person stays in control. ReplyRabbit makes the answers concrete: the processor for AI work is the provider you choose per mailbox (or nobody, with a local model), only enabled features send data, an agent sends every reply, and on the Team plan every AI action is logged. This isn't legal advice; it's the map of what to ask your counsel about.

Who is processing what
| GDPR question | The ReplyRabbit answer |
|---|---|
| Where is the data stored? | In your FreeScout database, on your server. ReplyRabbit adds no external storage. |
| Who processes it for AI? | The provider set on the mailbox. Cloud providers process it under their terms; Ollama or LM Studio process it on your server. |
| What's sent? | The conversation text needed for the enabled feature, plus your context and style. Nothing for filtered spam or noise. |
| Is there automated decision-making affecting the customer? | Drafts are never sent without an agent. Automated actions are internal (tags, issue creation on Team). |
| Can you show what happened? | The Team plan's audit log records every AI action across mailboxes. |
Your data processing agreement, if you use a cloud provider, is with that provider. Review its terms, retention and subprocessors before pointing a mailbox at it.
Lawful basis and purpose
Drafting a reply to a customer who wrote to you is the same purpose as replying by hand: handling their request. The AI is a tool in that processing, not a new purpose. Where it can become a new purpose is secondary use, for example analysing sentiment across all conversations for reporting. AI Signals and team analytics are optional features; turn them on deliberately, and record why.
Minimisation
- Enable only what you use. Each feature is a switch per mailbox. A mailbox that only needs drafts shouldn't have AI Signals or attachment reading on.
- Send only what's needed. ReplyRabbit already limits each call to the relevant conversation. Keep company context to business facts; don't paste customer lists into it.
- Keep trackers and Slack scoped. Issue handoffs carry a summary and a link, not the whole thread. Don't route sensitive mailboxes to a tracker or channel that shouldn't hold personal data.
- Prefer local for sensitive categories. Health, finance, legal and children's data are the obvious candidates for a local model, which removes the external processor entirely.

Human oversight
The strongest GDPR argument for ReplyRabbit's design is that a person makes every customer-facing decision. Drafts are saved as FreeScout drafts. Confidence scoring on Team tells the agent when to look harder. AI Signals can flag a conversation for human review before anyone opens it. If your policy needs a documented review step, the checklist in Support reply quality checklist for AI drafts is a starting point.
Subject rights and retention
Access, rectification and erasure requests are handled in FreeScout, where the data lives. Drafts, tags and issue links are attached to the conversation and go with it. What a cloud provider retains after processing is governed by that provider's terms, which is another reason to read them, or to use a local model where retention must be zero.
A short checklist for your records
- Which mailboxes use cloud AI, which use local, and why.
- Which provider each cloud mailbox uses, and where its DPA is filed.
- Which optional features are on per mailbox.
- Who reviews drafts, and how the audit log is checked.
- When API keys were last rotated.
The technical side is in AI privacy and security for self-hosted support teams. Provider terms are linked from Choosing an AI provider; local setup is in Ollama integration; mailbox switches are in How to set up ReplyRabbit; the FAQ has the short answers.
Official references
Provider names, model lists, pricing, privacy terms, and legal guidance change. Check the current source before setting a production policy.