Back to homepage
This English text is provided for your convenience. The binding version of this document is the Slovak original published by Blue Yasuo Consulting, s. r. o. at chatbotnamieru.sk. In case of any discrepancy, the Slovak version prevails.

PRIVACY POLICY

Blue Yasuo Consulting, s. r. o.

Company ID (IČO): 53199341 Tax ID (DIČ): 2121301556 Registered office: Romanova 1678/33, 851 02 Bratislava — Petržalka, Slovak Republic Email: blueyasuoconsulting@gmail.com Phone: +421 902 638 008 Website: aichatbotforweb.com

(hereinafter referred to as the "Controller")

Effective date: 18 July 2026 Last updated: 3 August 2026


1. Introduction

This Privacy Policy (hereinafter "Policy") informs data subjects about how the Controller collects, processes, stores, and protects personal data in connection with providing custom chatbot development and operation services (hereinafter the "Service").

This Policy has been prepared in accordance with:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter "GDPR");
  • Act No. 18/2018 Coll. on Personal Data Protection as amended.

2. Categories of Data Subjects

The Controller processes personal data of the following categories of data subjects:

2.1 Customers (B2B)

Entrepreneurs and representatives of legal entities who order the Service.

2.2 Consumers (B2C)

Natural persons — non-entrepreneurs who order the Service.

2.3 End Users of Chatbots

Persons who interact with chatbots deployed for the Controller's Customers.

2.4 Website Visitors

Persons who visit the Controller's website.


3. What Personal Data We Process

3.1 Customer Data

Data CategoryExamples
Identification dataName, surname, company name, Company ID, Tax ID
Contact dataEmail, phone number, registered office address
Billing dataBank account, billing address
Contractual dataCommunication content, chatbot requirements
Account dataEmail address, password (stored only as a cryptographic hash — never in readable form), account creation date, last sign-in
Usage dataNumber of messages used in the current period, the chatbot's configuration and uploaded documents, conversation history in your account

3.2 End User Data (Chatbot Users)

Data CategoryExamples
Conversational dataContent of chat messages with the chatbot
Technical dataIP address, browser type, operating system
Identification data (if collected)Name, email — only if the chatbot actively collects these data based on Customer configuration

Important: The scope of end user data depends on the specific chatbot configuration per the Customer's requirements. The Controller only processes data necessary for the chatbot's operation.

3.3 Website Visitor Data

Data CategoryExamples
Technical dataIP address, browser type, screen resolution
CookiesFunctional and analytical cookies (see Section 10)

4. Purposes and Legal Bases for Processing

PurposeLegal Basis (GDPR)Data Categories
Entering into and performing a contractArt. 6(1)(b) — performance of a contractIdentification, contact, billing, contractual
Creating and operating your user account (including the free plan)Art. 6(1)(b) — performance of a contractAccount data
Measuring your plan's message allowance and enforcing its limitsArt. 6(1)(b) — performance of a contractAccount data, usage data
Providing the chatbot serviceArt. 6(1)(b) — performance of a contract / Art. 6(1)(f) — legitimate interestConversational, technical data
Invoicing and accountingArt. 6(1)(c) — legal obligation (Accounting Act, VAT Act)Billing data
Improving service qualityArt. 6(1)(f) — legitimate interestConversational data (anonymized), technical data
Ensuring securityArt. 6(1)(f) — legitimate interestTechnical data, IP addresses
Marketing and commercial communicationArt. 6(1)(a) — consentContact data (email)
Fulfilling legal obligationsArt. 6(1)(c) — legal obligationDepending on the specific obligation

Legitimate interest: Where the Controller relies on legitimate interest, a balancing test has been conducted, concluding that the Controller's legitimate interests do not override the rights and interests of data subjects. Data subjects have the right to object to processing based on legitimate interest at any time.


5. Recipients and Processors

The Controller may share personal data with the following categories of recipients:

5.1 Processors (Sub-processors)

CompanyPurposeHeadquartersData Location
OpenAI, LLCProcessing conversations through the AI model (GPT)San Francisco, USAUSA
Supabase, Inc.Database — data storageSan Francisco, USAEU (Stockholm, Sweden)
Hostinger International Ltd.VPS hosting — website and chatbot operationKaunas, LithuaniaEU (Frankfurt, Germany)

5.2 Other Recipients

  • Accounting firm — processing of invoicing and accounting documents;
  • Public authorities — where required by law (e.g., tax office, courts);
  • Legal advisors — in the event of dispute resolution.

The Controller does not sell personal data to third parties for marketing purposes.


6. Transfer of Personal Data to Third Countries

6.1 OpenAI (USA)

When processing chatbot conversations, data is transferred to the servers of OpenAI, LLC in the USA. This transfer is safeguarded on the basis of:

  • Standard Contractual Clauses (SCC) pursuant to the European Commission Implementing Decision (EU) 2021/914; and/or
  • EU-US Data Privacy Framework (DPF) pursuant to the European Commission's adequacy decision of July 10, 2023, provided that OpenAI is certified under the DPF.

6.2 Supplementary Safeguards

  • Encryption of data in transit (TLS 1.2+);
  • Data minimization — the chatbot only sends the conversation content necessary for generating a response;
  • Under its terms (API Data Usage Policy), OpenAI does not use data submitted via the API to train its models.

6.3 Other Providers

Supabase (database in Stockholm) and Hostinger (VPS in Frankfurt) store data within the EU/EEA — no transfer to third countries occurs.


7. Data Retention Periods

Data CategoryRetention Period
Contractual and billing data10 years from contract termination (Accounting Act)
Chatbot conversational data12 months from creation, unless the Customer specifies otherwise
End User consent given in the widget12 months from the moment it is given; the widget then asks again
Technical data (logs, IP addresses)6 months
Marketing consentsUntil consent is withdrawn
Data for legitimate interestUntil objection is raised or legitimate interest ceases

After the retention period expires, personal data is deleted or anonymized.

Upon termination of the contract with a Customer, End User data from their chatbot is deleted within 90 days, unless legal regulations require a longer retention period.


8. Rights of Data Subjects

Under the GDPR, you have the following rights:

8.1 Right of Access (Art. 15 GDPR)

You have the right to obtain confirmation as to whether your personal data is being processed and, if so, to access the data and information about the processing.

8.2 Right to Rectification (Art. 16 GDPR)

You have the right to have inaccurate personal data corrected and incomplete data completed.

8.3 Right to Erasure — "Right to Be Forgotten" (Art. 17 GDPR)

You have the right to request the erasure of your personal data if:

  • The data is no longer necessary for the purpose for which it was collected;
  • You withdraw consent and there is no other legal basis;
  • You object to processing and there are no overriding legitimate grounds;
  • The data has been unlawfully processed.

8.4 Right to Restriction of Processing (Art. 18 GDPR)

You have the right to request restriction of processing in certain cases (e.g., if you contest the accuracy of the data).

8.5 Right to Data Portability (Art. 20 GDPR)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transfer it to another controller.

8.6 Right to Object (Art. 21 GDPR)

You have the right to object to processing based on legitimate interest. The Controller will cease processing unless it demonstrates compelling legitimate grounds.

8.7 Right to Withdraw Consent (Art. 7(3) GDPR)

Where processing is based on consent, you have the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing prior to its withdrawal.

8.8 Right to Lodge a Complaint

You have the right to lodge a complaint with the supervisory authority:

Office for Personal Data Protection of the Slovak Republic Hraničná 12, 820 07 Bratislava 27 Phone: +421 2 3231 3214 Email: statny.dozor@pdp.gov.sk Website: https://dataprotection.gov.sk

How to Exercise Your Rights

You may exercise your rights by sending a request to: blueyasuoconsulting@gmail.com. We will process your request without undue delay, within 30 days of receipt at the latest. In justified cases, this period may be extended by an additional 60 days, of which you will be informed.


9. Automated Decision-Making and Profiling

Chatbots operated by the Controller use artificial intelligence technology (specifically GPT language models from OpenAI) to generate responses.

Important notice:

  • Chatbot responses are automatically generated by an artificial intelligence algorithm;
  • The chatbot does not perform automated decision-making with legal effects or similarly significant impact on data subjects within the meaning of Art. 22 GDPR;
  • The chatbot is not used for profiling data subjects;
  • Customers are required to inform End Users that they are communicating with an AI chatbot, not a live person.

10. Cookies and Tracking Technologies

10.1 Types of Cookies

TypePurposeLegal Basis
Essential cookiesEnsuring basic website and chatbot functionalityLegitimate interest
Analytical cookiesTraffic and service usage analysisConsent
Marketing cookiesAd personalization (if used)Consent

10.2 Cookie Management

Upon your first visit to the website, an information banner (cookie bar) will be displayed, through which you can grant or refuse consent for non-essential cookies. You can change your cookie settings at any time through the website settings.


11. Security Measures

The Controller has implemented appropriate technical and organizational measures to protect personal data, including:

  • Data encryption in transit (TLS/SSL);
  • Data encryption at rest;
  • Access controls and authentication;
  • Regular data backups;
  • Restricting access to personal data to authorized employees/contractors only;
  • Access monitoring and logging;
  • Regular software and security patch updates.

12. Personal Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, the Controller shall:

  • Notify the Office for Personal Data Protection of the Slovak Republic within 72 hours of becoming aware of the breach;
  • If the breach is likely to result in a high risk to data subjects' rights, promptly inform the affected data subjects as well.

13. Processing Data on Behalf of the Customer (Controller vs. Processor)

13.1 When We Act as Controller

The Controller acts as a data controller when processing:

  • Data of its Customers (B2B and B2C) for the purpose of contract performance;
  • Data of visitors to its own website;
  • Data for its own marketing purposes.

13.2 When We Act as Processor

The Controller acts as a data processor when processing:

  • Personal data of End Users of chatbots deployed for B2B Customers.

In such cases, the Customer is the data controller and the Controller processes data solely under the Customer's instructions pursuant to a Data Processing Agreement (DPA).

13.3 Customer Obligations When Embedding the Chatbot Widget

A Customer who installs the chatbot widget on their website acts as the data controller towards End Users and is required in particular to:

a) Transparency towards End Users (art. 13/14 GDPR):

  • Clearly inform visitors of their website that an AI chatbot is running on it, not a human operator;
  • Publish their own privacy policy covering the processing carried out through the chatbot widget, with a reference to this Policy of the Controller (as processor);
  • Enter the address of that policy in the widget settings (Dashboard → Widget → Link to your privacy policy). The consent screen and the widget footer then link to the Customer's document — they are the controller towards End Users. If the field is left empty the widget links to this Policy, which is a fallback only and does not discharge the Customer's own duty to inform under art. 13 GDPR;
  • Inform End Users that conversations are processed through an AI model provided by OpenAI (USA) and that a transfer to a third country takes place, safeguarded by SCC/DPF.

b) Legal basis:

  • Determine their own legal basis under art. 6 GDPR (typically consent or legitimate interest) for processing End User messages;
  • Where the chatbot actively collects contact details (name, email, phone), ensure valid consent under art. 7 GDPR or another legal basis.

c) Consent to storing data on the device (art. 5 ePrivacy Directive):

  • Before first use, the widget shows the End User a consent screen (information about the AI assistant, processing through OpenAI/USA, link to the applicable privacy policy). Only after consent is given does it write to the browser's localStorage: cbnm_consent_* (the consent record with a timestamp) and cbnm_session_* (the conversation session identifier, expiring after 30 minutes of inactivity). Nothing is written to the device and neither chat nor call starts without consent. The Customer must list these items in their own cookie/storage policy;
  • Validity of consent: consent given lasts 12 months. After that the widget asks again;
  • Withdrawal of consent (art. 7(3) GDPR): a permanent "Withdraw consent" link is available in the widget footer. Clicking it immediately erases the consent record, the session identifier and the conversation in progress from the device, ends any call in progress and returns the widget to the consent screen — withdrawal is therefore as easy as giving consent. Withdrawal does not affect the lawfulness of processing carried out beforehand and does not replace the right to erasure under art. 17 GDPR, which the End User exercises with the Customer as controller;
  • The Customer remains responsible for their own cookie consent banner covering any other tracking technologies on their site.

d) DPA with the Controller:

  • Conclude a Data Processing Agreement with the Controller under art. 28 GDPR.

e) Responding to data subject requests:

  • Where an End User exercises their rights against the Customer (access, erasure, portability), the Customer is the primary point of contact. The Controller will assist, on the Customer's instructions, in locating, rectifying or erasing the relevant data.

14. Changes to This Privacy Policy

The Controller reserves the right to update this Policy. We will inform about material changes by:

  • Publishing the updated Policy on the website;
  • Emailing Customers if the changes significantly affect data processing.

We recommend regularly checking this page for current information.


15. Contact

If you have any questions regarding personal data protection, please contact us:

Blue Yasuo Consulting, s. r. o. Email: blueyasuoconsulting@gmail.com Phone: +421 902 638 008 Address: Romanova 1678/33, 851 02 Bratislava — Petržalka, Slovak Republic


This Privacy Policy is drawn up in the Slovak and English languages. In case of any discrepancy between the language versions, the Slovak version shall prevail.