GDPR-compliant live chat

Chat with website visitors without your customer data ever leaving your Microsoft 365 tenant

Most live chat tools store your conversations on their own servers, often outside the EU, and use them for analytics or AI training. uWebChat works differently: messages flow through Microsoft Azure straight into Microsoft Teams, and the platform itself keeps nothing. That makes GDPR compliance a property of the architecture, not a checkbox you have to configure.

What the GDPR requires from live chat

A website chat processes personal data the moment a visitor types a name, email address or order number. Under the General Data Protection Regulation you must have a legal basis for that processing, be transparent about what you collect, keep the data secure, sign a data processing agreement with your chat provider, and be able to delete or export the data on request. If your provider stores chat transcripts outside the EU you also need a valid transfer mechanism. Each of those obligations gets easier when the chat tool stores as little as possible.

Where your chat data lives

uWebChat runs entirely on Microsoft Azure in the EU region. Every message is forwarded to your Microsoft Teams environment and is therefore governed by the same Microsoft 365 security, retention and compliance policies you already apply to Teams. Your Microsoft 365 tenant is the only place the conversation exists. There is no separate uWebChat database of chats, and no copy in a third-party cloud.

No data storage by the platform

The platform does not retain chat conversations. If you want a record, agents or administrators can archive transcripts to OneDrive or send them by business email, both inside your own tenant. You decide what is kept, for how long, and who can access it. Deleting a customer's data means deleting it in your own environment, without a request to a vendor.

Control what you collect

With custom fields you choose exactly which details a visitor is asked for before a chat starts: nothing, just a name, or name plus email and company. Data minimisation is built in rather than bolted on. Visitors can request a transcript of their own conversation, which supports the right of access without extra tooling.

Know who you are chatting with

Anonymous chat is a risk when sensitive information is involved. uWebChat can require visitors to verify their identity with a one-time code by email or SMS before the conversation begins, so an agent never shares account details with the wrong person. Agents can ban abusive visitors with one click, and Enterprise customers can block entire countries from starting a chat.

Data processing agreement and ISO 27001

uWebChat is built and operated by Universal.cloud, an ISO 27001 certified Microsoft partner based in Arnhem, the Netherlands. A data processing agreement is available for customers who need one for their GDPR records. Because the platform stores no chat content, the agreement is short and the list of sub-processors is essentially Microsoft.

GDPR checklist for live chat on your website

  • Chat data is processed in the EU (Azure EU region)
  • No chat transcripts stored by the chat provider
  • Conversations stay inside your Microsoft 365 tenant
  • Data processing agreement available
  • You control which visitor fields are collected
  • Visitor identity verification by email or SMS
  • Agents can block abusive visitors, admins can block countries
  • Operated by an ISO 27001 certified company

Frequently asked questions about GDPR and live chat

Is live chat allowed under the GDPR?

Yes. Live chat is allowed as long as you have a legal basis, inform visitors about the processing, secure the data and have a data processing agreement with your provider. uWebChat makes this straightforward because the platform stores no conversations and all data stays in your own Microsoft 365 tenant.

Where does uWebChat store chat conversations?

Nowhere. Messages pass through Microsoft Azure in the EU and are delivered to Microsoft Teams. The only place a conversation exists is your own Microsoft 365 environment. Optional archiving goes to your own OneDrive or business email.

Do I need a data processing agreement for live chat?

Yes, the GDPR requires a data processing agreement with every processor that handles personal data on your behalf. uWebChat can provide one. Contact us and we will arrange it.

Does the GDPR apply to a chat widget if I only get a name?

Yes. A name, an email address or even an IP address counts as personal data. With uWebChat you can decide to collect no fields at all, which keeps the processing minimal.

Can visitors request or delete their chat data?

Visitors can request a transcript of their own chat. Because the platform holds no data, deletion requests are handled inside your own Microsoft 365 environment, where you already have retention and deletion tools.

Is uWebChat also suitable for the UK GDPR and other privacy laws?

The same architecture applies: no data stored by the platform, hosting on Microsoft Azure and full control in your own tenant. That satisfies the core requirements of the UK GDPR and comparable privacy laws as well.

Start with GDPR-compliant live chat today

Free for 1 agent. Install the widget in 5 minutes and answer visitors from Microsoft Teams.

Start free

Ready to transform your customer communication?

Start your free trial today and see the difference