This is the English version of our Polish Privacy Policy. In case of discrepancies, the Polish version prevails.
1. Data controller
| Company | ASAPDEVS SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ |
| Address | Pl. Jana Kilińskiego 2, 35-005 Rzeszów, Poland |
| VAT ID (NIP) | 8133889672 |
| KRS | 0001006209 |
| Contact | contact@asapdevs.it |
2. What AsapChat is
AsapChat is a SaaS platform that lets online store owners answer their customers with an AI assistant across a website chat widget, Allegro, e-mail, Messenger, Instagram and WhatsApp, and look up order status from connected store systems (WooCommerce, PrestaShop, BaseLinker, SellAsist, Apilo).
Our role. For panel user accounts (store owners and their staff) ASAPDEVS is the controller. For data of the stores' customers (people who write to a store) the store owner is the controller and ASAPDEVS acts as a processor under a data processing agreement included in our Terms of Service.
3. Data we process
- Account data – name, e-mail address, hashed password, company details – to create the account, verify the e-mail address and provide the service.
- Billing data – invoice details, payment history, Stripe customer ID. We do not store card numbers; payments are handled by Stripe.
- Conversation data – messages exchanged between store customers and the store, to generate AI replies and let the store staff answer.
- Knowledge base – documents uploaded by the user and publicly available content of the store's website that we fetch at the user's request, to prepare the AI assistant's instructions and answers.
- Integration data – API keys and tokens for connected platforms and mailbox credentials, stored encrypted and used only to operate the integration.
- Order data – order number, status, items and tracking number, fetched only when a store customer asks about their order.
- Logs – IP address, user agent, request times – for security and diagnostics.
4. Data from Google
AsapChat's use and transfer to any other app of information received from Google APIs will adhere to the
Google API Services User Data Policy,
including the Limited Use requirements.
- Sign in with Google – we receive your e-mail address, name and Google account ID (scopes
openid, email, profile) and use them only to create your account, sign you in and address you by your first name in the panel and in account e-mails. Google also returns a profile picture, which we do not store or use.
- Widget installation via Google Tag Manager – only when you explicitly click “Install with Google Tag Manager”, we request one-time access (scopes
tagmanager.edit.containers, tagmanager.edit.containerversions and, if you choose to publish immediately, tagmanager.publish) to: list your accounts and containers, create a separate workspace named “AsapChat” in the container you select, add a single tag that loads the AsapChat chat widget, create a container version and — if you choose so — publish it. We do not read, modify or delete any of your other tags, triggers or variables.
- The Google Tag Manager access token is short-lived (no refresh token is requested), kept only in a temporary server session for at most 50 minutes and deleted right after the installation. It is never written to our database. We keep only the account, container, workspace, tag and version IDs to show you the installation status. You can remove the widget at any time by deleting the “AsapChat widget” tag in Google Tag Manager.
- Google user data is never sold, never used for advertising, never used to train AI models, and never transferred to third parties except as required by law.
- We do not use Google APIs or Google user data to create, generate or distribute non-consensual intimate imagery (NCII) or any other sexual or intimate content.
- You can revoke access at any time at myaccount.google.com/permissions.
5. Legal bases (GDPR)
- Art. 6(1)(b) – performance of the contract (providing the service).
- Art. 6(1)(c) – legal obligations (e.g. accounting).
- Art. 6(1)(f) – legitimate interests (security, fraud prevention).
- Art. 6(1)(a) – consent, where required (e.g. marketing e-mails).
6. Sub-processors and recipients
- Hosting and infrastructure providers located in the European Economic Area.
- OpenAI – messages and knowledge-base documents are sent to the OpenAI API to generate replies and search the knowledge base. Data sent via the API is not used by OpenAI to train models and may be retained for up to 30 days for abuse monitoring.
- Cloudflare (Workers AI) – customer message text, with e-mail addresses, phone numbers and links removed, for automatic classification (topic, whether a human is needed, fraud detection). The result helps operators prioritise; Cloudflare does not retain the content after classification.
- Meta Platforms – only as needed to operate the Messenger, Instagram and WhatsApp APIs.
- Allegro and store systems (WooCommerce, PrestaShop, BaseLinker, SellAsist, Apilo) – data exchange at the user's request.
- Stripe – payments and subscriptions.
- Parcel tracking providers (e.g. InPost, Poczta Polska, AfterShip) – tracking number only.
- Google – only as described in section 4.
We do not sell personal data or share it for marketing purposes.
7. Security
TLS encryption in transit, hashed passwords, encrypted API credentials, least-privilege access for staff, regular backups, servers in the EEA, security monitoring.
8. Retention
- Account data – for the duration of the contract plus 3 years.
- Billing data and invoices – 5 years from the end of the tax year.
- Conversations and knowledge base – for the duration of the contract or until deleted by the user.
- Logs – up to 90 days. E-mail verification codes – up to 24 hours.
- Unfinished sign-ups – after 90 days of inactivity we delete the account if no shop was created in it. If a shop was created, we delete the setup wizard answers and request contents, and the account stays.
9. Your rights
You have the right to access, rectify, erase, restrict and port your data, to object to processing, and to lodge a complaint with the Polish supervisory authority (Prezes UODO, ul. Stawki 2, 00-193 Warszawa). Contact: contact@asapdevs.it. See also how to delete your data.
10. Cookies
Essential. The panel uses cookies required for it to work: login session, CSRF protection and remembering your consent choice (asap_consent, 12 months). They do not require consent.
Analytics (with consent). Only after you click "Akceptuję analitykę" in the banner do we load Google Tag Manager / Google Analytics (Google Ireland Ltd / Google LLC) and, on the login and sign-up pages, Microsoft Clarity (Microsoft Ireland Operations Ltd / Microsoft Corporation), for traffic statistics and service improvement. Any transfer of data outside the European Economic Area is subject to the safeguards required by the GDPR. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time with the "Cookies" button in the corner of the page. Microsoft Clarity is not used in the logged-in panel.
Widget on shop websites. The chat and search widgets store the conversation ID and content, and data needed for search (search history, favourites, session ID) in the browser (localStorage/sessionStorage). The shop is responsible for any consents required on its website.
11. Changes
We will notify users of material changes by e-mail or in the panel.