Skip to main content

Documentation Index

Fetch the complete documentation index at: https://docs.konnectbot.com/llms.txt

Use this file to discover all available pages before exploring further.

KonnectBot is committed to handling personal data responsibly and transparently. This page explains how we process data, what rights you and your customers have, and how to submit formal privacy requests. For the full details, refer to the KonnectBot Privacy Policy.

How KonnectBot handles personal data

KonnectBot processes two broad categories of personal data:
  • Account and workspace data — names, email addresses, company details, authentication identifiers, and billing contacts that you provide when setting up your workspace.
  • Conversation and customer data — messages, attachments, metadata (timestamps, routing, channel), agent actions, and any customer PII shared during chat sessions. If you connect Shopify or WooCommerce, order and customer context from those integrations is also processed within the conversation.
When your customers chat with your business through KonnectBot, your organization acts as the data controller. KonnectBot processes that conversation data on your instructions as a data processor, subject to our agreements with you.

GDPR alignment

KonnectBot processes personal data on lawful bases including contract performance, legitimate interests (balanced against individual rights), consent where required, and legal obligation. We support the following data subject rights for individuals in the EEA, UK, and Switzerland:
  • Access — the right to know what personal data is held about them
  • Correction — the right to fix inaccurate data
  • Deletion — the right to have data erased where applicable
  • Restriction — the right to limit processing in certain circumstances
  • Portability — the right to receive data in a structured, machine-readable format
  • Objection — the right to object to certain types of processing
If you receive a data subject request from one of your customers, you are responsible for responding to it as the data controller. KonnectBot will support you in fulfilling that request within the bounds of your plan and contractual commitments.

CCPA and CPRA readiness

KonnectBot is aligned with California Consumer Privacy Act (CCPA) and CPRA requirements. We do not sell personal information in the conventional sense. Where “sale” is defined broadly under U.S. state laws, we provide the choices required by those laws. California residents may have rights to know, delete, correct, and opt out of certain sharing. To exercise these rights, follow the process described in the section below.

How to submit a data subject request

To submit a formal privacy or data subject request — such as a request for data access, correction, or deletion — email privacy@konnectbot.com. Include enough information to identify the data subject and the nature of the request. We may need to verify your identity before fulfilling the request.
Contact privacy@konnectbot.com for all formal privacy requests, data subject rights inquiries, and Data Processing Agreement (DPA) questions. We will route your message to the appropriate team.

Data retention and export

Retention periods differ by data category and customer configuration. KonnectBot retains data for as long as needed to provide the service, comply with law, resolve disputes, and enforce agreements. When data is no longer needed, we delete or de-identify it in accordance with our internal schedules and contractual commitments. Export and retention options for conversation history depend on your plan and workspace settings. Contact support@konnectbot.com or sales@konnectbot.com with your specific compliance requirements to confirm what is available for your account.
Review your plan’s data retention settings in your workspace and configure them to match your compliance requirements before you go live. Aligning retention settings early is simpler than requesting retroactive changes.

Data Processing Agreement (DPA)

A Data Processing Agreement is available for enterprise customers who need a formal contractual basis for data processing under GDPR or similar regulations. Contact privacy@konnectbot.com to request a DPA or discuss the terms.

International data transfers

KonnectBot may process data in the United States and other countries where we or our providers operate. For transfers of personal data from the EEA, UK, or Switzerland, we use appropriate safeguards such as Standard Contractual Clauses or other mechanisms recognized by applicable law.

HIPAA

If your use case requires HIPAA compliance, contact sales@konnectbot.com to discuss qualified plans. A HIPAA Business Associate Agreement (BAA) is available for eligible customers.