1. About This Policy
This policy describes how Chattrick.ai processes data when the chatbot is used on a customer's website, and when the customer uses the service's portal for insights, chat logs and leads. We aim to be specific: what data we process, why we process it, how it is shared, and when it is deleted.
This policy is drafted in accordance with EU/EEA legislation and is intended to work alongside a Data Processing Agreement (DPA) for customers using the service in their business.
2. About Chattrick.ai and Contact Information
Chattrick.ai is a service provided by:
Chattrick Europe AB
Reg. no.: 559572-0490
Address: c/o Hedylity Technologies AB, Tyska Skolgänd 4, 111 31 Stockholm, Sweden
Chattrick.ai has not appointed a Data Protection Officer (DPO). The contact person for privacy matters is Rose-Linn Stenberg, Chief Platform Officer at Chattrick Europe AB, who can be reached at rose@chattrick.ai.
3. About the Chatbot
This chatbot is provided by Chattrick.ai and is used on the customer's website to answer questions, provide information and, where applicable, collect contact details from users.
The chatbot may use artificial intelligence to generate responses. Responses may therefore be incomplete or contain errors. Information from the chatbot should be evaluated before being relied upon for decisions.
The chatbot is not intended to provide legal, medical, financial or other professional advice.
We recommend that you do not enter national identity numbers, bank account numbers, passwords or other sensitive information in the chat. We also recommend avoiding sharing information about health, religion, political opinions or other special categories of personal data.
The user is solely responsible for how information from the chatbot is used.
The chatbot does not make automated decisions with legal effect for the user within the meaning of Article 22 of the General Data Protection Regulation (GDPR). All responses from the chatbot are purely informational and not legally binding. Users are encouraged to verify all important information independently.
4. Use of the Chatbot
The chatbot must not be used for unlawful purposes, attempts to circumvent security mechanisms, automated data extraction or any other use that may harm the service or associated systems.
It is not permitted to attempt to manipulate the chatbot into providing incorrect information, fake offers, discounts or other details that do not correspond to the business's actual offerings. Such use constitutes a breach of these terms and may result in access to the chatbot being revoked.
It is also not permitted to share graphic, offensive or abusive images or other content via the chatbot.
The provider may restrict or terminate access to the service if such use is detected.
5. Roles and Responsibilities
When the chatbot is used on the customer's website: The customer is generally the data controller. This means the customer determines the purpose of the processing (e.g. customer service, sales, booking) and what the data is used for. Chattrick.ai normally acts as the data processor and processes data on behalf of the customer, in accordance with the customer's instructions and agreements (including the DPA).
When the customer uses Chattrick.ai as a service: For account administration, access management, support and billing, Chattrick.ai acts as the data controller for the data necessary to deliver and administer the service.
If the service is distributed through a reseller or partner, the reseller may have its own obligations in relation to its customer relationship. For the processing that takes place within the platform itself, the allocation of roles normally follows the principles above.
6. What Data We Process
The scope depends on the customer's configuration, but will typically include:
- Chat and enquiry data: The content of the dialogue between the end user and the chatbot, including questions, answers and context necessary to provide relevant responses.
- Lead data (voluntarily provided): When lead collection is enabled, Chattrick.ai may send email notifications to addresses configured by the customer. The email typically contains contact details provided by the end user, along with a transcription or summary of the chat dialogue.
- Technical operations and security data: We process data such as IP addresses, timestamps, log data and error messages to ensure stable operations, troubleshooting and security.
7. Purpose of Processing
The data is processed in order to:
- Deliver chatbot functionality and provide relevant responses to enquiries.
- Enable follow-up with users who indicate that they wish to be contacted.
- Provide the business with insights through analysis of conversation data, including topics, user interests and needs, using AI-based analysis.
- Ensure stable operations, prevent misuse and maintain information security.
8. Legal Basis for Processing
The processing of personal data is based on the following legal grounds under Article 6 of the GDPR:
Legitimate interest (Art. 6(1)(f)):Delivery of chatbot functionality, AI-based analysis of conversation data to provide business insights, and ensuring stable operations and information security. The legitimate interest is the business's need to serve its customers and understand their enquiries. We consider that this interest is not overridden by the end user's rights, as the processing is limited to what is necessary to deliver the service.
Consent (Art. 6(1)(a)):When the user voluntarily provides contact details and requests to be contacted, these data are processed on the basis of the user's active consent.
9. No Training on Customer Data
Chattrick.ai does not use customer chat content, leads or uploaded documents to train its own models or improve general models for other customers. Customer data is used solely to deliver the service to the respective customer.
Should this practice change, it will only occur after clear prior notice and an update to the contractual framework. Where required by law, such a change will require explicit and active consent from the customer.
11. Storage Within the EU and Infrastructure
Customer data is stored and processed within the EU. The infrastructure is hosted by Hetzner in Frankfurt. We impose strict requirements on sub-processors to comply with applicable data protection regulations. A list of sub-processors is available on request or as part of the DPA.
The chatbot uses OpenAI's API service to generate responses. OpenAI acts as a sub-processor and processes data in accordance with their API terms. Chat content sent to OpenAI is retained for up to 30 days for security purposes and is then automatically deleted. OpenAI does not use API data to train its models. For more information, see OpenAI's data handling guidelines at platform.openai.com/docs/guides/your-data.
12. Retention and Deletion
We retain data for as long as necessary for the purpose or in accordance with the agreement:
- Chat dialogues: Retained for up to 2 years, unless the customer requests earlier deletion.
- Lead data: Retained for up to 2 years, unless the customer requests earlier deletion.
- Technical logs: Deleted on a rolling basis in accordance with operational and security procedures.
13. Information Security
We employ appropriate technical and organisational measures to protect data against unauthorised access, loss or misuse. This includes access control (least privilege), authentication, logging, secure communication (HTTPS) and established procedures for incident management.
14. End User Rights
When the chatbot is used on the customer's website, the customer is the data controller. End users have the following rights under the General Data Protection Regulation (GDPR):
- Right of access (Art. 15): Know what personal data is being processed about you.
- Right to rectification (Art. 16): Have inaccurate data corrected.
- Right to erasure (Art. 17): Request that personal data be deleted when it is no longer necessary for the purpose.
- Right to restriction of processing (Art. 18): Request that processing be restricted in certain situations.
- Right to data portability (Art. 20): Receive personal data you have provided in a structured, commonly used and machine-readable format, and transfer it to another data controller.
- Right to object (Art. 21): Object to processing based on legitimate interest.
Requests regarding access, rectification, erasure or other rights should be directed to Rose-Linn Stenberg, Chief Platform Officer at Chattrick Europe AB, at rose@chattrick.ai. The request will be forwarded from there to the appropriate channel, whether that is the business that owns the website or a reseller. The business operating the website remains the data controller under the GDPR and bears the overall responsibility for ensuring that your rights are upheld.
If you believe that the processing of your personal data is in breach of the GDPR, you have the right to lodge a complaint with a supervisory authority. In Sweden, this is the Swedish Authority for Privacy Protection, IMY (imy.se). In Norway, this is Datatilsynet (datatilsynet.no).
15. Security Incidents and Breaches
In the event of a personal data breach affecting customer data, we will notify the customer without undue delay, so that the customer can fulfil any notification obligations towards the supervisory authorities.
16. Changes
This policy and associated terms may be updated as needed, for example due to new functionality, changed legal requirements or regulatory changes. Material changes will be communicated directly to our customers.
17. Contact
Questions about privacy and data protection can be sent to:
Email: support@chattrick.ai
Subject: "Privacy – Chattrick.ai"