SilentChat
Back to BlogGDPR

Chatbot on your website: what goes into the privacy policy?

Marc WagnerOctober 5, 20265 min read
TL;DR

A chat processes personal data — at the latest with the first message. Your privacy policy therefore has to name the provider, purpose, legal basis, recipients, any transfer to third countries and the retention period. If an AI answers, the AI provider and the labelling come on top. A template for SilentChat is below.

Not legal advice. The template matches SilentChat's default settings — check it with your data protection officer.

What data a chat processes

The messages themselves are the obvious part. Then there are voluntary details such as name or email address, and technical data without which a chat does not work. With SilentChat these are a hashed IP address, browser user agent, operating system, device, language, referrer including campaign parameters, and the page where the chat started — plus files and screenshots if the visitor sends any. SilentChat records further visited pages only if you switch on visitor tracking — the default is off.

The required information under Art. 13 GDPR

  • Controller and provider: you — and the chat provider as your processor.
  • Purpose: answering enquiries, possibly customer service for existing contracts.
  • Legal basis: Art. 6(1)(b) GDPR for enquiries about contracts, otherwise usually (f), legitimate interest. If you ask for consent before the chat, it is (a).
  • Recipients: the chat provider and, for AI answers, the AI provider.
  • Third countries: whether and on what basis data leaves the EU — for example to the US under the Data Privacy Framework.
  • Retention: how long chats are kept. In SilentChat the default is 180 days after closing, adjustable between 7 and 365 days.
  • Rights: access, erasure, objection — and how visitors exercise them.

What AI answers add

  • Labelling: visitors must be able to tell that they are talking to an AI (Art. 50 AI Act). In SilentChat, AI labelling is a switch and on by default.
  • AI provider: who computes the answers and where. For SilentChat this is IONOS in data centres in Germany; according to IONOS, inputs are neither logged nor used for training.
  • No automated decision: a chatbot that answers questions does not make a decision within the meaning of Art. 22 GDPR. Still say that a human can take over at any time.

Cookies and storage in the browser

The ePrivacy rules (in Germany § 25 TDDDG) require consent for anything stored on the visitor's device unless it is strictly necessary for the requested service. SilentChat sets no cookies and creates no identifier before the first chat; the identifier only comes into being when the visitor starts a conversation and then remains in the browser. If you want to ask first, switch on “Require consent” in the widget — a notice with links to your privacy policy and imprint then appears before the chat, provided you have entered their addresses in the widget settings.

Don't forget the data processing agreement

You need a contract under Art. 28 GDPR with the chat provider. With SilentChat you conclude it in the dashboard, on every plan — including the free one.

Template for SilentChat

Matching the default settings. Replace the square brackets with your values; if you have switched on “Require consent”, also name Art. 6(1)(a) GDPR.

Live chat and AI assistant

On our website we offer a live chat with an AI assistant (provider: SilentChat, Forge12 Interactive GmbH, Donaueschingen, Germany, as a processor under Art. 28 GDPR). When you use the chat, we process your messages, files and screenshots you send yourself, voluntary details such as name and email address, and technical data (hashed IP address, browser user agent, operating system, device, language, referrer and campaign parameters, the page where the chat started) in order to answer your request. The data is stored on servers in Germany; it is not transferred to countries outside the EU.

The legal basis is Art. 6(1)(b) GDPR where your request concerns a contract or steps towards one, and otherwise our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR).

The chat sets no cookies. Only when you start a conversation does the chat store a visitor identifier and a session identifier in your browser's storage, so the conversation can continue and a later conversation can be linked to you. The visitor identifier remains until you clear your browser storage.

Answers may be generated by an AI assistant, which is labelled as AI in the chat. For this, the messages of the conversation are sent to IONOS Cloud GmbH and processed in data centres in Germany. The name and email address from your contact details are not included; anything you write into a message does reach the AI. No automated decision within the meaning of Art. 22 GDPR is made; you can request to be passed to a human at any time.

We delete chats [180] days after the conversation is closed; they are permanently removed after a further 30 days. Technical session data is deleted after 180 days. Name and email address are overwritten twelve months after your last visit. Backups are overwritten after 30 days at the latest.

You can request access, rectification, erasure or object at any time at [email address].

Further wording — for example for chat history in the browser or data subject rights — is in our GDPR guide. A checklist to tick off is at GDPR checklist for live chat.

dsgvodatenschutzerklärungchatbotkimustertext

Related articles

Chatbot and privacy policy: required information and template | SilentChat