Fortrolighedspolitik

Sidst opdateret: 28. september 2026

Denne privatlivspolitik findes på engelsk og tysk. Du ser den engelske version.

1. Introduction and scope

Protecting your personal data matters to us. This privacy policy explains which personal data AdSimple GmbH ("we", "us") processes when you use ChatReact, on which legal basis we do so, which service providers are involved and which rights you have under the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).

It applies to:

  • the website www.chatreact.ai including its language versions, the blog, the documentation and the API reference;
  • the ChatReact web application (dashboard, onboarding, account and billing area);
  • the chat widget, FAQ widget and form widget that our customers embed on their own websites, as well as our WordPress plugin and Shopify integration;
  • the REST API and the MCP server of ChatReact;
  • the Email Assistant, which connects a customer's Microsoft 365 mailbox to ChatReact;
  • our communication with you by email, phone and contact form.

ChatReact is a business-to-business service. Our customers are companies that create AI chatbots for their own websites. Wherever this policy speaks of "customers" it means these companies and the people who use ChatReact on their behalf. "Visitors" are people who browse our website. "End users" are the people who chat with a chatbot, use a form or write to a mailbox that a customer runs with ChatReact.

2. Controller and contact

The controller within the meaning of Art. 4 No. 7 GDPR is:

AdSimple GmbH
Fabriksgasse 20
2230 Gänserndorf
Austria

Phone: +43 2282 60 715
Email: [email protected]
Company register: FN 64500 d, Landesgericht Korneuburg

Full company details are available in our imprint. For all questions about data protection, and to exercise your rights, please write to [email protected].

3. Our role: controller or processor

Which role we have depends on whose data is processed:

SituationOur roleYour contact for data-protection questions
You visit www.chatreact.ai, read the blog or documentationControllerAdSimple GmbH
You register, use the dashboard, pay for a plan or contact usControllerAdSimple GmbH
You apply for or take part in the partner programControllerAdSimple GmbH
You chat with a chatbot, submit a form or send an email to a company that uses ChatReactProcessor (Art. 28 GDPR) on behalf of that companyThe company that operates the website or mailbox

For end-user data we act strictly on the documented instructions of our customer under a data processing agreement. Section 13 describes this processing in detail so that end users know what happens with their data. Requests from end users about access, rectification or erasure should be addressed to the company whose chatbot or form they used; we support that company in answering them.

We process personal data only if one of the following legal bases applies:

  • Art. 6(1)(a) GDPR – consent, for example for web analytics, advertising measurement and any other processing that we start only after you opt in. Consent can be withdrawn at any time with effect for the future.
  • Art. 6(1)(b) GDPR – contract, for everything needed to provide the service you registered for, including account management, billing and support.
  • Art. 6(1)(c) GDPR – legal obligation, for example the retention of invoices under Austrian tax law.
  • Art. 6(1)(f) GDPR – legitimate interests, for example securing our systems against abuse, error monitoring, cookieless reach measurement, defending legal claims and reasonable business communication with existing customers.

Where we act as a processor for a customer (Section 13), the customer is responsible for the legal basis toward its end users.

5. Hosting, infrastructure and technical service providers

To run ChatReact we use the following infrastructure providers. They process personal data on our behalf under data processing agreements (Art. 28 GDPR).

5.1 Vercel (hosting and content delivery)

Our website and application are hosted by Vercel Inc., USA. Our server-side code runs in Vercel's Frankfurt region (fra1). Static content is delivered through Vercel's global edge network. When you open a page or the widget contacts our servers, Vercel processes connection data such as your IP address, the requested URL, date and time, browser and operating system information and the referring page. We use this data to deliver the pages, to keep the service secure and to analyse faults. Legal basis: Art. 6(1)(f) GDPR (secure and reliable operation) and, for customers, Art. 6(1)(b) GDPR.

5.2 Neon (database)

Account, company, chatbot and conversation data are stored in a PostgreSQL database operated by Neon, Inc., USA. Our database is located in the AWS region eu-central-1 (Frankfurt, Germany). Legal basis: Art. 6(1)(b) and (f) GDPR.

5.3 Amazon Web Services (file storage)

Files that customers upload (knowledge-base documents, logos, images) are stored in Amazon S3 in the region eu-central-1 (Frankfurt), provided by Amazon Web Services EMEA SARL, Luxembourg. Legal basis: Art. 6(1)(b) GDPR.

5.4 Upstash (rate limiting)

To protect login, registration, the API and the widget against abuse we count requests per IP address or email address in short time windows of one minute. This uses the managed Redis service of Upstash, Inc., USA. The counters expire automatically after the time window. Legal basis: Art. 6(1)(f) GDPR (protection against abuse).

5.5 Inngest (background jobs)

Long-running tasks such as website crawls, translations, mailbox synchronisation and onboarding emails run as background jobs orchestrated by Inngest, Inc., USA. Job payloads contain technical identifiers (for example a job ID, a chatbot ID or a URL) and status information, not the content of your documents or conversations. Legal basis: Art. 6(1)(b) and (f) GDPR.

5.6 Sentry (error monitoring)

We use Sentry, a service of Functional Software, Inc., USA, to detect and analyse errors. When an error occurs, Sentry receives the error message, a stack trace, the page or endpoint concerned, browser and device information and a pseudonymous event ID. Session replays are recorded only when an error occurs, and all text is masked and all media blocked before the recording leaves your browser. A small share of requests is sampled for performance measurement. Legal basis: Art. 6(1)(f) GDPR (stability and security of the service).

5.7 Pusher (real-time messaging)

Live-chat messages between end users and a customer's support agents, as well as status updates in the dashboard, are delivered in real time through Pusher, a service of Pusher Ltd, United Kingdom. Pusher transports the message content and technical channel identifiers and does not store messages permanently. The United Kingdom benefits from an adequacy decision of the European Commission. Legal basis: Art. 6(1)(b) GDPR.

5.8 Web fonts

The fonts used on our website are delivered from our own servers. No connection to Google's font servers is established when you load a page.

6. Cookies, local storage and similar technologies

We use a small number of cookies and browser storage entries. Technically necessary entries are set on the basis of Art. 6(1)(f) GDPR and § 165(3) TKG 2021; all others only with your consent (Art. 6(1)(a) GDPR).

NameTypePurposeDuration
authjs.session-token, authjs.csrf-token, authjs.callback-url (with __Secure- or __Host- prefix)Cookie, necessaryKeeps you logged in and protects forms against cross-site request forgerySession cookie or 30 days
NEXT_LOCALE, chatreact-localeCookie, necessaryRemembers the language you chose so that pages and emails are shown in that language1 year
chatreact-locale, themeLocal storage, necessaryLanguage and light/dark preference in the appUntil deleted
cr_measurement_consentLocal storage, necessaryStores your choice in the privacy dialog180 days
cr_measurementCookie, necessary (HttpOnly)Server-side copy of your consent choice together with the pseudonymous Google Analytics client and session ID, so that a registration or purchase can be measured only if you agreed180 days
cr_meta_clickLocal storage, consentMeta ad click identifier from the fbclid URL parameter, stored only if you agreed to Meta ad measurement90 days
cr_funnel_engagementSession storage, consentMeasures whether you stayed on the site for five minutes (Google Analytics event)Browser session
affiliate_ref, affiliate_referral_idCookie, necessary (HttpOnly)Remembers that you arrived through a partner link so that the partner can be credited if you sign upDuration set by the partner program, 30 days by default
chatreact-exit-intent-dismissedLocal storage, necessaryEnsures the short "why are you leaving?" survey during onboarding is shown only onceUntil deleted
selectedChatbot_ (per company)Local storage, necessaryRemembers which chatbot you last worked on in the dashboardUntil deleted
_ga, _ga_ (property ID), _gid, _gcl_ (ad click)Cookie, consentGoogle Analytics and Google Ads measurement, only after consent (see Section 8)up to 2 years
__stripe_mid, __stripe_sidCookie, necessaryFraud prevention by Stripe during checkout1 year / 30 minutes

Cloudflare Turnstile (Section 9.3) may store its own technical data under the domain challenges.cloudflare.com while a bot check is running.

You can delete cookies and storage entries at any time in your browser settings. If you delete the consent entries, the privacy dialog is shown again on your next visit.

We use our own consent dialog rather than a third-party consent platform. On your first visit to www.chatreact.ai the dialog offers three optional categories: statistics (Google Analytics), Google ad measurement and Meta ad measurement. You can choose "Necessary only", accept all or save an individual selection. Your choice is stored in your browser (cr_measurement_consent) and in an HttpOnly cookie (cr_measurement) for 180 days and can be changed at any time via the button below or via "Privacy preferences" in the footer. If you are logged in, your choice is additionally stored in your account (acquisition profile) so that a registration or purchase is reported to Google or Meta only if you agreed. Without consent, nothing is loaded from Google or sent to Meta.

8. Web analytics and advertising measurement

8.1 Vercel Web Analytics and Speed Insights (no cookies)

To understand how many people visit which pages and how fast the pages load, we use Vercel Web Analytics and Vercel Speed Insights, both provided by Vercel Inc., USA. These tools do not set cookies and do not create persistent identifiers. Vercel derives a short-lived hash from the request to count visits and collects technical performance metrics (Core Web Vitals), the page path, the referrer, country, browser and device type. We cannot identify individual visitors with this data. Legal basis: Art. 6(1)(f) GDPR (reach measurement and performance monitoring).

If you agree to "statistics", we use Google Analytics 4 provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The Google script is loaded only after you have consented. We have configured Google Analytics as follows:

  • Consent Mode is initialised with all categories denied; only the categories you accepted are granted.
  • Google Signals, advertising personalisation and cross-device features are switched off.
  • Page URLs are cleaned before they are sent: query strings are removed, and pages inside the application are reported only as "/app". Referrers are not transmitted.
  • Events we measure: page views, viewing the sign-up form, the "check your email" page, sign-up errors, the pricing page, staying on the site for five minutes, completed registrations, chatbot setup steps, the first chatbot reply and completed payments. For payments we send the invoice ID, the amount and the currency. We never send email addresses, names, company details or chat content.
  • Registrations and payments are reported from our server through the Google Analytics Measurement Protocol using the pseudonymous client and session ID stored in the cr_measurement cookie.

Google processes a pseudonymous client ID, session ID, event data, approximate location, device and browser information. Google may transfer this data to Google LLC in the USA; Google LLC is certified under the EU-U.S. Data Privacy Framework and standard contractual clauses are in place. Legal basis: Art. 6(1)(a) GDPR. You can withdraw consent at any time via the privacy dialog; we then delete the Google cookies and stop all measurement.

We advertise ChatReact through Google Ads. If you additionally agree to "Google ad measurement", the Google Analytics account is allowed to link registrations and payments to the Google Ads campaign that brought you to our site. For this purpose the ad click identifiers (gclid, gbraid, wbraid) and campaign parameters (utm_*) from the landing page URL are kept in the measured page URL and the consent categories ad_storage and ad_user_data are granted. Ad personalisation stays disabled. We use this data solely to evaluate the success of our campaigns; we do not build advertising profiles. Provider: Google Ireland Limited (see 8.2). Legal basis: Art. 6(1)(a) GDPR.

We also advertise on Facebook and Instagram. If you separately agree to "Meta ad measurement", we report completed registrations to Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland, through the Conversions API (server to server, no Meta pixel is loaded in your browser). The report contains the event "CompleteRegistration", the time, an event identifier, the page on which you registered, a SHA-256 hash of your email address and, if you arrived through a Meta ad, the click identifier from the fbclid parameter, which we store for a maximum of 90 days. Meta can match the hashed email address to your Facebook or Instagram account, so this data is not anonymous to Meta. We do not send chat content, company details or names. Registrations are reported at most seven days after they occur and only if your consent is still valid. Meta may transfer the data to Meta Platforms, Inc. in the USA; Meta is certified under the EU-U.S. Data Privacy Framework. Legal basis: Art. 6(1)(a) GDPR. Withdrawal stops all future reports; reports already sent are subject to Meta's own retention.

9. Registration, login and your account

You register and log in with your email address only. We send you a one-time login link by email; no password is stored. We keep a verification token until the link is used or expires and a database session for up to 30 days (renewed daily while you are active). Legal basis: Art. 6(1)(b) GDPR.

9.2 Passkeys

Optionally you can add passkeys (WebAuthn) to your account. We store the public key, the credential ID, a signature counter, the authenticator type (platform or security key), the transport methods, a label you choose and the last use. Biometric data never leaves your device. Legal basis: Art. 6(1)(b) GDPR.

9.3 Bot protection

Our login and sign-up forms are protected by several measures:

  • Cloudflare Turnstile, a service of Cloudflare, Inc., USA, is loaded when you start filling in the form. Turnstile analyses technical signals of your browser and your IP address to distinguish humans from bots, and our server verifies the resulting token together with your IP address at Cloudflare. Cloudflare is certified under the EU-U.S. Data Privacy Framework.
  • Hidden honeypot fields that only automated scripts fill in.
  • Request limits per IP address and email address (Section 5.4).
  • Each guarded login request is recorded as a privacy-minimal audit event (outcome, time, hashed identifiers) that is deleted after 30 days.

Legal basis: Art. 6(1)(f) GDPR (protection against abuse and spam).

9.4 Verification of business email addresses

ChatReact is intended for businesses. If you register with an address of a free email provider, we ask you for your company's website. Our server retrieves the imprint, legal or contact page of that public website and checks whether your email address appears there. We store your email address, the website URL, the matched page and the time of verification. Legal basis: Art. 6(1)(f) GDPR (prevention of misuse of free plans) and Art. 6(1)(b) GDPR. If the check fails you can contact us and we will verify your request manually.

9.5 Account, company and team data

To run your account we store: email address, name, profile picture (optional), interface language, role, subscription plan and status, trial and billing period dates, Stripe customer and subscription IDs, notification preferences, onboarding progress and the companies you own or belong to. For each company we store its name, URL slug, website, logo, description and settings. When you invite team members we store their email address, role and the inviting user. Legal basis: Art. 6(1)(b) GDPR.

9.6 Audit logs

Important actions in the dashboard and all API requests are recorded in an audit log containing the action, the object concerned, your user and company ID, IP address, browser, HTTP method, path, status code, duration and, for write requests, a truncated request body. The log helps us to investigate security incidents and support requests. Retention: technical request logs 7 days, changes to data 30 days, security-relevant actions 365 days. When you delete your account the entries are anonymised. Legal basis: Art. 6(1)(f) GDPR (security, traceability) and Art. 6(1)(c) GDPR.

9.7 Onboarding emails and exit survey

If you have registered but not yet created a company, a chatbot or a knowledge base, we may send you up to three onboarding emails that explain the next step. These emails stop automatically as soon as you complete the setup, and you can object at any time by replying or writing to [email protected]. If you are about to leave the app during onboarding we may show a short survey asking for the reason; the answer, the optional free-text message, the page and the language are stored in your account. Legal basis: Art. 6(1)(f) GDPR (customer onboarding, product improvement) and § 174 TKG 2021.

10. Contact and communication

The contact form on our website is a ChatReact form. When you submit it we store the form fields you filled in (typically name, email address and message), the time, your IP address, browser and the referring page, and we run an automated spam check (Section 12.4). Emails and phone calls are processed to answer your request. Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps) or Art. 6(1)(f) GDPR (answering requests). Contact requests are kept as long as needed to handle them and for possible follow-up questions, unless a longer statutory retention applies.

11. Payments and billing

Paid plans are billed through Stripe, provided by Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Dublin 2, Ireland, and Stripe, Inc., USA. When you start a checkout we create a Stripe customer with your email address, your name and your ChatReact user ID. Payment details (card number, IBAN) are entered in Stripe's embedded checkout and go directly to Stripe; we never receive or store them. Stripe informs us about the status of subscriptions, payments and invoices via signed webhooks, and we store your Stripe customer and subscription ID, plan, status and billing period. Stripe uses cookies for fraud prevention (Section 6) and may transfer data to the USA under the EU-U.S. Data Privacy Framework and standard contractual clauses. Invoices and payment records are retained for seven years under § 132 BAO. Legal basis: Art. 6(1)(b) and (c) GDPR.

12. Processing within the ChatReact platform

This section describes what happens with data that you as a customer bring into ChatReact and with the data of your end users. For end-user data we act as your processor (Section 3).

12.1 Knowledge base and website crawler

Your chatbot answers questions based on the knowledge base you build: uploaded documents, pages of your website, FAQs and instructions. Documents are stored in Amazon S3 (Section 5.3) and, to make them searchable for the AI, uploaded to a vector store at OpenAI (Section 14) that belongs to your chatbot. Website pages are retrieved by our own crawler running on our servers or, if enabled in our platform settings, by the crawling service Firecrawl, USA, which receives the public URLs you entered. We only crawl publicly accessible pages of the websites you specify. When you delete a document or your account, we delete the file, the vector-store entries and the crawl results.

12.2 Chatbot conversations

When an end user writes to a chatbot we store a chat session with a random visitor ID generated in the browser, the messages, the page URL on which the chat took place, the browser language and, if you enabled a pre-chat form, the fields the visitor filled in (for example name and email address). The end user's messages, together with the relevant knowledge-base content and your instructions, are sent to OpenAI to generate the reply. Completed conversations may be analysed automatically to assign a confidence category, to propose FAQ entries, to detect improvement opportunities (Improvement Agent) and to create a review summary for you; for this we use Google Gemini and OpenAI (Section 14). Conversations remain available in your dashboard until you delete them or your account.

12.3 Live chat

If you enable live chat, end users can talk to your team in real time. We store the live-chat session, the visitor's name and email address if provided, the messages and which agent handled the conversation. Messages are delivered via Pusher (Section 5.7).

12.4 Leads, smart forms and contact forms

Chatbots and forms can collect leads with the fields you define (for example name, email address, phone number). Form submissions are stored with the submitted data, IP address, browser and referring page. Each submission is scored for spam by an AI model at OpenAI, which receives the submitted text; the score and a short explanation are shown to you so you can decide how to handle it. Leads can trigger notifications to your team and webhooks to your own systems (Section 12.7).

12.5 Email Assistant (Microsoft 365)

The Email Assistant connects a Microsoft 365 mailbox to a chatbot so that incoming emails are categorised, sorted and answered with drafts. When you connect a mailbox, you authorise ChatReact at Microsoft (Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland) with the permissions "Mail.ReadWrite", "Mail.Send", "MailboxSettings.ReadWrite" and "offline_access". We store the access and refresh tokens encrypted with AES-256-GCM; the encryption key is kept outside the database. We only process emails that arrive after the connection was made.

For each new email we send the sender, the subject and up to the first 4,000 characters of the body to Google Gemini (or, as a fallback, OpenAI) to determine whether it is a genuine enquiry and which category applies. Reply drafts are generated by OpenAI using your knowledge base and saved as drafts in your mailbox; nothing is sent automatically. Requests to OpenAI for the Email Assistant are sent with response storage disabled, so OpenAI does not keep the email content as a retrievable response object. We persist only metadata: message and conversation ID, sender address, the subject truncated to 200 characters, receipt time, category, outcome and draft ID. Email bodies are never stored by ChatReact. To personalise drafts, we keep a contact record per sender (email address, name, organisation, relationship, language, learned facts and your notes), which you can edit or delete in the dashboard. Disconnecting the mailbox deletes the tokens, categories and activity log immediately. You remain responsible for the emails in your mailbox; we act as your processor.

12.6 Dashboard assistant and bug reports

The dashboard contains an AI assistant that helps you operate ChatReact. Your questions, together with the relevant data of your account (for example the names of your chatbots), are sent to OpenAI to generate an answer, and the assistant may carry out dashboard actions you request. If you report a bug through the assistant, a ticket is created in our issue tracker at GitHub, Inc., USA, containing your description, your user ID and, if you attach one, a screenshot that is stored in a repository operated by us. Please do not include sensitive data in bug reports. Legal basis: Art. 6(1)(b) GDPR.

12.7 Webhooks, REST API, MCP server and integrations

You can connect ChatReact to your own systems. Webhooks send event data (for example a new lead or a finished conversation) to the URL you configure; you are responsible for the recipient. API keys and MCP access tokens are stored hashed; we record the prefix, the last use and the requests made with them (Section 9.6). Our WordPress plugin and Shopify integration call our API from your website using an integration key; end users who load the widget on your site connect to our servers as described in Section 13.

12.8 Notifications and transactional emails

We send emails that are necessary for the service: login links, team invitations, notifications about usage limits, processed documents, crawls, captured leads, live-chat requests, chat reviews and billing. You can configure most notifications and their digest frequency in your account. These emails are sent through the transactional email provider configured in our platform, currently Mailaura (mailaura.io); Amazon SES (AWS, Frankfurt) or Resend, Inc., USA, may be used as alternatives. The provider receives the recipient address, subject and content of the email for delivery. Legal basis: Art. 6(1)(b) GDPR.

12.9 Translations

Widget texts, FAQs and knowledge content can be translated into the 24 EU languages. The texts are sent to OpenAI or Google Gemini for translation; they may contain personal data only if you include it in the texts.

13. Information for end users of websites that use ChatReact

If you chat with a chatbot, use a form or write to a company that uses ChatReact, that company is the controller and we process your data on its behalf. The following applies:

  • Storage in your browser: the widget stores a random visitor ID, the current session ID, the recent messages, pre-chat form entries, a flag whether the chat was opened automatically and a live-chat session ID in the local storage of your browser under the prefix "chatreact_". No cookies are set by the widget. These entries exist only for the website you visited and can be deleted in your browser.
  • Data sent to our servers: your messages, the page URL, the referring page, your browser language and user agent, your IP address (used for rate limiting and server logs, not stored in the conversation), and any details you enter in pre-chat, lead or contact forms.
  • AI processing: your messages are processed by OpenAI to generate replies, and finished conversations may be analysed by Google Gemini or OpenAI on behalf of the company (Section 14). Emails you send to a mailbox that uses the Email Assistant are processed as described in Section 12.5.
  • Hosting: all data is stored in the EU (Frankfurt) as described in Section 5.
  • Retention: conversations are kept until the company deletes them or closes its account.
  • Your rights: please contact the company whose website or mailbox you used. We support the company in responding and will forward requests that reach us directly.

Please do not enter sensitive data (for example health or financial information) into a chatbot unless the company explicitly asks for it.

14. AI service providers

ChatReact uses large language models of external providers. We only send them the data needed for the specific task (a conversation, a document chunk, an email, a form submission or a text to translate) and we do not allow our data to be used for training their models.

ProviderUsed forData protection
OpenAI (OpenAI Ireland Ltd, Dublin, Ireland, and OpenAI, L.L.C., USA)Chatbot answers, knowledge-base search (vector stores), FAQ generation, Improvement Agent, form spam scoring, reply drafts, dashboard assistant, translationsData processing agreement; API data is not used for model training; OpenAI retains API inputs and outputs for abuse monitoring for a limited period according to its API data policy; transfers under standard contractual clauses and the EU-U.S. Data Privacy Framework
Google Gemini (Google Ireland Limited, Ireland, and Google LLC, USA)Categorisation and quality assessment of finished conversations, email triage, translationsData processing terms of the Gemini API; transfers under standard contractual clauses and the EU-U.S. Data Privacy Framework

AI-generated content can be wrong. Chatbot replies, categories, spam scores and drafts are suggestions that our customers review and remain responsible for; they do not produce legal effects on their own (Section 20).

15. Partner program

Companies and individuals can apply to our partner (affiliate) program. We process the data you provide in your application (company, website, motivation), your payout details (PayPal email address or IBAN, BIC, account holder and tax ID), your partner code and statistics about clicks, sign-ups, conversions, commissions and payouts. When a visitor arrives through your partner link we store the landing page, campaign parameters, a hashed IP address and the browser of that visitor, set the referral cookie (Section 6) and, if the visitor signs up within the cookie period, link the new account to your referral. Legal basis: Art. 6(1)(b) GDPR (partner agreement) and Art. 6(1)(c) GDPR (accounting). Payout and commission records are retained for seven years under § 132 BAO.

16. Recipients and transfers to third countries

We share personal data only with the service providers named in this policy, with authorities where we are legally obliged to, and with advisors bound by professional secrecy where necessary to defend legal claims. If ChatReact were to be transferred to another company, data would be passed on within the limits of the law.

Some of our providers are located in, or may transfer data to, the United States and the United Kingdom. The United Kingdom is covered by an adequacy decision. For the USA we rely on the EU-U.S. Data Privacy Framework where the provider is certified and, in addition, on the standard contractual clauses of the European Commission (Art. 46(2)(c) GDPR) together with supplementary measures such as encryption in transit and at rest.

ProviderPurposeLocation
Vercel Inc.Hosting, edge network, web analyticsUSA, servers in Frankfurt
Neon, Inc.DatabaseUSA, database in Frankfurt
Amazon Web Services EMEA SARLFile storage, optional email deliveryLuxembourg, servers in Frankfurt
Upstash, Inc.Rate limitingUSA
Inngest, Inc.Background jobsUSA
Functional Software, Inc. (Sentry)Error monitoringUSA
Pusher LtdReal-time messagingUnited Kingdom
Cloudflare, Inc.Bot protection (Turnstile)USA
Google Ireland Limited / Google LLCAnalytics, Google Ads measurement, Gemini AIIreland / USA
Meta Platforms Ireland LimitedAd measurement (Conversions API)Ireland / USA
OpenAI Ireland Ltd / OpenAI, L.L.C.AI models and vector storesIreland / USA
Stripe Payments Europe, Limited / Stripe, Inc.PaymentsIreland / USA
Microsoft Ireland Operations LimitedMailbox access (Email Assistant)Ireland
FirecrawlWebsite crawling (if enabled)USA
GitHub, Inc.Bug reportsUSA
Mailaura (mailaura.io), Resend, Inc.Transactional emailsee provider

17. Retention periods

We keep personal data only as long as necessary for the purposes described above. Key periods:

DataRetention
Account, company, chatbot and conversation dataUntil you delete them or delete your account; deletion removes files, vector stores, Stripe customer and database records, audit logs are anonymised
Login sessions30 days after the last renewal
Consent choice (privacy dialog)180 days, then asked again
Meta click identifier90 days
Partner referral cookiePartner-specific, 30 days by default
Audit logs7 / 30 / 365 days depending on severity
Rate-limit countersOne minute
Error reports (Sentry)According to Sentry's retention for our plan, typically 90 days
Invoices, payment and commission records7 years (§ 132 BAO)
Contact requestsUntil handled, plus follow-up period

18. Data security

We protect your data with technical and organisational measures appropriate to the risk: TLS encryption of all connections, encryption of data at rest at our hosting providers, AES-256-GCM encryption of mailbox tokens, hashed API keys and passwordless login with magic links and passkeys, role-based access control per company, rate limiting, audit logging, separation of production and test environments, the principle of least privilege for our staff and regular updates of our systems.

19. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15),
  • rectification of inaccurate data (Art. 16),
  • erasure (Art. 17) – you can delete your account yourself in the account settings,
  • restriction of processing (Art. 18),
  • data portability (Art. 20) – conversations, leads and FAQs can be exported from the dashboard,
  • object to processing based on legitimate interests (Art. 21),
  • withdraw consent at any time with effect for the future (Art. 7(3)), for example via the privacy dialog.

To exercise your rights, write to [email protected]. We may ask you to confirm your identity. If you believe that we process your data unlawfully, you can lodge a complaint with a supervisory authority. The authority responsible for us is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, Austria, phone +43 1 52 152-0, email [email protected], www.dsb.gv.at.

20. Automated decision-making

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). Automated checks such as the business-email verification, spam scoring and email categorisation only support decisions that are reviewed by our customers or by us, and you can always contact us to have a result reviewed by a person.

21. Minors

ChatReact is aimed at businesses. Our services may not be used by persons under 18 years of age, and we do not knowingly collect data from minors. If you believe that a minor has provided us with personal data, please contact us so that we can delete it.

22. Changes to this privacy policy

We update this privacy policy when our services, providers or the legal situation change. The current version with its date is always available at www.chatreact.ai/privacy. For material changes that affect existing customers we will inform you by email or in the dashboard.