Legal
Privacy Policy
This policy explains how ChatEaver handles personal information when people use our service, visit a customer's chatbot, or contact us.
Effective date: July 30, 2026
Who we are
ChatEaver, operated from Cambodia, provides hosted chatbot, knowledge, contact, outcome, and booking tools to customers worldwide. Contact us at chateaver@gmail.com.
This policy applies to ChatEaver's websites, dashboard, chatbot widget, and supported integrations.
Data we collect
- Account details such as name, email, password hash, verification, and authentication records.
- Workspace configuration, business profile, plan, credits, payment status, and transaction records.
- Knowledge sources including text, website URLs and content, FAQs, documents, and uploaded files.
- Widget messages, conversation history, session identifiers, handoff status, visitor contact details, outcomes, webhook records, and bookings.
- Images, audio, files, booking names, emails, phone numbers, requested times, and purposes supplied.
- Device, browser, IP address, origin or referrer, security, diagnostic, and operational information collected by our infrastructure.
- Support communications and privacy requests.
Purposes and legal bases
We process data to deliver the contracted service; authenticate accounts; perform customer-requested AI and knowledge processing; provide support; administer billing and accounting; prevent abuse; debug and maintain reliability; comply with law; and improve the product.
Depending on the context and applicable law, our legal bases include performance of a contract, legitimate interests in operating and protecting the service, compliance with a legal obligation, and consent. We respect applicable opt-out and consent-withdrawal rights.
Our privacy roles
ChatEaver as controller
ChatEaver acts as controller when it determines why and how account registration, identity, authentication, security, billing, diagnostics, abuse prevention, support, and legal-compliance data is processed.
Customer as controller; ChatEaver as processor
For information processed through a customer's workspace, the customer acts as controller and ChatEaver acts as processor or service provider. This includes business knowledge and files, visitor chats and contacts, handoff information, outcomes and webhook payloads, bookings, images, audio, and other submitted files. We process it to provide the configured service.
ChatEaver remains responsible for disclosed processing, appropriate transparency and safeguards, appropriate vendor selection and oversight, appropriate contracts and accurate disclosures about vendor categories, request assistance, ChatEaver's own compliance, and its applicable legal duties. This does not guarantee the accuracy, availability, or performance of third-party services or AI output.
Customer responsibilities
Each customer is responsible for:
- Having permission and a lawful basis for data it uploads, collects, or processes.
- Giving required privacy notices and obtaining consent where applicable.
- Avoiding unnecessary, unlawful, infringing, or highly sensitive data.
- Configuring and supervising its chatbot and reviewing AI output before consequential use.
- Responding to its end users' requests, with processor assistance from ChatEaver when needed.
- Its business decisions, bookings, representations, and promises made through the workspace.
- Securing accounts, workspace keys, integration credentials, and authorized-user access.
These responsibilities do not remove ChatEaver's own legal or security obligations.
AI and automated processing
Customer and visitor inputs may be sent to configured AI or transcription providers, including Google Gemini when configured, to generate responses, summaries, classifications, transcriptions, or drafts. AI output may be incomplete, outdated, or incorrect and is not a guaranteed substitute for professional or human judgment.
Customers must not use ChatEaver for solely automated decisions producing legal or similarly significant effects without an independently valid legal basis, required safeguards, and meaningful human review.
Vendors and international transfers
We use categories of vendors and subprocessors such as:
- Cloud hosting, database, monitoring, security, and infrastructure providers.
- Object and file storage, including Cloudflare R2 when enabled.
- AI and transcription providers, including Google Gemini when configured.
- Email delivery, payment, billing, and authentication providers, including Google when enabled.
- Customer-selected messaging integrations.
These services may process information outside your country. Where required, we use appropriate contractual or other lawful transfer safeguards.
Cookies and authentication
We use cookies and similar technologies necessary to keep users signed in, protect sessions, remember essential settings, and secure the service. Authentication providers may set their own technologies when a user chooses them. Where applicable, we request consent before using non-essential technologies.
How long we keep data
Our launch retention targets are:
- Account and workspace data: while active, then up to 30 days after a verified deletion request.
- Knowledge sources and uploaded files: until customer deletion or account closure, then up to 30 days in backups.
- Chat conversations, visitor contact details, outcomes, and bookings: 12 months by default, unless deleted earlier or a different supported period is configured.
- Security and operational logs: up to 90 days.
- Billing records: for periods required by applicable tax, accounting, and legal obligations.
- Verification and password-reset records: only as long as operationally necessary.
- Fraud, security incident, dispute, or legal-hold data: longer only when reasonably necessary.
These are retention targets, not a promise that every deletion is automated. We handle verified deletion requests and apply the periods above while retention cleanup is implemented and verified.
Your privacy rights
Depending on your location and applicable law, including in the EEA, UK, California, and other regions with comparable privacy rights, you may request information, access, correction, deletion, restriction, objection, portability, or withdrawal of consent. You may also have rights to opt out of sale, sharing, targeted advertising, or certain profiling, and to appeal or complain to a competent authority. We may verify identity before fulfilling a request.
For data controlled through a customer's chatbot or workspace, contact that customer first. ChatEaver will provide processor assistance. For ChatEaver-controlled data, email chateaver@gmail.com.
Children
The service is not directed to children under 13. Higher local age thresholds apply where required. If we learn that data was collected from a child contrary to applicable requirements, we will take appropriate steps to delete it.
Security and legal response
We apply reasonable technical and organizational safeguards, protect authentication credentials, and limit authorized access. No internet service is risk-free, so we cannot guarantee absolute security. We investigate incidents and give notices where applicable law requires.
We may preserve or disclose information to meet applicable legal duties or valid government requests, prevent harm, address fraud or disputes, or protect rights. Information may also transfer as part of a merger, financing, acquisition, reorganization, or sale, subject to appropriate protections.
We may update this policy as the service or requirements change. We will publish a revised date and give additional notice where required.
Governing location
ChatEaver is operated from Cambodia. This governing location does not waive mandatory rights or remedies available under the law of your jurisdiction.
Contact and complaints
Send privacy questions, rights requests, or complaints to chateaver@gmail.com. Please describe your relationship to ChatEaver and the information concerned. You may also complain to a competent privacy or data-protection authority where applicable.

