PRIVACY POLICY
Blue Yasuo Consulting, s. r. o.
Company ID (IČO): 53199341 Tax ID (DIČ): 2121301556 Registered office: Romanova 1678/33, 851 02 Bratislava — Petržalka, Slovak Republic Email: blueyasuoconsulting@gmail.com Phone: +421 902 638 008 Website: aichatbotforweb.com
(hereinafter referred to as the "Controller")
Effective date: 18 July 2026 Last updated: 3 August 2026
1. Introduction
This Privacy Policy (hereinafter "Policy") informs data subjects about how the Controller collects, processes, stores, and protects personal data in connection with providing custom chatbot development and operation services (hereinafter the "Service").
This Policy has been prepared in accordance with:
- Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter "GDPR");
- Act No. 18/2018 Coll. on Personal Data Protection as amended.
2. Categories of Data Subjects
The Controller processes personal data of the following categories of data subjects:
2.1 Customers (B2B)
Entrepreneurs and representatives of legal entities who order the Service.
2.2 Consumers (B2C)
Natural persons — non-entrepreneurs who order the Service.
2.3 End Users of Chatbots
Persons who interact with chatbots deployed for the Controller's Customers.
2.4 Website Visitors
Persons who visit the Controller's website.
3. What Personal Data We Process
3.1 Customer Data
| Data Category | Examples |
|---|---|
| Identification data | Name, surname, company name, Company ID, Tax ID |
| Contact data | Email, phone number, registered office address |
| Billing data | Bank account, billing address |
| Contractual data | Communication content, chatbot requirements |
| Account data | Email address, password (stored only as a cryptographic hash — never in readable form), account creation date, last sign-in |
| Usage data | Number of messages used in the current period, the chatbot's configuration and uploaded documents, conversation history in your account |
3.2 End User Data (Chatbot Users)
| Data Category | Examples |
|---|---|
| Conversational data | Content of chat messages with the chatbot |
| Technical data | IP address, browser type, operating system |
| Identification data (if collected) | Name, email — only if the chatbot actively collects these data based on Customer configuration |
Important: The scope of end user data depends on the specific chatbot configuration per the Customer's requirements. The Controller only processes data necessary for the chatbot's operation.
3.3 Website Visitor Data
| Data Category | Examples |
|---|---|
| Technical data | IP address, browser type, screen resolution |
| Cookies | Functional and analytical cookies (see Section 10) |
4. Purposes and Legal Bases for Processing
| Purpose | Legal Basis (GDPR) | Data Categories |
|---|---|---|
| Entering into and performing a contract | Art. 6(1)(b) — performance of a contract | Identification, contact, billing, contractual |
| Creating and operating your user account (including the free plan) | Art. 6(1)(b) — performance of a contract | Account data |
| Measuring your plan's message allowance and enforcing its limits | Art. 6(1)(b) — performance of a contract | Account data, usage data |
| Providing the chatbot service | Art. 6(1)(b) — performance of a contract / Art. 6(1)(f) — legitimate interest | Conversational, technical data |
| Invoicing and accounting | Art. 6(1)(c) — legal obligation (Accounting Act, VAT Act) | Billing data |
| Improving service quality | Art. 6(1)(f) — legitimate interest | Conversational data (anonymized), technical data |
| Ensuring security | Art. 6(1)(f) — legitimate interest | Technical data, IP addresses |
| Marketing and commercial communication | Art. 6(1)(a) — consent | Contact data (email) |
| Fulfilling legal obligations | Art. 6(1)(c) — legal obligation | Depending on the specific obligation |
Legitimate interest: Where the Controller relies on legitimate interest, a balancing test has been conducted, concluding that the Controller's legitimate interests do not override the rights and interests of data subjects. Data subjects have the right to object to processing based on legitimate interest at any time.
5. Recipients and Processors
The Controller may share personal data with the following categories of recipients:
5.1 Processors (Sub-processors)
| Company | Purpose | Headquarters | Data Location |
|---|---|---|---|
| OpenAI, LLC | Processing conversations through the AI model (GPT) | San Francisco, USA | USA |
| Supabase, Inc. | Database — data storage | San Francisco, USA | EU (Stockholm, Sweden) |
| Hostinger International Ltd. | VPS hosting — website and chatbot operation | Kaunas, Lithuania | EU (Frankfurt, Germany) |
5.2 Other Recipients
- Accounting firm — processing of invoicing and accounting documents;
- Public authorities — where required by law (e.g., tax office, courts);
- Legal advisors — in the event of dispute resolution.
The Controller does not sell personal data to third parties for marketing purposes.
6. Transfer of Personal Data to Third Countries
6.1 OpenAI (USA)
When processing chatbot conversations, data is transferred to the servers of OpenAI, LLC in the USA. This transfer is safeguarded on the basis of:
- Standard Contractual Clauses (SCC) pursuant to the European Commission Implementing Decision (EU) 2021/914; and/or
- EU-US Data Privacy Framework (DPF) pursuant to the European Commission's adequacy decision of July 10, 2023, provided that OpenAI is certified under the DPF.
6.2 Supplementary Safeguards
- Encryption of data in transit (TLS 1.2+);
- Data minimization — the chatbot only sends the conversation content necessary for generating a response;
- Under its terms (API Data Usage Policy), OpenAI does not use data submitted via the API to train its models.
6.3 Other Providers
Supabase (database in Stockholm) and Hostinger (VPS in Frankfurt) store data within the EU/EEA — no transfer to third countries occurs.
7. Data Retention Periods
| Data Category | Retention Period |
|---|---|
| Contractual and billing data | 10 years from contract termination (Accounting Act) |
| Chatbot conversational data | 12 months from creation, unless the Customer specifies otherwise |
| End User consent given in the widget | 12 months from the moment it is given; the widget then asks again |
| Technical data (logs, IP addresses) | 6 months |
| Marketing consents | Until consent is withdrawn |
| Data for legitimate interest | Until objection is raised or legitimate interest ceases |
After the retention period expires, personal data is deleted or anonymized.
Upon termination of the contract with a Customer, End User data from their chatbot is deleted within 90 days, unless legal regulations require a longer retention period.
8. Rights of Data Subjects
Under the GDPR, you have the following rights:
8.1 Right of Access (Art. 15 GDPR)
You have the right to obtain confirmation as to whether your personal data is being processed and, if so, to access the data and information about the processing.
8.2 Right to Rectification (Art. 16 GDPR)
You have the right to have inaccurate personal data corrected and incomplete data completed.
8.3 Right to Erasure — "Right to Be Forgotten" (Art. 17 GDPR)
You have the right to request the erasure of your personal data if:
- The data is no longer necessary for the purpose for which it was collected;
- You withdraw consent and there is no other legal basis;
- You object to processing and there are no overriding legitimate grounds;
- The data has been unlawfully processed.
8.4 Right to Restriction of Processing (Art. 18 GDPR)
You have the right to request restriction of processing in certain cases (e.g., if you contest the accuracy of the data).
8.5 Right to Data Portability (Art. 20 GDPR)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transfer it to another controller.
8.6 Right to Object (Art. 21 GDPR)
You have the right to object to processing based on legitimate interest. The Controller will cease processing unless it demonstrates compelling legitimate grounds.
8.7 Right to Withdraw Consent (Art. 7(3) GDPR)
Where processing is based on consent, you have the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing prior to its withdrawal.
8.8 Right to Lodge a Complaint
You have the right to lodge a complaint with the supervisory authority:
Office for Personal Data Protection of the Slovak Republic Hraničná 12, 820 07 Bratislava 27 Phone: +421 2 3231 3214 Email: statny.dozor@pdp.gov.sk Website: https://dataprotection.gov.sk
How to Exercise Your Rights
You may exercise your rights by sending a request to: blueyasuoconsulting@gmail.com. We will process your request without undue delay, within 30 days of receipt at the latest. In justified cases, this period may be extended by an additional 60 days, of which you will be informed.
9. Automated Decision-Making and Profiling
Chatbots operated by the Controller use artificial intelligence technology (specifically GPT language models from OpenAI) to generate responses.
Important notice:
- Chatbot responses are automatically generated by an artificial intelligence algorithm;
- The chatbot does not perform automated decision-making with legal effects or similarly significant impact on data subjects within the meaning of Art. 22 GDPR;
- The chatbot is not used for profiling data subjects;
- Customers are required to inform End Users that they are communicating with an AI chatbot, not a live person.
10. Cookies and Tracking Technologies
10.1 Types of Cookies
| Type | Purpose | Legal Basis |
|---|---|---|
| Essential cookies | Ensuring basic website and chatbot functionality | Legitimate interest |
| Analytical cookies | Traffic and service usage analysis | Consent |
| Marketing cookies | Ad personalization (if used) | Consent |
10.2 Cookie Management
Upon your first visit to the website, an information banner (cookie bar) will be displayed, through which you can grant or refuse consent for non-essential cookies. You can change your cookie settings at any time through the website settings.
11. Security Measures
The Controller has implemented appropriate technical and organizational measures to protect personal data, including:
- Data encryption in transit (TLS/SSL);
- Data encryption at rest;
- Access controls and authentication;
- Regular data backups;
- Restricting access to personal data to authorized employees/contractors only;
- Access monitoring and logging;
- Regular software and security patch updates.
12. Personal Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, the Controller shall:
- Notify the Office for Personal Data Protection of the Slovak Republic within 72 hours of becoming aware of the breach;
- If the breach is likely to result in a high risk to data subjects' rights, promptly inform the affected data subjects as well.
13. Processing Data on Behalf of the Customer (Controller vs. Processor)
13.1 When We Act as Controller
The Controller acts as a data controller when processing:
- Data of its Customers (B2B and B2C) for the purpose of contract performance;
- Data of visitors to its own website;
- Data for its own marketing purposes.
13.2 When We Act as Processor
The Controller acts as a data processor when processing:
- Personal data of End Users of chatbots deployed for B2B Customers.
In such cases, the Customer is the data controller and the Controller processes data solely under the Customer's instructions pursuant to a Data Processing Agreement (DPA).
13.3 Customer Obligations When Embedding the Chatbot Widget
A Customer who installs the chatbot widget on their website acts as the data controller towards End Users and is required in particular to:
a) Transparency towards End Users (art. 13/14 GDPR):
- Clearly inform visitors of their website that an AI chatbot is running on it, not a human operator;
- Publish their own privacy policy covering the processing carried out through the chatbot widget, with a reference to this Policy of the Controller (as processor);
- Enter the address of that policy in the widget settings (Dashboard → Widget → Link to your privacy policy). The consent screen and the widget footer then link to the Customer's document — they are the controller towards End Users. If the field is left empty the widget links to this Policy, which is a fallback only and does not discharge the Customer's own duty to inform under art. 13 GDPR;
- Inform End Users that conversations are processed through an AI model provided by OpenAI (USA) and that a transfer to a third country takes place, safeguarded by SCC/DPF.
b) Legal basis:
- Determine their own legal basis under art. 6 GDPR (typically consent or legitimate interest) for processing End User messages;
- Where the chatbot actively collects contact details (name, email, phone), ensure valid consent under art. 7 GDPR or another legal basis.
c) Consent to storing data on the device (art. 5 ePrivacy Directive):
- Before first use, the widget shows the End User a consent screen (information
about the AI assistant, processing through OpenAI/USA, link to the applicable
privacy policy). Only after consent is given does it write to the
browser's localStorage:
cbnm_consent_*(the consent record with a timestamp) andcbnm_session_*(the conversation session identifier, expiring after 30 minutes of inactivity). Nothing is written to the device and neither chat nor call starts without consent. The Customer must list these items in their own cookie/storage policy; - Validity of consent: consent given lasts 12 months. After that the widget asks again;
- Withdrawal of consent (art. 7(3) GDPR): a permanent "Withdraw consent" link is available in the widget footer. Clicking it immediately erases the consent record, the session identifier and the conversation in progress from the device, ends any call in progress and returns the widget to the consent screen — withdrawal is therefore as easy as giving consent. Withdrawal does not affect the lawfulness of processing carried out beforehand and does not replace the right to erasure under art. 17 GDPR, which the End User exercises with the Customer as controller;
- The Customer remains responsible for their own cookie consent banner covering any other tracking technologies on their site.
d) DPA with the Controller:
- Conclude a Data Processing Agreement with the Controller under art. 28 GDPR.
e) Responding to data subject requests:
- Where an End User exercises their rights against the Customer (access, erasure, portability), the Customer is the primary point of contact. The Controller will assist, on the Customer's instructions, in locating, rectifying or erasing the relevant data.
14. Changes to This Privacy Policy
The Controller reserves the right to update this Policy. We will inform about material changes by:
- Publishing the updated Policy on the website;
- Emailing Customers if the changes significantly affect data processing.
We recommend regularly checking this page for current information.
15. Contact
If you have any questions regarding personal data protection, please contact us:
Blue Yasuo Consulting, s. r. o. Email: blueyasuoconsulting@gmail.com Phone: +421 902 638 008 Address: Romanova 1678/33, 851 02 Bratislava — Petržalka, Slovak Republic
This Privacy Policy is drawn up in the Slovak and English languages. In case of any discrepancy between the language versions, the Slovak version shall prevail.