Privacy Policy
Last updated: July 27, 2026
David Langr, Business Registration No. (ICO): 04617002, with the place of business at V olsinach 1451/20, 100 00, Prague 10 - Strasnice, Czech Republic, operating as Chaterimo ("we", "us", or "our"), operates the Chaterimo platform (the "Service").
This Privacy Policy explains how we collect, use, store, and protect personal data when you use our Service, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Czech data protection law.
1. Data Controller
The data controller for the processing of your personal data is:
David Langr
ICO: 04617002
V olsinach 1451/20, 100 00, Prague 10 - Strasnice, Czech Republic
Email: info@chaterimo.com
2. What Data We Collect
We collect the following categories of personal data:
2.1. Account Data (provided during registration)
- Email address
- Name and username
- Organisation (business) details
- Password (stored as a secure hash, never in plain text)
- Language and locale preferences
- Marketing consent preferences
2.2. Billing Data
- Payment-processor customer identifier and subscription information
- Billing history and invoice data (managed with an external payment provider)
- We do not store credit card numbers or payment card data. Payment processing is handled by an external provider operating under applicable payment-security standards.
2.3. Service Usage Data
- Chatbot configuration and settings
- Knowledge base content (product catalogs, website content, uploaded documents)
- Chat conversations between end-users and chatbots
- Lead data collected through chat widgets (names, emails, phone numbers voluntarily provided by end-users)
- Email content (if email integration is enabled)
- Support ticket content (if ticketing is enabled)
2.4. Technical Data
- IP addresses (used for security, rate limiting, and abuse detection)
- Session identifiers
- Browser type and device information (collected via chat widget)
- Application logs (which may contain request metadata)
2.5. Credentials for Third-Party Services (if provided by the Customer)
- Credentials and authorization tokens for services and integrations selected by the Customer
- Connection metadata necessary to operate those integrations
- Sensitive credentials are encrypted at rest and access is restricted
3. How We Use Your Data
We process personal data for the following purposes:
- Service delivery: Providing and maintaining the Chaterimo platform, including AI-powered chatbot responses, knowledge base search, and e-commerce integrations
- Account management: Managing your registration, authentication, and subscription
- Payment processing: Processing subscription payments through an external payment provider
- Customer support: Responding to your inquiries and providing technical assistance
- Security: Protecting the Service from abuse, fraud, and unauthorized access through IP blocking, rate limiting, and malicious pattern detection
- Service improvement: Analyzing aggregated, anonymized usage data to improve the platform
- Legal compliance: Fulfilling our legal obligations under applicable law
- Communication: Sending transactional emails (account notifications, billing receipts, service updates) and, with your consent, marketing communications
4. Legal Basis for Processing
We process your personal data on the following legal bases under Article 6 GDPR:
- Performance of contract (Art. 6(1)(b)): Processing necessary to provide the Service you subscribed to (account data, service usage data, billing data)
- Legitimate interests (Art. 6(1)(f)): Security measures (IP blocking, rate limiting, logging), service improvement through aggregated analytics, and fraud prevention
- Consent (Art. 6(1)(a)): Marketing communications (you can withdraw consent at any time)
- Legal obligation (Art. 6(1)(c)): Tax and accounting record-keeping as required by Czech law
5. Data Sharing and Recipients
We disclose personal data only as necessary to provide the Service, comply with law, or follow the Customer's instructions. The relevant categories of recipients are:
- Cloud infrastructure, storage, and delivery providers
- AI service providers used to provide features configured by the Customer
- Payment and transactional communication providers
- Customer-enabled integration providers, such as email, messaging, CRM, e-commerce, and content-retrieval services
- Professional advisers and public authorities, where legally required
Optional providers receive data only when the relevant feature is enabled or requested. We do not sell personal data or disclose it to third parties for their own marketing.
Business customers may request the current named list of sub-processors, including their purpose, processing location, and applicable transfer safeguard, at info@chaterimo.com under the Data Processing Agreement.
6. International Data Transfers
Our primary hosting and storage are located in the EEA. Some service providers may process personal data outside the EEA. For such transfers, we rely on:
- The European Commission's adequacy decision for the EU-U.S. Data Privacy Framework (where the provider is certified)
- Standard Contractual Clauses (SCCs) approved by the European Commission (Decision (EU) 2021/914)
- Where available, we contract with the EU/EEA subsidiary of providers to minimize cross-border transfers
7. Data Retention
- Account data: Retained for the duration of your subscription and for a reasonable period thereafter to allow for account reactivation, unless you request deletion
- Service usage data (chat sessions, leads, knowledge base): Retained for the duration of your subscription. Upon termination, deleted from active systems within 30 days and from backups within 90 days
- Billing data: Retained as required by Czech tax and accounting laws (typically 10 years for invoices)
- Application logs: Retained according to the logging provider's retention schedule
- IP addresses used for security blocking: Cached temporarily (up to 24 hours) and not stored in the database
8. Data Security
We implement technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit and protection of sensitive credentials at rest
- Access controls, authentication, and organisation-based logical data separation
- Measures against abuse, unauthorized access, and malicious requests
- Backup, recovery, monitoring, and incident-response procedures
- Confidentiality obligations and access limited to operational need
Further information is available in Annex 2 of our Data Processing Agreement.
9. Your Rights Under GDPR
As a data subject, you have the following rights:
- Right of access (Art. 15): Request a copy of the personal data we hold about you
- Right to rectification (Art. 16): Request correction of inaccurate or incomplete data
- Right to erasure (Art. 17): Request deletion of your personal data, subject to legal retention obligations
- Right to restriction (Art. 18): Request restriction of processing in certain circumstances
- Right to data portability (Art. 20): Receive your data in a structured, commonly used format. Self-service CSV exports are available for leads and chat history.
- Right to object (Art. 21): Object to processing based on legitimate interests
- Right to withdraw consent (Art. 7(3)): Withdraw your consent to marketing communications at any time
To exercise any of these rights, contact us at info@chaterimo.com. We will respond within 30 days as required by the GDPR.
10. Data Processing on Behalf of Customers
When our Customers use the Service to deploy chatbots on their websites, we process personal data of the Customers' end-users (chat visitors) on behalf of the Customer. In this relationship:
- The Customer is the data controller for their end-users' data
- Chaterimo is the data processor
This processing is governed by our Data Processing Agreement (DPA), which forms part of the Terms of Service. The Customer is responsible for providing appropriate privacy notices to their end-users.
11. External Connectors and AI Agents
Customers may connect Chaterimo to an external client or AI agent. When enabled, Chaterimo processes the authentication credentials, requested organisation data, and limited security and audit metadata necessary to provide and protect the connection.
Data is disclosed to the external client only in response to actions authorized by the Customer. The external client is a recipient selected by the Customer and its own privacy terms govern its subsequent processing. The Customer is responsible for choosing the client, granting appropriate access, and ensuring a lawful basis for the disclosure.
Connections are restricted to the authorized organisation and can be revoked by the Customer. Related operational records are retained under Section 7.
12. Cookies and Tracking
The Chaterimo website uses cookies for essential functionality (session management, authentication, language preferences). We do not use third-party advertising or tracking cookies.
The Chaterimo chat widget, when embedded on a Customer's website, uses session storage to maintain chat state. The Customer is responsible for disclosing the widget's data collection in their own cookie/privacy policy.
13. Children's Privacy
The Service is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at info@chaterimo.com and we will delete it promptly.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to registered users via email. The current version is always available on our website.
15. Contact and Complaints
For any questions or concerns about this Privacy Policy or our data processing practices, contact us at:
Email: info@chaterimo.com
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. The competent authority for the Czech Republic is:
Office for Personal Data Protection (UOOU)
Pplk. Sochora 27, 170 00 Prague 7, Czech Republic
Website: www.uoou.cz