All articles
SecurityJuly 8, 20265 min read

Data security and privacy with an AI receptionist: the SMB guide

Before you trust an AI with your customers' requests, ask yourself (and your vendor) the right questions about GDPR, EU servers and data protection. Practical 2026 guide.


When you hand your phone calls and messages over to an AI, you're giving it access to sensitive data: names, numbers, emails, sometimes health or financial information. It's the question every business owner should ask before signing, and almost no one does: where does this data end up, who can see it, and what happens if something goes wrong?

In 2026 the Italian Data Protection Authority tightened its scrutiny of automated systems, and the EU AI Act is fully in force. Picking the wrong vendor isn't just a technical risk: it's a legal and reputational one that lands on you, the data controller.

This guide isn't marketing: it's the checklist of questions you should ask any conversational-AI vendor — Nexus included — with our honest answer to each.

Want to see how we handle a real conversation before we even talk contracts? Call the Medical Practice demo: +39 06 2019 7018. Notice what the AI asks — and, more importantly, what it does not ask.

Why it's your problem, not just the vendor's

Under GDPR, you are the data controller and the AI vendor is the data processor. Translation: if your vendor mishandles your customers' data, the legal responsibility — and the fines, up to 4% of turnover — fall first on you.

That's why security due diligence isn't a luxury for large companies. It's exactly what protects you when a customer asks "where do you keep my data?" or when an inspection shows up.

The 7 questions to ask an AI vendor

1. Where are the servers physically located?

Why it matters: if your Italian customers' data ends up on servers in the US or Asia, you step into the minefield of non-EU transfers. Many cheap chatbots run on global infrastructure with no localization guarantees.

Our answer: Nexus customer data is hosted on servers in the European Union (Azure, Italian region). No conversational data leaves the European Economic Area to run the service. It's a compliance requirement we treat as non-negotiable.

2. Is my data used to train the models?

Why it matters: some services use customer conversations to train their models. That means fragments of your business data can "live" inside a model shared with others.

Our answer: your customers' conversations and data power your assistant — not shared model training. The Knowledge Base you upload stays yours.

3. Who inside the vendor can access the data?

Why it matters: "the data is safe" means nothing if half the vendor's team can read it. The right principle is least privilege: everyone accesses only what they need.

Our answer: data access on a need-to-know basis, separation between environments, and access logging. No operator has blanket access to customer conversations.

4. How do you manage keys, passwords and secrets?

Why it matters: this is the technical question that exposes the amateurs. API keys written inside the code, passwords shared over email, credentials that are never changed: that's how most breaches happen.

Our answer: secrets (API keys, credentials) live in a dedicated secret store, never inside the code, and are rotated periodically. Every integration has its own individually revocable key, so a contained problem stays contained.

5. How do you handle consent and cookies?

Why it matters: the chat widget on your site collects data. Without compliant consent management, you're the one facing the regulator's fine, not the widget vendor.

Our answer: the widget and tracking respect Google Consent Mode v2 and a granular cookie banner: no analytics or marketing cookie is written before the user's explicit consent.

6. What happens in the event of a data breach?

Why it matters: no system is 100% invulnerable. The difference between a serious vendor and an improvised one is what they do when something goes wrong: detection, rapid containment, and notifying the authority within the 72 hours GDPR requires.

Our answer: continuous monitoring, timely security updates on dependencies, and an incident-response procedure that includes notification within legal deadlines. Security is a process, not a box ticked once.

7. Can I export and delete the data?

Why it matters: the right to erasure and to portability are guaranteed by GDPR. If the vendor makes it hard to take your data away or delete it, you have a structural compliance problem.

Our answer: your data stays yours. You can request export or deletion, with defined retention periods — not "forever by default".

What a well-designed AI receptionist does (for security)

  • Minimizes data: asks only what's needed to complete the request, not an endless form.
  • Hands off to a human for cases involving particularly sensitive data, instead of collecting it automatically.
  • Doesn't "make things up" and doesn't promise what it can't keep.
  • Leaves a verifiable trace of what it said and did.

What it should NOT do (red flags)

  • Ask for detailed health or financial data over an unprotected chat.
  • Keep call recordings indefinitely for no reason.
  • Fail to offer a signable DPA (data processing agreement).
  • Be unable to answer question 1 ("where are the servers?").

If a vendor stumbles on these, it's not a matter of price: it's a matter of risk.

Our approach, in one line

We treat your customers' data the way we'd want ours treated: in Europe, minimized, encrypted in transit, with secrets managed properly and a continuous security process — not a slogan on the homepage.

Transparency first: find our data and AI principles on the AI Transparency page, and the terms in the DPA and Privacy Policy.

Conclusion

Choosing an AI receptionist isn't (only) a marketing decision: it's a decision about the security of your customers' data, which you're legally responsible for. The 7 questions above let you tell a serious vendor from one that will offload the risk onto you — in 15 minutes.

The golden rule: if a vendor can't clearly answer "where are the servers" and "how do you manage keys", the conversation is already over.

Next step: ask us these 7 questions, no filter. Talk to our team or see the plans. If the answers convince you, we'll set up your assistant with security done right from day one.

Read next: AI receptionist for hotels · Italian voicebot: an SMB guide · AI Transparency

For enterprises & system integrators

Deploy Nexus. Or distribute it to your clients.

Multi-tenant by design — built for enterprises that want to automate, and for the integrators that want a platform to resell.

CallWhatsApp
Data security and privacy with an AI receptionist: the SMB guide | Nexus AI