Privacy Policy
Effective date: 1 October 2025
Who we are: DatBot Technologies (“DatBots”, “we”, “our”, “us”)
Website & services: datbots.com and related pages, apps, and offerings (the “Services”).
We collect the minimum necessary data to run our Services, keep it secure, and never sell your personal information. When we use AI providers, your inputs/outputs are processed only to deliver the feature; we configure providers to not use your data for training where controls exist.
1) Scope
This Policy explains how we collect, use, disclose, and protect personal information when you use our Services, contact us, or interact with our content (e.g., newsletters, courses, demos, workshops).
2) The data we collect
A. You provide directly
-
Account/contact: name, email, company, role, billing details, phone (optional).
-
Content you submit: messages, files, forms, feedback, support requests.
B. Collected automatically
-
Usage and device data: IP address, browser type, OS, pages viewed, time on page, referring URLs, general geolocation, error logs.
-
Cookies and similar tech: session cookies (essential), analytics cookies ([ANALYTICS PROVIDER e.g., GA4/Matomo]), preference cookies. See Section 10 (Cookies).
C. From third parties
-
Business partners and platforms (e.g., webinar hosts, newsletter providers).
-
Public sources (professional profiles, company websites).
Sensitive information: We do not require sensitive personal information. Please don’t include it in prompts, uploads, or support requests.
3) How we use data (purposes & legal bases)
-
Provide, operate, and improve the Services (performance of contract / legitimate interests).
-
Respond to inquiries and provide support (contract / legitimate interests).
-
Fraud prevention, security, debugging (legitimate interests / legal obligation).
-
Analytics, research, and product development (legitimate interests; consent where required).
-
Marketing communications with your consent (you can opt out anytime).
-
Compliance with laws, enforcing terms, protecting rights (legal obligation/legitimate interests).
GDPR/UK GDPR legal bases: consent, performance of a contract, legitimate interests, and legal obligations—as applicable per activity.
4) AI features & your data
Some features may leverage third-party AI models (e.g., [MODEL PROVIDER: OpenAI / Google / Anthropic / etc.]).
-
Processing: Prompts, instructions, and outputs are sent to AI providers solely to generate results you request.
-
Training: We configure providers not to use your data for training where such controls are offered.
-
Minimize PII: Don’t include personal or confidential information in prompts unless necessary; redact where possible.
-
Retention: We retain AI interaction logs only as long as needed for troubleshooting and audit ([RETENTION WINDOW, e.g., 30–90 days]), then delete/anonymize.
-
Vendors: See Section 6 for categories of vendors.
5) How we share information
We do not sell personal information. We may share with:
-
Service providers / processors: hosting, analytics, email, customer support, payment, AI model providers, logging/monitoring. These providers may process data on our behalf under contracts that include confidentiality and security obligations.
-
Professional advisors: lawyers, accountants, auditors.
-
Business transfers: in a merger, acquisition, or similar event, subject to this Policy.
-
Legal & safety: where required to comply with law or protect rights, security, or safety.
6) International transfers
We may transfer and store data outside your country (e.g., Japan, the EU, the US). We use appropriate safeguards for cross-border transfers (e.g., Standard Contractual Clauses for GDPR/UK GDPR) and ensure vendors meet comparable protections.
7) Data retention
We retain personal data only as long as needed for the purpose collected:
-
Account, billing, and transaction records: [7 years] (tax/legal).
-
Support and communications: [24 months].
-
Analytics & logs: [12 months] (aggregated/anonymized thereafter).
-
AI logs: see Section 4.
When no longer needed, we delete or irreversibly anonymize data.
8) Your rights
Under Japan’s APPI: request disclosure, correction, addition, deletion, use-suspension, or third-party-provision-suspension of retained personal data, subject to law.
Under GDPR/UK GDPR (if applicable): access, rectification, erasure, restriction, portability, and objection; right to withdraw consent; right to lodge a complaint with a supervisory authority.
California (CCPA/CPRA) Notice: We do not “sell” or “share” personal information as defined by CPRA. California residents can request access, deletion, and correction, and can limit use of sensitive information (if collected). To exercise rights, see Section 9.
Notice at Collection: We collect the categories described in Sections 2–3 for the purposes in Section 3. We don’t sell/share personal information; retention is described in Section 7.
9) How to exercise your rights
Submit a request to [PRIVACY REQUEST EMAIL]. We may need to verify your identity (and authority, if applicable). We’ll respond within the timeframe required by law. If we decline a request, we’ll explain why (unless prohibited by law).
10) Cookies & tracking
-
Essential cookies (strictly necessary): site security, session management.
-
Analytics cookies: usage metrics to improve the Services
-
Preferences: remember settings like language.
Your choices: Manage cookies via your browser settings or our [Cookie Preferences] banner. Some features may not function without essential cookies. We don’t respond to “Do Not Track” signals due to lack of standardization.
11) Security
We use administrative, technical, and physical safeguards (e.g., encryption in transit, access controls, least-privilege, logging). No system is 100% secure; please use strong passwords and avoid sending sensitive data in plain text.
12) Children’s privacy
Our Services are not directed to children under 13 (or higher age where required). We do not knowingly collect personal information from children. If you believe a child provided personal data, contact us to delete it.
13) Third-party links
Our Services may link to third-party sites or services. Their privacy practices are governed by their own policies.
14) Changes to this Policy
We may update this Policy from time to time. The “Effective date” above reflects the latest version. Material changes will be highlighted on the site or via email where appropriate.