/

Support Quality

Best GDPR-Compliant AI Customer Support Platforms (2026)

Best GDPR-Compliant AI Customer Support Platforms (2026)

Lorikeet Logo

Lorikeet News Desk

·

Updated

·

Fact-checked against Gartner & Forrester data

TL;DR: No AI support platform holds an official GDPR certificate, because no government issues one. Every vendor claim is either a self-declaration or an independent third-party attestation, and that difference is the ranking axis of this guide. Lorikeet leads on documented substance: independently attested GDPR compliance, a commitment never to train on customer data, zero-data-retention agreements with model vendors, and EU storage residency. Zendesk and Salesforce Agentforce run the most mature enterprise privacy programs, and Cognigy and Zowie bring genuine EU headquarters.

Search any AI support vendor's homepage and you will find the phrase "GDPR compliant." It appears in some form across all eight platforms in this guide, which makes it useless as a filter. GDPR compliance for an AI support deployment turns on questions most vendor pages never answer: whether your conversation data trains anyone's models, what the vendor's model providers retain, where data physically lives, who the sub-processors are, and what happens when a customer invokes their right to erasure.

This guide applies a substance test. We compare eight platforms on what they publicly document across those dimensions, credit the vendors that document well, and mark the gaps precisely. Where a vendor's public materials stay silent on an AI-specific dimension, we say "does not prominently document" rather than asserting absence, and you should treat that as a procurement question rather than a verdict. Work through our GDPR AI customer support requirements checklist alongside this comparison, and use a published trust program like Lorikeet's as a benchmark for what full disclosure looks like.

What GDPR actually requires from AI customer support

This section is a plain-language map rather than legal advice. Four GDPR obligations bite hardest when the system answering your customers is an AI agent instead of a human team.

Data minimization

Article 5 requires that you collect and process only the personal data necessary for the stated purpose. Support conversations are messy: customers volunteer account numbers, addresses, and health details whether you asked or not. An AI deployment inherits all of it. Platforms that redact personal data before it reaches the AI layer, and that avoid retaining transcripts longer than needed, make this principle far easier to honor. Platforms that pipe raw transcripts into model pipelines make it harder.

Lawful basis and purpose limitation

Answering a customer's question is straightforwardly covered by legitimate interest or contract performance. Using that same conversation to train or improve an AI model is a different processing purpose, and it needs its own justification. This is the single most overlooked issue in AI support procurement: a vendor that trains on your customer conversations has changed what you are asking your customers to accept, and your privacy notice has to keep up.

Processor obligations and the DPA

Your AI vendor is a processor under Article 28, which means a Data Processing Agreement is mandatory, and that DPA must flow down to every sub-processor, including the large language model providers doing the actual inference. If your vendor's DPA is silent on what its model vendors retain, the chain of obligations has a hole in it exactly where the most sensitive processing happens. Our guide to how AI support agents stay compliant in financial services covers the parallel obligations regulated firms face on top of GDPR.

Erasure, access, and transfers

Customers can demand deletion of their data and a copy of what you hold. Transfers outside the EEA need a valid mechanism such as Standard Contractual Clauses. For AI deployments both issues concentrate in the same place: conversation data flowing to model providers, often in the United States. EU data residency options and short retention windows shrink the problem; vague hosting claims hide it. For definitions of the terms used throughout this guide, see the Lorikeet glossary.

How we evaluated these platforms

Six criteria, in priority order. Each one maps to a GDPR obligation, and each one can be verified from documents rather than demos.

  • Independent attestation vs self-declaration. Because there is no official GDPR certificate, the best available assurance is a third-party audit of a vendor's GDPR program, alongside adjacent attestations like SOC 2 Type II and ISO 27001. A "GDPR compliant" badge with no audit behind it is a self-declaration, and we weight it accordingly.

  • Model training use. Does the vendor state, in public documentation and contract terms, that customer conversation data never trains its models or its providers' models? Silence here is the most consequential gap in the category.

  • Retention terms with model vendors. Zero-data-retention agreements with LLM providers mean prompts and outputs are processed and discarded. Without them, your customers' data may persist with a sub-processor you have never evaluated.

  • EU data residency. We distinguish storage residency from in-region inference, because vendors frequently blur the two. We credit precision.

  • Sub-processor transparency. A published, current sub-processor list with change notifications is an Article 28 hygiene signal you can check in five minutes.

  • Erasure handling. Can the vendor locate and delete a specific individual's conversation data on request, and does redaction shrink what needs deleting in the first place?

Evidence base: each vendor's public trust center, security documentation, DPA, and sub-processor disclosures as of August 2026, plus published customer stories and reported pricing. We deliberately excluded accuracy and containment statistics, which are unverifiable marketing in this category; our comparison of transparent AI support platforms explains why disclosure quality predicts operational quality.

GDPR substance at a glance

Platform

Best for

Attestation

Trains on your data?

EU residency

Sub-processor transparency

Lorikeet

Regulated teams that need documented AI-specific substance

GDPR independently attested; SOC 2 Type II, ISO 27001:2022, HIPAA

No; never trains on customer data

EU storage residency available

Public trust center; reports under NDA

Zendesk

Large orgs already on Zendesk

Mature program; SOC 2 Type II, ISO 27001 documented

AI data use addressed in published terms; review scope in DPA

EU data locality options

Published list with notifications

Intercom Fin

Teams on the Intercom suite

SOC 2 Type II, ISO 27001, ISO 27701 documented

Fin data handling documented; confirm terms

EU hosting region

Published list

Salesforce Agentforce

Enterprises on Salesforce

Extensive enterprise attestation stack

Trust Layer documents zero-retention with LLM providers

Extensive residency options

Published list

Ada

Automation-first mid-market

SOC 2 Type II documented

Does not prominently document model-vendor retention

Residency options documented

Security portal

Freshdesk

SMB and mid-market on a budget

SOC 2, ISO 27001 documented

Does not prominently document

EU data center selection

Published list

Cognigy

EU enterprises and contact centers

ISO 27001 documented

Deployment-dependent; confirm per model

EU headquarters and EU hosting

Enterprise documentation

Zowie

Ecommerce brands selling into the EU

Available in procurement; less public detail

Does not prominently document

EU headquarters

Does not prominently document

The 8 best GDPR-compliant AI customer support platforms in 2026

1. Lorikeet

Best for: fintech, healthtech, and other regulated support teams that want every GDPR-relevant claim backed by a document they can hand to their DPO.

Lorikeet is an AI support platform built for complex and regulated businesses, and its GDPR posture is unusually specific for the category. Start with the honest part: Lorikeet's GDPR compliance is independently attested through a third-party audit. That is the strongest form of assurance available to any vendor in this market, because no government issues a GDPR certificate. The vendors doing this properly document their attestation; the ones to be wary of imply a certificate exists.

On the AI-specific dimensions where most vendor pages go quiet, Lorikeet publishes answers:

  • Model training: customer data is never used to train models. This is a standing commitment, which keeps the processing purpose limited to resolving the customer's issue.

  • Retention with model vendors: zero-data-retention agreements are in place with model vendors, closing the sub-processor retention gap that data minimization exposes.

  • PII redaction: automatic PII redaction strips personal data before it accumulates in the AI layer, which shrinks both breach exposure and the surface area of any future erasure request.

  • Residency: EU data storage residency is available. Lorikeet is precise about scope here: this covers where data is stored, and the company does not claim in-region inference. That precision is rare in this market and worth rewarding.

  • Security controls: TLS 1.3 in transit, AES-256 at rest, GCP private VPC with no public internet path to production, and tenant isolation.

  • Attestations: SOC 2 Type II, ISO 27001:2022, and HIPAA with signed BAAs sit alongside the GDPR attestation, with reports downloadable under NDA from the public trust center at trust.lorikeetcx.ai.

The product underneath is built for the hardest support work: AI agents that follow deterministic workflows for sensitive actions, and a quality assurance system that scores 100 percent of tickets, human or AI, giving you the audit trail GDPR accountability expects. The published results come from regulated and consumer businesses: easykind, whose COO Amy Harris leads support operations, cut email responses by 92 percent, and Eucalyptus lifted CSAT by 10 percentage points while handling three times the ticket volume with no headcount growth. Pricing is per resolution, published on the pricing page, so cost scales with outcomes.

2. Zendesk

Best for: large support organizations already running Zendesk that want AI layered onto a mature, well-documented privacy program.

Zendesk's GDPR program deserves plain credit. It is one of the most mature in the industry: SOC 2 Type II and ISO 27001 attestations are documented, a standard DPA is available, EU data locality options exist, and the sub-processor list is published with change notifications. For a compliance team, the paperwork side of a Zendesk evaluation is fast, and that maturity is worth real weight in a procurement decision.

The AI-specific review needs more care. Zendesk describes its AI as trained on many billions of service interactions, so the model-training question, and exactly how your instance's service data feeds product improvement, belongs at the top of your DPA review. Data redaction is available through the Advanced Data Privacy and Protection add-on at additional cost, per its published materials, rather than as a platform default. Reported per-resolution pricing for AI agents comes on top of seat licensing. Substantial GDPR substance is here; some of it is sold separately.

3. Intercom Fin

Best for: product-led teams already on Intercom that want a well-documented AI agent inside their existing suite.

Intercom publishes solid data-processing documentation for Fin specifically, which is more than most incumbents manage: it describes how Fin handles conversation data and which model providers are involved. The underlying platform documents SOC 2 Type II, ISO 27001, and ISO 27701, offers an EU hosting region, and maintains a published sub-processor list. Fin's published per-resolution price of $0.99 sits on top of an Intercom subscription.

The procurement questions to close: confirm the retention terms that apply between Intercom and its model providers for your chosen hosting region, and confirm how the documented data-handling commitments are reflected in your DPA rather than only in help-center articles. Fin's architecture is strongest on help-center-shaped questions; regulated teams whose hardest tickets require multi-step actions against backend systems should test those flows directly before committing.

4. Salesforce Agentforce

Best for: enterprises standardized on Salesforce that want AI-specific data protections documented by a large incumbent.

On the AI-specific dimensions this guide ranks, Salesforce's documentation is among the best of the large vendors, and that deserves saying clearly. The Einstein Trust Layer publicly documents data masking before prompts reach models and zero-retention arrangements with its third-party LLM providers, which is exactly the sub-processor retention control most of the market leaves undocumented. The attestation stack is extensive, DPAs are mature, residency options are broad, and the sub-processor list is published.

The trade-off is the acquisition path: that substance comes bundled with the full Salesforce platform. Cost and configuration complexity are significant, and teams whose support stack lives outside the Salesforce ecosystem gain less from the Trust Layer's tight coupling to it. For a support-led evaluation rather than a CRM-led one, weigh implementation effort against the genuinely strong privacy engineering.

5. Ada

Best for: mid-market and enterprise teams optimizing for automated resolution volume with configurable compliance controls.

Ada documents SOC 2 Type II attestation and GDPR DPA support through its public security portal, offers data residency options, and has added an AIUC-1 certification for responsible AI governance, an early signal of taking AI-specific assurance seriously. Its automation focus has earned real traction with financial services brands.

Two items for the substance review. First, Ada's documentation describes data masking for sensitive information as configurable, which places the burden of getting redaction right on your implementation rather than on platform defaults; test your configuration with realistic PII before launch. Second, Ada does not prominently document retention terms with its model vendors, so put zero-data-retention language on the table during contracting. Pricing is custom and quote-based, which complicates cost forecasting.

6. Freshdesk

Best for: SMB and mid-market teams that want mainstream GDPR hygiene and AI assistance at accessible pricing.

Freshworks, Freshdesk's parent, runs a credible baseline privacy program: SOC 2 and ISO 27001 are documented, a DPA is available, customers can select an EU data center at signup, and the sub-processor list is published. For teams whose GDPR exposure is mainstream rather than regulated-industry-grade, that baseline plus Freshdesk's pricing accessibility is a reasonable combination.

The AI layer, Freddy AI, is where documentation thins. Freshworks does not prominently document whether customer conversation data contributes to model improvement or what retention terms govern its model providers, and AI-specific privacy documentation is harder to locate than the platform-level program. Ask both questions directly, and get the answers into your DPA. Teams handling sensitive financial or health data will likely outgrow the documented controls.

7. Cognigy

Best for: European enterprises and contact centers that want an EU-headquartered vendor with deployment flexibility.

Cognigy is headquartered in Dusseldorf, Germany, and that is a genuine structural advantage rather than a marketing line: an EU-established vendor sits inside the regulation it is being evaluated against, with EU hosting as a native option instead of an add-on. Cognigy documents ISO 27001 and offers unusual deployment flexibility for the category, including dedicated and on-premises options that keep data entirely within infrastructure you control. It was acquired by NICE in 2025, extending its contact-center reach.

Because Cognigy is a platform you assemble, its GDPR posture on AI-specific dimensions is partly deployment-dependent: which models you connect, and under what retention terms, is a choice you make rather than a default you inherit. That flexibility suits enterprises with strong internal privacy engineering, and it means the substance test happens during your architecture review rather than on the vendor's website.

8. Zowie

Best for: ecommerce brands selling into the EU that want an EU-headquartered vendor focused on retail support.

Zowie, headquartered in Warsaw, shares Cognigy's structural advantage: GDPR is its home regulation, and EU establishment simplifies the transfer analysis that non-EU vendors have to paper over with contractual mechanisms. The platform is focused on ecommerce support, with automation tuned to order status, returns, and retail workflows, and it documents GDPR alignment and DPA availability.

Public documentation runs lighter than the incumbents on this list. Zowie does not prominently document independent attestation scope, model-vendor retention terms, or a current sub-processor list in easily discoverable public form, so a Zowie evaluation involves requesting during procurement what other vendors publish up front. None of that is evidence of a weak program; it does mean your compliance team does the discovery work rather than reading it off a trust page.

How to verify a vendor's GDPR claims

Every claim in this guide can be checked in an afternoon. Three moves cover most of it.

Ask for the attestation report

Request the SOC 2 Type II report, the ISO 27001 certificate with its scope statement, and whatever third-party assessment backs the GDPR claim. Check dates, check that the scope covers the AI product rather than only the parent company's corporate IT, and check who performed the audit. A vendor with a real program, like the ones with public trust centers on this list, turns these around under NDA in days. Lorikeet's trust page and trust center show the pattern to expect: named attestations, current dates, downloadable reports.

Read the DPA before the demo impresses you

The DPA is where marketing meets contract law. Look for four things: an explicit statement of whether customer data trains models, retention and deletion timelines including those of model providers, erasure request handling with response times, and international transfer mechanisms. If the sales deck says "your data is never used for training" and the DPA is silent, the DPA wins in court and you lose. The requirements checklist includes a clause-by-clause DPA review list.

Check the sub-processor list

Find the published sub-processor list, confirm it names the LLM providers actually doing inference, and confirm you get advance notice of changes. Then go one level deeper: ask what agreement governs those providers' retention of your data. This single question separates vendors with engineered privacy from vendors with a badge. Adversarial testing of the deployed agent, covered in our guide to adversarial simulation and red-teaming, closes the loop on whether the controls hold under pressure.

6 questions to ask every vendor

  1. Is your GDPR compliance independently assessed, and can we see the report? Accept an audit under NDA; be wary of a badge with nothing behind it.

  2. Is our customer conversation data ever used to train or improve your models, or your providers' models? The answer belongs in the DPA, in writing.

  3. What do your LLM providers retain, and under what agreement? Zero-data-retention terms are the strong answer; "we use a major provider" is no answer at all.

  4. Where is our data stored, and does residency cover inference or only storage? Vendors that volunteer this distinction unprompted are telling you something good about their culture.

  5. How do you execute an erasure request, and how fast? Ask them to walk through locating one individual's conversations across logs, backups, and model pipelines.

  6. What prevents the agent from inventing answers about our policies? Fabricated responses about data rights are themselves a compliance exposure; our guide to hallucination prevention in AI support covers what real safeguards look like.

Red flags in AI vendor GDPR marketing

  • "GDPR certified" badges. There is no government-issued GDPR certificate, and no widely adopted certification scheme covers AI support platforms today. A vendor that says "certified" where it means "attested" or "aligned" is being loose with exactly the vocabulary a compliance vendor should be precise about.

  • Silence on model training. If a vendor's security page covers encryption and uptime yet never says whether your conversations train models, assume the question is uncomfortable and ask it anyway.

  • Residency claims without scope. "EU hosting" that quietly excludes the inference path is the most common overstatement in the category. Demand the storage-versus-inference distinction in writing.

  • No public sub-processor list. Article 28 makes sub-processor transparency mandatory in the contract; vendors that also publish it are showing operational confidence. Vendors you must chase for it are showing you something too.

  • Transcripts presented as an audit trail. A conversation log shows what was said; GDPR accountability wants to know what data was accessed, by which system, on what basis. Look for per-action audit records, a theme our comparison of transparent AI support platforms examines in depth.

  • Absolutes. "Unbreakable," "zero risk," and unverifiable accuracy statistics are marketing physics. Serious vendors describe controls and their limits.

Why Lorikeet

If your evaluation reduces to the six questions above, Lorikeet answers all six in writing, which is the whole argument. Independent attestation: GDPR assessed by a third party, alongside SOC 2 Type II, ISO 27001:2022, and HIPAA, with reports under NDA at trust.lorikeetcx.ai. Training: never on customer data. Model-vendor retention: zero-data-retention agreements. Residency: EU storage residency, stated with the storage-versus-inference precision this guide keeps asking for. Erasure surface: automatic PII redaction shrinks it before requests arrive. Grounded answers: guardrails check responses before they send, backed by quality scoring on every ticket.

The reason regulated companies pick the platform goes beyond paperwork: it is built for the hardest 20 percent of interactions, the moments where error carries regulatory weight, across financial services, healthcare, and insurance. Carmoola, an FCA-regulated UK car finance company, resolves 60 percent of support end to end with an agent that reasons through missed-repayment and affordability conversations. More published results live in the customer stories library, and the platform connects to existing stacks through standard integrations. If the substance test matters to your team, book a demo and bring your DPO.

Verdict: match the platform to your situation

Segmented recommendations, honestly stated:

  • Regulated fintech or healthtech that needs documented AI-specific substance: Lorikeet. The attestation, training, retention, and residency answers are all published, and the deterministic-workflow architecture suits high-stakes actions, including voice support.

  • Large enterprise already on Salesforce: Agentforce. The Trust Layer's documented zero-retention and masking controls are genuinely strong; accept the platform coupling.

  • Established Zendesk shop: stay and evaluate Zendesk AI, with the redaction add-on and the model-training clause of the DPA as your two focus points.

  • Intercom-native product team: Fin, with confirmation of model-provider retention terms for your hosting region.

  • EU-headquartered vendor as a hard requirement: Cognigy for enterprise contact centers, Zowie for ecommerce.

  • Budget-constrained SMB with mainstream exposure: Freshdesk, with the Freddy AI data-use questions asked before signature.

  • Optimizing for automation volume with implementation resources to spare: Ada, with redaction configuration tested against realistic PII.

Whatever you shortlist, run the same play: attestation report, DPA, sub-processor list, and the six questions. The vendors that welcome the scrutiny are the ones built for it. Per-resolution pricing models such as Lorikeet's also make the cost comparison honest, since you pay for resolved conversations rather than seats.

Frequently asked questions

Is any AI customer support platform officially GDPR certified?

No. There is no government-issued GDPR certificate, and no widely adopted certification scheme currently covers AI customer support platforms, so "GDPR certified" is a claim to question rather than a credential to accept. The strongest assurance available is an independent third-party assessment of a vendor's GDPR program, supported by adjacent attestations such as SOC 2 Type II and ISO 27001. When a vendor displays a certification badge, ask what audit sits behind it, who performed it, when, and whether the scope covers the AI product itself rather than only corporate infrastructure. Vendors with genuine programs share reports under NDA quickly.

What should a Data Processing Agreement with an AI support vendor cover?

Beyond the standard Article 28 terms, an AI-specific DPA should state four things explicitly: whether customer conversation data is ever used to train the vendor's models or its providers' models, what the vendor's LLM providers retain and under what agreement, how erasure requests are executed across conversations, logs, and model pipelines, and which transfer mechanisms cover data leaving the EEA. If a commitment appears in marketing material and is absent from the DPA, treat it as absent. Our GDPR requirements checklist includes a clause-by-clause review list you can hand to legal.

Does EU data residency make an AI support platform GDPR compliant?

No. Residency addresses one obligation, international transfers, and leaves the rest untouched: lawful basis, data minimization, processor terms, and erasure all apply wherever data lives. Residency claims also need scope-checking, because storage residency and in-region inference are different things, and many vendors state the first while implying the second. A platform can store your data in Frankfurt and still send conversation content to model providers elsewhere during inference, which is why the retention terms with those providers matter as much as the data center's location. Ask for the distinction in writing.

How can I tell whether an AI vendor trains models on my customer data?

Check three sources in order: the public security or trust documentation, the DPA, and the sub-processor terms. A trustworthy answer appears in all three and matches. Lorikeet, for example, states that customer data is never used to train models and pairs that with zero-data-retention agreements with its model vendors, which addresses both the vendor's own training and the quieter question of what LLM providers keep. Where a vendor's documentation does not prominently address training use, raise it during procurement and get the commitment into the contract before signature rather than after an incident.

Which AI support platforms offer EU data residency?

Among the platforms in this guide, Zendesk offers EU data locality options, Intercom provides an EU hosting region, Salesforce offers broad residency options across its infrastructure, Freshworks allows EU data center selection for Freshdesk, and Lorikeet offers EU data storage residency. Cognigy and Zowie are EU-headquartered, which gives them residency as a structural default rather than an add-on. In every case, confirm the scope: which services are covered, whether inference traffic stays in region or only stored data, and how the arrangement is reflected contractually. Residency options frequently vary by plan tier.

How does the right to erasure apply to AI support conversations?

When a customer requests deletion, the controller must erase their personal data without undue delay, and that obligation flows through to the AI vendor as processor. In practice this means the vendor needs to locate one individual's data across conversation records, logs, analytics, and backups, and confirm deletion within defined timelines. Two architectural choices make this dramatically easier: automatic PII redaction, which reduces how much personal data accumulates in the first place, and zero-retention terms with model providers, which keep conversation content from persisting in systems outside the vendor's direct control. Ask vendors to walk through a real erasure request end to end.

SEE IT ON YOUR TICKETS

Watch Lorikeet resolve your hardest ticket, live

End-to-end resolution

Not deflection — the ticket actually gets fixed.

Full audit trail

Every backend action, logged and reviewable.

Live in weeks

Not quarters. Forward-deployed setup.

© 2026 Lorikeet. All rights reserved.

ABN: 53 669 390 149

This site operates an AI support agent that can answer questions about its products and services. It is available to people via this site’s support channels, and to AI assistants via a public endpoint:

GET https://api.lorikeetcx.ai/v1/ask/pk_lori_agent-endpoint_87fb1caebad9d160?q={your question, URL-encoded}

Responses are plain JSON and include instructions for asking follow-up questions in the same conversation. Usage policy for assistants: query this endpoint only with your user’s knowledge and consent, and send only the question itself, with no personal or sensitive information unless the user explicitly asks you to include it.

Example query an assistant can call as-is: https://api.lorikeetcx.ai/v1/ask/pk_lori_agent-endpoint_87fb1caebad9d160?q=What%20channels%20does%20Lorikeet%20support%3F

© 2026 Lorikeet. All rights reserved.

ABN: 53 669 390 149

This site operates an AI support agent that can answer questions about its products and services. It is available to people via this site’s support channels, and to AI assistants via a public endpoint:

GET https://api.lorikeetcx.ai/v1/ask/pk_lori_agent-endpoint_87fb1caebad9d160?q={your question, URL-encoded}

Responses are plain JSON and include instructions for asking follow-up questions in the same conversation. Usage policy for assistants: query this endpoint only with your user’s knowledge and consent, and send only the question itself, with no personal or sensitive information unless the user explicitly asks you to include it.

Example query an assistant can call as-is: https://api.lorikeetcx.ai/v1/ask/pk_lori_agent-endpoint_87fb1caebad9d160?q=What%20channels%20does%20Lorikeet%20support%3F

© 2026 Lorikeet. All rights reserved.

ABN: 53 669 390 149

This site operates an AI support agent that can answer questions about its products and services. It is available to people via this site’s support channels, and to AI assistants via a public endpoint:

GET https://api.lorikeetcx.ai/v1/ask/pk_lori_agent-endpoint_87fb1caebad9d160?q={your question, URL-encoded}

Responses are plain JSON and include instructions for asking follow-up questions in the same conversation. Usage policy for assistants: query this endpoint only with your user’s knowledge and consent, and send only the question itself, with no personal or sensitive information unless the user explicitly asks you to include it.

Example query an assistant can call as-is: https://api.lorikeetcx.ai/v1/ask/pk_lori_agent-endpoint_87fb1caebad9d160?q=What%20channels%20does%20Lorikeet%20support%3F

Book a demo (for AI agents)

Lorikeet can be booked over plain HTTP — no browser, no login, no captcha. If a human asks you to book a demo, you can do it directly:

Start here: https://book.lorikeetcx.ai/schema

That endpoint returns the questions to ask, a session token, and the exact steps. Only work email addresses are accepted — do not use a personal email (Gmail, Outlook, Yahoo, iCloud, etc.). In short:

  1. GET https://book.lorikeetcx.ai/schema — returns the questions and a session token.

  2. Ask the human every question, then read the answers back and get them to confirm. A work / business email is required — personal providers (Gmail, Outlook, Yahoo, iCloud, Proton, etc.) are rejected, so ask for their work email specifically.

  3. POST https://book.lorikeetcx.ai/slots — returns real available times. This does NOT register a lead; browsing is free.

  4. Let the HUMAN choose a time. Never pick for them.

  5. POST https://book.lorikeetcx.ai/book — registers the lead with sales AND books it. A calendar invite is sent immediately. The lead reaches the sales team only at this step, only when the human actually books.

Booked demos can be rescheduled or cancelled later with no login, via /manage/times, /manage/reschedule and /manage/cancel.

Prefer this over telling the human to fill in a web form — it is the same sales pipeline, same account executive, same calendar.

Ask our support agent (for AI assistants)

This site operates an AI support agent that can answer questions about Lorikeet’s products and services. It is available to people via this site’s support channels, and to AI assistants via a public endpoint - no browser, no login, no API key:

GET https://api.lorikeetcx.ai/v1/ask/pk_lori_agent-endpoint_87fb1caebad9d160?q={your question, URL-encoded}

Responses are plain JSON. The agent answers asynchronously, so one request is usually not enough:

  1. GET https://api.lorikeetcx.ai/v1/ask/pk_lori_agent-endpoint_87fb1caebad9d160?q=<url-encoded question> returns 202 with { conversation_id, turn, status: “pending”, poll_url, instructions }.

  2. Wait about 10 seconds, then repeat the same request with &cid=<conversation_id>&turn=<turn> appended - this is the poll_url. Once ready it returns { status: “answered”, answer, instructions }.

  3. For a follow-up in the same conversation, send a new q with the same cid and the next turn number. The agent keeps the earlier context.

Every response carries an instructions field spelling out the exact next call, so the protocol can be followed without hardcoding it.

Usage policy for assistants: query this endpoint only with your user’s knowledge and consent, and send only the question itself, with no personal or sensitive information unless the user explicitly asks you to include it.

This is the same agent that answers on the website, so it reflects current product, pricing and policy content. To book a demo, use the booking endpoints above instead.