Privacy Policy
Last updated: December 2024
Introduction
At Hal, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our customer chat platform service.
Data Controller
Hal is the data controller responsible for your personal data. If you have questions about this policy or our data practices, please contact us at privacy@chatwithhal.com.
Data We Collect
We collect different types of information depending on how you interact with our service:
Account Data
When you register, we collect your email address, name, company name, and password. We also store your notification preferences and account settings.
Conversation Data
We store messages exchanged between your team and website visitors, including timestamps, sender information, and any files shared during conversations.
Visitor Data
We collect information about visitors who use the chat widget on your website, including their name (if provided), email (if provided), browser type, and pages visited.
Analytics Data
We use PostHog (with EU data hosting) to collect anonymized usage analytics to improve our service, including feature usage, performance metrics, and error tracking.
How We Use Your Data
We use your personal data for the following purposes:
- To provide and maintain our chat service
- To generate AI-powered response suggestions using Claude (Anthropic)
- To send you important service notifications
- To improve and personalize your experience
- To process payments via Stripe (for paid plans)
Legal Basis for Processing
Under GDPR Article 6, we process your data based on:
- Contract - Processing necessary to fulfill our service agreement with you
- Consent - For AI features and marketing communications, where you've given explicit consent
- Legitimate Interest - For analytics and service improvement, balanced against your privacy rights
Third-Party Processors
We share data with the following trusted third parties who process data on our behalf:
- Anthropic (Claude AI) - AI response suggestions (Claude). Data is processed per Anthropic's privacy policy and is not used to train their models.
- PostHog - Product analytics with EU data hosting (eu.posthog.com). Anonymized usage data only.
- Stripe - Payment processing for paid subscriptions. Handles payment card data directly.
- Railway - EU-based infrastructure hosting for our API and database.
- Cloudflare - Content delivery and DDoS protection for our dashboard and website.
Data Retention
We retain your data for as long as your account is active. Conversation history is retained based on your plan (30 days to unlimited). When you delete your account, we schedule permanent deletion after a 30-day grace period, during which you can reactivate your account.
Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of Access - You can request a copy of all personal data we hold about you
- Right to Rectification - You can update or correct your personal data at any time
- Right to Erasure - You can request deletion of your account and all associated data
- Right to Data Portability - You can export your data in a machine-readable JSON format
- Right to Object - You can object to processing based on legitimate interests
To exercise these rights, visit your Profile page in the dashboard and use the Data & Privacy section, or contact us at privacy@chatwithhal.com.
International Data Transfers
All your data is stored and processed within the European Union. We do not transfer personal data outside the EU/EEA. Our infrastructure providers (Railway, Cloudflare) maintain EU data centers, and our analytics provider (PostHog) uses their EU hosting option.
Security Measures
We implement industry-standard security measures including encryption in transit (TLS 1.3), encryption at rest, secure password hashing, and regular security audits. Access to personal data is restricted to authorized personnel only.
Children's Privacy
Our service is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email and update the "Last updated" date. Continued use of our service after changes constitutes acceptance of the updated policy.
Contact Us
For privacy-related questions or to exercise your data rights, contact our Data Protection team at privacy@chatwithhal.com. You also have the right to lodge a complaint with your local data protection authority.
AI Processing of Chat Conversations
When you use the chat widget on websites powered by Hal, your messages may be processed by AI to help provide faster, more accurate support.
How AI Processing Works
Your chat messages may be sent to Claude (by Anthropic) to generate suggested responses for the support team. This helps agents respond more quickly and accurately to your questions.
Human Oversight
All AI-suggested responses are reviewed by human agents before being sent to you. The AI assists but does not replace human judgment. You are always communicating with real people who make the final decision on every response.
Your Right to Opt Out
You can disable AI processing of your conversations at any time through the widget settings. Click the settings icon in the chat widget and toggle off "AI-assisted responses". Your preference is saved and respected for all future conversations.
How Your Data Is Used
Your chat messages are used solely to generate contextual responses during your conversation. Your data is NOT used to train AI models. Messages are processed in real-time and are not retained by Anthropic for training purposes.