Try free Sign in Contact sales
Compliance / Live Today

GDPR-Compliant Workflow Automation

GDPR isn't on our roadmap — it's the law we operate under every day, as an EU company handling EU data. Data minimization, transparent subprocessors, and data-subject rights are live today, not something we're building toward.

Try Chasa free Read our Privacy Policy
GDPR-compliant by design — live today RELACON GmbH — Vienna, Austria

GDPR has no certification scheme — it's a legal obligation, not a badge. This page describes what we actually do; the full legal detail is on our Privacy page.

What GDPR covers

The EU General Data Protection Regulation governs how organizations collect, process, store, and share personal data belonging to people in the EU/EEA. It requires a lawful basis for every processing activity, minimizing what you collect, disclosing who you share data with and why, honoring data-subject rights (access, correction, deletion, portability), and being accountable for where data is hosted and by whom. For a SaaS vendor, that means every workflow touching customer or invoice data has to be built with those obligations in mind from day one — not retrofitted after the fact.

How Chasa supports GDPR

Chasa is built by RELACON GmbH, an Austrian company — GDPR is our home law, not a checkbox for an overseas market. Everything below is live today. Full detail is in our Privacy Policy.

Live today Data Minimization by Design Free, no-account use stores nothing about your invoices on our servers — drafts are generated per request and never retained.
Live today Transparent Subprocessors Every third party that touches your data is listed with the reason we use it on our Privacy page — currently Cloudflare (hosting, D1 database, Workers AI), Resend, Stripe, and (consent-gated) Microsoft Clarity. Nothing undisclosed.
Live today Data Subject Rights Access, correction, deletion, and portability requests are handled directly — email [email protected] and we respond within a reasonable time, no ticket system required.
Live today EU-Native Hosting & Jurisdiction Chasa is a product of RELACON GmbH, Vienna, Austria — the data controller for personal data, operating under EU law and subject to the Austrian Datenschutzbehörde.
Live today Encrypted in Transit Every connection to Chasa — app, API, and webhooks — runs over TLS/HTTPS, with outbound webhook payloads HMAC-signed so receiving systems can verify authenticity.

Example GDPR workflows

Real requests Chasa handles today under GDPR:

  • Data access request: a user asks what personal data we hold; we compile and send it.
  • Right-to-erasure request: a user asks us to delete their account data; we do, subject to limited billing/tax retention.
  • Data portability export: a user asks for their data in a portable format so they can move it elsewhere.
  • Subprocessor disclosure review: a prospective customer's legal team reviews our published subprocessor list before signing up.
  • Consent management for analytics: a visitor accepts or declines optional analytics cookies, with the choice honored immediately and reversible anytime.

Why teams choose Chasa

EU jurisdiction by default
Transparent subprocessors
Minimal data retention
Built by an EU company

Try Chasa free

GDPR-compliant by design, not by promise — because we're an EU company operating under EU law. Get started free, no account or invoice data stored unless you sign in.

Try Chasa free Read our Privacy Policy

Questions about your data? Talk to us or email [email protected].

Related

Compliance overview → All frameworks we support today and are building toward. SOC 1 workflow automation → Financial-control approvals and audit trails. Security & Trust Center → What's live today vs. on our compliance roadmap. Privacy Policy → The full legal detail behind this page.