hazelchatLog in

Legal

Privacy notice

Last updated 14 September 2026. This notice explains how personal data is processed when you visit hazelchat.co, use a Hazelchat account at app.hazelchat.co, or talk to a Hazelchat chat installed on a customer's website.

1. Who is responsible

The controller for the processing described in sections 3 to 9 is:

Jan-Philipp Peters
Sole trader, trading as Hazelchat
Germany (the postal address is provided on request by email)
Email: hello@hazelchat.co

Privacy questions and requests: hello@hazelchat.co. No data protection officer has to be appointed for this service; write to the address above.

For conversations and enquiries that visitors submit through a chat installed on a customer's website, the customer is the controller and Hazelchat processes that data on the customer's behalf. Section 10 explains what this means for you as a visitor.

2. Three situations this notice covers

3. Hosting and connection data

Both sites run on a server rented from netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany. When you open a page or the application, the server processes the connection data that is technically necessary to deliver it: your IP address, the time of the request, the requested resource, the response status and the browser identification your browser sends. The web server keeps no access log. The application stores no IP addresses; its rate limits use a keyed hash of the address that expires within a day.

The application itself writes operational logs that contain request identifiers, route names, status codes and durations, but no page contents, questions, messages, email addresses or tokens. These logs are kept for 30 days.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is delivering the sites reliably and detecting abuse.

4. Cookies and browser storage

hazelchat.co sets no cookies. app.hazelchat.co sets one strictly necessary session cookie after you sign in. It is limited to that host, not readable by scripts, expires after seven days or 24 hours of inactivity, and is removed when you sign out. There is no analytics, advertising or cross-site tracking, and the emails we send have open and click tracking disabled.

The chat installed on customer websites keeps its conversation credential in page memory only and sets no cookies. If the business has configured short opener messages next to the chat button, the widget keeps two flags in your browser's session storage — that a page of the site was viewed in this tab session, and which opener message was already shown — so that an opener appears at most once per session; they contain no identifier, are read only in your browser and disappear when the tab is closed. Customers can defer loading the widget until their own consent manager allows it.

Legal basis: § 25(2) no. 2 TDDDG for the strictly necessary cookie; Art. 6(1)(b) GDPR for providing the account you requested.

5. Contacting us

If you email hello@hazelchat.co, we process your address, the content of your message and the time it arrived in order to answer you. The mailbox is hosted on Microsoft 365 (Exchange Online), provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, and resold by GoDaddy; mailbox data is stored in Microsoft's data centres in the European Union. Messages are kept for as long as the conversation and any resulting business relationship require, and then deleted unless statutory retention applies.

Legal basis: Art. 6(1)(b) GDPR where your message concerns a contract or pre-contractual steps, otherwise Art. 6(1)(f) GDPR (answering enquiries).

6. Customer accounts

To create an account we process your email address, a salted hash of your password (never the password itself), the times you sign in, hashed technical identifiers used only to throttle repeated sign-in attempts, and your session records. Signup and password recovery use single-use links that expire after 30 minutes; the link itself is never stored in clear text.

Inside the workspace we store what you add: imported website text, uploaded document text after you review it, approved questions and answers, appearance and action settings, published versions, and the privacy details you choose to show visitors. Uploaded original files are processed in memory and are not retained. You are responsible for the content you add and for any personal data it contains.

Retention: account and workspace data are kept while the account exists. Closing the account removes the account, workspace, jobs, exports and recovery records immediately; encrypted backup copies expire within 30 days (section 9).

Legal basis: Art. 6(1)(b) GDPR (providing the service); Art. 6(1)(f) GDPR for sign-in throttling and other security measures.

7. Transactional email

Signup, recovery and account emails, and the short notification that a new enquiry has arrived, are sent through Brevo (Sendinblue SAS, 7 rue de Madrid, 75008 Paris, France). Brevo receives the recipient address, the message content and delivery events. Enquiry notifications contain a link to your workspace but no visitor name, email address, message or transcript. Delivery, bounce and failure events are stored for 30 days after completion so that you can see whether a notification reached you.

Legal basis: Art. 6(1)(b) GDPR. Brevo acts as our processor.

8. AI evidence selection

Hazelchat answers questions only with passages taken word for word from the sources a customer has approved and published. By default this uses a deterministic retrieval engine on our server. A customer can additionally enable an AI model, chosen from a catalogue, to select the most relevant passages.

When AI mode is enabled, each question (up to 1,500 characters) and up to eight retrieved passages from the customer's approved sources are sent to OpenRouter, Inc., 169 Madison Avenue, New York, NY 10016, USA, which forwards them to the selected model provider. Requests are restricted to routes the provider offers without data retention, and we deny provider-side data collection. No account details, visitor contact details or identifiers are sent; the question text contains whatever the person typed. The model's output is checked by our server and discarded unless it consists of exact passages from the retrieved sources.

Transfer safeguard: standard contractual clauses approved by the European Commission (Art. 46 GDPR), as provided in OpenRouter's privacy policy and data processing agreement. Legal basis: Art. 6(1)(b) GDPR for customers who enable the feature; for visitor conversations the customer's legal basis applies (section 10).

9. Backups, recovery and monitoring

We take an encrypted backup of the application database once a day. Backups are encrypted on our server before upload, with a key the storage provider does not hold, and stored in a Backblaze B2 bucket in the European Union (EU Central region, Amsterdam, Netherlands). Backblaze, Inc., 201 Baldwin Avenue, San Mateo, CA 94401, USA, operates the storage. Backup copies are kept for at most 30 days. A separate record of deletions is kept so that data you have deleted is deleted again automatically if an older backup ever has to be restored. Transfer safeguard: standard contractual clauses in Backblaze's data processing addendum; in addition, the archives are encrypted before upload with a key Backblaze does not hold, so it cannot read them.

Availability is monitored by Better Stack, Inc. (a Delaware corporation, USA, which processes its data primarily in the European Union), which requests our public pages from its own network and receives content-free heartbeat signals from our server. It receives no account, workspace or visitor content.

Legal basis: Art. 6(1)(f) GDPR (protecting the service and your data against loss and outages).

10. Talking to a Hazelchat chat on a customer's website

When you use the chat on a business's website, that business is the controller. Its own privacy notice is shown in the chat before you send your first message. Hazelchat processes the following on the business's behalf and instructions, under a data processing agreement:

Conversations and enquiries are kept for the period the business configures, by default 90 days, and are then deleted automatically. Leaving contact details is always optional; you can ask questions without an enquiry. To exercise your rights over these records, contact the business named in its notice. We support businesses in answering such requests and will forward requests that reach us directly.

11. Payments

We do not currently process payments online. If paid plans are introduced, a payment provider will process payment data and this notice will be updated before that starts.

12. Recipients and transfers

RecipientRoleLocationWhat it receives
netcup GmbHHostingGermanyAll data on the server. The server disk is not encrypted at rest; physical and access security are the provider's; backups are encrypted before they leave the server
Brevo (Sendinblue SAS)Transactional emailFranceRecipient address, email content, delivery events
Backblaze, Inc.Encrypted backup storageEU data center; US companyEncrypted backup archives only
OpenRouter, Inc. and the selected model providerAI evidence selection (if enabled by the customer)USA / depends on modelQuestion text and retrieved source passages
Better Stack, Inc.Availability monitoringEU (processing); US companyPublic page responses, heartbeat signals
Microsoft Ireland Operations Limited (Microsoft 365, resold by GoDaddy)Mailbox for hello@hazelchat.coIreland; EU data centresEmails you send us

Where a recipient is outside the European Economic Area, we rely on the safeguard named in the relevant section above. We do not sell personal data.

13. How long we keep data

DataRetention
Account, password hash, verified emailWhile the account exists
Sessions7 days, or 24 hours of inactivity
Signup and recovery links30 minutes
Workspace content and published versionsWhile the account exists, or until the customer deletes them
Visitor conversations and enquiriesConfigured by the customer; default 90 days
Import staging7 days after completion
Exports generated by a customer24 hours
Operational logs, audit and notification metadata30 days
Encrypted backups30 days

14. Your rights

Under the GDPR you can ask for access to your personal data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and you can object to processing based on legitimate interests (Art. 21). Where processing relies on consent, you can withdraw it at any time with effect for the future (Art. 7(3)). Account holders can export their workspace and close their account in Settings without contacting us.

Contact for requests: hello@hazelchat.co. You also have the right to lodge a complaint with a supervisory authority, in particular in the member state of your residence, workplace or the place of the alleged infringement. The German supervisory authorities are listed by the Federal Commissioner for Data Protection and Freedom of Information at bfdi.bund.de.

15. Security

Connections use HTTPS. Passwords are stored as salted scrypt hashes. Access to the server is limited to key-based administration. Backups are encrypted before they leave the server. Uploaded documents are parsed in an isolated environment without network access. No measure is absolute; if a personal data breach affects you, we will inform you as the law requires.

16. Automated decisions and changes

We make no automated decisions with legal or similarly significant effect. We will update this notice when our processing changes and show the date of the latest version at the top.