Legal · Last updated 5 October 2026
Privacy Policy
This is a template provided for transparency and is pending review by legal counsel. It is not legal advice and may change before launch.
ChatKit (“we”, “us”) provides an AI support agent and live chat inbox for websites. This policy explains what personal data we process, why, and the rights you have under the EU General Data Protection Regulation (GDPR) and similar laws.
01Who is responsible
For our customers' account data (people who sign up for ChatKit), we are the controller.
For visitor chats on our customers' websites, the website owner is the controller and we act as their processor. We process visitor messages only on their documented instructions, under our Data Processing Agreement (DPA). If you chatted with an agent on someone else's site, please contact that business first.
02Data we process
- Account data: name, email, workspace name, billing details (handled by Stripe — we never store full card numbers).
- Knowledge content: pages, files and Q&A you add to train your agent.
- Visitor chat data: messages, timestamps, approximate location derived from IP, browser information, and any contact details a visitor chooses to share (e.g. email for lead capture).
- Usage data: product analytics and error logs used to keep the service reliable.
03Why we process it
- To provide the service: generate answers, deliver chats to your inbox, send notifications (contract).
- To bill you and prevent fraud (contract, legal obligation).
- To secure and improve the service (legitimate interests).
- To send product updates you can opt out of at any time (consent / legitimate interests).
04AI processing
Visitor questions and relevant snippets of your knowledge content are sent to our AI model provider to generate answers. We use API terms under which this data is not used to train the provider's models.
We do not use your content or your visitors' conversations to train models for other customers.
05Subprocessors
We use a small number of vetted subprocessors. Transfers outside the EEA rely on Standard Contractual Clauses.
| Provider | Purpose | Location |
|---|---|---|
| OpenAI | Generating AI answers and embeddings | USA (SCCs) |
| Clerk | Account authentication | USA (SCCs) |
| Stripe | Payments and invoicing | USA / EU (SCCs) |
| Resend | Transactional email | USA (SCCs) |
| EU hosting provider | Application servers and database | European Union |
We will notify customers of material changes to this list in advance.
06Retention
Account data is kept while your account is active and deleted within 30 days after closure, except where we must retain invoices by law. Customers control retention of visitor conversations and can delete them at any time; deleted data is removed from backups within 30 days.
07Security
Data is hosted in the EU, encrypted in transit (TLS) and at rest. Access is limited to staff who need it, and secrets such as integration tokens are encrypted at the application level.
08Your rights
You can request access, correction, deletion, restriction, portability, or object to processing. Email [email protected]. You may also complain to your local data protection authority. Visitors to a customer's website should contact that business, and we will assist them.
10Contact
Questions about privacy or our DPA? Email [email protected].