Privacy policy
1. Who we are
Chatmerce is a conversational agent platform operated by Prosit AS, a company registered in Norway (organisasjonsnummer: to be filled in after registration). Contact email: hello@chatmerce.eu. Prosit AS is the data controller within the meaning of Regulation (EU) 2016/679 (GDPR).
In this policy, “we”, “us” and “Chatmerce” mean Prosit AS. “You” means the data subject — usually a user of the app.chatmerce.eu dashboard, but also an end-user conversing with an agent deployed by our customer.
2. What data we collect
2.1 Sign-up and account data
- Name and email address (from OAuth: Google, Microsoft, Apple)
- External authentication identifier (
subfrom OAuth, opaque to us) - Avatar (URL from your OAuth provider, optional)
- Company name, VAT number, billing address (when you register as an organisation)
- Passwords never reach our systems — authentication is handled by Clerk (see sub-processors)
2.2 Technical and log data
- IP address (anonymised after 30 days)
- User-Agent header
- Login times and dashboard actions
- Session identifier (HttpOnly cookie)
2.3 Configuration data (“Customer Data”)
- Agent prompts and instructions
- Uploaded knowledge sources (PDFs, links, plain text)
- Agent configuration
This data belongs to you. We process it solely to operate the service.
2.4 Conversation data
- Message content from the end-user and the agent
- Session identifier (anonymous for the web widget; phone number for RCS)
- Message time, channel (web/RCS), agent version
- Technical metadata: token count, conversation cost, LLM model used
2.5 Billing data
- Company name, VAT number, invoice address
- Payment history (Stripe, once paid billing goes live)
3. Why we collect it and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) | Data |
|---|---|---|
| Providing the service (account, agent operation) | Art. 6(1)(b) — performance of a contract | account, config, conversations |
| Issuing invoices, tax obligations | Art. 6(1)(c) — legal obligation | billing |
| Security, abuse prevention | Art. 6(1)(f) — legitimate interest | logs, IP |
| First-party marketing (newsletter, if you opt in) | Art. 6(1)(a) — consent | |
| Usage analytics, product improvement | Art. 6(1)(f) — legitimate interest | aggregates (no conversation content) |
4. Whom we share data with (sub-processors)
Each sub-processor has a Data Processing Agreement (DPA) with us and is either established within the EEA or operates under the Standard Contractual Clauses (SCC) per Commission Implementing Decision (EU) 2021/914.
| Sub-processor | What it processes | Location |
|---|---|---|
| Google Cloud (Cloud Run, Firestore, BigQuery, Secret Manager) | hosting, database, secrets | europe-west4 (Netherlands) |
| Google (Gemini API) | LLM request processing | europe-west4 |
| Clerk, Inc. | user authentication | USA — SCC + DPF |
| SerwerSMS (Vercom S.A.) | RCS message delivery (if you use this channel) | Poland |
| Cloudflare, Inc. | CDN, marketing site hosting | global — SCC + DPF |
| Stripe Payments Europe | subscription billing (once enabled) | Ireland |
The current full list with change dates is available on request: hello@chatmerce.eu. Enterprise plan: list delivered as an annex to the contract.
5. International data transfers
For sub-processors outside the EEA we use Clerk (USA) and Cloudflare (global). Both are certified under the EU–U.S. Data Privacy Framework (DPF) and have signed Standard Contractual Clauses with us. All other data stays inside the EEA.
6. How long we keep data
- User account: until account deletion + 30 days (undo window)
- Conversations: 24 months from the last message (unless you delete them earlier)
- Technical logs: 90 days
- Invoices and billing data: 5 years (Polish accounting act, art. 74)
- Backups: 35 days
After expiry, data is automatically deleted or anonymised by a scheduled job.
7. Your rights (GDPR Art. 15–22)
You have the right to:
- Access your data (Art. 15)
- Rectification of incorrect data (Art. 16)
- Erasure (“right to be forgotten”, Art. 17) — from the panel or by email
- Restriction of processing (Art. 18)
- Data portability in JSON/CSV format (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Not be subject to decisions based solely on automated processing (Art. 22)
All requests go to hello@chatmerce.eu. We respond within 30 days (Art. 12(3) GDPR).
You may also file a complaint with a supervisory authority:
- Poland: Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl
- Norway: Datatilsynet, Postboks 458 Sentrum, 0105 Oslo, datatilsynet.no
- Or the authority competent for your country of residence.
8. Cookies
We use a minimal set of cookies:
chatmerce-theme— theme preference (light/dark). 1 year.__session(Clerk) — logged-in session. Duration of the session.cf_bm(Cloudflare) — bot protection. 30 minutes.
We do not use analytics or marketing cookies without your explicit consent. The marketing site has no Meta or Google Ads pixels. For visit statistics we use Cloudflare Web Analytics — no cookies, no profiling, no cross-site tracking. The lawful basis is our legitimate interest (GDPR art. 6(1)(f)), and we process aggregates only. Cloudflare is one of our sub-processors.
9. Children
Chatmerce is not directed at persons under 16. We do not knowingly collect data from children.
10. Security
- Encryption in transit (TLS 1.3) and at rest (AES-256, keys managed by Google KMS)
- Secrets in Google Secret Manager — never in the database, logs, or source repository
- Production access limited to two people (Prosit AS founders), with 2FA enforced
- External pentest: first scheduled for Q3 2026 (annually thereafter)
- Business-continuity plan: cross-region backups, RTO 24h, RPO 1h
11. Data breaches
If we determine that a breach poses a risk to your rights:
- We notify the supervisory authority within 72 hours (Art. 33 GDPR)
- We notify you directly if the risk is high (Art. 34 GDPR)
- We publish a post-mortem on status.chatmerce.eu within 14 days
12. Policy changes
We announce material changes by email with 30 days’ notice. The change history is available on request at hello@chatmerce.eu.
13. Contact
Data protection matters: hello@chatmerce.eu
Data Protection Officer: not appointed. The processing carried out by Prosit AS does not require a DPO under Art. 37(1) GDPR. All data matters are handled directly by the founders of Prosit AS.
Correspondence address: Prosit AS — to be filled in after registration in the Norwegian Brønnøysundregistrene.