Effective [EFFECTIVE DATE]
Privacy Policy
1. Who we are
WebIntel AI (“WebIntel”, “we”, “us”) provides an embeddable AI chat assistant that answers a website’s visitors using only that website’s own content. This platform is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. For any privacy question, contact us at [privacy@yourdomain.com].
2. Our two roles
We handle personal data in two distinct capacities, and this matters for your rights:
- As a controller — for the personal data of our own customers (the businesses who buy WebIntel): account details, billing information, and support correspondence. This policy governs that data.
- As a processor — for the data that flows through a customer’s chatbot (their website visitors’ messages and any details a visitor volunteers). Here the customer is the controller and decides why the data is processed; we act only on their instructions under our Data Processing Agreement. If you are a visitor to a site that uses WebIntel, please also read that site operator’s own privacy policy.
3. Data we collect
From our customers
- Account: name, email address, and a securely hashed password.
- Billing: subscription plan and status. Card details are entered directly with our payment processor (Stripe) and are never stored on our servers.
- Website content: the pages of the website a customer asks us to crawl, which we convert into a searchable knowledge base for their bot.
- Usage: conversation counts and aggregate analytics used to operate the service and enforce plan limits.
From website visitors (on our customers’ behalf)
- Chat messages and the assistant’s replies. Detected personal data (such as emails and phone numbers) is redacted before storage and is never written to our logs or traces.
- Lead details (e.g. name, email, phone) only when a visitor chooses to provide them in the conversation, together with a record of the consent wording shown at the time.
- Technical context: a coarse, truncated IP address (network-level only, not the full address), browser user-agent, page origin, locale, and timestamps — used for security, rate limiting, and abuse prevention.
4. How we use data
- To provide the chat service — retrieve relevant content and generate grounded answers.
- To operate accounts, process subscriptions, and enforce plan quotas.
- To secure the service — detect and block prompt-injection, abuse, and fraud.
- To produce aggregate analytics for the customer (topics asked, usage, quality).
- To provide support and send essential service communications.
We do not sell personal data, and we do not use visitor conversations to train third-party foundation models.
5. Legal bases (GDPR)
Where the GDPR applies, we rely on: performance of a contract (to provide the service to our customers); legitimate interests (to secure and improve the service, balanced against your rights); consent (where required, e.g. a visitor volunteering contact details); and legal obligation (e.g. tax records). For visitor data processed on a customer’s behalf, the customer is responsible for establishing the legal basis.
6. Sub-processors
We use a small set of vetted providers to run the service. Each is bound by data-protection terms and processes data only as needed to deliver its function.
| Provider | Purpose | Data involved |
|---|---|---|
| Cloud hosting [e.g. Hetzner / Oracle] | Application, database, and job servers | All service data (encrypted in transit) |
| Qdrant Cloud | Vector search index | Embedded website content + tenant identifiers |
| Groq | Answer generation (LLM) | Query + retrieved context at request time |
| Google (Gemini) | Text embeddings | Query and content text at index/query time |
| Portkey [if enabled] | LLM gateway (routing, caching) | Prompts/responses in transit (cache namespaced per customer) |
| Stripe | Payments | Customer billing details (entered directly with Stripe) |
| Pydantic Logfire [if enabled] | Observability | Operational telemetry — hashes and lengths only, never message text |
A current list is maintained; material changes are notified per the DPA.
7. Retention
Conversation records and leads are retained for the period configured for each customer and then deleted automatically (each record carries an expiry). Account and billing records are kept for as long as the account is active and thereafter only as required by law. Customers can request deletion of their tenant’s data at any time.
8. Security
All traffic crossing the public internet is encrypted with TLS. Customer data is isolated per tenant and that isolation is enforced in the storage layer. Passwords are hashed; widget keys are cryptographically derived and origin-restricted. Detected personal data is redacted before storage and never logged. No method is perfectly secure, but we design for defence in depth.
9. International transfers
Our providers may process data in countries other than yours. Where required, such transfers are covered by appropriate safeguards (e.g. the EU Standard Contractual Clauses).
10. Your rights
Depending on where you live (e.g. under the GDPR, UK GDPR, CCPA/CPRA, or India’s DPDP Act), you may have the right to access, correct, delete, port, or restrict the processing of your personal data, and to object or withdraw consent. To exercise these rights, contact [privacy@yourdomain.com]. If you are a website visitor, direct your request to the site operator (the controller); we will assist them in responding. You may also lodge a complaint with your local supervisory authority.
11. Cookies
We use only essential cookies and local storage — see our Cookie Policy. We do not use advertising or cross-site tracking cookies.
12. Children
The service is intended for businesses and is not directed at children. We do not knowingly collect personal data from children.
13. Changes
We may update this policy; we will revise the “Effective” date above and, for material changes, notify customers by email or in the dashboard.
14. Contact
[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
Privacy: [privacy@yourdomain.com]
[· Data Protection Officer, if appointed]