Data and privacy
What is stored about your visitors and about you, where it lives, who else touches it, how long it is kept, and what that means for your own privacy notice.
This page is the practical version. The formal one is our privacy notice.
Who is responsible for what
For your visitors' conversations, you are the controller and we are your processor: we store and process them on your behalf, to run your agent, and for nothing else. We do not sell data, show advertising or build profiles, and we do not train models on your content or your conversations.
Agencies sit in between: your client is the controller, you are their processor, and we are yours.
What is stored about a visitor
| What | Details |
|---|---|
| The conversation | Every message and answer, with the time, the sources used and the measurements, and the page of your site each question was asked on: its address, with numbers and codes masked when the agent does not know the page as a source |
| A random visitor number | Made in the visitor's browser when they first send a message or a file, and kept until the tab is closed, so that one visit's messages and files can be told apart from another's. It is not linked to an account or an IP address, nor to a name unless the visitor leaves one in the contact form or a ticket. |
| A rating | If the visitor gave a thumbs up or down |
| Contact details | Only if you switched the contact form on and the visitor filled it in: what the form asked, whether they want news and offers, the words they were shown, and the page. Kept 3 years. |
| A ticket | Only if you switched tickets on and the visitor opened one: their e-mail address, their name if they gave it, their question, the page and the widget's language, the replies by e-mail either way with the address each came from, mail held back, and your team's notes. Kept 2 years after it is solved. |
| What opened the chat | With each conversation: the button, or its greeting or second nudge. How often the chat is opened is counted per hour, with nothing that identifies a visitor. |
| Files the visitor sent | Only if you switched files from visitors on: the file and the text read from it, for 30 days, and a picture without what its camera stored in it, such as where it was taken. After that only the name stays with the conversation. |
| The IP address | Not stored. For the message limit we keep a fingerprint of it for 24 hours. It is made with a key that changes every day and is deleted minutes after the day ends. Without that key the fingerprint cannot be turned back into the address. Like anything we delete, the key stays a while longer in the backups our database host keeps for restoring. |
The widget sets no cookies, and keeps nothing in the visitor's browser before they use the chat unless your site passes their consent for the second nudge. It asks for no name or e-mail address unless you switch on the contact form or tickets. What a visitor types is up to them, and people do type personal details into chat windows. If your subject invites that, say in the Notice above the chat what not to share.
A Calendly booking goes straight from the visitor to Calendly. We record that a booking happened, not who made it.
Where it lives and who touches it
| What | Who | Where |
|---|---|---|
| The application | Vercel | Frankfurt, Germany |
| The database: agents, sources, conversations | Neon (Postgres) | EU |
| Uploaded files, visitors' files and logos | Cloudflare R2 | EU jurisdiction |
| Writing answers, and the grounding check | Cortecs, a European model gateway | For each answer it receives your instructions, the page the visitor is on, the passages found, the recent conversation and any file the visitor sent with the question, and a visitor's scan, to read its text within the EU |
| Turning text into search vectors | OpenAI | United States |
| Report e-mails, the e-mails telling you of new leads and tickets, which carry what the visitor left, and a ticket's mail both ways: to the visitor, and the replies that come back | Resend | United States. The mail we send leaves from servers in the EU (Ireland) |
| Sign-in to the dashboard | Clerk | Concerns you, not your visitors |
| Payments | Stripe | Concerns you, not your visitors. Card details never reach us. |
The two steps outside the EU. To search by meaning, every passage of your sources is turned into a row of numbers when you add it, and every question is turned into numbers the same way when it is asked. That step runs at OpenAI in the United States, under its data-processing terms. OpenAI does not use this data to train its models. It means the text of your sources, and the text of each question, passes through the US briefly. The e-mails we send, the reports, the e-mails telling you of new leads and tickets with what the visitor left, and a ticket's mails to the visitor, go through Resend, and the replies to a ticket come in through Resend too. Resend processes mail in the United States under the EU-US Data Privacy Framework and standard contractual clauses. We say so here rather than let "EU-hosted" suggest otherwise.
How long it is kept
| What | How long |
|---|---|
| Conversations | Until you delete the conversation, or the agent |
| Sources | Until you delete them, or the agent. Passages and the stored file go at the same moment. |
| Uploads that never completed | 1 hour |
| Files from visitors | 30 days. The name stays with the conversation. |
| Files attached and never sent | 2 hours |
| Leads | 3 years, or until you delete the lead, its conversation or the agent |
| Tickets | 2 years after being solved, or until you delete the ticket, its conversation or the agent. A ticket that is not solved stays until you delete it. |
| Rate-limit fingerprints | 24 hours |
| The audit log | 2 years. See The EU AI Act. |
| Usage and billing records | As long as the account exists, for invoicing |
There is no automatic deletion of conversations. You erase one yourself with Delete at the top of it in Activity, or over the API. What the agent did stays in the audit trail, which is a record of what the system did rather than of what anyone said.
Requests from visitors
Under the GDPR a visitor can ask you what you hold about them, and ask for it to be corrected or erased. For chat conversations that means: find the conversation in Activity (the visitor can tell you roughly when it took place), export or read it, and delete it if that is what they asked for. A visitor who sent the wrong file can have just that file erased, with Delete file in Activity. Contact details a visitor left are on the Leads page, each with its own Delete, and a visitor's tickets are on the Tickets page, each with its own Delete too. We do not answer such requests in your place, because the data is yours, and you no longer need us to carry one out.
What to put in your own privacy notice
Three sentences usually cover it:
- that your site has a chat assistant which is an AI, and that conversations are stored to answer questions and to improve the service
- that ChatterLab processes them on your behalf, in the EU, with the two exceptions named above
- how long you keep them, and how to ask for deletion
If visitors can send files, add that a file, and the text read from it, is kept for 30 days.
If the chat asks for contact details, add what you use them for and that they are kept 3 years. Leads lists what else the law asks of you.
If visitors can open tickets, add that their address and question are used to answer them by e-mail, and that a ticket is kept 2 years after it is solved.
If your site passes its visitors' consent for the second nudge, your cookie notice names the value the button keeps for the visit, under the category you chose for it.
For a data processing agreement, write to management@sri-group.eu.
For agencies
- Decide per client whether the monthly report may show the conversations. Where visitors may share personal matters, figures alone are the safer choice.
- The Client link opens without a password. Send it only to the client, and read Clients on what to do if it leaks.
- Your fees are never shown to a client and are kept out of the audit log.