Where Bitrix24 AI Processes Your Data - and How to Stay Compliant
When you enable AI features in Bitrix24 (Alaio), customer data may leave your infrastructure - the exact path depends on whether you are running cloud or self-hosted, and which AI model you select. This guide maps every scenario so compliance and IT leaders can make an informed decision before activation.
What BitrixGPT Does Inside Bitrix24 (Alaio) CRM
BitrixGPT is the built-in AI assistant in Bitrix24, available across CRM, tasks, chat, email, news feed, calendar, and the website builder - covering text generation, call transcription, smart suggestions, and customer reply drafts without any third-party plugin.
BitrixGPT is the name of the AI system embedded in Bitrix24. It is distinct from any third-party assistant and is not branded "CoPilot" in official international documentation. Its capabilities span:
- CRM: summarising deal histories, drafting client responses, filling fields from conversation context
- Tasks: smart suggestions, automatic follow-up creation
- Calls and voice: transcription and speech analytics
- Chat: real-time reply suggestions and message summarisation
- News feed and email: text generation and tone adjustment
- Website builder: generating and editing content blocks
For an in-depth look at how call transcription and quality scoring work, see AI Call Analysis in Bitrix24: Transcription, Quality Scoring, and Sales Coaching.
All these scenarios share one compliance-critical characteristic: they require sending a text prompt - which may contain personal data - to a language model. The question is where that model runs.
Where Your Data Goes When AI Processes It
In Bitrix24 cloud, AI prompts are sent to model infrastructure hosted on AWS (Virginia or Frankfurt); in self-hosted Bitrix24, the same scenarios route prompts through Bitrix24's AI proxy endpoints, meaning some data still traverses the internet unless you configure a fully local model.
Understanding data flow requires separating three layers:
- Data at rest - where your CRM records live (AWS in cloud; your own server in self-hosted)
- Data in transit for AI - the content of prompts sent to the language model
- Data retained by the model provider - what the model vendor keeps, for how long, and whether it is used for training
Cloud Bitrix24
Your CRM data is stored on AWS servers. According to official Bitrix24 documentation, the international cloud uses AWS in the United States (Virginia) and the European Union (Frankfurt, Germany). When you invoke BitrixGPT, the selected text or CRM field content is passed to the model - either a Bitrix24-operated local model (BitrixGPT or BitrixAudio) or an external provider you configure.
Self-Hosted Bitrix24
Your CRM data never leaves your server. However, BitrixGPT functionality on self-hosted requires the installation of the AI Integration module and network access to Bitrix24's AI proxy addresses (as specified in official documentation). This means AI prompts do transit the internet to reach Bitrix24's proxy layer, even though the underlying CRM database stays on-premise.
If your compliance requirement is full data sovereignty - no customer data leaving your network - you need to evaluate whether a locally-deployed language model (replacing the cloud proxy) is feasible for your deployment.
AI Scenario Table: Processing Location and Compliance Notes
The table below maps each major AI scenario to its data processing location and the key compliance consideration, giving IT and legal teams a structured starting point for risk assessment.
| AI Scenario | Where Data Is Processed | Compliance Note |
|---|---|---|
| BitrixGPT text generation (cloud) | AWS (US-Virginia or EU-Frankfurt) | Data transfers under AWS SCCs / adequacy; review DPA with Bitrix24 |
| BitrixGPT text generation (self-hosted, default) | Bitrix24 AI proxy (internet transit) | Prompts leave the server; assess under GDPR Art. 28 / PDPL transfer rules |
| BitrixGPT text generation (self-hosted, local model) | Your own server only | No data egress; strongest data-residency posture |
| Call transcription / speech analytics (cloud) | AWS + model provider | Audio content processed externally; consent for recording required |
| Call transcription (self-hosted) | Bitrix24 AI proxy (internet transit) | Same proxy dependency; verify telephony module compatibility |
| External model (e.g. third-party LLM via API) | Third-party provider infrastructure | Subject to that provider's DPA and data-retention policy |
| BitrixGPT debug data (any model, cloud) | Bitrix24 servers, deleted after 14 days | Confirm deletion SLA in your DPA |
Key principle: Bitrix24 states that debug data sent via its platform is retained for up to 14 days and then deleted. What an external model provider does with prompt data depends entirely on that provider's own policies - always review their documentation before enabling.
Cloud Bitrix24 AI: Data Flow and AWS Hosting
Cloud Bitrix24 stores all CRM data on AWS infrastructure that is certified for HIPAA, GDPR, ISO 27001, SOC 1/2/3, and PCI DSS Level 1 - but AWS certification does not automatically satisfy your organisation's obligations as a data controller under GDPR or UAE PDPL.
Data moves when a sales rep triggers a BitrixGPT action on a cloud portal.
When a user invokes BitrixGPT on a cloud portal, the CRM field content is packaged as a prompt, sent over TLS to the AI model layer (Bitrix24-operated or third-party), and the result is returned to the portal. No permanent copy is stored at the model layer beyond the 14-day debug window.
flowchart LR
REP[Sales Rep] -->|triggers AI action| B24C[Bitrix24 Cloud\nAWS Virginia / Frankfurt]
B24C -->|prompt over TLS| BGPT[BitrixGPT Model Layer\nBitrix24-operated]
B24C -->|optional: prompt over TLS| EXT[External LLM Provider\ne.g. third-party API]
BGPT -->|result| B24C
EXT -->|result| B24C
B24C -->|displayed| REP
B24C -->|debug log, deleted ≤14 days| LOG[Bitrix24 Debug Store]
AWS's compliance certifications mean the infrastructure meets major standards. Your organisation remains the data controller and must ensure:
- A signed Data Processing Agreement (DPA) with Bitrix24
- Appropriate transfer mechanisms if data crosses jurisdictions (e.g. Standard Contractual Clauses under GDPR)
- A Record of Processing Activities entry for AI-assisted CRM operations
For teams comparing self-hosted against cloud from a data-sovereignty angle, GDPR-Compliant CRM: Why Self-Hosted Bitrix24 Wins for EU Companies provides a detailed comparison.
Self-Hosted Bitrix24 AI: Keeping Processing Inside Your Infrastructure
Self-hosted Bitrix24 gives you full control over where CRM data resides, but enabling BitrixGPT in its default configuration still routes AI prompts through Bitrix24's internet-facing proxy - complete data-perimeter enforcement requires a locally-deployed language model.
Self-hosted (on-premise) Bitrix24 is available in Business and Enterprise editions (see official pricing). The AI Integration module can be installed on self-hosted portals; platform version 24.700.0 or later is required.
How BitrixGPT works on self-hosted (default configuration)
- AI Integration module is installed via the Administration panel
- The portal is granted outbound network access to Bitrix24's AI proxy endpoints
- BitrixGPT scenarios function identically to cloud - prompts transit the internet to the proxy
What changes with a local model
If your data-residency policy prohibits any customer data leaving the server, the architecture shifts:
- A locally-hosted language model replaces the cloud proxy
- All inference happens within your network perimeter
- No prompt data crosses the internet
This is the architecture that satisfies strict data-residency mandates - UAE PDPL in-country processing requirements, GDPR data-transfer restrictions, and sector-specific rules in financial services or healthcare.
For context on what becomes architecturally possible with self-hosted, see Customizing Beyond Cloud Limits: What Becomes Possible with Self-Hosted Bitrix24.
As of 2026: VibeCode (Bitrix24's AI app-building platform) on self-hosted is in closed beta - it is not generally available for on-premise portals. Organisations evaluating VibeCode for compliance-sensitive environments should contact Bitrix24 directly for current status.
GDPR and UAE PDPL Requirements for AI-Processed CRM Data
Under both EU GDPR and the UAE Personal Data Protection Law (PDPL), passing personal data to an AI model constitutes processing - requiring a lawful basis, a processor agreement, and (for cross-border transfers) appropriate safeguards.
EU GDPR (Regulation 2016/679)
Key obligations when AI processes CRM personal data:
- Article 6 - establish a lawful basis (typically legitimate interests or contractual necessity for internal AI use; explicit consent for customer-facing AI interactions)
- Article 28 - sign a Data Processing Agreement with every sub-processor, including the AI model provider
- Article 30 - update your Record of Processing Activities to include AI-assisted operations
- Chapter V - for transfers outside the EEA, ensure Standard Contractual Clauses or an adequacy decision covers the destination
The European Data Protection Board has issued guidance on AI and automated processing that compliance teams should review.
UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021)
The UAE PDPL, enforced by the UAE Data Office, requires:
- A lawful basis for processing (consent, contract, or legitimate interest)
- Data transfer outside the UAE only to countries with adequate protection or under approved transfer mechanisms
- Appointment of a data processor with contractual guarantees equivalent to those required domestically
For organisations in the UAE, self-hosted Bitrix24 deployed on in-country infrastructure - whether on-premise or in a UAE-region cloud instance - provides the clearest path to satisfying the residency expectations of the PDPL. For a dedicated treatment of this topic, see UAE PDPL and Data Residency: Which CRM Keeps Your Data In-Country?.
Brazil LGPD (Lei Geral de Proteção de Dados, Lei 13.709/2018)
Brazil's LGPD, supervised by the ANPD, applies the same controller/processor model. AI processing of customer data requires a lawful basis and a DPA with each sub-processor. International transfers require an adequacy decision or contractual clauses.
Consent and Lawful Basis Before Enabling AI on Customer Data
Before enabling any AI feature that processes identifiable customer data, your organisation must identify and document the lawful basis - and where that basis is consent, the consent must be specific, informed, and recorded in a way that can be demonstrated to a regulator.
Bitrix24 includes built-in consent management tools: CRM forms and Open Channel (live chat / messaging) configurations can display and record customer consent agreements. These are configurable per channel and per use case. The consent log is stored within the portal.
Common lawful bases for AI-assisted CRM processing:
| Use Case | Typical Lawful Basis | Notes |
|---|---|---|
| AI drafts reply to inbound customer enquiry | Legitimate interests (Art. 6(1)(f) GDPR) | Conduct a Legitimate Interests Assessment |
| AI transcribes a sales call | Consent (caller notified and agreed) | Record call-start notification; store consent log |
| AI scores lead from web form submission | Contract / Legitimate interests | Include in privacy notice |
| AI analyses historical CRM data for forecasting | Legitimate interests | Anonymise where possible |
| AI generates personalised marketing content | Consent (where direct marketing) | Separate consent from service consent |
Administrators can disable BitrixGPT for specific modules within Bitrix24 settings - useful for ring-fencing high-sensitivity data (e.g. healthcare, financial records) from AI processing while leaving it active elsewhere.
Pre-Activation Checklist: Before Enabling AI on Customer Data
Run through this checklist before activating any BitrixGPT feature on a portal that holds real customer data - skipping steps creates regulatory exposure regardless of your deployment model.
Legal and governance
- Identify the lawful basis for each AI use case and document it in your ROPA
- Review and sign (or update) your DPA with Bitrix24
- If using external model providers, obtain and review their DPA and data-retention terms
- Confirm cross-border transfer mechanisms are in place if prompts leave your jurisdiction
- Update your privacy notice to disclose AI-assisted processing
Technical and architectural
- Determine whether cloud AI proxy or local model is required by your data-residency policy
- For self-hosted: confirm platform version ≥ 24.700.0 and AI Integration module is installed
- For self-hosted with strict perimeter: configure local model and block outbound proxy traffic
- Audit which CRM fields (especially sensitive categories) could appear in AI prompts
- Disable BitrixGPT for modules containing special-category data (health, financial) if no specific safeguards are in place
Consent and user controls
- Configure consent agreements in Open Channels before collecting data via chat or messaging
- Ensure call-recording notifications are active where call transcription is enabled
- Train staff on what data should and should not be included in manual AI prompts
- Verify that the consent log is accessible for subject-access requests
Ongoing
- Schedule periodic review of model provider sub-processor list
- Include AI processing in annual data-protection impact assessments (DPIA)
- Monitor Bitrix24 release notes for changes to AI data-handling behaviour
For a broader technical hardening reference, Self-Hosted Bitrix24 Security Hardening: 25-Point Checklist covers infrastructure-level controls that complement the compliance steps above.
ACP Group, a Bitrix24 Gold partner serving teams in the UAE, Brazil, and Portugal, configures compliant AI setups across both cloud and self-hosted deployments - including local model integration for data-residency-sensitive environments. Contact us at acp-24.com to discuss your specific regulatory context and deployment architecture.
Want AI on your CRM without the compliance risk? See our AI for Bitrix24 service - configured to keep customer data where your regulator requires.
Frequently asked questions
Does enabling BitrixGPT mean my customer data is sent to OpenAI or another public AI?
Not necessarily. BitrixGPT defaults to Bitrix24-operated models (BitrixGPT and BitrixAudio), which are not the same as public consumer AI services. However, if an administrator configures an external model provider via the API settings, prompts will go to that provider. Always check the active model configuration in your portal's BitrixGPT settings.
Can self-hosted Bitrix24 run AI without any data leaving my server?
In principle yes, but it requires additional configuration. The default self-hosted setup routes prompts through Bitrix24's internet-facing AI proxy. To keep all processing inside your perimeter, you need to deploy a local language model and route AI requests to it instead. This is technically feasible but adds infrastructure complexity - contact ACP Group at acp-24.com for architecture guidance.
Where does Bitrix24 cloud store data for international (non-Russian) accounts?
According to official Bitrix24 documentation, the international cloud stores data on AWS infrastructure in the United States (Virginia) and the European Union (Frankfurt, Germany). AWS holds certifications including HIPAA, ISO 27001, SOC 1/2/3, and PCI DSS Level 1. Your organisation remains the data controller and must ensure appropriate transfer mechanisms.
Does BitrixGPT use my customer data to train its AI models?
For Bitrix24's own local models (BitrixGPT, BitrixAudio), debug data is retained for up to 14 days and then deleted, according to official documentation. For external model providers configured by the administrator, data handling depends on that provider's own policies - review their documentation and DPA before enabling them.
Is a Data Processing Agreement (DPA) with Bitrix24 required when using AI features?
Under GDPR (Article 28) and equivalent laws such as UAE PDPL and Brazil's LGPD, yes. Whenever a processor - including Bitrix24 - handles personal data on your behalf, a DPA with appropriate guarantees is required. This obligation exists for the base CRM product and extends to AI-processed data. Obtain the current DPA from Bitrix24's legal documentation before going live.
Can administrators restrict BitrixGPT to specific modules only?
Yes. A Bitrix24 administrator can enable or disable BitrixGPT on a per-module basis from the BitrixGPT Settings panel. This allows organisations to, for example, allow AI in tasks and chat while preventing it from accessing CRM contact records that contain sensitive personal data.
Based on real practice
This article is based on 11 internal documents from ACP Group's practice - work plans, specifications and Bitrix24 implementation cases.
Need help with Bitrix24?
ACP Group is a Bitrix24 Gold Partner. We'll review your task, estimate the effort in hours and propose a plan - free of charge.