Privacy Policy
Supportson AB ("Supportson", "we", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data when you use our services.
1. Data Controller
The data controller is Supportson AB, a company registered in Sweden with its registered office in Stockholm. For privacy inquiries, contact us at privacy@supportson.com.
2. Data We Collect
Account Data
When you create an account, we collect your name, email address, and company name. If you subscribe to a paid plan, we collect payment information processed by Stripe.
Conversation Data
We store chat messages, voice/video call metadata, and support conversation history to provide our services. AI conversations are processed to generate responses but are not used to train third-party AI models.
Widget Visitor Data
When visitors interact with a Supportson widget on your website, we collect:
- Browser type and version
- IP address (anonymized after 30 days)
- Pages visited on the host website
- Chat messages and conversation content
- Country-level geographic data
Usage Data
We collect anonymous usage statistics to improve our service, including page views, feature usage, and error reports.
3. How We Use Your Data
- To provide and maintain our service
- To process your transactions
- To send service-related communications
- To provide customer support
- To detect and prevent fraud
- To improve our service and develop new features
4. Legal Basis for Processing
We process your data based on:
- Contract performance: To provide the services you signed up for
- Legitimate interests: To improve our services and prevent fraud
- Consent: For marketing communications (you can opt out at any time)
- Legal obligation: To comply with applicable laws
5. Data Storage and Security
All data is stored on servers within the European Union. We use industry-standard encryption (TLS 1.3) for data in transit and AES-256 encryption for data at rest. Access to personal data is restricted to authorized personnel only.
6. Data Retention
We retain your account data for as long as your account is active. Conversation data is retained for 12 months after the last interaction unless you request earlier deletion. After account deletion, all personal data is removed within 30 days.
7. Your Rights
Under the GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data
- Portability: Receive your data in a structured format
- Restriction: Limit how we process your data
- Objection: Object to processing based on legitimate interests
To exercise your rights, email privacy@supportson.com. We will respond within 30 days.
8. Third-Party Services
We use the following third-party services:
- Stripe: Payment processing (US, EU data processing)
- Supabase: Database and authentication (EU servers)
- Google AI: AI model inference (data processing agreement in place)
9. Cookies
We use essential cookies to maintain your session and preferences. We do not use tracking cookies or third-party advertising cookies. The Supportson widget uses a session cookie to maintain conversation continuity.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a notice on our website. Continued use of our services after changes constitutes acceptance of the updated policy.
11. Contact
For privacy-related questions or to exercise your data rights:
Supportson AB
Stockholm, Sweden
privacy@supportson.com