Skip to main content
Search

Where your data is stored

Where your EPAV Desk site and its database run, which services see conversations for AI answers, what the hosting agreement says about the United States, and what to expect from availability.

Your EPAV Desk site, with its conversations, contacts, files, knowledge base and settings, runs on Railway in the EU West region (Amsterdam, Netherlands), as a separate installation with its own database. Railway is a US company, and its data processing agreement says that primary processing takes place in the United States, so EPAV does not promise that your data never leaves the EU.

A separate installation for each company

Every company gets its own installation: its own application, database, cache and knowledge server, not an account inside a panel shared with other customers. Data of different customers is kept physically apart, not just separated by a filter.

Hosting region and the United States

The servers of your site, the application and its database, run on Railway in the EU West region, in Amsterdam, the Netherlands. Railway is a US company, and under its data processing agreement primary processing takes place in the United States. The GDPR applies to all of this processing, and the obligations of the controller of your customers' personal data remain yours.

Where AI requests go

Every request to an AI model passes through EPAV's AI gateway, which also runs on Railway and follows the provider list you set under Admin > AI > Providers. Where the text goes next depends on that list:

  • the cloud AI of your plan, after payment, works through OpenRouter, a US company that passes each request to the host of the model. It covers everything the AI does for your site:
  • writing answers, searching the knowledge base and transcribing voice messages go to hosts that keep no data (zero data retention). Searching sends the visitor's question and, when articles are imported or changed, their text;
  • ordering the found pieces of articles by relevance goes to Voyage AI (MongoDB) under EPAV's own account, which has opted out of data use, so Voyage keeps none of it. When that account does not answer, the same Voyage model is reached through OpenRouter, with data collection denied but without a zero retention condition;
  • images go first to a separate model by Alibaba that describes them, with data collection denied but without a zero retention condition;
  • our free model, which answers on the trial and when the cloud AI budget runs out, runs on EPAV's own capacity, see Availability below;
  • your own cloud provider receives, with your API key, the conversation text and the pieces of your articles needed for each answer, and processes them where it operates, under its own terms;
  • your own model on a computer in your office, which EPAV sets up for a separate fee, writes the answers, searches the knowledge base and transcribes voice messages on that machine, so no AI provider sees your conversations. The help desk with its conversations and knowledge base still runs on Railway.

Images that customers send in a conversation go to the model as well, while Model supports image input is on in the provider settings. See AI providers and your own model.

A backup provider sees what it answers

When the first model in your list cannot answer, for example because your office machine is off or offline, the request goes to the next provider in the list, and that provider sees the conversations it answers during that time. Without a backup provider, those conversations go to your agents instead. If this matters to you, choose a backup provider that processes data in the EU.

Knowledge base search and voice messages

Other models see parts of your data too:

  • the search model turns your articles and your customers' questions into search data. By default it is ours. A backup search provider, if one is set up, receives the text of all your articles to index them, and your customers' questions whenever it stands in for ours;
  • when reranking is available, a reranking model reads each question together with the pieces of articles that search found for it;
  • voice messages go as audio to the Speech recognition model: ours by default, or a provider you choose under Admin > AI > Providers, such as OpenAI or Groq.

The chat on your website

The program of the chat widget loads from EPAV's servers. The conversation itself, with the messages and the visitor's session, travels directly between the visitor's browser and your site.

Payments, email and messengers

Other services handle parts of your data in their own roles:

  • payments run on the page of creem, EPAV's payment provider, and EPAV does not receive your card details;
  • email from your customers arrives through your own mailbox, and emails to your agents go out through your own mail server or, with the EPAV mailbox, through the EPAV cabinet and the email delivery service EPAV uses;
  • messages in Telegram and WhatsApp pass through Telegram and Meta under their own terms;
  • webhooks and the assistant's custom tools send data only to the addresses you set up for them.

What EPAV can access

EPAV keeps access to your site to operate it. Your site has built-in service accounts that EPAV Desk uses, for example to set up the site, change its address and collect the usage figures shown in the cabinet, and they should not be edited or deleted. The cabinet also keeps a copy of the panel password it issued, which stops working once you set your own, see Signing in to the panel.

Model training

EPAV does not train or fine-tune models on your knowledge base or your conversations: the assistant looks up the matching articles each time it answers. Articles suggested from resolved conversations enter the knowledge base only after you approve them, see Learning from resolved conversations. What a cloud provider does with the requests it receives is governed by that provider's own terms.

Availability

The platform runs on Railway infrastructure, and you can follow its current status at https://status.railway.com. EPAV has no separate availability agreement. When the cloud AI of your plan does not answer, our free model takes over, and that one has no availability guarantee. For full cover, add your own provider as a backup. When no model can answer, the visitor is told that a colleague will reply, and the conversation goes to your agents.

Getting your data out

You can take your data with you at any time:

  • the whole knowledge base, through your own AI assistant connected over MCP, see Connect your AI (MCP);
  • a single conversation, with Download transcript in the conversation menu;
  • the data of one contact, with Export data on the contact page, for agents whose role includes the Export contact data permission;
  • conversations, messages, contacts and other records in bulk, through the REST API, see API keys and REST API.

Merging two contacts of one person

The same person writing from Telegram, WhatsApp and your website starts as separate contacts. On the contact page, Merge with… finds the other contact by email or phone, lets you choose which one to keep, and asks for confirmation. Conversations, messages, notes and channel links of the other contact move to the one you keep, empty fields are filled from it, its email, if different, is kept as a note, and the other contact is deleted; this cannot be undone. Two contacts signed in to your website or app as different users cannot be merged. The action needs the Merge contacts permission (Admin has it) and is recorded in the activity log.

When you leave

At the bottom of the cabinet, Delete my account and data sends EPAV a deletion request; it is carried out within 7 days, see Plans, limits and billing. When EPAV removes your account, your site is taken out of service and is never given to another customer; after that it is deleted together with its database.

Was this article helpful?