Legal
Privacy Policy
This policy explains what personal data CertifChat handles, why, who we share it with, and the rights you have over it.
Last updated: July 24, 2026
1. Overview
CertifChat ("CertifChat", "we", "us", or "our") provides an AI assistant that trains on your website and documents and answers questions through an embeddable chat widget. This Privacy Policy describes how we handle personal data across our website, dashboard, API, and widget (the "Service"). You can contact us about privacy any time at hello@certifchat.com.
2. Our two roles
We handle personal data in two capacities, and the difference matters for your rights:
- As a controller, for data about our own customers and website visitors: the account, contact, and billing information you give us, and how you use our website and dashboard. This policy governs that data.
- As a processor, for the content our customers connect and for the conversations end users have with a customer's chatbot. Here the customer is the controller and decides why the data is processed. We process it on the customer's instructions under our Data Processing Agreement. If you are an end user chatting with a chatbot on someone else's website, that website operator is responsible for your data; please contact them, and see section 9 below.
3. Data we collect
As a controller, we collect:
- Account data: your name, email address, password (stored only as a hash), and team or sub-account membership.
- Billing data: your plan, subscription status, credit usage, and payment records. Card details are collected and stored by Paddle, our Merchant of Record and payment provider, not by us; we receive limited information such as the last four digits, card brand, and billing status.
- Usage and device data: log data, IP address, browser and device information, pages viewed, and actions taken, collected through our servers and analytics.
- Communications: messages you send us for support or sales, and email you receive from us.
As a processor, on our customers' behalf we handle the sources customers connect (which may contain personal data), and the widget conversation data those chatbots collect from end users, such as the messages exchanged, a visitor identifier, IP address, ratings, and any contact details an end user chooses to submit.
4. How we use controller data
- to create and run your account and provide the Service;
- to process payments, manage subscriptions and credits, and prevent fraud;
- to secure the Service, enforce our terms, and debug and improve how it works;
- to send you service messages, and, where permitted, occasional product updates you can opt out of; and
- to comply with legal obligations and resolve disputes.
We do not sell your personal data, and we do not use customer content or end-user conversations to train our own or any third party's general AI models.
5. Legal bases
Where the GDPR or similar laws apply, we rely on these legal bases: the performance of our contract with you (to provide the Service and billing); our legitimate interests (to secure, maintain, and improve the Service and to communicate with you), balanced against your rights; your consent (for optional analytics cookies and marketing email, which you can withdraw); and compliance with a legal obligation.
6. Providers who process data for us
We share data with a small set of vetted providers so we can run the Service. Each processes data only to provide their part of it:
- OpenAI: large language model and embedding processing that powers answers and search.
- Supabase: database, authentication, and file storage for account data and connected content.
- Paddle: our Merchant of Record for payments, subscriptions, and billing.
- Resend: transactional and account email delivery.
- Hostinger: hosting for our API and content crawler, including a caching and queue layer.
- Google Analytics: aggregate website analytics, used with consent where required.
These providers operate in the United States and the European Union, and personal data may be processed in those regions depending on each provider's configuration. We may also disclose data to comply with the law, enforce our terms, protect rights and safety, or as part of a merger, acquisition, or sale of assets, in which case we will require the recipient to honor this policy. A current list of the providers we use as a processor is kept in our Data Processing Agreement.
7. International transfers
We operate globally, and the providers above operate in the United States and the European Union, so your data may be transferred and processed outside your country. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses together with the providers' own transfer commitments.
8. Retention
We keep controller data for as long as your account is active and for a reasonable period afterward to meet legal, tax, accounting, and security needs, then delete or anonymize it. Content and conversation data we process for a customer are retained per that customer's settings and instructions and deleted after termination as described in our Data Processing Agreement.
9. If you are an end user of a chatbot
When you chat with a CertifChat-powered assistant embedded on a business's website, that business decides what data is collected and why, and it is the controller of your conversation. We only process that data to run the chatbot for them. To access, correct, or delete your conversation data, or to ask how it is used, please contact the business whose site you used. You can also contact us at hello@certifchat.com and we will route your request to the right customer.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, to withdraw consent, and to not receive discrimination for exercising these rights. If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your data protection authority. If you are in California or a similar jurisdiction, you have rights to know, delete, correct, and opt out of the sale or sharing of personal information; we do not sell or share personal information as those terms are defined. To exercise any right, email hello@certifchat.com. We will verify your request and respond within the time the law requires.
11. Cookies and analytics
We use strictly necessary cookies to keep you signed in and to keep the Service secure. With your consent where required, we use analytics cookies to understand how the website is used so we can improve it. You can control cookies through your browser settings. Blocking necessary cookies may stop parts of the Service from working.
12. Security
We protect data with encryption in transit, hashed passwords, scoped access controls, origin checks on the widget, rate limiting, and least- privilege access to our systems. No method of transmission or storage is completely secure, but we work to protect your data and to notify you and the relevant authorities of a breach where the law requires.
13. Children
The Service is for businesses and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. We will change the date above and, for material changes, take reasonable steps to notify you. Your continued use of the Service after an update means you accept the revised policy.
15. Contact
For any privacy question or request, email hello@certifchat.com or visit our contact page.
