Back to home
Privacy

Privacy policy

Effective: 28 July 2026

1. Who we are

Chatmerce is a conversational agent platform operated by Prosit AS, a company registered in Norway (organisasjonsnummer: to be filled in after registration). Contact email: hello@chatmerce.eu. Prosit AS is the data controller within the meaning of Regulation (EU) 2016/679 (GDPR).

In this policy, “we”, “us” and “Chatmerce” mean Prosit AS. “You” means the data subject — usually a user of the app.chatmerce.eu dashboard, but also an end-user conversing with an agent deployed by our customer.

2. What data we collect

2.1 Sign-up and account data

  • Name and email address (from OAuth: Google, Microsoft, Apple)
  • External authentication identifier (sub from OAuth, opaque to us)
  • Avatar (URL from your OAuth provider, optional)
  • Company name, VAT number, billing address (when you register as an organisation)
  • Passwords never reach our systems — authentication is handled by Clerk (see sub-processors)

2.2 Technical and log data

  • IP address (anonymised after 30 days)
  • User-Agent header
  • Login times and dashboard actions
  • Session identifier (HttpOnly cookie)

2.3 Configuration data (“Customer Data”)

  • Agent prompts and instructions
  • Uploaded knowledge sources (PDFs, links, plain text)
  • Agent configuration

This data belongs to you. We process it solely to operate the service.

2.4 Conversation data

  • Message content from the end-user and the agent
  • Session identifier (anonymous for the web widget; phone number for RCS)
  • Message time, channel (web/RCS), agent version
  • Technical metadata: token count, conversation cost, LLM model used

2.5 Billing data

  • Company name, VAT number, invoice address
  • Payment history (Stripe, once paid billing goes live)
PurposeLegal basis (GDPR Art. 6)Data
Providing the service (account, agent operation)Art. 6(1)(b) — performance of a contractaccount, config, conversations
Issuing invoices, tax obligationsArt. 6(1)(c) — legal obligationbilling
Security, abuse preventionArt. 6(1)(f) — legitimate interestlogs, IP
First-party marketing (newsletter, if you opt in)Art. 6(1)(a) — consentemail
Usage analytics, product improvementArt. 6(1)(f) — legitimate interestaggregates (no conversation content)

4. Whom we share data with (sub-processors)

Each sub-processor has a Data Processing Agreement (DPA) with us and is either established within the EEA or operates under the Standard Contractual Clauses (SCC) per Commission Implementing Decision (EU) 2021/914.

Sub-processorWhat it processesLocation
Google Cloud (Cloud Run, Firestore, BigQuery, Secret Manager)hosting, database, secretseurope-west4 (Netherlands)
Google (Gemini API)LLM request processingeurope-west4
Clerk, Inc.user authenticationUSA — SCC + DPF
SerwerSMS (Vercom S.A.)RCS message delivery (if you use this channel)Poland
Cloudflare, Inc.CDN, marketing site hostingglobal — SCC + DPF
Stripe Payments Europesubscription billing (once enabled)Ireland

The current full list with change dates is available on request: hello@chatmerce.eu. Enterprise plan: list delivered as an annex to the contract.

5. International data transfers

For sub-processors outside the EEA we use Clerk (USA) and Cloudflare (global). Both are certified under the EU–U.S. Data Privacy Framework (DPF) and have signed Standard Contractual Clauses with us. All other data stays inside the EEA.

6. How long we keep data

  • User account: until account deletion + 30 days (undo window)
  • Conversations: 24 months from the last message (unless you delete them earlier)
  • Technical logs: 90 days
  • Invoices and billing data: 5 years (Polish accounting act, art. 74)
  • Backups: 35 days

After expiry, data is automatically deleted or anonymised by a scheduled job.

7. Your rights (GDPR Art. 15–22)

You have the right to:

  • Access your data (Art. 15)
  • Rectification of incorrect data (Art. 16)
  • Erasure (“right to be forgotten”, Art. 17) — from the panel or by email
  • Restriction of processing (Art. 18)
  • Data portability in JSON/CSV format (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Not be subject to decisions based solely on automated processing (Art. 22)

All requests go to hello@chatmerce.eu. We respond within 30 days (Art. 12(3) GDPR).

You may also file a complaint with a supervisory authority:

  • Poland: Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl
  • Norway: Datatilsynet, Postboks 458 Sentrum, 0105 Oslo, datatilsynet.no
  • Or the authority competent for your country of residence.

8. Cookies

We use a minimal set of cookies:

  • chatmerce-theme — theme preference (light/dark). 1 year.
  • __session (Clerk) — logged-in session. Duration of the session.
  • cf_bm (Cloudflare) — bot protection. 30 minutes.

We do not use analytics or marketing cookies without your explicit consent. The marketing site has no Meta or Google Ads pixels. For visit statistics we use Cloudflare Web Analytics — no cookies, no profiling, no cross-site tracking. The lawful basis is our legitimate interest (GDPR art. 6(1)(f)), and we process aggregates only. Cloudflare is one of our sub-processors.

9. Children

Chatmerce is not directed at persons under 16. We do not knowingly collect data from children.

10. Security

  • Encryption in transit (TLS 1.3) and at rest (AES-256, keys managed by Google KMS)
  • Secrets in Google Secret Manager — never in the database, logs, or source repository
  • Production access limited to two people (Prosit AS founders), with 2FA enforced
  • External pentest: first scheduled for Q3 2026 (annually thereafter)
  • Business-continuity plan: cross-region backups, RTO 24h, RPO 1h

11. Data breaches

If we determine that a breach poses a risk to your rights:

  • We notify the supervisory authority within 72 hours (Art. 33 GDPR)
  • We notify you directly if the risk is high (Art. 34 GDPR)
  • We publish a post-mortem on status.chatmerce.eu within 14 days

12. Policy changes

We announce material changes by email with 30 days’ notice. The change history is available on request at hello@chatmerce.eu.

13. Contact

Data protection matters: hello@chatmerce.eu

Data Protection Officer: not appointed. The processing carried out by Prosit AS does not require a DPO under Art. 37(1) GDPR. All data matters are handled directly by the founders of Prosit AS.

Correspondence address: Prosit AS — to be filled in after registration in the Norwegian Brønnøysundregistrene.