"Trustworthy, scalable AI agents."
Rasa is a platform for AI chatbots, voicebots, and service automation. It is aimed at companies that want to integrate dialog-based assistants into their own systems, CRM, contact center, and communication channels in a controlled manner.
Rasa Platform
Trustworthy, scalable AI agents.
Location: Germany ⓘ Germany / USA. Rasa operates a German GmbH and a US company.
Free local or production use for one bot with limited conversation volume and community support. Other Enterprise Scalable agent platform for production chat, voice, and service automation with enterprise support and custom deployment requirements.
Professional Services Consulting, implementation, architecture, agent design, and long-term support from Rasa.
Self-Hosted Deployment Operation in your own cloud, private cloud, on-premises, or air-gapped environment.
Own model providers Combination with self-hosted or external LLMs, speech, and integration services.
Target audience
Rasa is aimed at companies, public authorities, insurers, banks, telecommunications providers, service organizations, and AI teams that want not just to test chatbots or voicebots, but to integrate them into operational processes in a controlled way. The platform is particularly suitable for technical teams that need self-hosting, custom interfaces, and clear governance.
Outstanding features
Rasa offers dialogue management, NLU, cross-channel bot integration, APIs, workflows, and human handover logic. The focus is on controllable, production-ready assistants rather than purely standard chatbots.
Main application areas
Typical scenarios include customer service, voicebots, call center automation, appointment scheduling, support triage, CRM integration, internal service bots, status inquiries, document assistants, and knowledge assistants.
Usage & notes
Rasa should be introduced with clearly defined dialogues, escalation paths, role-based permissions, test cases, and monitoring. For production voice or LLM functions, data protection, call recording, model providers, and data flows must be assessed separately.
| Target audience | Assessment |
|---|---|
| Private individuals | No – too technical and geared toward professional agent development. |
| Self-employed / freelancers | Conditionally – useful for specialized chatbot, voicebot, or integration projects. |
| SMEs | Yes, with a technical team – suitable for customer service, lead qualification, and internal service automation. |
| Large enterprises | Very well suited – especially for regulated, complex, or omnichannel service processes. |
| Developers / AI teams | Very well suited – core target group for agent logic, APIs, integrations, and LLM control. |
| Contact centers / customer service | Very well suited – for chat, voice, handovers to staff, and controlled service flows. |
| Privacy-sensitive organizations | Very well suited with self-hosting – data and models can be operated on their own infrastructure. |
Hosting & Data
1) On-prem / local hosting
Meaning: The company operates the solution on its own hardware or within its own infrastructure. In the strictest sense, not only the application runs locally, but ideally the model as well.
2) Private cloud / data center
Meaning: The solution runs in a dedicated or more clearly separated cloud environment, often with a hosting provider or hyperscaler, but in a German data center or in a particularly controlled environment.
3) EU SaaS / managed
Meaning: The provider operates the solution itself as a service. The company uses the tool as a ready-made cloud service, ideally with EU data residency.
4) Hybrid
Meaning: One part of the processing remains internal / local / in a private cloud, while another part runs in an external cloud or EU SaaS.
5) AVV / DPA
Meaning: This is the data processing agreement or Data Processing Addendum. It governs that the provider processes personal data on behalf of the customer and is bound by the customer's instructions.
6) No training
Meaning: The provider does not use your prompts, uploads, attachments, chat histories, or outputs for training or improving the general model — ideally excluded by contract.
7) Open-source / transparency path
Meaning: There is a path toward greater technical transparency and sovereignty, for example through:
- open models
- documented components
- self-hostable parts
- traceable architecture
- export / switching options
| On-prem / local hosting | ✅ |
| Private cloud / data center | ✅ |
| EU SaaS / Managed | ⚠️ |
| Hybrid | ⚠️ |
| DPA / AVV | ✅ |
| No training on customer data | ❓ |
| Open source / transparency path | ✅ |
On-Prem / local hosting: covered
Clearly documented on the website. Rasa mentions on-premise, own infrastructure, fully offline or air-gapped deployments, and documents self-hosted installation of Rasa Studio with Docker Compose or Helm.
Private cloud / data center: covered
Clearly documented on the website. Rasa states that the entire stack can be hosted in a private cloud or on infrastructure of the customer's choice and promotes deployment 'in your cloud'.
EU SaaS / managed: partially
There are references to 'fully managed' or managed service, but on the website there is no specifically named EU/EEA hosting location and no clearly stated EU data residency for a standard SaaS variant. Therefore only partially covered.
Hybrid: partially
A hybrid path is indirectly indicated because Rasa describes both self-hosted/private-cloud and services/managed offerings, and the products can integrate with third-party services. However, an explicit product page that describes a standardized hybrid operating model in detail was not clearly found on the website.
DPA / AVV: covered
Covered by the published DPA/AVV. In it, Rasa commits to processing based on documented customer instructions, regulates subprocessors, restricted transfers, as well as return/deletion of data after the end of the contract.
No training: unclear
A clear statement on the website that prompts, uploads, chat histories, or outputs are generally not used to train general models was not found. Although the DPA prohibits the marketing/sale/resale of personal data, it is not a clear general 'no AI training' clause.
Open-source / transparency path: covered
Rasa explicitly refers to open-source software; the Product Privacy mentions 'Rasa Open Source Software', and the FAQ says that 'Rasa Open Source' is licensed under Apache 2.0. Together with self-hosting, this creates a clear transparency/sovereignty path.
Data processing
The website describes Rasa strongly as a controllably deployable platform. For EU/EEA users, the most privacy-friendly path is self-hosting or operation in their own EU/EEA infrastructure or private cloud. Then data processing can remain within their own environment. If Rasa provides services, according to Product Privacy, Rasa may process personal data, for example for support or assistance with training within the customer's environment. In contractually regulated hosted/managed scenarios, the specific hosting location is only determined in the contract according to the website.
Conclusion
For a European directory, Rasa Platform is particularly strong because the provider offers a clearly documented path to high data sovereignty: self-hosted, private cloud, on-premise and offline. This argues for 'yes' regarding GDPR status when the best available path is evaluated. Less strongly documented, by contrast, are a publicly named EU data residency for managed/SaaS, a public subprocessor list, and an explicit website-side opt-out or exclusion for AI training.
Sources
| On-prem / local hosting | ✅ |
| Private cloud / data center | ✅ |
| EU SaaS / Managed | ⚠️ |
| Hybrid | ⚠️ |
| DPA / AVV | ✅ |
| No training on customer data | ❓ |
| Open source / transparency path | ✅ |
On-Prem / local hosting: covered
Clearly documented on the website. Rasa mentions on-premise, own infrastructure, fully offline or air-gapped deployments, and documents self-hosted installation of Rasa Studio with Docker Compose or Helm.
Private cloud / data center: covered
Clearly documented on the website. Rasa states that the entire stack can be hosted in a private cloud or on infrastructure of the customer's choice and promotes deployment 'in your cloud'.
EU SaaS / managed: partially
There are references to 'fully managed' or managed service, but on the website there is no specifically named EU/EEA hosting location and no clearly stated EU data residency for a standard SaaS variant. Therefore only partially covered.
Hybrid: partially
A hybrid path is indirectly indicated because Rasa describes both self-hosted/private-cloud and services/managed offerings, and the products can integrate with third-party services. However, an explicit product page that describes a standardized hybrid operating model in detail was not clearly found on the website.
DPA / AVV: covered
Covered by the published DPA/AVV. In it, Rasa commits to processing based on documented customer instructions, regulates subprocessors, restricted transfers, as well as return/deletion of data after the end of the contract.
No training: unclear
A clear statement on the website that prompts, uploads, chat histories, or outputs are generally not used to train general models was not found. Although the DPA prohibits the marketing/sale/resale of personal data, it is not a clear general 'no AI training' clause.
Open-source / transparency path: covered
Rasa explicitly refers to open-source software; the Product Privacy mentions 'Rasa Open Source Software', and the FAQ says that 'Rasa Open Source' is licensed under Apache 2.0. Together with self-hosting, this creates a clear transparency/sovereignty path.
Data processing
The website describes Rasa strongly as a controllably deployable platform. For EU/EEA users, the most privacy-friendly path is self-hosting or operation in their own EU/EEA infrastructure or private cloud. Then data processing can remain within their own environment. If Rasa provides services, according to Product Privacy, Rasa may process personal data, for example for support or assistance with training within the customer's environment. In contractually regulated hosted/managed scenarios, the specific hosting location is only determined in the contract according to the website.
Conclusion
For a European directory, Rasa Platform is particularly strong because the provider offers a clearly documented path to high data sovereignty: self-hosted, private cloud, on-premise and offline. This argues for 'yes' regarding GDPR status when the best available path is evaluated. Less strongly documented, by contrast, are a publicly named EU data residency for managed/SaaS, a public subprocessor list, and an explicit website-side opt-out or exclusion for AI training.
Sources
Strengths & weaknesses at a glance
| Strengths | Weaknesses |
|---|---|
| • Self-hosting and high architectural control | • Not a plug-and-play chatbot for laypeople |
| • Chat, voice, and service automation | • Requires dialog design, integration, monitoring, and technical support |
| • API, CRM, and contact center integration | • Data protection also depends on connected LLMs, speech services, and channels |
| • Open-source components and developer ecosystem | • Enterprise features are not fully included in the free Developer plan |
| • DPA available for enterprise use |
Reviews
0 reviews in total
There are no confirmed reviews for this tool yet.
Submit review
Your review will only become visible after email confirmation. This protects the portal against abuse.
Report review
Please select the reason why this review should be checked.
GDPR-compliant usage possible?
Rasa Platform can be assessed as usable for the EU/EEA region in the best available usage path in a GDPR-compliant manner, because Rasa provides a DPA/AVV and, according to its own website, the platform can be self-hosted or deployed in customer-owned infrastructure, private cloud, on-premise, and even in fully offline-operated environments. This provides a straightforward way to keep processing entirely within your own EU/EEA infrastructure. However, for the services provided by Rasa itself, the documentation remains partly unclear or only contractually regulated regarding server locations, EU data residency, and subprocessors.
Positive
Positive aspects are the published DPA/AVV, the explicit classification under GDPR, the commitment to process only on documented customer instructions, and the strong self-hosting/private-cloud focus. The product privacy policy also states that the products can be privately hosted by customers and that Rasa generally does not process personal data as part of the products. The website also mentions self-hosted deployment for Rasa Studio and promotes deployment in your own infrastructure, private cloud, on-premise, and even offline.
Negative
Negative or limiting is that the website states no specific EU/EEA server location for a managed SaaS or hosting option. The DPA only says that customer data is hosted in the location specified in the agreement. In addition, the subprocessor list is not openly published on the website, but is only provided 'upon written request'. A clear, general statement on the website that customer data is not used to train general models was also not found.
Server location
No specific server/data center location for Rasa Platform is stated on the website. The DPA only states that 'Customer Data is hosted in the location set forth in the Agreement'. Therefore, there is no publicly specified standard statement for EU/EEA data residency; however, through self-hosting/private cloud, the customer can determine the EU/EEA location themselves.