Privacy Policy
Paskutinis redagavimas: 2026-08-21
Informational translation. The binding version of this document is the Lithuanian one. If the two ever differ, the Lithuanian text prevails — see the language clause in §14 of the Terms. Read the Lithuanian original.
This policy explains how Klizai MB processes personal data in providing the SmartChat service. It covers two distinct roles — see section 1, because who you should contact about your data depends on which one applies.
1. Who the data controller is
Klizai MB, company code 307582652, VAT number LT100020601019, registered office Melioratorių g. 7, Šventupės k., LT-20362 Ukmergės r., Lithuania. Contact for data matters: hello@smartchat.lt.
Klizai MB has not appointed a Data Protection Officer and considers that Art. 37 GDPR does not require one. All data questions are answered at the address above.
Two roles that should not be confused:
- Customer (store) account data. Here Klizai MB is the controller. We decide why and how it is processed: registration, billing, support.
- Conversation data from store visitors. Here Klizai MB is only a processor. The controller is the store that installed the chat window, and we process that data solely on its instructions. If you are a store visitor and want to exercise your rights, contact the store whose website you were chatting on. The contractual terms for this role are in the DPA.
2. What data we collect
2.1. Customer account (controller — Klizai MB). Email address and a cryptographic hash of the password (handled by Supabase Auth), the store domain, the subscription plan and status, and billing details through Stripe. We neither store nor see the card number — Stripe handles it.
2.2. Conversations with the chat window (processor — the store is the controller). The following data is processed:
- Conversation messages — everything a visitor types and the AI’s replies (
messages.content). If a visitor types personal data into the chat window, it is stored. - visitor_id — a random identifier generated in the browser and kept in
localStorage. It is not linked to your name and does not travel between sites, but it lets conversations by the same visitor in the same store be linked. - Technical metadata — the page address where the conversation started (
source_url), the browseruser_agent, the conversation language, timestamps. - Contact details, where the visitor provides them — name, email, message (the
leadstable). Only when the visitor deliberately fills in a form. - visitor_email and email content — if the store enabled the email channel and the visitor writes in.
- Unanswered queries (
knowledge_gaps) — the text of the question is stored when the AI finds no answer, so the store can extend its knowledge base. That text may contain the visitor’s own words.
2.3. IP address. The IP is used for request rate limiting (abuse protection) through Upstash Redis. It is not written to the conversation tables in our database.
2.4. What we do not collect. The SmartChat site carries no Google Analytics, Meta Pixel, Hotjar or any other advertising or analytics tracker. We do not profile visitors for advertising and we do not sell data.
3. Why, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating an account and providing the service | Performance of a contract — Art. 6(1)(b) GDPR |
| Billing, accounting, retention of invoices | Legal obligation — Art. 6(1)(c) GDPR (Lithuanian accounting rules) |
| Processing conversations on the store’s behalf | The store (controller) determines the basis. We process on its instructions — Art. 28 GDPR. |
| System security, abuse prevention, rate limiting | Legitimate interest — Art. 6(1)(f) GDPR. The interest: protecting the service and its users from automated abuse and overload. |
| Error monitoring and keeping the service running | Legitimate interest — Art. 6(1)(f) GDPR. The interest: detecting and fixing faults so the service works as agreed. |
4. Whether providing data is required
Creating an account requires an email address and a store domain — without them we cannot conclude the contract or provide the service. Billing details are necessary to meet statutory accounting obligations.
Nothing has to be provided in the chat window. A visitor decides what to write; not providing contact details only means we cannot reply to that person individually.
Children. The service is aimed at adult business customers and is not directed at children. We do not knowingly collect data from anyone under 14 (the Art. 8 GDPR age threshold in Lithuania). If we learn that such data has ended up in a conversation record, we delete it.
5. How long we keep it
Precision matters here, because it is easy to promise more than the system does:
- Conversations and messages. Each store can set its own retention window in days; a nightly process at 03:00 deletes conversations outside it. By default no window is set, so conversations are kept indefinitely until the store sets one or deletes them. We do not call that compliance — it is a default the store ought to change.
- Leads. The automatic purge does not touch them — they are sales records the store manages itself. They stay until the store deletes them or an erasure request is carried out.
- Account data. Kept while the contract is in force. After a subscription is cancelled — a further 30 days, then deleted automatically.
- Accounting documents. Kept as long as Lithuanian law requires — 10 years.
6. Transfers and processors
The primary location of the data is the European Union — the database in Frankfurt (Supabase), application execution in Frankfurt (Vercel, region fra1), rate limiting in Ireland (Upstash), error monitoring in Frankfurt (Sentry EU region).
For accuracy: all conversation content is handled by a function running in Frankfurt. Before reaching it, a request passes through Vercel’s global edge network, which refreshes the signed-in customer’s session cookie and adds security headers. No conversation content is processed at that stage, but the session cookie may pass through a node outside the EU.
Transfers to the United States. To generate AI answers, conversation messages are sent to Anthropic (Claude), and to vectorise text, to OpenAI (text-embedding-3-small). Both companies are established in the United States, so conversation content leaves the EU/EEA, and this happens in every conversation rather than as an exception. This is a transfer to a third country under Chapter V GDPR. Its legal basis is the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914, which form part of each provider’s data processing agreement; because SmartChat itself acts as a processor, Module 3 (processor to processor) applies. We do not rely on EU–US Data Privacy Framework certification. You may obtain a copy of the standard contractual clauses by writing to hello@smartchat.lt — that is your right under Art. 13(1)(f) GDPR.
The full list of processors with locations and transfer bases is at /en/subprocessors.
Model training. Neither Anthropic nor OpenAI uses content sent through the API to train their models. Section B of Anthropic’s commercial terms states that Anthropic may not train models on customer content (anthropic.com/legal/commercial-terms), and OpenAI’s API documentation states that data sent through the API is not used to train or improve models unless the customer explicitly opts in; that has applied since 1 March 2023 (developers.openai.com/api/docs/guides/your-data). For abuse monitoring OpenAI retains content for up to 30 days. Provider terms verified on 2026-08-20.
8. Your rights
Under the GDPR you have the right to access your data (Art. 15), rectify it (Art. 16), erase it (Art. 17), restrict processing (Art. 18), port it (Art. 20) and object to processing (Art. 21).
Right to object. Where we process data on the basis of legitimate interest (system security, abuse prevention, error monitoring), you have the right to object at any time on grounds relating to your particular situation. On receiving an objection we stop the processing unless we demonstrate compelling legitimate grounds that override your interests.
Consent. No processing is currently based on your consent — the legal bases are listed in section 3, and this site uses only strictly necessary cookies, for which consent is not required. There is therefore no consent to withdraw. If processing based on consent is introduced in future, it will be as easy to withdraw as to give, and withdrawal will not affect the lawfulness of processing carried out beforehand.
Who to contact. If you are a store’s visitor, contact that store. It is the controller and we act on its instructions; when it comes to us, we have the tools to carry the request out. If you are our customer (an account holder), write directly to hello@smartchat.lt.
A technical limit worth knowing. The deletion and export tools identify a person by email address. If you chatted with the widget and never left an email, your conversation is linked only to a random visitor_id, so we cannot reliably single out your records by name — in that case you will need to provide the visitor_id or the context of the conversation.
For Shopify stores the mandatory Shopify GDPR webhooks (customers/redact, customers/data_request, shop/redact) are handled automatically.
You may lodge a complaint with the Lithuanian State Data Protection Inspectorate (L. Sapiegos g. 17, Vilnius, vdai.lrv.lt).
9. Automated decision-making
SmartChat generates answers automatically, but does not take decisions producing legal effects or similarly significantly affecting a person within the meaning of Art. 22 GDPR. The chatbot advises — it does not set prices, conclude contracts or reject orders on its own.
10. Security
We apply: tenant isolation at the database level (PostgreSQL Row Level Security), encryption in transit (TLS) and at rest, application-level encryption of sensitive access tokens (Shopify, WordPress, Gmail), request rate limiting, and restricted database access. No measure offers an absolute guarantee.
11. Changes to this policy
We notify customers of material changes by email or in the account at least 30 days before they take effect.