1. Introduction
LiveChatAi is committed to protecting the personal data of our customers and their website visitors in compliance with the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and the UK GDPR where applicable.
This policy applies to all personal data processed through the LiveChatAi platform and supplements our Privacy Policy. If you are a customer deploying LiveChatAi on your website, you are responsible for ensuring your own use of the platform is GDPR-compliant with respect to your website visitors.
2. Roles & Responsibilities
2.1 LiveChatAi as Data Controller
We are the Data Controller for personal data relating to our registered customers, including:
- Account information (name, email, billing details)
- Usage analytics and service logs
- Support communications
2.2 LiveChatAi as Data Processor
When your website visitors interact with the LiveChatAi widget, we act as a Data Processor on your behalf. You (the customer) are the Data Controller for visitor personal data. We process visitor data strictly according to your instructions and for the purpose of providing the chat service.
2.3 Your Responsibilities as Data Controller
As a website operator using LiveChatAi, you are responsible for:
- Informing your visitors that a chat service is active and how their data is processed
- Obtaining any necessary consents from visitors before activating the chat widget
- Including LiveChatAi in your own privacy policy as a data sub-processor
- Responding to data subject requests from your visitors
3. Lawful Basis for Processing
We rely on the following lawful bases under Article 6 GDPR:
| Processing Activity | Lawful Basis |
|---|---|
| Account registration and management | Contract (Art. 6(1)(b)) |
| Billing and payment processing | Contract (Art. 6(1)(b)) |
| Sending transactional emails | Contract (Art. 6(1)(b)) |
| Visitor chat message processing | Legitimate Interest / Contract (Art. 6(1)(f)/(b)) |
| Security and fraud prevention | Legitimate Interest (Art. 6(1)(f)) |
| Legal compliance and records | Legal Obligation (Art. 6(1)(c)) |
| Marketing communications (where opted in) | Consent (Art. 6(1)(a)) |
4. Categories of Personal Data We Process
4.1 Customer Account Data
- Identification data: name, email address
- Authentication data: hashed password
- Financial data: billing address, payment method token (held by payment processor)
- Technical data: IP address, browser type, login timestamps
4.2 Visitor Chat Data (processed on your behalf)
- Message content exchanged during chat sessions
- Visitor session metadata (page URL, browser, IP address)
- Timestamps and session identifiers
We do not collect special categories of data (Article 9 GDPR) intentionally. If a visitor shares sensitive data in a chat, it is processed as ordinary message content.
5. Data Subject Rights
Under the GDPR, individuals have the following rights. We are committed to honouring them within statutory timeframes (typically 30 days):
Right of Access (Art. 15)
Request a copy of all personal data we hold about you, including its source and how it is used.
Right to Rectification (Art. 16)
Correct any inaccurate or incomplete personal data without undue delay.
Right to Erasure (Art. 17)
Request deletion of your personal data where no overriding legitimate basis exists for retention.
Right to Restriction (Art. 18)
Request that we limit the processing of your data while a dispute is being resolved.
Data Portability (Art. 20)
Receive your personal data in a structured, commonly used, machine-readable format (JSON/CSV).
Right to Object (Art. 21)
Object to processing based on legitimate interests, including direct marketing.
To exercise any right, email support@live-chat.ai with your request and proof of identity. We will respond within 30 days. If we cannot fulfil your request, we will explain why.
You also have the right to lodge a complaint with your national supervisory authority (e.g. the ICO in the UK, or the relevant DPA in your EU member state).
6. International Data Transfers
LiveChatAi may process personal data outside the European Economic Area (EEA). Where such transfers occur, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Transfers to countries with an adequacy decision under Article 45 GDPR
- Binding Corporate Rules where applicable
AI providers you configure (e.g. OpenAI in the US) may process message data outside the EEA. We recommend reviewing their own GDPR compliance documentation before use.
7. Sub-Processors
We use the following categories of sub-processors to deliver the Service:
| Category | Purpose | Location |
|---|---|---|
| Cloud Infrastructure | Hosting and data storage | EU / US |
| Email Delivery | Transactional emails | EU / US |
| Payment Processor | Billing and subscription management | US |
| AI Providers (user-configured) | Generating chat responses | Varies |
All sub-processors are bound by data processing agreements that require them to protect personal data to a standard equivalent to this policy.
8. Data Retention & Deletion
We retain personal data only for as long as necessary:
- Account data: Duration of the account + 30-day deletion grace period
- Chat history: 12 months (Free) / Active subscription period (Pro)
- Billing records: 7 years (legal obligation)
- Security logs: 90 days
Upon account deletion, personal data is anonymised or permanently deleted within 30 days, except where longer retention is required by law.
9. Data Breach Procedure
In the event of a personal data breach, we will:
- Assess the breach within 24 hours of discovery
- Notify relevant supervisory authorities within 72 hours where required by Article 33 GDPR
- Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights (Article 34 GDPR)
- Document the breach, its effects, and remedial actions taken
10. Data Processing Agreement
If you are a business using LiveChatAi and need a formal Data Processing Agreement (DPA) to document our processor relationship under Article 28 GDPR, please contact us at support@live-chat.ai.
We will provide a DPA that covers the subject matter, duration, nature, and purpose of processing, the type of personal data involved, and your obligations as Data Controller.
11. Data Protection Officer & Contact
For all GDPR-related enquiries, data subject requests, or to obtain a DPA: