What your IT team wants to know
CHEQ is operated by Talk-A-Bot Zrt. and built for enterprise environments. This page sums up what an IT evaluation asks first — detailed security documentation (policies, DPA, SLA) is available on request.
- GDPR compliance
- EU data storage
- Dedicated environment
- OWASP-based pentesting
- On-prem option
The essentials in six points
Isolated infrastructure
Every customer gets a dedicated environment — separate application and database instances. No shared database, no data mixing.
Data storage & GDPR
Personal data is stored within the European Union by default, in the data centres of leading cloud providers. Our data processing complies in every respect with Regulation (EU) 2016/679 (GDPR).
Encryption
Data travels over encrypted channels end to end. Passwords for encrypted documents (e.g. payslips) arrive via a separate channel and are never stored.
Minimal data footprint
We only process what messaging and authentication require: platform ID, display name, language — plus name, token and employee ID. During usage, only messages and their timestamps are collected.
Testing & monitoring
Regular penetration tests based on the OWASP methodology, continuous monitoring, centralised logging and alerting — and daily backups of the whole system.
Integration
CHEQ starts with zero backend integration by default. On demand, API, automated CSV or HR-system sync is available, with out-of-the-box Microsoft Entra ID (Azure AD) support.
Contractual guarantees
CHEQ is backed by a complete contractual framework: a service agreement, general terms, a data processing agreement (DPA) and a service level agreement (SLA). A few commitments from these:
99% availability
Monthly 99% availability, committed in a contractual SLA (on top of planned maintenance windows).
2-hour response time
We respond to critical (P1) incidents within 2 working hours at most — with support in Hungarian and English.
GDPR Article 28 DPA
We sign a data processing agreement with every customer, with a public list of sub-processors.
EU data centres
Personal data is processed and stored within the European Union.
Daily backups
The system is backed up daily, and incident handling follows a documented three-level escalation process.
Data returned on exit
On contract termination we return or delete your data, whichever you choose; conversation data is anonymised after one year of inactivity.
Common IT questions
Where does CHEQ run?
On the infrastructure of leading European cloud providers, in a dedicated, isolated environment per customer — with its own application and database. As a premium option, on-premise deployment or a customer-owned private cloud is also available.
What data does the system store about employees?
As little as possible. Messaging needs a platform ID, a display name and a language preference; access verification needs a name, a token and an employee ID. Optional HR attributes (e.g. department, site) only enter the system if you need them for targeted messaging.
Is the service GDPR-compliant?
Yes. We sign a data processing agreement (DPA) under Article 28 of the GDPR with every customer, data is stored in the EU, and the list of sub-processors is public. Details are in our privacy policy.
Is Viber safe for company communication?
The employee channel is end-to-end encrypted, and CHEQ connects to the platform over an encrypted connection. Sensitive content — such as payslips — additionally arrives with separate password protection, and the password reaches the employee via another channel.
How does encrypted document delivery work?
The document is encrypted in transit and at rest; the password needed to open it is sent via a separate channel (SMS) and is never stored. The unencrypted file is not retained at any point in the process.
Do we need to integrate it with our existing IT systems?
Not necessarily: the standard rollout works with zero backend integration. If you want automated employee-list updates, there are flexible options: an API connection, scheduled CSV imports or a custom integration — with out-of-the-box Microsoft Entra ID (Azure AD) support.
Who can access our data?
Your data lives exclusively in your dedicated environment, access is governed by the principle of least privilege, and every access is logged. Talk-A-Bot does not use personal data handled in CHEQ for its own purposes.
How do you test security?
We run regular penetration tests following the OWASP methodology. The system is continuously monitored through centralized logging and alerting. We operate under documented information-security and system-operations policies, which we share on request.
What happens to the data if we part ways?
On termination you choose: we return or delete your data, then delete the remaining copies. Conversation data is anonymised after one year of inactivity in any case.
Full details of our data processing are in the privacy policy: Privacy policy
We'll show you the rest live
The 30-minute demo covers your IT questions too — and we share the detailed security documentation on request.
