Privacy Policy

At YourChatbot.app, we are committed to protecting the privacy of our users and ensuring transparency in how we collect, store, and process data. This Privacy Policy outlines how we handle data, including through our chatbot services. We comply with applicable data protection laws, including the General Data Protection Regulation (GDPR) where applicable.

1. Information We Collect

When using our chatbot or subscribing to our services, we may collect the following information:

  • Email address (if you voluntarily provide it for subscribing or during interactions).
  • Conversation data between you and our chatbot (to improve the service and ensure better responses).
  • IP address and browser details (for security and analytics purposes).
  • Additional information provided through third-party integrations (e.g., Google Workspace APIs).

2. Legal Basis for Processing Your Information

We process your personal data based on the following legal grounds:

  • Consent: When you provide explicit consent for us to process your data for specific purposes.
  • Performance of a Contract: To fulfill our obligations under the services you have subscribed to.
  • Legitimate Interests: To improve our services, ensure security, and conduct analytics, provided that such interests do not override your rights and freedoms.

3. How We Use Your Information

The information we collect is used to:

  • Improve and personalize your experience with our chatbot.
  • Analyze interactions for insights into customer behavior.
  • Provide customer support and respond to your inquiries.
  • Contact you via email if you've opted to receive updates or if follow-up communication is required.
  • Ensure the security and integrity of our services.

4. Data Retention

We retain collected data only as long as necessary to fulfill the purposes outlined in this policy, or as required by law. Conversation data may be anonymized and used for improving the chatbot’s functionality. Specific retention periods are as follows:

  • Personal data associated with active accounts: retained for the duration of the account and as needed for service provision.
  • Inactive accounts: data retained for one (1) year after account deactivation unless a longer retention period is required or permitted by law.
  • Aggregate and anonymized data: retained indefinitely for analytical purposes.

5. Data Security

We use industry-standard security measures to protect your information, including encryption and secure servers. Our data protection mechanisms include:

  • Encryption: All customer data is encrypted using industry-standard encryption algorithms both at rest and in transit.
  • Access Control: We employ user roles and permissions to ensure that only authorized personnel can access sensitive data.
  • Rate Limiting: To protect against abuse, we implement rate limiting on our chatbots, controlling the number of requests per user.
  • Domain Allowlist: We provide controls to specify which domains your chatbot can be embedded on, adding an extra layer of security.
  • Infrastructure Security: Our database and application run on GCP infrastructure.
  • Compliance: We are GDPR compliant and are in the process of obtaining SOC 2 compliance to further strengthen our security measures.
  • No AI Training: We do not use your data to train AI models. We use Retrieval-Augmented Generation (RAG) to generate responses without compromising your data.

While we strive to protect your data, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

6. Sharing of Information

We do not sell or share your personal data with third parties except:

  • To trusted third-party services such as hosting and AI platforms (e.g., GCP, Google) that assist in running our service, all of which comply with relevant data privacy regulations.
  • To service providers who perform services on our behalf, such as payment processing, data storage, and customer support.
  • If required by law or to protect our legal rights.
  • To address emergencies or acts of God.
  • To address disputes or enforce our agreements.

We ensure that all third-party service providers comply with applicable data protection laws and have appropriate safeguards in place.

7. Transferring Personal Data to the U.S.

Your personal data is processed and stored in the United States. The United States has not sought nor received a finding of “adequacy” from the European Union under Article 45 of the GDPR. Pursuant to Article 46 of the GDPR, we provide appropriate safeguards by entering into binding, standard data protection clauses, enforceable by data subjects in the EEA and the UK.

Depending on the circumstance, we also collect and transfer to the U.S. personal data with consent; to perform a contract with you; or to fulfill a compelling legitimate interest of YourChatbot.app in a manner that does not outweigh your rights and freedoms. We endeavor to apply suitable safeguards to protect the privacy and security of your personal data and to use it only consistent with your relationship with us and the practices described in this policy. We also enter into data processing agreements and model clauses with our vendors whenever feasible and appropriate. Since our inception, we have received zero government requests for information.

8. Data Subject Rights

The European Union’s General Data Protection Regulation (GDPR) and other countries’ privacy laws provide certain rights for data subjects. Your rights under GDPR include the following:

  • Right to be Informed: You have the right to be informed about the collection and use of your personal data.
  • Right of Access: You have the right to access your personal data and obtain information about how it is being processed.
  • Right to Rectification: You have the right to have inaccurate personal data corrected or completed if it is incomplete.
  • Right to Erasure: You have the right to request the deletion or removal of personal data where there is no compelling reason for its continued processing.
  • Right to Restrict Processing: You have the right to request the restriction or suppression of your personal data under certain conditions.
  • Right to Data Portability: You have the right to obtain and reuse your personal data for your own purposes across different services.
  • Right to Object: You have the right to object to the processing of your personal data in certain circumstances.
  • Rights Related to Automated Decision Making and Profiling: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

If you wish to exercise any of these rights, please contact us at privacy@yourchatbot.app. We will respond to your request within the statutory timeframe.

9. Cookies

We may use cookies to enhance your experience and track usage of our services. These cookies do not collect personal information and can be disabled in your browser settings. For more detailed information about the cookies we use and how to manage them, please refer to our Cookie Notice.

10. Use of Google Workspace APIs

YourChatbot.app uses Google Workspace APIs to provide certain functionalities within our service. We want to explicitly affirm that any data obtained through Google Workspace APIs is not used to develop, improve, or train generalized AI and/or ML models. The data accessed through these APIs is solely used for the specific purposes of providing our service features and is handled in accordance with our privacy practices as outlined in this policy.

11. Data Protection Mechanisms

At YourChatbot.app, we implement robust data protection mechanisms to safeguard your sensitive information:

  • Encryption: All customer data is encrypted using industry-standard encryption algorithms both at rest and in transit.
  • Access Control: We employ user roles and permissions to ensure that only authorized personnel can access sensitive data.
  • Rate Limiting: To protect against abuse, we implement rate limiting on our chatbots, controlling the number of requests per user.
  • Domain Allowlist: We provide controls to specify which domains your chatbot can be embedded on, adding an extra layer of security.
  • Infrastructure Security: Our database and application run on GCP infrastructure.
  • Compliance: We are GDPR compliant and are in the process of obtaining SOC 2 compliance to further strengthen our security measures.
  • No AI Training: We do not use your data to train AI models. We use Retrieval-Augmented Generation (RAG) to generate responses without compromising your data.

For more detailed information about our security practices and compliance measures, please contact us at support@yourchatbot.app.

12. Data Storage and Retention

Your personal data is stored by YourChatbot.app on its servers, and on the servers of the cloud-based database management services YourChatbot.app engages, located in the United States. YourChatbot.app retains service data for the duration of the customer’s business relationship with YourChatbot.app and for a period of time thereafter, to analyze the data for YourChatbot.app’s own operations, and for historical and archiving purposes associated with YourChatbot.app’s services. YourChatbot.app retains prospect data until such time as it no longer has business value and is purged from YourChatbot.app systems. All personal data that YourChatbot.app controls may be deleted upon verified request from Data Subjects or their authorized agents. For more information on where and how long your personal data is stored, and for more information on your rights of erasure and portability, please contact us at: privacy@yourchatbot.app.

13. Children’s Data

We do not knowingly attempt to solicit or receive information from children. Our services are not directed to anyone under the age of 13, and we do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal data, we will take steps to delete such information promptly.

14. Changes to This Policy

We reserve the right to update this Privacy Policy at any time. Any changes will be reflected on this page, and we encourage you to review it periodically. Your continued use of our services after any changes are posted signifies your acceptance of those changes.

15. Questions, Concerns, or Complaints

If you have any questions, concerns, complaints, or would like to exercise your rights, please contact us at:

YourChatbot.app
[Your Address Here, if applicable]
privacy@yourchatbot.app