Legal

Privacy Policy

Last updated: 3 September 2026

Two things worth reading before the rest: section 3 explains that anything you upload becomes answerable to anyone who can reach your widget, and section 4 covers data belonging to your own visitors, where you are the controller and we act for you.

1. Who this covers

This policy explains how [LEGAL ENTITY NAME] (“ChatAgentLy”, “we”) handles personal data. It applies to our website, our dashboard, and the assistant service our customers embed on their own sites.

There are two different relationships here and they carry different responsibilities:

  • Our customers. The people and businesses who sign up. We decide what we collect about them and why, so for that data we are the controller.
  • Our customers' end users. Visitors who ask a question of an assistant embedded on a customer's website. We process that data on the customer's instructions, so for it the customer is the controller and we are the processor. Section 4 covers this.

If you are an end user with a question about an assistant you used, the business whose website you were on controls that data. Contact them first; we will help them respond.

2. What we collect about our customers

Account data. Name, email address, and optionally a phone number, extension and company name. Authentication is handled by our identity provider, which also records sign-in method and session activity. We never see or store your password.

Billing data. Plan, subscription status, billing history and invoices. Card details are entered directly with our payment processor and never reach our servers; we hold only a customer identifier and the last-four/brand our processor exposes.

Content you provide. The documents, images, web pages and configuration you add as sources, together with any personal data they happen to contain. See section 3.

Usage and technical data. Requests to our API, feature usage, token counts and estimated cost, error reports, and IP address for rate limiting and abuse prevention.

Support and enquiries. What you send us through the contact form or by email, including any phone number you choose to give.

We do not collect special category data, and you should not put it into the Service.

3. Content you upload

Files you upload are stored privately. They are never given a public URL and are readable only by your own account. Content is indexed into embeddings so the assistant can retrieve from it, and the text is sent to our model provider at the moment a question is asked in order to generate an answer.

We do not use your content to train models, ours or anyone else's, and our model provider is contractually bound not to train on it either.

What you upload becomes answerable to the public. Your assistant has no login. Anyone who can reach a page where your widget is embedded can ask it questions and receive answers drawn from your sources. Do not upload confidential material, personal data about third parties, credentials, or payment details. This is a decision you make each time you add a source, and it is the single most important privacy choice in the product.

4. Data about your end users

When a visitor uses an assistant on your website, we process on your behalf: the question text, any feedback or rating they submit, the page they were on, a session identifier used to group a conversation, their IP address for rate limiting, and the generated answer.

We act only on your instructions, do not use this data for our own purposes, and do not sell it or use it for advertising. The session identifier is held in the browser's session storage and clears when the tab closes; it is not a tracking cookie and does not follow anyone between sites.

Your obligations as controller. You are responsible for telling your visitors that the assistant is automated where the law requires it, for having a lawful basis for the processing, for referencing it in your own privacy notice, and for handling requests your visitors make about their data. We will assist you in responding to such requests.

Questions typed by visitors may contain personal data you did not anticipate. We do not screen for this. Abusive or harmful text is filtered before it reaches storage where possible, but that is a safety measure and not a privacy control.

5. Why we process it, and on what basis

  • To provide the Service — performance of our contract with you.
  • To bill you and keep financial records — contract, and legal obligation for tax and accounting records.
  • To keep the Service secure and available, including rate limiting, abuse prevention and error monitoring — our legitimate interest in operating a service that is not abused.
  • To support you and answer enquiries — contract and legitimate interest.
  • To send service and account emails such as usage alerts, incident notices and billing notifications — contract. These are not marketing and cannot be turned off while you hold an account, though you control digest frequency and recipients.

We do not sell personal data, and we do not share it for cross-context behavioural advertising, under any definition of those terms.

6. Who we share it with

We use a small number of sub-processors to run the Service. Each is bound by contract to process data only on our instructions and to protect it:

  • Hosting and content delivery — runs the application and serves the widget.
  • Database hosting — stores accounts, sources, questions and usage.
  • Authentication — sign-in, sessions, organizations and team membership.
  • Payment processing — subscriptions, invoices and card handling.
  • Language and embedding models — receives source text and questions to generate answers. Bound not to train on it.
  • Email delivery — sends account, alert and digest email.

We also disclose data where we are legally required to, to enforce our Terms of Service, to protect rights and safety, and to a successor in a merger or acquisition, in which case this policy continues to apply until replaced.

Some sub-processors operate outside your country. Where personal data is transferred internationally, that transfer relies on an appropriate safeguard such as standard contractual clauses.

7. How long we keep it

Question and feedback history is kept until you delete it. The Service has a retention setting that automatically removes logs older than a chosen number of days. It is off by default, which means the default behaviour is to keep everything, so if you want a shorter retention period you must set one.

Sources are kept until you remove them or delete the account. Deleting a source removes its stored file and its embeddings.

Account and billing records are kept for as long as you hold an account and afterwards for as long as tax and accounting law requires.

On cancellation, the content your assistant answers from is removed and your question history is retained, so the analytics you gathered do not disappear. On account deletion, sources, database connections and API keys are removed and everyone is removed from the account. Backups are cycled out on a rolling basis, so deleted data may persist in a backup for a limited period before it is overwritten.

8. How we protect it

Data is encrypted in transit. Uploaded files are stored privately with no public URL. Credentials for any system you connect are encrypted at rest. Every query is scoped to a single account at the database layer, so one customer's content cannot be reached from another's.

Access to production data is limited to those who need it to operate the Service. Your widget API key is an identifier embedded in your public pages rather than a secret, and you control the domains it may be used from.

No system is perfectly secure. If a breach affecting your personal data occurs, we will notify you and the relevant regulator where the law requires it, without undue delay.

9. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you, and receive a copy;
  • correct data that is inaccurate or incomplete;
  • delete your data, subject to records we must keep;
  • restrict or object to certain processing;
  • receive your data in a portable format;
  • withdraw consent where processing relies on it; and
  • complain to your local data protection authority.

Much of this is self-service: your account settings let you view and correct your details, export or delete sources, and delete the account entirely. For anything else, contact us at contact@chatagently.com and we will respond within the period the law allows. We will not discriminate against you for exercising a right.

If your request concerns data processed on behalf of one of our customers, we will refer you to that customer, who is the controller for it.

10. Cookies and similar technologies

We use cookies that are strictly necessary to run the Service: keeping you signed in, remembering your organization, and security. We do not use advertising cookies and we do not track you across other websites.

Your theme choice and some interface preferences are kept in your browser's local storage rather than sent to us. The widget uses session storage to group a conversation, which clears when the tab closes.

11. Children

The Service is not directed at children and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes, and how to reach us

We may update this policy. Where a change materially affects how we handle your personal data, we will give notice by email or in the Service before it takes effect. The date at the top of this page is the date of the current version.

Questions, requests, or complaints: contact@chatagently.com, or write to us at [NOTICE ADDRESS]. Our establishment for data protection purposes is [JURISDICTION].

See also our Terms of Service, or get in touch.