Privacy Policy
Effective date: 2023-03-27
1. Introduction
Welcome to Chatsimple.
Chatsimple ("us", "we", or "our") operateschatsimple.ai (hereinafter referred to as "Service").
Our Privacy Policy governs your visit tochatsimple.ai, and explains how we collect, safeguard, and disclose information that results from your use of our Service.
We use your data to provide and improve Service. By using Service, you agree to the collection and use of information in accordance with this policy. Unless otherwise defined in this Privacy Policy, the terms used in this Privacy Policy have the same meanings as in our Terms and Conditions.
Our Terms and Conditions ("Terms") govern all use of our Service and together with the Privacy Policy constitutes your agreement with us ("agreement").
2. Definitions
- SERVICE means the chatsimple.ai website operated by Chatsimple.
- PERSONAL DATA means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession).
- USAGE DATA is data collected automatically either generated by the use of Service or from Service infrastructure itself (for example, the duration of a page visit).
- COOKIES are small files stored on your device (computer or mobile device).
- DATA CONTROLLER means a natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal data are, or are to be, processed. For the purpose of this Privacy Policy, our customers (the entities integrating our chatbot app into their websites) are considered Data Controllers of the personal data collected through their use of our services.
- DATA PROCESSOR (OR SERVICE PROVIDER)means our company, Chatsimple, which processes personal data on behalf of our customers (the Data Controllers) by providing services related to the use of our chatbot app. We act as Data Processors and carry out data processing activities as instructed by our customers for the efficient functioning of our services.
- DATA SUBJECT is any living individual who is the subject of Personal Data.
- THE USER is the individual using our Service. The User corresponds to the Data Subject, who is the subject of Personal Data.
3. Information Collection and Use
We collect several different types of information for various purposes to provide and improve our Service to you.
4. Types of Data Collected
We collect personal information from or about you to deliver, improve, and promote our Services, as well as to communicate with you effectively. This section outlines the categories of personal information we may collect. Providing us with the personal information identified in this Notice is voluntary; however, failing to provide certain information may limit our ability to offer you some or all of our Services.
- Contact and Demographic Information:This includes your first and last name; billing address; telephone number; affiliated organization and industry; job title; timezone; and email address.
- Payment Information:Should you make a purchase, our payment processor will collect your payment information including your name, credit card information, and billing address, alongside the details of your purchase. Payment information is not collected by us.
- Account Information: We may collect login credentials, such as your user ID, password and access token.
- Location Data: While using our Services, your mobile device or browser may share your location data, through WiFi and GPS, and IP address or MAC address based on the settings of your phone and browser.
- Education and Employment Information:If you apply for employment with Chatsimple, we may collect information regarding your employment and work history, as well as personal information concerning your potential employment. This may include your education and employment history, address and contact information, demographic information, and the contents of your resume.
- Communication Information:We may collect audio, electronic, or visual information, which includes screen sharing views; any data in any files uploaded, emailed or otherwise provided by customers; the contents of your communications with Chatsimple, whether via e-mail, social media, Slack, telephone or otherwise; and inferences we may draw from other personal information we collect.
- Document and File Information:Any files uploaded to the Chatsimple platform will be collected and stored.
- Chatbot Interaction Information:When you interact with our chatbot services, we may also collect and process the following information:
- User-Generated Content:We collect and store the text-based conversations you have with our chatbot.
- Device Information:We may collect technical information such as your device's IP address, browser type, and operating system for security and analytical purposes.
5. Use of Data
Chatsimple uses the collected data for various purposes:
- 5.1. to provide and maintain our Service;
- 5.2. to notify you about changes to our Service;
- 5.3. to allow you to participate in interactive features of our Service when you choose to do so;
- 5.4. to provide customer support;
- 5.5. to gather analysis or valuable information so that we can improve our Service;
- 5.6. to monitor the usage of our Service;
- 5.7. to detect, prevent and address technical issues;
- 5.8. to fulfil any other purpose for which you provide it;
- 5.9. to carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection;
- 5.10. to provide you with notices about your account and/or subscription, including expiration and renewal notices, email-instructions, etc.;
- 5.11. to provide you with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless you have opted not to receive such information;
- 5.12. in any other way we may describe when you provide the information;
- 5.13. it may be used by our online data partners or vendors to associate your activities with other personal information they or others have about you, including by association with your email or home address. We (or service providers on our behalf) may then send communications and marketing to these email or home addresses. You may opt out of receiving this advertising by visiting https://app.retention.com/optout;
- 5.14. for any other purpose with your consent.
6. Retention of Data
We will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
We will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer time periods.
7. Transfer of Data
Your information, including Personal Data, may be transferred to – and maintained on – computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.
Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.
Chatsimple will take all the steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organisation or a country unless there are adequate controls in place including the security of your data and other personal information.
8. Disclosure of Data
We may disclose personal information that we collect, or you provide:
- 8.1. Disclosure for Law Enforcement.Under certain circumstances, we may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities.
- 8.2. Business Transaction. If we or our subsidiaries are involved in a merger, acquisition or asset sale, your Personal Data may be transferred.
- 8.3. Other cases. We may disclose your information also:
- 8.3.1. to our subsidiaries and affiliates;
- 8.3.2. to contractors, service providers, and other third parties we use to support our business;
- 8.3.3. to fulfill the purpose for which you provide it;
- 8.3.4. for the purpose of including your company's logo on our website;
- 8.3.5. for any other purpose disclosed by us when you provide the information;
- 8.3.6. with your consent in any other cases;
- 8.3.7. if we believe disclosure is necessary or appropriate to protect the rights, property, or safety of the Company, our customers, or others.
9. Security of Data
The security of your data is important to us but remember that no method of transmission over the Internet is 100% secure. We strive to use commercially acceptable means to protect your Personal Data.
10. Deletion of Data
If you wish for your data to be deleted from our databases, please email [email protected].
11. Your Data Protection Rights Under General Data Protection Regulation (GDPR)
If you are a resident of the European Union (EU) and European Economic Area (EEA), you have certain data protection rights, covered by GDPR. Your data will not be transferred outside of Europe.
We aim to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data. If you wish to be informed what Personal Data we hold about you and if you want it to be removed from our systems, please email us at [email protected].
In certain circumstances, you have the following data protection rights:
- 11.1. the right to access, update or to delete the information we have on you;
- 11.2. the right of rectification. You have the right to have your information rectified if that information is inaccurate or incomplete;
- 11.3. the right to object. You have the right to object to our processing of your Personal Data;
- 11.4. the right of restriction. You have the right to request that we restrict the processing of your personal information;
- 11.5. the right to data portability. You have the right to be provided with a copy of your Personal Data in a structured, machine-readable and commonly used format;
- 11.6. the right to withdraw consent. You also have the right to withdraw your consent at any time where we rely on your consent to process your personal information;
Please note that we may ask you to verify your identity before responding to such requests. Please note, we may not able to provide Service without some necessary data.
You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the European Economic Area (EEA).
12. Your Data Protection Rights under the California Consumer Privacy Act (CCPA)
If you are a California resident, you are entitled to learn what data we collect about you, ask to delete your data and not to sell (share) it. To exercise your data protection rights, you can make certain requests and ask us:
12.1. What personal information we have about you. If you make this request, we will return to you:
- 12.1.1. The categories of personal information we have collected about you.
- 12.1.2. The categories of sources from which we collect your personal information.
- 12.1.3. The business or commercial purpose for collecting or selling your personal information.
- 12.1.4. The categories of third parties with whom we share personal information.
- 12.1.5. The specific pieces of personal information we have collected about you.
- 12.1.6. A list of categories of personal information that we have sold, along with the category of any other company we sold it to. If we have not sold your personal information, we will inform you of that fact.
- 12.1.7. A list of categories of personal information that we have disclosed for a business purpose, along with the category of any other company we shared it with.
Please note, you are entitled to ask us to provide you with this information up to two times in a rolling twelve-month period. When you make this request, the information provided may be limited to the personal information we collected about you in the previous 12 months.
12.2. To delete your personal information. If you make this request, we will delete the personal information we hold about you as of the date of your request from our records and direct any service providers to do the same. In some cases, deletion may be accomplished through de-identification of the information. If you choose to delete your personal information, you may not be able to use certain functions that require your personal information to operate.
12.3. To stop selling your personal information. We don't sell or rent your personal information to any third parties for any purpose. We do not sell your personal information for monetary consideration. However, under some circumstances, a transfer of personal information to a third party, or within our family of companies, without monetary consideration may be considered a "sale" under California law. You are the only owner of your Personal Data and can request disclosure or deletion at any time.
If you submit a request to stop selling your personal information, we will stop making such transfers.
Please note, if you ask us to delete or stop selling your data, it may impact your experience with us, and you may not be able to participate in certain programs or membership services which require the usage of your personal information to function. But in no circumstances, we will discriminate against you for exercising your rights.
To exercise your California data protection rights described above, please send your request(s) by[email protected].
Your data protection rights, described above, are covered by the CCPA, short for the California Consumer Privacy Act. To find out more, visit the official California Legislative Information website. The CCPA took effect on 01/01/2020.
13. Service Providers
We may employ third party companies and individuals to facilitate our Service ("Service Providers"), provide Service on our behalf, perform Service-related services or assist us in analysing how our Service is used.
These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
Google user data is obtained with Google Workspace. For Google Workspace APIs, Google user data is not used to train generalized ML/AI models.
Third parties that have access to personal information are stated below:
- Amazon Web Services: PII storage and processing. Stores and processes user account information.
- Stripe: PII storage and processing. Stores and processes payment information.
- OpenAI: PII storage and processing. Stores and processes conversations between visitors and chatbot.
- Microsoft Azure: PII storage and processing. Stores and processes conversations between visitors and chatbot.
Training materials data is securely stored on AWS and Pinecone, two highly reputable cloud storage platforms.
14. Analytics
We may use third-party Service Providers to monitor and analyze the use of our Service.
15. CI/CD tools
We may use third-party Service Providers to automate the development process of our Service.
16. Behavioral Remarketing
We may use remarketing services to advertise on third-party websites to you after you visited our Service. We and our third-party vendors use cookies to inform, optimise and serve ads based on your past visits to our Service.
17. Payments
We may provide paid products and/or services within Service. In that case, we use third-party services for payment processing (e.g. payment processors).
We will not store or collect your payment card details. That information is provided directly to our third-party payment processors whose use of your personal information is governed by their Privacy Policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information.
18. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.
We will let you know via email and/or a prominent notice on our Service, prior to the change becoming effective and update "effective date" at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
19. Contact Us
If you have any questions about this Privacy Policy, please contact us by email: [email protected].