Nantes-based French customer-messaging platform (Crisp IM SAS, founded 2015); fully bootstrapped, no VC, 200k+ customers, flat-rate pricing.
- FROM
- $45/mo
- CLOUD ACT
- MATERIAL
A single roll-up of ownership and CLOUD Act exposure.
RSG Digital, trading as CustomerEagle: Dutch sole proprietorship (eenmanszaak), KvK 42085647, Blauwven 7, 5508 RC Veldhoven, Netherlands; registered 18 May 2026
Dutch AI support inbox for chat, email, WhatsApp, Messenger and Instagram (RSG Digital, 2026) with a public DPA; hosted on Railway in Amsterdam, AI by DeepSeek (China) by default or OpenAI.
CustomerEagle, in the Helpdesk category, offers EU hosting with the Netherlands as its hosting location, but a US parent or sub-processor leaves material CLOUD Act exposure.
CustomerEagle is run by RSG Digital, a Dutch sole proprietorship (eenmanszaak; KvK 42085647, Veldhoven, registered 18 May 2026) trading under the CustomerEagle name, with no outside investors found, so ownership is EU. Disclosure is better than most of the category: a public Art. 28 DPA under Dutch law and a sub-processor table that gives every provider a processing location, including the uncomfortable ones. That table is also what sets the score. Customer conversations are hosted on Railway (US-owned; its only EU region is Amsterdam) behind Cloudflare (US), email goes out through Resend (US) and AI answers can run on OpenAI (US) under SCCs, so every service provider that holds or processes conversation content is US-owned and CLOUD Act exposure is material. On top of that, the DPA names DeepSeek (Hangzhou, China) as the default provider for AI features and states that DeepSeek offers neither Standard Contractual Clauses nor an Art. 28 agreement, so CustomerEagle relies on automated masking of identifiers instead of a Chapter V transfer mechanism. Masking removes direct identifiers, but free-text support conversations can still identify a person, so it is not the same as anonymisation. A default AI path to a country without an adequacy decision and without a transfer mechanism, on infrastructure that is US-owned throughout, puts the listing at 2. The privacy policy (SCCs wherever data is transferred) and the security page (AI processing 'including in the US') describe the transfers more favourably than the DPA does.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
Where ultimate control over the operating company sits.
CustomerEagle is an AI-first customer-support inbox launched in 2026 by RSG Digital, a sole proprietorship registered with the Dutch Chamber of Commerce on 18 May 2026 (KvK 42085647, Veldhoven, North Brabant). It brings website chat, email, WhatsApp, Facebook Messenger and Instagram into shared inboxes; an AI agent answers from the knowledge base and help-centre content the customer has approved, cites its sources and hands the conversation to a person with a summary when it is not confident. Around that sit an agent copilot for drafts and summaries, workflow rules with SLA escalation and human approval for actions such as refunds, a public help centre, Shopify and WooCommerce order lookups gated by an email-and-order-number match, co-browsing and translation add-ons, a light CRM with pipelines, a marketing add-on, and an AI Voice phone agent available on request. Contracting party is a sole trader, which a procurement team should know, although none of the legal documents states the legal form.
The disclosure is unusually complete for a company this young, and it is the disclosure that determines the rating. The public DPA names every service provider with a processing location. Conversations and the database are hosted on Railway, a US company whose only EU region is Amsterdam (hosting country: Netherlands), with Cloudflare in front of every hostname and for object storage, Resend for outgoing email and OpenAI for AI answers under Standard Contractual Clauses, so every provider that holds or processes conversation content is US-owned (CLOUD Act rating: Material). The DPA also names DeepSeek, based in Hangzhou, as the default provider for AI text generation and classification, and says plainly that DeepSeek offers no SCCs and no Art. 28 agreement, so CustomerEagle masks names, email addresses and phone numbers before sending content instead of relying on a Chapter V transfer mechanism. The privacy policy and security page are less precise: the first says transfers use SCCs, the second says AI processing can happen outside the EEA "including in the US" without mentioning China. The AI Voice add-on names no telephony or speech provider in any document, and its own page says post-call redaction does not change what the AI hears live, so the DPA's masking promise cannot cover voice. WhatsApp, Messenger and Instagram necessarily run through Meta's APIs, which the DPA treats as integrations the customer connects and controls.
Pricing is in EUR per agent and month, billed monthly, excluding VAT: a Free plan for one agent with email, live chat and one shared inbox; Standard €24.99 with 50 AI resolutions per agent, Messenger and Instagram; Professional 49.99 EUR with 150 resolutions, WhatsApp and AI drafting; Premium 84.99 EUR with 350 resolutions, SSO/SAML and SCIM. Extra AI resolutions cost 0.49 to 0.99 EUR each under a configurable spend cap, annual billing saves up to 20 percent, and paid plans can be trialled for 30 days without a card. Best fit: small e-commerce and SaaS teams that want an inexpensive AI-first inbox with a free tier and Shopify order context, and can accept US-owned hosting and a non-EU AI provider. Buyers who want conversations stored at rest by an EU-owned host should compare Userlike (Hetzner) in this category, and anyone who needs a transfer mechanism for every AI provider should ask CustomerEagle to switch the default away from DeepSeek before signing.
CDN in front of every hostname, object storage and custom domains. DPA location "Global edge (EU / US)".
Error and performance monitoring where configured. Operator not named; DPA location "EU / US".
Messaging channels, only when the customer connects them (Messenger and Instagram from Standard, WhatsApp from Professional). DPA calls them customer-directed; privacy policy lists Meta as a provider.
AI-generated answers and drafting for enabled features. Processed in the US under the EU SCCs; inputs masked first per the DPA.
Company mailbox for customereagle.com. Compiled from MX and SPF records; not named in any CustomerEagle document.
Application and database hosting (customer conversations at rest). DPA location "EU / US"; Railway's EU region is Amsterdam.
Transactional email delivery, including replies sent on the customer's behalf. DPA location "EU / US".
Billing and payments for CustomerEagle's own customer relationship (controller-side per the DPA); no conversation data.
Default provider for enabled AI features: text generation and classification. Processed in China; no SCCs or Art. 28 DPA, relies on input masking per the DPA.
Order and product lookups, only when the customer connects a Shopify store. Customer-directed per the DPA; location "EU / US".
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Cloudflare, Inc. | United States | CDN in front of every hostname, object storage and custom domains. DPA location "Global edge (EU / US)". | US |
| GlitchTip / Sentry-compatible monitoring | United States | Error and performance monitoring where configured. Operator not named; DPA location "EU / US". | US |
| Meta Platforms (WhatsApp, Messenger, Instagram) | United States | Messaging channels, only when the customer connects them (Messenger and Instagram from Standard, WhatsApp from Professional). DPA calls them customer-directed; privacy policy lists Meta as a provider. | US |
| OpenAI Ireland Ltd (OpenAI) | United States | AI-generated answers and drafting for enabled features. Processed in the US under the EU SCCs; inputs masked first per the DPA. | US |
| Rackspace Email | United States | Company mailbox for customereagle.com. Compiled from MX and SPF records; not named in any CustomerEagle document. | US |
| Railway Corporation | Netherlands | Application and database hosting (customer conversations at rest). DPA location "EU / US"; Railway's EU region is Amsterdam. | US |
| Resend | United States | Transactional email delivery, including replies sent on the customer's behalf. DPA location "EU / US". | US |
| Stripe | United States | Billing and payments for CustomerEagle's own customer relationship (controller-side per the DPA); no conversation data. | US |
| Hangzhou DeepSeek Artificial Intelligence Co., Ltd. | China | Default provider for enabled AI features: text generation and classification. Processed in China; no SCCs or Art. 28 DPA, relies on input masking per the DPA. | non-US |
| Shopify | Canada | Order and product lookups, only when the customer connects a Shopify store. Customer-directed per the DPA; location "EU / US". | non-US |
Held by the provider that operates the hosting, not by CustomerEagle itself.
Nantes-based French customer-messaging platform (Crisp IM SAS, founded 2015); fully bootstrapped, no VC, 200k+ customers, flat-rate pricing.
Cologne-based German live-chat platform (Userlike UG, founded 2011); acquired by Swedish Lime Technologies AB (Nasdaq Stockholm-listed) and renamed Lime Connect in September 2025.
Wrocław-based Polish customer-service suite (Text S.A., WSE-listed since 2014), 28k+ customers in 150+ countries; LiveChat + ChatBot + HelpDesk.