Privacy notice

How ChatterLab handles data

Who is responsible

The controller for the data described here is SRI Group BV, Korte Gasthuisstraat 18 bus 301, 2000 Antwerpen, Belgium, enterprise number 1037.052.239, which runs ChatterLab. For any question or request about your data, write to management@sri-group.eu.

Two kinds of people

Customers create an account, build agents and pay for a plan. Visitors talk to an agent on a customer’s website. Customers are the controllers of what their visitors say; ChatterLab processes it on the customer’s behalf.

On chatterlab.ai and in the dashboard, the chat is an agent of our own, built with ChatterLab, and we are its customer: what you write to it, and the details you leave in its contact form or a ticket, are kept as a visitor’s are, below, with us as their controller.

What we store

  • Account. Your name, email address and sign-in identity, held by our authentication provider, and the workspace and agents you create.
  • Team members. Where a workspace invites colleagues, the address each invitation is sent to, the role it offers, who sent it and when, and the language it is sent in; once a colleague joins, their address and name as their account shows them, brought up to date as they use the workspace, and when they last used it. Colleagues read the workspace’s conversations, contact details and tickets as its owner does; what else they may do depends on their role. The link at the foot of every invitation mail stops all invitation mails to that address; we then keep a key derived from the address, not the address itself, so as never to mail it one again.
  • Knowledge. The files, pages and text you give an agent, the passages they are split into, and a numerical representation of each passage used to find relevant ones.
  • Conversations. Every message a visitor sends and every answer an agent gives, with the model used, the passages it drew on, a confidence score and any rating the visitor left. A random identifier, made in the visitor’s browser when they first send a message or a file and kept only until the tab is closed, holds one visit’s messages and files together; it is not linked to a person unless the visitor leaves their details in the contact form or opens a ticket, below.
  • The chat button. On a site that passes its visitors’ consent, and only while the customer has switched on its greeting or second message, the button keeps a small record of the visit in the browser until the tab is closed: when the visit began, how many pages were seen and which message was shown. It times the second message and is never sent to us. How often the chat is opened is counted per hour, with nothing that identifies a visitor, and each conversation records whether the button or one of its messages opened it.
  • Files visitors send. Where a customer allows it, a document a visitor attaches to a question, and the text read from it, kept for 30 days. After that only its name stays with the conversation.
  • Contact details visitors leave. Where a customer switches on the chat’s contact form, what the visitor enters in it (a name, an email address, a phone number or a company, as the customer chooses), whether they want news and offers, the words they were shown and the page they were on. They are e-mailed to the addresses the customer names and kept for 3 years.
  • Tickets. Where a customer switches on tickets, the e-mail address, name and question a visitor leaves for the customer’s team, and the page they were on. The visitor is sent one confirmation and the team’s answers by e-mail. The visitor’s replies by e-mail are received and added to the ticket, as is what the team writes, including notes only the team sees. A received mail is kept as its text; its attachments are not.
  • Mail to an agent. Where a customer lets an agent answer e-mail, the mail their customers send to the customer’s own address and forward to the agent: who sent it, its subject and its text, kept as a conversation, as one in the chat is, with the agent’s answer or its draft when none was sent. Attachments are not read or kept. Mail forwarded while this is switched off is not kept.
  • Webhooks. Where a customer adds a webhook, each new lead and ticket, with the details in it, is sent to the address the customer names, which is theirs to choose and to answer for. What is sent is kept for 7 days, to try again while that address does not answer.
  • Helpdesks. Where a customer connects Freshdesk, Zoho Desk or Zendesk, a ticket is made there instead of here: the visitor’s address and name, the question, the page and the conversation so far go to the customer’s own helpdesk, which they chose and answer for. The key or the permission for it is kept encrypted.
  • Usage and billing. Message counts, tokens and credits per month, and a reference to your subscription. Card details never reach us; they are handled by our payment provider.
  • Audit trail. A record of significant events, such as an agent created, a source added or a plan changed, kept for 24 months, as the EU AI Act requires at least six.
  • Abuse protection. The public chat endpoints are rate-limited per visitor address. Only a fingerprint of the address is stored, for one day. It is made with a key that changes every day and is deleted minutes after its day ends; without that key the fingerprint cannot be turned back into the address. Like anything we delete, the key remains for a while in our database host’s backups.

Who processes it

  • Hosting: Vercel, in Frankfurt. Every request to the application passes through it, with the address it came from.
  • Database and files: Neon (Postgres) and Cloudflare R2, both in EU regions with the EU jurisdiction setting on storage.
  • Answers: Cortecs, an EU-hosted model gateway. The passages an answer draws on, the recent conversation and any file the visitor sent with the question are sent to it for each reply.
  • Passage representations: OpenAI’s embedding service, in the United States, under its data-processing terms; API data is not used to train its models. The text of each passage is sent to it when a source is added or retrained, and the text of each question when it is asked, since a question has to be represented the same way to be matched. With e-mail, below, it is one of the two steps that run outside the EU.
  • E-mail: Resend, which sends the reports and the contact details a visitor leaves to the addresses a customer enters, sends the mail about tickets, an agent’s answers to mail and the invitations to join a workspace, and receives the replies to it and the mail forwarded to an agent. Resend processes mail in the United States, under the EU-US Data Privacy Framework and standard contractual clauses; the mail itself leaves from, and arrives at, servers in the EU (Ireland).
  • Sign-in: Clerk, which also receives an invited address when its owner creates an account from the invitation’s mail. Payments: Stripe, including EU VAT handling.

How long

Knowledge and conversations stay until the customer deletes the source, the agent, or the account; deleting an agent removes its conversations and every uploaded file. Usage records stay with the account for billing. Files visitors send, and the text read from them, are deleted after 30 days, or sooner with their conversation. Contact details visitors leave are deleted after 3 years, or sooner with their conversation or when the customer deletes them. A ticket is deleted 2 years after it was solved, or sooner with its conversation or when the customer deletes it; one that is never solved stays until the customer deletes it. Mail to an agent stays as its conversation does. What a webhook sent is deleted after 7 days. An invitation that expired, was taken back or was declined, and a team member’s place they left or were removed from, are deleted 30 days later, each with the address it carried. The key that stops invitation mails to an address is kept for as long as we send them. The audit trail is deleted after 24 months. Rate-limit hashes are deleted after a day.

Your rights

Under the GDPR you can ask what we hold about you, have it corrected or deleted, receive a copy, and object to or restrict its processing. Visitors should ask the website they were talking to, which controls that data; we help that customer answer. Anyone can also complain to their national data-protection authority.

Changes

This notice is updated when the product changes what it stores or who processes it. The date on the footer is the last update.