Compliance
This page summarises EnaChat’s compliance posture as it works today. The full documentation (DPA, justification report, declarations) is delivered with the contract.
GDPR
- Roles: the council is the data controller; Enantena is the data processor with a standard DPA.
- Data processed: conversation text (it may contain personal data the citizen types, which is why the chat asks them not to) and aggregated usage statistics. No citizen registration or identification. If a citizen asks to talk to a person and leaves an email, that email is stored with the hand-off.
- Retention: conversations and hand-offs purged after 90 days (configurable). IP addresses are not stored in the database: they are used in memory for rate limits, and the technical logs of blocked attempts keep only a truncated form.
- Sub-processors: application and database hosting in the EU (Frankfurt); answers drafted with Google’s Gemini models through the Gemini API, which receives the question and the source excerpts it needs; Resend for hand-off emails to the citizen office; Cloudflare Turnstile (Cloudflare, Inc.) as the anti-bot check on the staff login and on the “Write to the OAC” form of the chat’s own website (not on the embedded widget): it processes the IP address and technical browser data to tell people from bots, is a necessary security measure (Art. 32 GDPR), sets no cookies on our domains and may process data outside the EU under Cloudflare’s data processing terms; Cloudflare also uses these signals, as an independent controller, to improve its bot detection (Turnstile privacy addendum). Moving Gemini to EU-located endpoints (Vertex AI) is planned. Full list in the DPA. Observability traces contain metadata only — never citizen text.
- Rights: exercised before the council; the chat’s privacy page explains how, and how to identify a conversation to have it deleted early.
EU AI Act
Visible “automated assistant (AI)” disclosure from the first message and an “AI” indicator on every answer. No high-risk categories: it doesn’t decide about people, doesn’t profile, doesn’t transact.
Spanish National Security Scheme (ENS)
Designed for ENS basic-level conformity: EU hosting with mandatory HTTPS (HSTS); individual staff accounts per town, strong passwords staff can change from the panel and a temporary lockout after repeated failed logins (two-factor authentication is on the roadmap and not available today); records of conversations, hand-offs and the delivery status of every email to the citizen office, plus the change history of the administration console; daily off-server database backups. Conformity declaration and file-ready report delivered at onboarding.
Data journey
Widget → HTTPS → EnaChat service (EU) → search over the town’s database (EU) → answer drafting: the question and the needed source excerpts go to Google’s Gemini API (move to Vertex AI in the EU planned) → answer with citations back to the citizen. Today step 4 does not guarantee that model processing stays inside the European Union; the Vertex AI migration with an EU endpoint is the planned change that will.
Accessibility
Widget conforms to WCAG 2.1 AA / EN 301 549, with the citizen office’s phone/in-person channel always visible.