Legal

Privacy Policy

Last updated 23 September 2026

Chatbot CRM ("we", "us") is operated by Chatbot CRM (Influbriz). This policy explains what we collect when you create an account, build a business website and run an AI receptionist on chatbot.influbriz.cloud, what happens to the data of the visitors who talk to that receptionist, and the choices you have. It applies to the platform at https://chatbot.influbriz.cloud, the websites we host for our customers and the chat widget embedded on third-party sites.

1. Who this policy covers

  • Account holders: people who sign up with an email address and password or with Google, and their teammates (owners, admins, managers and editors).
  • Businesses: the companies whose website, chatbot and inbox are managed through an account.
  • Visitors: people who read a hosted business website or chat with its AI receptionist, on the hosted site or through the embed code on the business's own site.
  • Where a business uses our platform to serve its customers, the business is the data controller of its visitor data and we act as its processor. This policy describes our processing; the business's own privacy notice applies to its customers.

2. Information we collect

  • Account data: name, email address, profile picture (from Google sign-in), country, phone number (optional), password hash (never the password), sign-up and last-login times, and the workspace you opened last.
  • Business data: business name, category, description, address, phone, WhatsApp number, opening hours, website address, Google Business Profile details (rating, reviews, photos, hours) retrieved from Google, social profile links, uploaded documents, logos, images, branding, SEO settings, custom domains and marketing tag IDs you configure.
  • Website and chatbot content: the website copy and images generated for you, the Knowledge Base answers you write, quick replies, greeting and widget settings, and the knowledge index (embeddings) built from your data.
  • Conversations and leads: every message exchanged with the AI receptionist or a team member, internal notes, tags, the visitor's name, phone number, email address and appointment details when the visitor provides them, WhatsApp handoff records and message delivery status.
  • Visitor technical data: an anonymous visitor identifier and chat session token (stored in a cookie and in the browser's local storage), the page the chat started on, referrer, browser type, approximate time zone, and page-view events recorded by the hosted website's analytics.
  • AI provider data: if you add your own AI API key it is encrypted with AES-256-GCM and only ever decrypted on our servers to call the provider; we store the last four characters for display. Each AI call is logged with provider, model, token counts, latency and outcome for usage reporting.
  • Team and audit data: invitations, roles, and an audit log of changes made in a workspace (who changed branding, domains, knowledge, team membership, and so on).
  • Support and email data: messages you send through our contact form and a log of the emails we send you (subject, recipient, delivery status).

3. How we use it

  • To provide the service: create and host your website, find your Google listing, collect data from your website and public sources, generate copy and images, train and run the AI receptionist, deliver team replies, and show conversations, leads, bookings and analytics in your dashboard.
  • To answer visitors: visitor messages, the conversation history and your business data are sent to an AI model provider to generate replies and short conversation summaries (title, topic, extracted contact details).
  • To notify you: lead, booking, handoff and team-invitation emails, and WhatsApp summaries when you enable the handoff.
  • To keep the platform safe: rate limiting, abuse prevention, security monitoring and audit logs.
  • To improve the product: aggregated usage statistics (for example AI replies per month) that do not identify individual visitors.
  • To comply with law and enforce our Terms.

4. AI processing and sub-processors

AI replies, summaries, embeddings and generated images are produced by third-party AI providers. By default we use Google Gemini, with Anthropic Claude and Voyage AI as automatic fallbacks; the platform may also route requests through OpenAI, OpenRouter, DeepSeek or an OpenAI-compatible endpoint configured by the platform administrator or by you (your own key). Only the data needed for the request is sent: the visitor's message, recent conversation history, the relevant excerpts of your business data and your Knowledge Base answers. We do not use your data or your visitors' conversations to train our own models.

Other sub-processors: Google (sign-in and Google Places / Business Profile data), Resend (transactional email), Meta / WhatsApp Business (handoff messages when you enable them), and our hosting provider, where the database (PostgreSQL) and cache (Redis) run. Marketing tags you configure (Google Analytics, Google Tag Manager, Meta Pixel, TikTok Pixel, LinkedIn Insight) load on your hosted website under your own accounts and their policies.

5. Cookies and local storage

We use a small number of strictly necessary cookies (sign-in session, visitor identifier, chat session) and a theme preference. The chat widget also stores the session, conversation and visitor identifiers in the browser's local storage so the conversation continues across pages and visits. Details, lifetimes and how to control them are in our Cookie Policy at https://chatbot.influbriz.cloud/cookies.

6. Retention

  • Account and business data: for as long as the account or business exists. Archiving a business takes its website and chatbot offline while keeping the data; deleting a business permanently removes its website, knowledge base, images, documents, conversations, leads, bookings and notes.
  • Conversations, leads and bookings: kept while the business exists so the team can follow up; the business can close conversations and delete internal notes at any time.
  • Visitor memory: the last 50 messages a visitor exchanged with a business are kept so the assistant remembers returning visitors; the visitor can clear this from the widget (Clear chat).
  • Visitor cookies: the visitor identifier lasts 30 days from the last chat; the chat session cookie lasts up to one year.
  • Backups: database backups are taken before every deployment and nightly, and rotate automatically.
  • AI usage logs and audit logs: kept for reporting and security, without message content.

7. Your rights

Depending on where you live (including under the GDPR, the UK GDPR, India's Digital Personal Data Protection Act and similar laws) you may have the right to access, correct, export or delete your personal data, to restrict or object to processing, and to withdraw consent. Account holders can edit their details and business data in Settings, archive or delete a business, and delete conversations and notes. Team members can be removed by an owner or admin.

Visitors of a hosted business website should contact that business first, since it controls the data collected about them; we assist businesses in fulfilling such requests. For anything else, or to exercise your rights with us directly, email influbriz@gmail.com. We reply within 30 days.

8. Security

Data is transmitted over HTTPS. Passwords are hashed with bcrypt; API keys and tokens are encrypted at rest; every read and write in the dashboard is scoped to a business the signed-in person is a member of; platform administrators opening a customer business are recorded in that business's audit log. Uploaded SVG logos are sanitised and served sandboxed. No system is perfectly secure, so please use a strong password and keep your API keys private.

9. Children

The platform is for businesses and is not directed at children under 16. We do not knowingly collect their data; contact us if you believe a child has provided personal data through a hosted website and we will remove it.

10. International transfers

Our servers and sub-processors may be located outside your country. Where required we rely on standard contractual clauses or equivalent safeguards. AI providers process requests in their own regions.

11. Changes

We update this policy when the product changes. The date at the top shows the last revision; material changes are announced in the dashboard or by email.

12. Contact

Chatbot CRM (Influbriz) · influbriz@gmail.com · https://chatbot.influbriz.cloud/contact