Privacy Policy for 5chat
Last Updated: 06/06/2025
This Privacy Policy is effective as of 06/06/2025.
1. Introduction
Welcome to 5chat (hereinafter referred to as "5chat," "we," "us," or "our"). We are committed to protecting the privacy of individuals who interact with our services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our SaaS platform and our live chat widget (collectively, the "Services").
This policy applies to our Customers (website owners who install our widget) and, indirectly, to the End-Users (visitors to our Customers' websites who interact with the 5chat widget). Please read this Privacy Policy carefully. If you do not agree with the terms of this privacy policy, please do not access or use our Services.
We respect your privacy and comply with applicable data protection laws, including the General Data Protection Regulation (GDPR) where applicable.
2. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person.
- Customer: The website owner or entity that installs and uses the 5chat live chat widget and SaaS platform.
- End-User: A visitor to a Customer's website who interacts with the 5chat live chat widget.
- Controller: The entity that determines the purposes and means of processing Personal Data.
- Processor: The entity that processes Personal Data on behalf of the Controller.
- Services: The 5chat SaaS platform and the 5chat live chat widget.
- Processing: Any operation or set of operations performed on Personal Data, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
3. Our Roles Under Data Protection Laws
Understanding our role is important for understanding how your data is handled:
- 5chat as Data Controller: When we collect and process Personal Data directly from our Customers (e.g., account registration, billing information, platform usage data for our own service improvement), 5chat acts as the Data Controller.
- 5chat as Data Processor: When End-Users interact with the 5chat live chat widget embedded on our Customer's website, our Customer is the Data Controller for the Personal Data collected from those End-Users. In this scenario, 5chat acts as a Data Processor, processing End-User data solely on behalf of and in accordance with the instructions of our Customer, as stipulated in our Data Processing Agreement (DPA).
We collect different types of information depending on your interaction with our Services.
4.1. Information Collected from Our Customers (5chat as Controller)
When you, as a Customer, register for and use our Services, we may collect the following Personal Data:
- Account and Registration Information: Name, email address.
- Website Details: Website URL, website name, website logo.
- Automatically Collected Information:
- Cookies for Functionality: We use first-party cookies for essential functionalities such as authentication and the creation and maintenance of your account.
- First-Party Analytics: We use first-party analytics (Matomo) to understand how you use our platform, which helps us improve our Services. This may include IP address, device type, browser type, pages visited on our platform, and referring URL.
- Payment Information: to handle payment information. We do not store your full credit card details."]
- Communications: Records of your communications with us, such as support requests or feedback.
4.2. Information Collected from End-Users via the 5chat Widget (5chat as Processor)
When an End-User interacts with the 5chat widget on our Customer's website, we process the following Personal Data on behalf of our Customer:
- Information Voluntarily Provided by End-Users: Any information End-Users voluntarily provide in the chat, such as their name, email address, phone number, and the content of their messages.
- Information Collected Automatically:
- IP address, device type, browser type, operating system, pages visited on the Customer's website, referring URL.
- Cookies for Identification: We use first-party cookies to identify the End-User via their Visitor ID on the Customer's website. This helps in maintaining chat continuity and providing a consistent experience.
- Information Passed via API: We may collect additional information about End-Users if our Customer (the website owner) passes this information to us via our API, in accordance with their own privacy policies and legal basis for collection.
Our Customers are responsible for informing their End-Users about the data collection practices of the 5chat widget on their websites and for obtaining any necessary consents.
4.3. Sensitive Personal Information
We do not knowingly collect sensitive personal information (e.g., health information, financial details beyond payment for our service) from our Customers or through the widget from End-Users.
The way we use information depends on whether we are acting as a Controller or a Processor.
5.1. Use of Customer Information (5chat as Controller)
We use the Personal Data collected from our Customers for the following purposes:
- To Provide and Maintain the Service: To create and manage your account, provide access to our platform, and ensure the functionality of our Services.
- For Billing and Account Management: To process payments, send invoices, and manage your subscription.
- To Send Service-Related Communications: To inform you about service updates, security alerts, and other administrative messages.
- For Marketing Our Own Services: To inform you about new features, products, or promotions related to 5chat Services, in accordance with your communication preferences and applicable law. You can opt-out of these communications.
- For Analytics and Service Improvement: To analyze trends, monitor usage of our platform, and improve the functionality and user experience of our Services (using our first-party Matomo analytics).
5.2. Use of End-User Information (5chat as Processor)
We use the Personal Data collected from End-Users via the 5chat widget solely on behalf of and as instructed by our Customers (the Data Controllers). These purposes typically include:
- To Facilitate the Chat: To enable real-time communication between the End-User and our Customer (the website owner).
- To Provide "Visitor Insights": To provide our Customers with analytics and insights about End-User interactions on their website through the chat widget, as configured by the Customer.
- For Analytics and Service Improvement (for the Customer): To help our Customers analyze trends and improve their own services and the End-User experience on their website. Any analytics or improvements to the 5chat widget itself using aggregated and anonymized End-User data will be done in a way that does not identify individuals and will be subject to the terms of our DPA with the Customer.
5chat does not use End-User Personal Data collected via the widget for its own independent purposes, such as marketing its services to End-Users, unless explicitly instructed or permitted by the Customer and allowed under applicable law.
6. Legal Basis for Processing Personal Data (GDPR)
If you are located in the European Economic Area (EEA), UK, or Switzerland, our legal basis for collecting and using the Personal Data described above will depend on the Personal Data concerned and the specific context in which we collect it.
6.1. For Customer Data (5chat as Controller)
We process Personal Data from our Customers based on one or more of the following legal bases:
- Performance of a Contract: When processing is necessary to provide the Services you have requested, manage your account, and fulfill our contractual obligations (e.g., Article 6(1)(b) GDPR).
- Legitimate Interests: When processing is necessary for our legitimate interests, such as improving our Services, marketing our services to you, ensuring security, or for administrative purposes, provided these interests are not overridden by your data protection interests or fundamental rights and freedoms (e.g., Article 6(1)(f) GDPR).
- Consent: For certain processing activities, such as sending non-essential marketing communications, we will rely on your explicit consent (e.g., Article 6(1)(a) GDPR). You have the right to withdraw your consent at any time.
- Legal Obligation: When processing is necessary for compliance with a legal obligation to which we are subject (e.g., Article 6(1)(c) GDPR).
6.2. For End-User Data (5chat as Processor)
When we process Personal Data from End-Users via the 5chat widget, we do so as a Data Processor on behalf of our Customer (the Data Controller). Our Customers are solely responsible for establishing and documenting a lawful basis for the collection and processing of End-User Personal Data (e.g., consent from the End-User, legitimate interest of the Customer). Our processing is governed by the Data Processing Agreement (DPA) with our Customer and their lawful instructions.
7. Sharing and Disclosure of Information
We do not sell your Personal Data. We may share or disclose Personal Data in the following circumstances:
8. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to operate and improve our Services. A cookie is a small text file stored on your device.
8.1. Cookies Used by 5chat's Website and Platform (for Customers)
- First-Party Functionality Cookies: We use these cookies for essential functions such as authenticating you when you log in, remembering your preferences, and managing your account session. These are necessary for the operation of our platform.
- First-Party Analytics Cookies (Matomo): We use Matomo analytics cookies to collect information about how you interact with our website and platform. This helps us understand usage patterns and improve our Services. The data collected is processed by us and is not shared with third-party analytics providers for their own use.
8.2. Cookies Used by the 5chat Live Chat Widget (for End-Users on Customer Websites)
- First-Party Identification Cookies: The 5chat widget uses first-party cookies (set on the Customer's domain) to identify an End-User via their unique Visitor ID. This cookie is essential for the widget's functionality, such as maintaining chat continuity across pages or visits on the Customer's website.
The specific cookies used, their purpose, and duration are detailed in our Cookie Policy: [Link to Cookie Policy].
8.3. Your Choices Regarding Cookies
- For 5chat Customers: You can manage your cookie preferences for our website and platform through your browser settings or through the cookie consent banner presented on our website. Please note that disabling essential functionality cookies may affect your ability to use our platform.
- For End-Users: The 5chat widget's cookies are deployed on our Customer's website. Our Customers (the website owners) are responsible for obtaining valid consent from End-Users for any non-essential cookies set by the 5chat widget on their websites, in compliance with GDPR, the ePrivacy Directive, and other applicable laws. We provide our Customers with information about the cookies our widget uses to help them meet their transparency and consent obligations. End-Users should refer to the cookie policy of the specific website they are visiting to manage their cookie preferences for that site.
9. Data Retention and Security
9.1. Data Retention
We retain Personal Data for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable laws or contractual obligations.
- Customer Data: We store Customer Personal Data as long as the Customer is registered with our Services. Customers have the right to request the deletion of their account and their information. Upon such a request, we will delete or anonymize their Personal Data in accordance with applicable law, unless we have a legal obligation or a legitimate interest to retain it for a longer period (e.g., for billing records, dispute resolution).
- End-User Data (Visitor ID): We store the Visitor ID collected via the widget for one year from its creation. Other End-User data (like chat transcripts) processed on behalf of our Customers is retained according to the instructions of the Customer, as detailed in our DPA. Customers may have options to configure retention periods for their End-User data within our platform [if applicable, otherwise remove this part].
9.2. Data Security
We implement appropriate technical and organizational security measures designed to protect the security of any Personal Data we process. These measures aim to prevent unauthorized access, disclosure, alteration, or destruction of Personal Data.
The security measures we have in place include:
- Encryption of data in transit (e.g., using HTTPS/TLS).
- Encryption of sensitive information at rest, such as passwords and device IDs.
- Access controls within our organization to limit access to Personal Data to authorized personnel on a need-to-know basis.
However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure. Therefore, we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Transmission of Personal Data to and from our Services is at your own risk.
10. User Rights and Choices
Under applicable data protection laws (such as GDPR), you have certain rights regarding your Personal Data.
10.1. Rights of Our Customers (5chat as Controller)
As a Customer of 5chat, you have the following rights concerning your Personal Data that we control:
- Right to Access: You can request access to the Personal Data we hold about you.
- Right to Rectification: You can request correction of inaccurate or incomplete Personal Data.
- Right to Erasure (Right to be Forgotten): You can request the deletion of your Personal Data, subject to certain legal limitations. You can request deletion of your account and associated information.
- Right to Restrict Processing: You can request that we restrict the processing of your Personal Data under certain conditions.
- Right to Data Portability: You can request to receive your Personal Data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.
- Right to Object: You can object to the processing of your Personal Data based on our legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: If we process your Personal Data based on your consent, you can withdraw your consent at any time.
To exercise these rights, please contact us via email at [email protected]. We will respond to your request in accordance with applicable data protection laws.
Opt-out of Marketing Communications: You can opt-out of receiving marketing communications from us by using the "unsubscribe" link in the emails we send or by changing your preferences in your account settings via a checkbox.
10.2. Rights of End-Users (5chat as Processor)
If you are an End-User who has interacted with the 5chat widget on one of our Customer's websites, our Customer is the Data Controller for your Personal Data. Therefore, to exercise your rights (such as access, correction, deletion, etc.) regarding the data collected through the chat widget, you should direct your request to the owner of the website you interacted with.
5chat is responsible for the data as we store it. We are committed to assisting our Customers in fulfilling Data Subject Requests from End-Users in accordance with our Data Processing Agreement and applicable law. End-Users may also contact us at [email protected] with their request, and we will forward it to the relevant Customer (the Data Controller) or assist as appropriate and legally permissible.
10.3. Opt-out of Data Collection (General)
Customers can manage their data and opt-out of certain data collection or marketing communications through their user settings via a checkbox.
End-Users wishing to opt-out of data collection via the chat widget should refer to the privacy and cookie policies of the website they are visiting for instructions on how to manage their preferences for that specific site.
11. International Data Transfers
Your Personal Data may be stored and processed in any country where we have facilities or in which we engage service providers.
- Data Storage and Processing Location: Your data is stored and processed on our servers. We do not share this data with anyone beyond what is outlined in the "Sharing and Disclosure of Information" section. "].
- International Transfers: We do not share data internationally beyond the necessary processing by our sub-processors as detailed in our sub-processor list and DPA. except as may be necessary for the provision of services by our sub-processors, which is governed by appropriate data transfer mechanisms as required by law."]. Based on your input "Data not shared internationally," this section reflects that.
12. Children's Privacy
Our Services are not directed to children under the age of 13 (or a different age depending on the jurisdiction, such as 16 in the EEA unless a Member State provides for a lower age, but not below 13).
- We do not knowingly collect Personal Data from children.
- If you are a parent or guardian and believe that your child has provided us with Personal Data without your consent, please contact us at [email protected]. If we become aware that we have collected Personal Data from a child in violation of applicable law, we will take steps to delete that information as soon as possible.
Our Customers are responsible for ensuring their use of the 5chat widget on their websites complies with all applicable children's privacy laws, including obtaining verifiable parental consent if their website is directed to children and collects Personal Data from them.
13. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. The "Last Updated" date at the top of this policy indicates when it was last revised.
We will notify you of any material changes to this Privacy Policy via email communication to our Customers. We encourage you to periodically review this Privacy Policy to stay informed about how we are protecting your information.
If you have any questions, concerns, or complaints about this Privacy Policy, our data practices, or if you wish to exercise your rights regarding your Personal Data, please contact us:
5chat
Attn: Privacy Officer / Data Protection Officer
Email: [email protected]
Phone: +48 793 450 637
If you have appointed a Data Protection Officer (DPO), their contact details are: