# Privacy policy

Source: https://chatmerce.eu/en/privacy/
Language: en
Effective: 2026-07-28

---

## 1. Who we are

Chatmerce is a conversational agent platform operated by **Prosit AS**, a company registered in Norway (organisasjonsnummer: to be filled in after registration). Contact email: [hello@chatmerce.eu](mailto:hello@chatmerce.eu). Prosit AS is the data controller within the meaning of Regulation (EU) 2016/679 (GDPR).

In this policy, "we", "us" and "Chatmerce" mean Prosit AS. "You" means the data subject — usually a user of the `app.chatmerce.eu` dashboard, but also an end-user conversing with an agent deployed by our customer.

## 2. What data we collect

### 2.1 Sign-up and account data

- Name and email address (from OAuth: Google, Microsoft, Apple)
- External authentication identifier (`sub` from OAuth, opaque to us)
- Avatar (URL from your OAuth provider, optional)
- Company name, VAT number, billing address (when you register as an organisation)
- **Passwords never reach our systems** — authentication is handled by Clerk (see sub-processors)

### 2.2 Technical and log data

- IP address (anonymised after 30 days)
- User-Agent header
- Login times and dashboard actions
- Session identifier (HttpOnly cookie)

### 2.3 Configuration data ("Customer Data")

- Agent prompts and instructions
- Uploaded knowledge sources (PDFs, links, plain text)
- Agent configuration

This data belongs to you. We process it solely to operate the service.

### 2.4 Conversation data

- Message content from the end-user and the agent
- Session identifier (anonymous for the web widget; phone number for RCS)
- Message time, channel (web/RCS), agent version
- Technical metadata: token count, conversation cost, LLM model used

### 2.5 Billing data

- Company name, VAT number, invoice address
- Payment history (Stripe, once paid billing goes live)

## 3. Why we collect it and on what legal basis

| Purpose                                           | Legal basis (GDPR Art. 6)                | Data                                 |
| ------------------------------------------------- | ---------------------------------------- | ------------------------------------ |
| Providing the service (account, agent operation)  | Art. 6(1)(b) — performance of a contract | account, config, conversations       |
| Issuing invoices, tax obligations                 | Art. 6(1)(c) — legal obligation          | billing                              |
| Security, abuse prevention                        | Art. 6(1)(f) — legitimate interest       | logs, IP                             |
| First-party marketing (newsletter, if you opt in) | Art. 6(1)(a) — consent                   | email                                |
| Usage analytics, product improvement              | Art. 6(1)(f) — legitimate interest       | aggregates (no conversation content) |

## 4. Whom we share data with (sub-processors)

Each sub-processor has a Data Processing Agreement (DPA) with us and is either established within the EEA or operates under the Standard Contractual Clauses (SCC) per Commission Implementing Decision (EU) 2021/914.

| Sub-processor                                                 | What it processes                              | Location                   |
| ------------------------------------------------------------- | ---------------------------------------------- | -------------------------- |
| Google Cloud (Cloud Run, Firestore, BigQuery, Secret Manager) | hosting, database, secrets                     | europe-west4 (Netherlands) |
| Google (Gemini API)                                           | LLM request processing                         | europe-west4               |
| Clerk, Inc.                                                   | user authentication                            | USA — SCC + DPF            |
| SerwerSMS (Vercom S.A.)                                       | RCS message delivery (if you use this channel) | Poland                     |
| Cloudflare, Inc.                                              | CDN, marketing site hosting                    | global — SCC + DPF         |
| Stripe Payments Europe                                        | subscription billing (once enabled)            | Ireland                    |

The current full list with change dates is available on request: [hello@chatmerce.eu](mailto:hello@chatmerce.eu). Enterprise plan: list delivered as an annex to the contract.

## 5. International data transfers

For sub-processors outside the EEA we use **Clerk (USA)** and **Cloudflare (global)**. Both are certified under the EU–U.S. Data Privacy Framework (DPF) and have signed Standard Contractual Clauses with us. All other data stays inside the EEA.

## 6. How long we keep data

- **User account**: until account deletion + 30 days (undo window)
- **Conversations**: 24 months from the last message (unless you delete them earlier)
- **Technical logs**: 90 days
- **Invoices and billing data**: 5 years (Polish accounting act, art. 74)
- **Backups**: 35 days

After expiry, data is automatically deleted or anonymised by a scheduled job.

## 7. Your rights (GDPR Art. 15–22)

You have the right to:

- **Access** your data (Art. 15)
- **Rectification** of incorrect data (Art. 16)
- **Erasure** ("right to be forgotten", Art. 17) — from the panel or by email
- **Restriction** of processing (Art. 18)
- **Data portability** in JSON/CSV format (Art. 20)
- **Object** to processing based on legitimate interest (Art. 21)
- **Not be subject to decisions based solely on automated processing** (Art. 22)

All requests go to [hello@chatmerce.eu](mailto:hello@chatmerce.eu). We respond within 30 days (Art. 12(3) GDPR).

You may also file a complaint with a supervisory authority:

- **Poland**: Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, [uodo.gov.pl](https://uodo.gov.pl)
- **Norway**: Datatilsynet, Postboks 458 Sentrum, 0105 Oslo, [datatilsynet.no](https://datatilsynet.no)
- Or the authority competent for your country of residence.

## 8. Cookies

We use a minimal set of cookies:

- `chatmerce-theme` — theme preference (light/dark). 1 year.
- `__session` (Clerk) — logged-in session. Duration of the session.
- `cf_bm` (Cloudflare) — bot protection. 30 minutes.

We do not use analytics or marketing cookies without your explicit consent. The marketing site has **no Meta or Google Ads pixels**. For visit statistics we use Cloudflare Web Analytics — no cookies, no profiling, no cross-site tracking. The lawful basis is our legitimate interest (GDPR art. 6(1)(f)), and we process aggregates only. Cloudflare is one of our sub-processors.

## 9. Children

Chatmerce is not directed at persons under 16. We do not knowingly collect data from children.

## 10. Security

- Encryption in transit (TLS 1.3) and at rest (AES-256, keys managed by Google KMS)
- Secrets in Google Secret Manager — never in the database, logs, or source repository
- Production access limited to two people (Prosit AS founders), with 2FA enforced
- External pentest: first scheduled for Q3 2026 (annually thereafter)
- Business-continuity plan: cross-region backups, RTO 24h, RPO 1h

## 11. Data breaches

If we determine that a breach poses a risk to your rights:

- We notify the supervisory authority within **72 hours** (Art. 33 GDPR)
- We notify you directly if the risk is high (Art. 34 GDPR)
- We publish a post-mortem on status.chatmerce.eu within 14 days

## 12. Policy changes

We announce material changes by email with 30 days' notice. The change history is available on request at [hello@chatmerce.eu](mailto:hello@chatmerce.eu).

## 13. Contact

Data protection matters: [hello@chatmerce.eu](mailto:hello@chatmerce.eu)

**Data Protection Officer**: not appointed. The processing carried out by Prosit AS does not require a DPO under Art. 37(1) GDPR. All data matters are handled directly by the founders of Prosit AS.

**Correspondence address**: Prosit AS — to be filled in after registration in the Norwegian Brønnøysundregistrene.
