Technology4 min read
Herodesk’s AI processes your customer data in the EU
Herodesk runs AI on infrastructure in Denmark and Germany and does not send conversations to OpenAI or Anthropic. See what that means for your data and GDPR.

Herodesk runs its AI models on infrastructure in Denmark and Germany. Customer conversations are not sent to OpenAI, Anthropic or other external model providers.
That means a simpler data flow, fewer sub-processors and better control over your customer data.
When AI helps with customer service, the model necessarily has to process the content it works with. That can include names, order numbers, contact details, complaints and other parts of the customer conversation.
So choosing AI is not only about how well the model replies. It is also about where the data is sent, who gets access to it, and who controls the infrastructure.
Many helpdesk tools connect their platform to external model providers such as OpenAI or Anthropic. That can still be part of a lawful GDPR setup, but it creates more data flows, more vendor relationships and more documentation.
Herodesk has chosen a different approach.
We have removed the extra AI layer
We do not use OpenAI, Anthropic or another external model provider to process your customer conversations.
The AI features in Herodesk run on models we host and manage ourselves on infrastructure in Denmark, connected to the rest of our European setup in Germany.
That includes:
- Translation of customer conversations
- Suggested replies
- AI agents that answer customer enquiries
- AI agents that take action through your integrations
Your customer conversations are therefore not sent on to an external American model API to generate a reply.
That does not mean the AI features become less advanced. It simply means the processing happens on infrastructure Herodesk controls in the EU.
Server location does not tell the whole story
Having a server in Frankfurt, Dublin or another European city is a plus, but location cannot stand on its own.
You also need to look at who owns and controls the vendor, who has access to the data, which sub-processors are used, and which rules apply to any transfers.
In 2018, the United States passed the CLOUD Act. It concerns US authorities’ access to electronic information held by US-based global providers, including when that information is located outside the United States.
That does not mean every American vendor automatically breaches GDPR. Personal data can, among other things, be transferred lawfully to participating US companies through the EU-US Data Privacy Framework, or by using other relevant transfer tools.
But it does mean that a European server location does not necessarily give the full picture of who can access the data.
Why Article 48 matters
GDPR Article 48 states that a decision or order from an authority in a third country cannot automatically be used as a lawful basis for disclosing personal data from the EU.
According to the European Data Protection Board, a specific disclosure needs both a legal basis under GDPR Article 6 and to meet the rules on transfers to third countries in GDPR Chapter V.
So businesses should not only ask where a vendor’s servers are. They should also ask who controls the data, which vendors are involved, and how many places customer data is processed.
At Herodesk, we have made that data flow as simple as possible.
What does this mean for you in practice?
When you use AI in Herodesk:
- Customer conversations are not sent to OpenAI or Anthropic
- AI requests are processed on infrastructure in the EU
- You avoid an external AI model provider as an extra sub-processor
- Your data flow becomes simpler to describe and document
- You keep features such as translation, suggested replies and automated AI agents
That especially matters when you need to review a data processing agreement, fill in a security questionnaire, or document how your vendors process personal data.
GDPR is about more than hosting
Processing AI data in the EU does not automatically make every use GDPR-compliant.
GDPR also depends on, among other things, the legal basis, purpose, access control, data minimisation, retention, deletion, security, and how the individual company actually uses the system.
But the technical architecture matters.
With Herodesk, we remove a substantial complexity: your customer conversations do not have to be sent to an external American model provider for you to use modern AI in customer service.
That is a deliberate choice.
AI should make customer service faster and better without making control over customer data harder to see.
That is why we built Herodesk’s AI to run on our own European infrastructure.
Book a demo and see how it works in practice.
Give your team time back
Start your free trial with free VIP onboarding. Meet a product specialist online and get personal help until everything is up and running to your satisfaction.

Ken Primby
CEO · Pluspige
From a Herodesk customer
4–6
hours saved on cleanup after live sales
Read the customer story“Herodesk brought all our channels together, saved us several hours of manual cleanup after our live sales and gave the team a clear overview.”
















