Privacy Policy

Last updated: 20 Dec 2025

1. Introduction

Welcome to ChatVia ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

ChatVia is designed to help you create AI agents by ingesting your documents and using advanced AI technologies to provide contextual responses. We are committed to protecting your privacy and ensuring transparency about our data practices.

2. Information We Collect

2.1 Personal Information

  • Name and email address (for account creation)
  • Password (encrypted and stored securely)
  • Account settings and preferences

2.2 Content and Documents

  • Documents you upload for agent training
  • Chat conversations with your agents
  • Agent configurations and settings
  • Metadata associated with your content

2.3 Usage Information

  • Log data and usage patterns
  • Device information and IP addresses
  • Performance metrics and error reports

3. How We Use Your Information

3.1 RAG Processing

When you create training-based agents, ChatVia processes your documents through our RAG (Retrieval-Augmented Generation). This involves:

  • Document chunking and indexing
  • Vector embedding generation
  • Semantic search and retrieval
  • Context preparation for AI models

3.2 Service Provision

  • Creating and managing your AI agents
  • Processing chat requests and generating responses
  • Maintaining account security and authentication
  • Providing customer support

3.3 Improvement and Analytics

  • Improving our RAG system
  • Analyzing website usage patterns using privacy-focused analytics (Plausible)
  • Monitoring system performance and reliability

Note: Our analytics tool (Plausible) does not collect personal data, use cookies, or track individuals across websites.

4. EU-Based Infrastructure

Your data never leaves the European Union. ChatVia operates on 100% EU-based infrastructure to ensure the highest level of data protection and GDPR compliance.

4.1 Data Storage (Germany)

All your data, including documents, chat history, and account information, is stored exclusively on Hetzner servers located in Germany. Hetzner is a German company operating under strict EU data protection laws.

  • Database: All data securely stored in Germany
  • Files & Documents: Uploaded files stored in Germany
  • Location: 🇩🇪 Germany (EU)
  • Privacy Policy: Hetzner Privacy Policy

4.2 Document Processing (France)

Document parsing and text extraction is handled using Mistral AI, a French company providing state-of-the-art AI models. Mistral processes your uploaded documents to extract and analyze their content.

  • Purpose: Document parsing, text extraction, and content analysis
  • Provider: Mistral AI
  • Location: 🇫🇷 France (EU)
  • Privacy Policy: Mistral AI Privacy Policy

4.3 AI Processing (France)

AI models and chat processing are provided by Scaleway, hosted exclusively in France. We use state-of-the-art open-source AI models including Llama, DeepSeek, Qwen, Mistral, and Gemma.

  • AI Models: Open-source models (Llama, DeepSeek, Qwen, Mistral, Gemma)
  • Processing: All AI inference happens on Scaleway infrastructure
  • Location: 🇫🇷 France (EU)
  • Privacy Policy: Scaleway Privacy Policy

4.4 Payment Processing (Ireland)

Payment processing is handled by Stripe. For customers located outside the Americas (including the EU, EEA, Switzerland, UK, Middle East, Africa, and Asia Pacific), payments are processed by Stripe Technology Company, Limited (STC), an Irish company operating under Irish and EU law.

  • Entity: Stripe Technology Company, Limited (STC)
  • Location: 🇮🇪 Ireland (EU)
  • Role: Data controller for payment processing
  • Compliance: GDPR compliant, authorized under Irish law
  • Data Processed: Payment card details, billing information, transaction history
  • Privacy Policy: Stripe Privacy Policy

Important: We do not store your complete payment card details on our servers. Payment information is securely processed and stored by Stripe in compliance with PCI-DSS standards.

4.5 Website Analytics (EU)

We use Plausible Analytics, a privacy-focused analytics tool, to understand how visitors use our website. Plausible is hosted in the EU and is fully GDPR compliant.

  • Purpose: Website traffic analysis and usage statistics
  • Provider: Plausible Analytics
  • Location: 🇪🇺 European Union
  • Privacy Features: No cookies, no personal data collection, no cross-site tracking
  • GDPR Compliant: Plausible Privacy Information

✓ Zero US Data Processing

Unlike many AI platforms, ChatVia does not process any data in the United States or share data with US-based providers. All infrastructure, data storage, and AI processing remain within the European Union, ensuring full compliance with EU data protection regulations.

4.6 No Training on Your Data

Important: We do not train AI models on your data. ChatVia uses RAG (Retrieval-Augmented Generation) technology to find relevant information from your documents and send it to your chosen AI model for processing. Your data is never used to train or improve the underlying AI models.

5. Data Storage and Security

5.1 Storage Locations

All your data is stored exclusively within the European Union:

  • Data Storage: Hetzner data centers in Germany 🇩🇪
  • Uploaded Files: Securely stored in Germany 🇩🇪
  • Document Processing: Mistral AI in France 🇫🇷
  • AI Processing: Scaleway infrastructure in France 🇫🇷
  • Payment Processing: Stripe Technology Company, Limited (Ireland) 🇮🇪
  • Website Analytics: Plausible Analytics (European Union) 🇪🇺

🇪🇺 EU Data Sovereignty

Your data is protected by European data protection laws and never leaves EU borders. All our infrastructure partners (Hetzner, Mistral AI, Scaleway, Plausible Analytics) are EU-based companies committed to GDPR compliance.

5.2 Security Measures

  • Data encryption at rest and in transit (TLS/HTTPS)
  • Regular security audits and monitoring
  • Access controls and multi-factor authentication
  • Secure backup and disaster recovery procedures
  • Network isolation and firewall protection

6. Your Rights Under GDPR

If you are an EU resident, you have the following rights under the General Data Protection Regulation (GDPR):

Right to Access

Request a copy of your personal data we hold

Right to Rectification

Correct inaccurate or incomplete data

Right to Erasure

Request deletion of your personal data

Right to Portability

Transfer your data to another service

Right to Object

Object to processing of your personal data

Right to Restrict

Limit how we process your data

7. Data Retention and Deletion

We retain your data only as long as necessary to provide our services and comply with legal obligations:

  • Account Data: Retained while your account is active
  • Chat History: Retained according to your settings
  • Uploaded Documents: Retained until you delete them
  • Usage Logs: Retained until you delete your account

Easy Data Deletion

You can delete your data at any time through your account settings. When you choose to delete data, it is permanently removed from our systems immediately, including all documents, agents, and metadata (such as images) associated with your documents. This action cannot be undone, and once deleted, we cannot recover your account or its contents.

8. Cookies and Tracking

We use essential cookies and similar technologies to:

  • Maintain your login session
  • Remember your preferences
  • Ensure security and prevent fraud

8.1 Privacy-Focused Analytics

For website analytics, we use Plausible Analytics, which does not use cookies and does not collect any personal data. Plausible is fully GDPR compliant and respects user privacy by design. No consent is required for Plausible as it does not track individuals or store personal information.

9. Children's Privacy

ChatVia is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically for any changes.

11. Contact Us

If you have any questions about this Privacy Policy, want to exercise your rights, or need to contact our Data Protection Officer, please reach out to us:

Privacy Contact Information

12. Legal Basis for Processing

Under GDPR, we process your personal data based on the following legal grounds:

  • Contract Performance: To provide ChatVia services you've requested
  • Legitimate Interest: To improve our services and ensure security
  • Consent: For optional features like analytics (where applicable)
  • Legal Obligation: To comply with applicable laws and regulations

This Privacy Policy is effective as of 10 Aug 2025 and applies to all users of ChatVia.