LiveChatAi LiveChat
Contact Us How It Works Pricing
Sign In Dashboard Start Free
GDPR

GDPR Compliance Policy

Last updated: July 2026  ·  Effective: July 1, 2026

Contents

  • 1. Introduction
  • 2. Roles & Responsibilities
  • 3. Lawful Basis
  • 4. Personal Data We Process
  • 5. Data Subject Rights
  • 6. International Transfers
  • 7. Sub-Processors
  • 8. Retention & Deletion
  • 9. Data Breach Procedure
  • 10. Data Processing Agreement
  • 11. DPO Contact

1. Introduction

LiveChatAi is committed to protecting the personal data of our customers and their website visitors in compliance with the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and the UK GDPR where applicable.

This policy applies to all personal data processed through the LiveChatAi platform and supplements our Privacy Policy. If you are a customer deploying LiveChatAi on your website, you are responsible for ensuring your own use of the platform is GDPR-compliant with respect to your website visitors.

LiveChatAi acts as both a Data Controller (for account data) and a Data Processor (for visitor chat data processed on your behalf).

2. Roles & Responsibilities

2.1 LiveChatAi as Data Controller

We are the Data Controller for personal data relating to our registered customers, including:

  • Account information (name, email, billing details)
  • Usage analytics and service logs
  • Support communications

2.2 LiveChatAi as Data Processor

When your website visitors interact with the LiveChatAi widget, we act as a Data Processor on your behalf. You (the customer) are the Data Controller for visitor personal data. We process visitor data strictly according to your instructions and for the purpose of providing the chat service.

2.3 Your Responsibilities as Data Controller

As a website operator using LiveChatAi, you are responsible for:

  • Informing your visitors that a chat service is active and how their data is processed
  • Obtaining any necessary consents from visitors before activating the chat widget
  • Including LiveChatAi in your own privacy policy as a data sub-processor
  • Responding to data subject requests from your visitors

3. Lawful Basis for Processing

We rely on the following lawful bases under Article 6 GDPR:

Processing ActivityLawful Basis
Account registration and managementContract (Art. 6(1)(b))
Billing and payment processingContract (Art. 6(1)(b))
Sending transactional emailsContract (Art. 6(1)(b))
Visitor chat message processingLegitimate Interest / Contract (Art. 6(1)(f)/(b))
Security and fraud preventionLegitimate Interest (Art. 6(1)(f))
Legal compliance and recordsLegal Obligation (Art. 6(1)(c))
Marketing communications (where opted in)Consent (Art. 6(1)(a))

4. Categories of Personal Data We Process

4.1 Customer Account Data

  • Identification data: name, email address
  • Authentication data: hashed password
  • Financial data: billing address, payment method token (held by payment processor)
  • Technical data: IP address, browser type, login timestamps

4.2 Visitor Chat Data (processed on your behalf)

  • Message content exchanged during chat sessions
  • Visitor session metadata (page URL, browser, IP address)
  • Timestamps and session identifiers

We do not collect special categories of data (Article 9 GDPR) intentionally. If a visitor shares sensitive data in a chat, it is processed as ordinary message content.

5. Data Subject Rights

Under the GDPR, individuals have the following rights. We are committed to honouring them within statutory timeframes (typically 30 days):

Right of Access (Art. 15)

Request a copy of all personal data we hold about you, including its source and how it is used.

Right to Rectification (Art. 16)

Correct any inaccurate or incomplete personal data without undue delay.

Right to Erasure (Art. 17)

Request deletion of your personal data where no overriding legitimate basis exists for retention.

Right to Restriction (Art. 18)

Request that we limit the processing of your data while a dispute is being resolved.

Data Portability (Art. 20)

Receive your personal data in a structured, commonly used, machine-readable format (JSON/CSV).

Right to Object (Art. 21)

Object to processing based on legitimate interests, including direct marketing.

To exercise any right, email support@live-chat.ai with your request and proof of identity. We will respond within 30 days. If we cannot fulfil your request, we will explain why.

You also have the right to lodge a complaint with your national supervisory authority (e.g. the ICO in the UK, or the relevant DPA in your EU member state).

6. International Data Transfers

LiveChatAi may process personal data outside the European Economic Area (EEA). Where such transfers occur, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Transfers to countries with an adequacy decision under Article 45 GDPR
  • Binding Corporate Rules where applicable

AI providers you configure (e.g. OpenAI in the US) may process message data outside the EEA. We recommend reviewing their own GDPR compliance documentation before use.

7. Sub-Processors

We use the following categories of sub-processors to deliver the Service:

CategoryPurposeLocation
Cloud InfrastructureHosting and data storageEU / US
Email DeliveryTransactional emailsEU / US
Payment ProcessorBilling and subscription managementUS
AI Providers (user-configured)Generating chat responsesVaries

All sub-processors are bound by data processing agreements that require them to protect personal data to a standard equivalent to this policy.

8. Data Retention & Deletion

We retain personal data only for as long as necessary:

  • Account data: Duration of the account + 30-day deletion grace period
  • Chat history: 12 months (Free) / Active subscription period (Pro)
  • Billing records: 7 years (legal obligation)
  • Security logs: 90 days

Upon account deletion, personal data is anonymised or permanently deleted within 30 days, except where longer retention is required by law.

9. Data Breach Procedure

In the event of a personal data breach, we will:

  • Assess the breach within 24 hours of discovery
  • Notify relevant supervisory authorities within 72 hours where required by Article 33 GDPR
  • Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights (Article 34 GDPR)
  • Document the breach, its effects, and remedial actions taken

10. Data Processing Agreement

If you are a business using LiveChatAi and need a formal Data Processing Agreement (DPA) to document our processor relationship under Article 28 GDPR, please contact us at support@live-chat.ai.

We will provide a DPA that covers the subject matter, duration, nature, and purpose of processing, the type of personal data involved, and your obligations as Data Controller.

11. Data Protection Officer & Contact

For all GDPR-related enquiries, data subject requests, or to obtain a DPA:

support@live-chat.ai
support@live-chat.ai (DPA requests)
Support Center
Privacy Policy Terms of Service Back to Home

© 2026 Live Chat Ai. All rights reserved.  ·  Privacy  ·  Terms  ·  GDPR