§1Who controls the data
Chatvoxo is operated by FORCESCRIPTS LTD, registered in England and Wales, company number 17110478. Address: Suite 10647, 5 Brayford Square, London, United Kingdom, E1 0SG. Website: https://www.chatvoxo.com.
For any request about your personal data, write to [email protected]. Other legal mail: [email protected]. Support: [email protected] and WhatsApp +44 754 143 8660.
§2Who this policy covers
This policy follows UK GDPR and the Data Protection Act 2018 and, for people in the European Economic Area (EEA), the EU General Data Protection Regulation (GDPR).
We are the controller for the data of customers who open an account, the agents in their teams, and visitors to chatvoxo.com. This policy covers that data.
For visitors who write in the chat window a customer places on their own website, the controller is the customer who runs that website. We process that data only on the customer’s behalf and on their instructions (as a processor). That relationship is set out in the Data processing agreement. If you chatted on a website, send requests about your data to that website first; if you write to us, we pass your request to the customer and help them answer it.
§3What we process
Account: first name, last name, username, email, phone, language preference, and a one-way hash of the password. We do not store the password itself. If you sign in with Google, the name and email Google shares with us.
Workspace: workspace and site names, domains, logo, chat window settings, business information text, quick replies, AI functions, and agents’ online status and last-seen time.
API key: the AI key you connect on the Pro plan is stored encrypted in the application layer and is never shown as plain text in the dashboard.
Chat data (on a customer’s behalf): messages, files sent, contact fields the visitor fills in such as name, email and phone, and the chat rating and comment.
Visit details (on a customer’s behalf, only for visitors who start a chat): IP address and the country it indicates, browser, operating system and device type, screen size, language and time zone, where the visit came from (referring address and campaign tags), landing page, the pages and page titles viewed while the chat is open, number of visits and date of the first visit, and whether the visitor is still on the site while the chat is open. For visitors who do not start a chat, none of this leaves their browser.
Messages, files, and visitor and visit details are stored encrypted in the database.
Plan, payment and balance: plan, subscription status, balance top-ups and spending, and AI usage (token counts). We never see or store card details; Stripe processes them. For a USDT or USDC payment, the sending wallet address, amount and transaction id.
Email: the recipient and content of service emails we send to you or to visitors (password links, team invitations, chat notifications).
Notification subscription: if an agent turns on notifications at the desk, that browser’s push address and encryption keys. They are deleted when notifications are turned off.
Technical data: session and security cookies, and server and security logs that include IP address and browser details.
§4Why we use it and the legal basis
Opening the account, providing the service, delivering chats, generating AI replies and sending service emails: performance of a contract (GDPR Article 6(1)(b)).
Collecting plan and balance payments and keeping invoice and accounting records: performance of a contract and legal obligation (Articles 6(1)(b) and 6(1)(c)).
Keeping the service secure, preventing fraud and abuse (reCAPTCHA, sign-in attempt limits, security logs), keeping the service running and fixing faults: legitimate interests (Article 6(1)(f)). We have assessed that these interests do not override your rights; you can object to this processing.
Chat data on customers’ websites: the customer’s instructions (Article 28). The customer, as controller, decides the legal basis for that data.
We do not send marketing email, sell personal data, build advertising profiles, or train AI models on our customers’ data.
§5Who receives it
We share data only as far as needed to run the service, and only with providers under a written contract.
AI provider: when Chatvoxo AI writes a reply, the chat text goes to the model provider Chatvoxo uses (currently OpenAI). OpenAI does not use data sent through its API to train models and may keep it for up to 30 days for abuse monitoring.
Your own key: if you connect your own key on the Pro plan, chat text goes to the provider you chose, under your own contract with that company. You choose that provider; its terms and privacy policy apply.
Stripe: card payments, subscriptions and invoices. For sales made through Stripe Managed Payments, Stripe is the merchant of record and controls the payment data under its own privacy policy.
Resend (Resend, Inc., United States): sending service emails.
Cloudflare (Cloudflare, Inc., United States; storage in the European Union): storing files and images sent in chats. Files are encrypted on our servers before they are sent, so Cloudflare cannot read them.
Browser push services (Google, Mozilla, Apple, Microsoft): notifications to agents are delivered end-to-end encrypted through the push service of the agent’s browser; the service cannot read them.
Google: bot checks when reCAPTCHA is turned on for our forms, and authentication if you choose to sign in with Google.
Our hosting and infrastructure provider (Turkey): servers and database. Account data and chat messages are stored on servers in Turkey; chat files are stored encrypted in Cloudflare’s EU storage.
Authorities, where the law requires it or to protect rights; and, if the company is transferred, the buyer under the same protections.
The list of sub-processors we use for data processed on customers’ behalf is in the Data processing agreement.
§6International transfers
The service’s servers are in Turkey, and some providers process data in the United States, so data of people in the UK and the EEA is transferred to these countries. As there is no adequacy decision for Turkey, that transfer relies on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. For providers in the United States we rely on adequacy regulations (the UK–US data bridge, the EU–US Data Privacy Framework) or on the same clauses. You can ask for a copy of these safeguards at [email protected].
§7How long we keep it
Account data: while the account is open. You can ask for your account to be deleted with the form on the Settings page or at [email protected]; we complete the request within 30 days. Deletion permanently removes your account, sites, chats, files, the agent accounts you added to your team and your saved payment method.
Payment records: balance and subscription records made of the amount, the date and the payment transaction id are kept for 6 years for accounting and tax obligations. When the account is deleted they are separated from your name and email.
Record of the deletion request: to show that we carried out the request, its date and outcome are kept with a one-way hash of your email address instead of the address itself.
Chats and files: for the period the customer sets. Automatic deletion can be chosen in the site settings; if none is set, data stays until the customer deletes it or the account closes.
Invoice, payment and balance records: 6 years, as UK tax and company law require.
Security and server logs: up to 90 days, unless an incident needs to be investigated.
Deleted data leaves our backups when the backup cycle completes.
USDT and USDC transactions stay on the public, unchangeable records of the Avalanche network. We cannot delete those; we delete our own link to them on the schedule above.
§8Security
Connections are encrypted with HTTPS. Passwords are stored as one-way hashes, and API keys and chat content are encrypted in the application layer. Dashboard access is limited by role. If a personal data breach happens, we notify the supervisory authority within 72 hours where required, and tell you without undue delay if there is a high risk to your rights.
§9Your rights
You have the right to access your data, to have it corrected, erased or its processing restricted, to object to processing based on legitimate interests, and to receive a portable copy. Where processing is based on consent, you can withdraw it at any time.
Write to [email protected]. Requests are free; we answer within one month. For complex requests this can be extended by two further months, and we will tell you if it is. We may ask for information to confirm the request comes from you.
You also have the right to complain: in the United Kingdom to the Information Commissioner’s Office (https://ico.org.uk), and in the EEA to the data protection authority of the country where you live or work. If you write to us first, we will try to resolve it with you.
§10Automated decisions
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. AI replies in the chat window are informational, and a visitor can always ask for a human agent.
§11Do you have to give us the data
To open an account we need your first name, last name, username, email, phone and a password; without them we cannot enter into the contract. Whether the chat window asks visitors for contact details is the choice of the customer who runs the website.
§12Cookies
The cookies we use and how long they last are listed in the Cookie policy.
§13Children
Chatvoxo is not a service for anyone under 18. We do not knowingly collect account data from children.
§14Changes
We may update this policy. We announce significant changes before they take effect, by email to your account address or in the dashboard. The date of the current version is at the top of this page.
Write to [email protected].