Legal
Privacy notice
1. Who is responsible
The controller for the processing described in sections 3 to 9 is:
Jan-Philipp PetersSole trader, trading as Hazelchat
Germany (the postal address is provided on request by email)
Email: hello@hazelchat.co
Privacy questions and requests: hello@hazelchat.co. No data protection officer has to be appointed for this service; write to the address above.
For conversations and enquiries that visitors submit through a chat installed on a customer's website, the customer is the controller and Hazelchat processes that data on the customer's behalf. Section 10 explains what this means for you as a visitor.
2. Three situations this notice covers
- Visiting hazelchat.co. A static information site. It sets no cookies and loads no analytics or third-party scripts.
- Using a Hazelchat account. Businesses sign up at app.hazelchat.co to build, review and publish a chat for their own website.
- Talking to a Hazelchat chat on a customer's website. The customer decides why and how visitor data is used and shows its own privacy notice inside the chat before the first message.
3. Hosting and connection data
Both sites run on a server rented from netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany. When you open a page or the application, the server processes the connection data that is technically necessary to deliver it: your IP address, the time of the request, the requested resource, the response status and the browser identification your browser sends. The web server keeps no access log. The application stores no IP addresses; its rate limits use a keyed hash of the address that expires within a day.
The application itself writes operational logs that contain request identifiers, route names, status codes and durations, but no page contents, questions, messages, email addresses or tokens. These logs are kept for 30 days.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is delivering the sites reliably and detecting abuse.
4. Cookies and browser storage
hazelchat.co sets no cookies. app.hazelchat.co sets one strictly necessary session cookie after you sign in. It is limited to that host, not readable by scripts, expires after seven days or 24 hours of inactivity, and is removed when you sign out. There is no analytics, advertising or cross-site tracking, and the emails we send have open and click tracking disabled.
The chat installed on customer websites keeps its conversation credential in page memory only and sets no cookies. If the business has configured short opener messages next to the chat button, the widget keeps two flags in your browser's session storage — that a page of the site was viewed in this tab session, and which opener message was already shown — so that an opener appears at most once per session; they contain no identifier, are read only in your browser and disappear when the tab is closed. Customers can defer loading the widget until their own consent manager allows it.
Legal basis: § 25(2) no. 2 TDDDG for the strictly necessary cookie; Art. 6(1)(b) GDPR for providing the account you requested.
5. Contacting us
If you email hello@hazelchat.co, we process your address, the content of your message and the time it arrived in order to answer you. The mailbox is hosted on Microsoft 365 (Exchange Online), provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, and resold by GoDaddy; mailbox data is stored in Microsoft's data centres in the European Union. Messages are kept for as long as the conversation and any resulting business relationship require, and then deleted unless statutory retention applies.
Legal basis: Art. 6(1)(b) GDPR where your message concerns a contract or pre-contractual steps, otherwise Art. 6(1)(f) GDPR (answering enquiries).
6. Customer accounts
To create an account we process your email address, a salted hash of your password (never the password itself), the times you sign in, hashed technical identifiers used only to throttle repeated sign-in attempts, and your session records. Signup and password recovery use single-use links that expire after 30 minutes; the link itself is never stored in clear text.
Inside the workspace we store what you add: imported website text, uploaded document text after you review it, approved questions and answers, appearance and action settings, published versions, and the privacy details you choose to show visitors. Uploaded original files are processed in memory and are not retained. You are responsible for the content you add and for any personal data it contains.
Retention: account and workspace data are kept while the account exists. Closing the account removes the account, workspace, jobs, exports and recovery records immediately; encrypted backup copies expire within 30 days (section 9).
Legal basis: Art. 6(1)(b) GDPR (providing the service); Art. 6(1)(f) GDPR for sign-in throttling and other security measures.
7. Transactional email
Signup, recovery and account emails, and the short notification that a new enquiry has arrived, are sent through Brevo (Sendinblue SAS, 7 rue de Madrid, 75008 Paris, France). Brevo receives the recipient address, the message content and delivery events. Enquiry notifications contain a link to your workspace but no visitor name, email address, message or transcript. Delivery, bounce and failure events are stored for 30 days after completion so that you can see whether a notification reached you.
Legal basis: Art. 6(1)(b) GDPR. Brevo acts as our processor.
8. AI evidence selection
Hazelchat answers questions only with passages taken word for word from the sources a customer has approved and published. By default this uses a deterministic retrieval engine on our server. A customer can additionally enable an AI model, chosen from a catalogue, to select the most relevant passages.
When AI mode is enabled, each question (up to 1,500 characters) and up to eight retrieved passages from the customer's approved sources are sent to OpenRouter, Inc., 169 Madison Avenue, New York, NY 10016, USA, which forwards them to the selected model provider. Requests are restricted to routes the provider offers without data retention, and we deny provider-side data collection. No account details, visitor contact details or identifiers are sent; the question text contains whatever the person typed. The model's output is checked by our server and discarded unless it consists of exact passages from the retrieved sources.
Transfer safeguard: standard contractual clauses approved by the European Commission (Art. 46 GDPR), as provided in OpenRouter's privacy policy and data processing agreement. Legal basis: Art. 6(1)(b) GDPR for customers who enable the feature; for visitor conversations the customer's legal basis applies (section 10).
9. Backups, recovery and monitoring
We take an encrypted backup of the application database once a day. Backups are encrypted on our server before upload, with a key the storage provider does not hold, and stored in a Backblaze B2 bucket in the European Union (EU Central region, Amsterdam, Netherlands). Backblaze, Inc., 201 Baldwin Avenue, San Mateo, CA 94401, USA, operates the storage. Backup copies are kept for at most 30 days. A separate record of deletions is kept so that data you have deleted is deleted again automatically if an older backup ever has to be restored. Transfer safeguard: standard contractual clauses in Backblaze's data processing addendum; in addition, the archives are encrypted before upload with a key Backblaze does not hold, so it cannot read them.
Availability is monitored by Better Stack, Inc. (a Delaware corporation, USA, which processes its data primarily in the European Union), which requests our public pages from its own network and receives content-free heartbeat signals from our server. It receives no account, workspace or visitor content.
Legal basis: Art. 6(1)(f) GDPR (protecting the service and your data against loss and outages).
10. Talking to a Hazelchat chat on a customer's website
When you use the chat on a business's website, that business is the controller. Its own privacy notice is shown in the chat before you send your first message. Hazelchat processes the following on the business's behalf and instructions, under a data processing agreement:
- the questions you type, the answers and the source passages shown, and the published version that produced them;
- if you choose to leave an enquiry: your name, email address and message, the exact permission wording and notice version you saw, and the time of submission;
- hashed technical identifiers used only to limit abuse, and a short-lived conversation credential that lives in your browser's memory;
- content-free usage events — that the chat was opened, that an offered link was followed, that an opener message was shown or clicked — recorded by kind and, where one exists, the conversation, never with the page you were on or any identifier.
Conversations and enquiries are kept for the period the business configures, by default 90 days, and are then deleted automatically. Leaving contact details is always optional; you can ask questions without an enquiry. To exercise your rights over these records, contact the business named in its notice. We support businesses in answering such requests and will forward requests that reach us directly.
11. Payments
We do not currently process payments online. If paid plans are introduced, a payment provider will process payment data and this notice will be updated before that starts.
12. Recipients and transfers
| Recipient | Role | Location | What it receives |
|---|---|---|---|
| netcup GmbH | Hosting | Germany | All data on the server. The server disk is not encrypted at rest; physical and access security are the provider's; backups are encrypted before they leave the server |
| Brevo (Sendinblue SAS) | Transactional email | France | Recipient address, email content, delivery events |
| Backblaze, Inc. | Encrypted backup storage | EU data center; US company | Encrypted backup archives only |
| OpenRouter, Inc. and the selected model provider | AI evidence selection (if enabled by the customer) | USA / depends on model | Question text and retrieved source passages |
| Better Stack, Inc. | Availability monitoring | EU (processing); US company | Public page responses, heartbeat signals |
| Microsoft Ireland Operations Limited (Microsoft 365, resold by GoDaddy) | Mailbox for hello@hazelchat.co | Ireland; EU data centres | Emails you send us |
Where a recipient is outside the European Economic Area, we rely on the safeguard named in the relevant section above. We do not sell personal data.
13. How long we keep data
| Data | Retention |
|---|---|
| Account, password hash, verified email | While the account exists |
| Sessions | 7 days, or 24 hours of inactivity |
| Signup and recovery links | 30 minutes |
| Workspace content and published versions | While the account exists, or until the customer deletes them |
| Visitor conversations and enquiries | Configured by the customer; default 90 days |
| Import staging | 7 days after completion |
| Exports generated by a customer | 24 hours |
| Operational logs, audit and notification metadata | 30 days |
| Encrypted backups | 30 days |
14. Your rights
Under the GDPR you can ask for access to your personal data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and you can object to processing based on legitimate interests (Art. 21). Where processing relies on consent, you can withdraw it at any time with effect for the future (Art. 7(3)). Account holders can export their workspace and close their account in Settings without contacting us.
Contact for requests: hello@hazelchat.co. You also have the right to lodge a complaint with a supervisory authority, in particular in the member state of your residence, workplace or the place of the alleged infringement. The German supervisory authorities are listed by the Federal Commissioner for Data Protection and Freedom of Information at bfdi.bund.de.
15. Security
Connections use HTTPS. Passwords are stored as salted scrypt hashes. Access to the server is limited to key-based administration. Backups are encrypted before they leave the server. Uploaded documents are parsed in an isolated environment without network access. No measure is absolute; if a personal data breach affects you, we will inform you as the law requires.
16. Automated decisions and changes
We make no automated decisions with legal or similarly significant effect. We will update this notice when our processing changes and show the date of the latest version at the top.