# Privacy Policy

Effective: April 14, 2026

This Privacy Policy explains how chatebot collects, uses, stores, shares, and transfers personal data when you use our website, products, APIs, support channels, and related services.

## 1. Controller and Contact

Data Controller: CHATEBOT (SMC-Private) Limited, Pakistan. Data is processed and stored in the EU (Frankfurt, Germany) via our cloud infrastructure provider.

- Privacy: support@chatebot.com
- Legal: legal@chatebot.com

## 2. Data We Collect

- Account owner data: name, email, login metadata, workspace membership, and profile preferences.
- Billing data: plan, invoices, tax details, billing address, and payment metadata from our payment provider.
- Website visitor data: device details, IP-derived location, and cookie preferences.
- Support data: emails, tickets, troubleshooting logs, and attachments you share with support.
- Transactional email data: recipient email address, delivery events, and message metadata used for service notifications.
- Bot conversation data: prompts, messages, generated output, moderation signals, and usage logs.
- Knowledge base data: files, links, text snippets, embeddings, and indexing metadata uploaded by customers.

## 3. How We Use Data

We use personal data to operate and secure the Services, authenticate users, process billing, provide support, improve system quality, detect abuse, and comply with legal obligations.

## 4. Legal Bases

- **Contract**: to provide and maintain the Services you requested.
- **Legitimate interests**: to secure, improve, and operate the platform responsibly.
- **Consent**: where required for optional cookies, marketing communication, or region-specific processing.
- **Legal obligation**: to comply with laws, tax requirements, lawful requests, and recordkeeping duties.

## 5. Controller vs Processor Roles

For account, billing, and website operations, chatebot acts as controller. For bot conversation data and customer-uploaded knowledge base content processed on behalf of customers, chatebot acts as processor under the Data Processing Agreement (DPA).

## 6. Sharing and Subprocessors

We share data with contracted providers that help deliver hosting, analytics, payments, transactional email delivery, and AI processing. Current providers and processing purposes are listed on our Subprocessors page.

## 7. International Transfers

We operate with primary EU hosting but may transfer personal data to providers in other jurisdictions, including the United States, where required for service delivery. We use transfer safeguards such as Standard Contractual Clauses, adequacy decisions, and equivalent legal mechanisms where applicable.

## 8. Cookies and Tracking

We use necessary cookies for core operation and optional analytics and marketing cookies based on consent where required. See our Cookie Policy for provider-level details and opt-out controls.

## 9. Retention

- Account and billing records are retained for the subscription lifecycle and statutory accounting periods.
- Support records are retained for operational continuity, dispute handling, and service quality review.
- Conversation and knowledge base data are retained according to workspace settings and product retention controls.
- Security, fraud, and audit logs are retained for detection, prevention, and legal compliance periods.
- When retention is no longer required, data is deleted or irreversibly anonymized.

## 10. Your Rights

- Access, correction, deletion, restriction, objection, and portability rights where applicable.
- Right to withdraw consent for consent-based processing at any time.
- Right to lodge a complaint with your local supervisory authority.

## 11. Children's Data

The Services are not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child submitted personal data, contact support@chatebot.com.

## 12. Policy Updates

We may update this Policy. Material updates will be communicated by website notice, in-product notice, or email where appropriate.

## Related Pages

- Home: https://chatebot.com/home.md
- Pricing: https://chatebot.com/pricing.md
- Terms and Conditions: https://chatebot.com/legal/terms.md
- Data Processing Agreement: https://chatebot.com/legal/dpa.md
- Cookie Policy: https://chatebot.com/legal/cookies.md
- Subprocessors: https://chatebot.com/legal/subprocessors.md
- Billing and Cancellation: https://chatebot.com/legal/billing-and-cancellation.md
- Contact: https://chatebot.com/contact.md
