1. Scope and our role
This Privacy Policy applies to Chateor’s public website, accounts, customer support workspace, website widget, APIs, and related services.
For account, billing, website, and direct support information, Chateor generally decides why and how personal data is used. For conversations and customer data submitted to a workspace, the organization that owns that workspace generally controls the data and Chateor processes it to provide the Service on that organization’s behalf.
If you are a visitor chatting with a business that uses Chateor, that business’s own privacy notice also applies. Questions about how that business uses your conversation should be directed to the business.
2. Personal data we collect
Account and business information
This can include your name, work email, phone number, company name and website, role, support team size or volume, current support platform, goals, additional details you provide, and authentication information.
Conversations and customer context
We process chat messages, contact details, conversation history, assignments, notes, attachments, and other context a workspace chooses to collect or connect. The exact fields depend on how the workspace configures Chateor.
Usage and technical information
We may collect device and browser information, IP address, timestamps, pages or features used, diagnostic data, security events, and session information. When a website owner enables optional widget statistics, Chateor may use an anonymous visitor identifier and limited technical context to measure use and keep conversations working.
Integrations and API information
When a workspace connects another product, we process connection settings, identifiers, authorization data, webhook events, and the information that the workspace directs the integration to exchange.
Subscription records
We process plan, invoice, payment status, and transaction records needed to administer subscriptions. Payment providers may process payment credentials under their own privacy terms.
3. Where data comes from
We receive data directly from account holders and website visitors, from organizations that create or administer workspaces, automatically from browsers and devices, and from connected products when an authorized user enables an integration.
4. How we use personal data
- provide, operate, maintain, and secure the Service;
- create accounts, authenticate users, manage sessions, and administer workspaces;
- deliver conversations, AI-assisted answers, assignments, notifications, APIs, and integrations;
- respond to support requests and communicate about the Service;
- measure performance, diagnose faults, prevent abuse, and improve features;
- administer subscriptions and business records;
- comply with law, enforce agreements, and protect rights and safety; and
- send product or service communications where allowed, with available opt-out choices.
5. Legal bases
Where applicable law requires a legal basis, we rely on the basis appropriate to the situation: performing a contract, taking steps requested before a contract, our legitimate interests in operating and protecting the Service, compliance with legal obligations, or consent.
When Chateor processes workspace conversation data on behalf of a customer, the customer determines the applicable legal basis and instructions.
7. International processing
Chateor and its service providers may process data in countries other than the one where you live. Where required, we use recognized contractual or other safeguards for international transfers.
8. Data retention
We retain personal data for as long as needed to provide the Service, maintain required business and security records, resolve disputes, enforce agreements, and comply with law. Retention depends on the type of data, workspace settings, contractual instructions, legal requirements, and whether an account remains active.
Workspace owners control many records inside their workspace and may have their own retention obligations. Backup copies may remain for a limited period before they are overwritten.
9. Security
We use organizational and technical measures designed to protect personal data. Chateor supports controls such as email verification, managed sessions, two-factor authentication, roles and permissions, audit history, separate API keys, and signed webhooks.
No online service can guarantee absolute security. You should use strong unique passwords, enable available security controls, keep credentials private, review workspace access, and promptly report suspected misuse. Read more on our Security page.
10. Your choices and rights
Depending on your location and relationship with Chateor, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, or to withdraw consent. You may also have the right to complain to a local data protection authority.
If your data belongs to a Chateor customer’s workspace, contact that customer first. We assist customers with valid requests as required. Account holders can update certain information and security settings in the Service.
11. Children
The Service is intended for business use and is not directed to children. Do not knowingly submit children’s personal data unless it is lawful, necessary for your use case, and supported by appropriate notices, consent, and safeguards.
12. Policy changes
We may update this Policy as our Service, practices, or legal obligations change. The effective date at the top identifies the current version. We will provide additional notice when required by law or when a change materially affects how we use personal data.
13. Contact
To ask a privacy question or submit a request, contact Chateor through the support widget on chateor.com. We may need to verify your identity and authority before completing a request.