GDPR compliance overview
OneClickClaw is based in the European Union (Greece) and is fully GDPR compliant. Data protection is built into our platform from the ground up, not added as an afterthought. All data processing occurs within the EU, we collect only the minimum data necessary to provide the service, and you retain full control over your personal data at all times.
Note
As an EU-based company, GDPR compliance is built into our platform from the ground up, not an afterthought.
Controller vs. processor
Under GDPR, roles are clearly defined:
- You are the data controller for your end users' data. If people interact with your AI agent, you determine the purpose and means of processing their data (messages, conversations, etc.).
- OneClickClaw is the data processor. We process personal data only on your behalf and only to the extent needed to provide the hosting service (account management, billing, server provisioning).
This distinction means you are responsible for informing your end users about how their data is handled when they interact with your AI agent. We provide the infrastructure; you control the data processing decisions.
Your rights under GDPR
As a OneClickClaw user, you have the following rights regarding your personal data:
- Right of access: You can view all your account data, server metrics, and agent configuration from your dashboard at any time.
- Right to rectification: You can update your account information through your dashboard settings or by contacting support.
- Right to erasure: You can request complete deletion of all your data. Your VPS is destroyed, your account record is deleted, and billing records are retained only as required by EU tax law.
- Right to data portability: You can download a diagnostic bundle containing your server configuration and logs. For a complete data export, contact support.
- Right to restriction: You can request that we limit processing of your data while a complaint is being resolved.
Option 1: Dashboard
Option 2: Email
Option 3: Support Ticket
How to exercise your rights
You can exercise any of these rights through two channels:
- Email: Contact info@oneclickclaw.io with your request. Include your account email so we can verify your identity. We respond to all requests within 30 days, as required by the GDPR.
- Dashboard: Many actions (viewing data, updating account info, downloading diagnostic bundles) are available directly from your dashboard settings without needing to contact us.
Tip
If you are not satisfied with our response to a data request, you have the right to lodge a complaint with your local data protection authority.
Subprocessors
OneClickClaw uses a limited number of trusted subprocessors to deliver the service:
| Subprocessor | Purpose | Location | Data Safeguards |
|---|---|---|---|
| Stripe | Payment processing | USA | EU Standard Contractual Clauses (SCCs), PCI DSS Level 1 |
| Webdock | VPS infrastructure | Denmark (EU) | EU jurisdiction, no access to VPS software/data |
| Resend | Transactional email | USA | EU Standard Contractual Clauses (SCCs) |
| Google OAuth | Authentication | USA | EU Standard Contractual Clauses (SCCs), limited to name/email |
Note
OneClickClaw does not use your data for marketing, profiling, or automated decision-making. We do not sell or share your data with third parties beyond the subprocessors listed above.
For a detailed breakdown of what data we collect and store, see Data & Privacy.
