Effective Date: 1st January, 2024 · Version 1.0
This Privacy Policy ("Policy") describes how Cybersharp Technology LLP, a limited liability partnership incorporated under the laws of India, trading as Chatzy AI ("Chatzy", "we", "us", or "our"), collects, uses, discloses, retains, and protects personal data in connection with its AI-powered Software-as-a-Service platform and all associated services, products, APIs, and tools (collectively, the "Services"), accessible at https://www.chatzy.ai.
By accessing or using the Services, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree with this Policy, you must not use the Services.
This Policy may be updated at any time without prior notice. Updates take effect immediately upon publication at https://www.chatzy.ai/privacy-policy. Continued use of the Services constitutes acceptance of the updated Policy. It is your responsibility to review this Policy periodically.
For the purposes of applicable data protection law, including the Digital Personal Data Protection Act, 2023 (India) ("DPDPA") and the Information Technology Act, 2000 ("IT Act"), Chatzy acts as the Data Fiduciary / Data Controller in respect of personal data collected directly from Website Visitors and Users accessing the Services.
In the context of B2B deployments where a Customer uses the Services to process personal data of its own customers or end-users ("End-User Data"), Chatzy acts as a Data Processor / Data Principal's Consent Manager on behalf of the Customer, and the Customer acts as the Data Fiduciary / Data Controller. In such cases, the applicable Data Processing Agreement between Chatzy and the Customer governs the processing of End-User Data.
In this Policy, the following terms have the meanings set out below. Capitalised terms not defined here bear the meanings given in the applicable Governing Agreement.
When you create an account, subscribe to the Services, or contact us, we may collect:
When you access or use the Services, we automatically collect:
If you choose to register or log in using a third-party authentication service (such as Google SSO), we receive limited profile data from that service in accordance with your privacy settings on that service, including your name, email address, and profile picture. We do not receive your password for those services.
We use Cookies and similar tracking technologies within the Services and on our website. For detailed information about the Cookies we use, please refer to our In-Product Cookie Policy at https://www.chatzy.ai/cookie-policy.
We do not intentionally collect the following categories of sensitive personal data through the Services:
CUSTOMER RESPONSIBILITY: If you (as a Customer) submit any of the above sensitive categories of data to the Services as part of your Input, you do so at your own risk and in breach of the Platform Guidelines. Chatzy accepts no liability for the processing of sensitive data submitted without authorisation under a signed Data Processing Agreement.
Chatzy uses personal data for the following purposes:
| Purpose | Details |
|---|---|
| Service Delivery | To create and manage your account, provide access to the Services, process transactions, and fulfil our contractual obligations. |
| Authentication & Security | To verify your identity, maintain secure sessions, detect and prevent fraud, abuse, and unauthorised access. |
| Platform Improvement | To analyse usage patterns, diagnose errors, conduct A/B testing, and improve the performance, features, and reliability of the Services. |
| AI Model Operation | To process Inputs submitted to the Services and generate Outputs in response. Customer Input is not used to train Chatzy's shared AI models without explicit consent, except as set out in Section 5.1 below. |
| Customer Support | To respond to support requests, investigate complaints, and resolve disputes. |
| Communications | To send service notifications, product updates, security alerts, and (where you have opted in) marketing communications. |
| Legal & Compliance | To comply with applicable law, respond to lawful requests from authorities, enforce our Governing Agreements, and protect Chatzy's legal rights. |
| Business Transfers | In connection with a merger, acquisition, restructuring, or sale of assets, personal data may be transferred to the acquiring entity subject to equivalent privacy protections. |
Chatzy does not use Customer Input or End-User Data to train, fine-tune, or improve shared or publicly available AI models without the Customer's express prior written consent. Chatzy may use anonymised, aggregated, de-identified usage data for internal model improvement and platform optimisation purposes, provided that such data cannot reasonably be used to identify any individual. Where a Customer has expressly agreed to a model training arrangement in their Governing Agreement, the terms of that arrangement shall apply.
Chatzy does not sell, rent, or trade personal data to third parties for monetary or other consideration. Chatzy does not share personal data with advertisers or advertising networks for the purpose of serving targeted advertising.
Chatzy does not serve third-party advertising within the authenticated Services environment. The Services are an ad-free platform.
Chatzy processes personal data on the following legal bases under applicable Indian law (DPDPA, IT Act) and, where applicable to EU/EEA data subjects, under the GDPR:
Where Chatzy relies on legitimate interests as a legal basis, it has assessed that those interests are not overridden by the privacy rights of data subjects. You may request information about this assessment by contacting legal@chatzy.ai.
| Legal Basis | Processing Activities |
|---|---|
| Contractual Necessity | Processing necessary to provide the Services, manage your account, process payments, and fulfil Chatzy's obligations under the Governing Agreement. |
| Legitimate Interests | Platform security and fraud prevention; service improvement and analytics; communicating about product updates and security matters; enforcing Chatzy's legal rights. |
| Consent | Marketing communications (where you have opted in); use of non-essential Cookies; AI model training (where separately agreed). |
| Legal Obligation | Responding to lawful requests from courts, regulators, and law enforcement; compliance with tax, audit, and record-keeping obligations. |
| Vital Interests | Situations where processing is necessary to prevent serious harm to individuals (applicable in limited circumstances). |
Chatzy shares personal data with trusted third-party service providers who assist in delivering and operating the Services. These providers act as data processors under binding contractual data protection obligations and are only permitted to process personal data in accordance with Chatzy's instructions and for the specified purpose. See Section 8 for details of key third-party processors.
Chatzy may share personal data with its affiliates (entities under common control) for internal operational purposes. Affiliates are required to handle personal data in accordance with this Policy.
If Chatzy is involved in a merger, acquisition, asset sale, restructuring, or other corporate transaction, personal data may be transferred to the relevant counterparty as part of that transaction. We will take reasonable steps to ensure that any acquirer or successor is bound by privacy obligations substantially equivalent to this Policy. Where required by applicable law, we will notify affected users prior to such transfer.
Chatzy may disclose personal data to courts, law enforcement agencies, regulators, or other public authorities where:
Where legally permitted to do so, Chatzy will notify the relevant Customer of any such request before complying.
Chatzy may disclose personal data to third parties for other purposes where you have given explicit prior consent to such disclosure.
Chatzy does not sell, license, or transfer personal data to third-party data brokers, advertisers, or marketing networks for any consideration.
The following third-party service providers may process personal data in connection with the Services. Chatzy has data processing agreements or equivalent contractual protections in place with each provider.
ADVERTISING NOTICE: Chatzy does not engage Google AdSense, DoubleClick, Facebook Ads, or any other third-party advertising network within the in-product Services environment. No advertising processor cookies are deployed within the authenticated platform. Any residual references to advertising processors in previous policy versions are superseded by this Policy.
| Category / Provider | Purpose & Privacy Policy |
|---|---|
| ANALYTICS — Google Analytics (Google LLC) | Website and in-product usage analytics. Opt-out: https://tools.google.com/dlpage/gaoptout | Privacy: https://policies.google.com/privacy |
| ANALYTICS — Amplitude, Inc. | Product usage analytics and feature adoption tracking. Opt-out: https://amplitude.com/privacy |
| ANALYTICS — FullStory, Inc. | Session recording and UX analysis within the Services (anonymised). Opt-out: https://www.fullstory.com/optout |
| ANALYTICS — Mixpanel Inc. | Event-based product analytics. Opt-out: https://mixpanel.com/optout/ |
| PAYMENTS — Stripe, Inc. | Payment processing and subscription billing. Privacy: https://stripe.com/privacy |
| PAYMENTS — PayU (India) Pvt Ltd | Payment processing for Indian customers. Privacy: https://payu.in/privacy-policy |
| SECURITY — Cloudflare, Inc. | DDoS protection, CDN, and bot management. Privacy: https://www.cloudflare.com/privacypolicy/ |
| SECURITY — FingerprintJS Inc. | Browser fingerprinting for fraud and abuse prevention. Privacy: https://fingerprint.com/privacy-policy/ |
| AUTHENTICATION — Google (Google SSO) | Optional third-party authentication. Privacy: https://policies.google.com/privacy |
| EMAIL — User.com | Email marketing and customer communications (opted-in only). Privacy: https://user.com/en/privacy-policy/ |
| INFRASTRUCTURE — Cloud Hosting Providers | Cloud compute, storage, and infrastructure. Data residency details available upon request at legal@chatzy.ai. |
ADVERTISING NOTICE: Chatzy does not engage Google AdSense, DoubleClick, Facebook Ads, or any other third-party advertising network within the in-product Services environment. No advertising processor cookies are deployed within the authenticated platform. Any residual references to advertising processors in previous policy versions are superseded by this Policy.
Chatzy uses Cookies and related tracking technologies on its website (https://www.chatzy.ai) and within the authenticated Services. The types of Cookies used include:
Chatzy does not use Targeting or Advertising Cookies within the Services. For full details of the specific Cookies in use, their duration, and how to manage them, please refer to our In-Product Cookie Policy at https://www.chatzy.ai/cookie-policy. Note that disabling Essential Cookies will impair or prevent your use of the Services.
Chatzy retains personal data only for as long as is necessary for the purposes set out in this Policy, or for as long as is required or permitted by applicable law. Retention periods are determined by reference to: the duration of the Governing Agreement; legal, regulatory, and tax record-keeping obligations; the resolution of disputes or enforcement of legal agreements; and Chatzy's legitimate operational interests.
Personal data associated with an active Customer account is retained for the duration of the subscription plus a period of up to ninety (90) days following termination or expiry of the Governing Agreement, during which Customer may request export of its data. Following this period, Customer data will be deleted or anonymised unless Chatzy is required by law to retain it for longer.
Usage Data and server logs are generally retained for a shorter period (typically twelve (12) months), except where retention for longer periods is necessary for: security incident investigation; legal proceedings or regulatory compliance; or platform improvement purposes using anonymised data.
Data in backup systems may persist for up to ninety (90) days following deletion from the primary production environment before being overwritten in the ordinary course of backup rotation.
Notwithstanding the above, Chatzy may retain personal data for longer periods where required to comply with a legal hold, regulatory investigation, court order, or other lawful obligation. Chatzy may also retain certain identifying information indefinitely for fraud prevention and platform security purposes.
Customers are solely responsible for their own data retention obligations with respect to End-User Data processed through the Services. Chatzy's retention obligations with respect to End-User Data are governed by the applicable Data Processing Agreement.
Chatzy implements and maintains commercially reasonable technical, organisational, and administrative security measures designed to protect personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures include, without limitation:
IMPORTANT DISCLAIMER: No method of electronic transmission or storage is 100% secure. While Chatzy strives to use commercially reasonable means to protect personal data, Chatzy cannot guarantee absolute security. In the event of a personal data breach affecting your data, Chatzy will notify you in accordance with applicable law. Customer is responsible for maintaining the security of its own account credentials and for implementing appropriate security measures within its own systems and for its own Users.
Depending on your jurisdiction, you may have various rights with respect to your personal data. The following rights are available under applicable Indian law (DPDPA) and, where applicable, under the GDPR for EU/EEA data subjects.
| Right | Description |
|---|---|
| Right of Access | Request a copy of the personal data Chatzy holds about you, along with information about how it is processed. |
| Right to Correction | Request correction of inaccurate or incomplete personal data Chatzy holds about you. |
| Right to Erasure | Request deletion of your personal data where there is no longer a lawful basis for Chatzy to retain it, subject to Chatzy's legal obligations and legitimate interests. |
| Right to Restriction | Request restriction of processing of your personal data in certain circumstances (e.g., while accuracy is being verified). |
| Right to Data Portability | Receive your personal data in a structured, commonly used, machine-readable format, and request that it be transferred to another controller, where technically feasible. |
| Right to Object | Object to processing of your personal data where Chatzy relies on legitimate interests or where processing is for direct marketing purposes. |
| Right to Withdraw Consent | Where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of prior processing. |
| Right to Nominate | Under the DPDPA, nominate another individual to exercise your rights on your behalf in the event of your death or incapacity. |
| Right to Complain | Lodge a complaint with the Data Protection Board of India (under DPDPA) or the relevant supervisory authority in your jurisdiction. |
To exercise any of the above rights, please submit a written request to legal@chatzy.ai. We may ask you to verify your identity before processing your request. We will respond within the timeframes required by applicable law (and in any event within thirty (30) days for standard requests, extendable to sixty (60) days for complex requests with notice).
Certain rights may be limited or unavailable where: Chatzy is required by law to retain the relevant data; the exercise of the right would adversely affect the rights of other persons; or the data has been anonymised and can no longer be linked to you. Where Chatzy declines a request, it will provide reasons in accordance with applicable law.
Rights requests are generally processed free of charge. Chatzy reserves the right to charge a reasonable administrative fee for manifestly unfounded, excessive, or repetitive requests.
If you are an End-User of a Customer's Chatzy-powered deployment and you wish to exercise rights over your personal data, you should contact the relevant Customer (the Data Fiduciary / Controller) directly. Chatzy will cooperate with the Customer in fulfilling such requests in accordance with the applicable Data Processing Agreement.
Chatzy is headquartered in India. Your personal data is primarily processed and stored on servers located in India or in jurisdictions approved by the Indian government for cross-border data transfer under applicable law.
In connection with the operation of the Services, personal data may be transferred to and processed by Chatzy's service providers in other countries, including the United States, the European Union, and other jurisdictions. Where personal data is transferred outside India, Chatzy ensures that:
By using the Services and providing personal data, you acknowledge and consent to the transfer of your personal data as described in this Section, subject to the safeguards described above.
The Services are not directed to individuals under the age of 18. Chatzy does not knowingly collect, process, or store personal data from children under the age of 18. If you believe that a child under 18 has provided personal data to Chatzy, please contact us immediately at legal@chatzy.ai and we will take prompt steps to delete such data.
Customers must not submit or permit the submission of personal data relating to individuals under the age of 18 to the Services without executing a specific Data Processing Agreement with Chatzy that addresses the processing of children's data and obtains appropriate consents from parents or guardians.
The Services and our website may contain links to third-party websites, applications, or services that are not operated or controlled by Chatzy. Chatzy has no control over, and assumes no responsibility for, the content, privacy practices, or data handling of any third-party site or service. We strongly recommend that you review the privacy policy of every third-party site you visit.
Chatzy's inclusion of a link to a third-party site does not imply endorsement of that site's privacy practices or any association between Chatzy and the relevant third party.
To the maximum extent permitted by applicable law, Chatzy's liability in connection with this Policy and the processing of personal data shall be subject to the limitation of liability provisions set out in the applicable Governing Agreement. Chatzy shall not be liable for any indirect, consequential, incidental, or punitive damages arising from any data breach, loss of data, or privacy incident, except to the extent caused by Chatzy's gross negligence or wilful misconduct.
Customer shall indemnify, defend, and hold harmless Chatzy, its affiliates, and their respective officers, directors, and employees from and against all claims, liabilities, damages, losses, penalties, and expenses (including legal fees) arising from: (a) Customer's or any User's breach of this Policy or the Platform Guidelines in connection with personal data; (b) Customer's submission of sensitive or prohibited categories of personal data to the Services without authorisation; (c) Customer's failure to comply with applicable data protection laws in connection with End-User Data; or (d) any third-party claim arising from Customer's collection, use, or sharing of personal data through the Services.
Chatzy makes no warranty, express or implied, that this Policy or any security measure will prevent all unauthorised access to, or disclosure of, personal data. The security of personal data depends in part on actions taken by Customer and Users, for which Chatzy bears no responsibility.
Chatzy reserves the absolute right to modify, update, or replace this Policy at any time and for any reason, with immediate effect upon publication at https://www.chatzy.ai/privacy-policy. It is your responsibility to review this Policy periodically.
For material changes to this Policy (i.e., changes that significantly alter how we process your personal data), Chatzy will use commercially reasonable efforts to notify you by email to your registered address or through a prominent in-platform notice. However, Chatzy shall have no liability for any failure to provide such notice, and your continued use of the Services following any update constitutes your unconditional acceptance of the revised Policy.
Where a change in processing is incompatible with the legal basis under which your personal data was originally collected, Chatzy will seek fresh consent where required by applicable law.
For privacy-related queries, rights requests, complaints, or concerns regarding this Policy or Chatzy's data handling practices, please contact:
Under the DPDPA, if you are not satisfied with our response to your grievance, you may escalate your complaint to the Data Protection Board of India. For EU/EEA residents, you have the right to lodge a complaint with your local data protection supervisory authority.
Cybersharp Technology LLP · Chatzy AI