Privacy Policy
Effective Date: 23 May 2025
This Privacy Policy describes how ChatNav d.o.o. (“ChatNav”, “we”, “us”, or “our”) collects, uses, and protects your personal data when you visit our website www.chatnav.ai or interact with our services. We are committed to handling personal data responsibly and in compliance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
1. Who We Are and Our Role
ChatNav d.o.o. is a technology company based in Zagreb, Croatia, specializing in AI-powered virtual assistants. When you visit our website, contact us, or request a product demo, we act as the data controller of the information you provide.
However, when we provide our AI assistant as a service embedded on third-party websites (for example, on a hotel or clinic’s page), we act as a data processor. In those cases, the client who owns the website is the data controller, and we process user inputs on their behalf under a separate data processing agreement.
2. What Data We Collect
When you visit our website, we may collect certain information automatically, including your IP address, browser type and version, pages visited, and device characteristics. This data is used to ensure the website functions securely and efficiently.
If you contact us, for example, via our contact form or to request a demo, we may collect your name, email address, company name, phone number (if provided), and any message you choose to send us.
When you interact with our chatbot, either during a product demonstration or on a client’s website, we collect the text you input and the assistant’s responses. Please note that responses provided by our AI assistant are automatically generated and not reviewed by a human unless explicitly stated during a demo or support interaction. This may also include session metadata such as timestamps and interaction logs. We use this data to provide the chatbot service and improve its performance.
We do not knowingly collect personal data from individuals under the age of 16. If we learn that we have collected such data without proper consent, we will delete it immediately.
3. How and Why We Use Your Data
We use personal data for the following purposes:
- To respond to your inquiries or demo requests.
- To provide, maintain, and improve our chatbot and website services.
- To analyze usage patterns and enhance user experience (where applicable).
- To comply with legal obligations and protect our rights.
The legal bases for processing your data include your consent (e.g., for cookies or demo requests), the necessity of processing to perform a contract or respond to your request, our legitimate interest in operating a secure and functional website, and our legal obligations.
4. Data Hosting and International Transfers
All personal data we store is hosted within the European Union, specifically on secure servers located in Germany using Amazon Web Services (AWS).
When chatbot interactions are processed by AI models, we may transfer the message content to OpenAI, L.L.C., a company based in the United States. This transfer is necessary for generating real-time responses and is carried out based on our legitimate interest in providing AI-powered assistance, or—when applicable—based on your consent during product demonstrations. In such cases, data is transferred under the European Commission’s Standard Contractual Clauses (SCCs), which provide appropriate safeguards under GDPR.
We currently use Google Analytics to help us understand how visitors use our website and to improve the user experience. Google may collect anonymized usage data, including IP addresses and interaction patterns, which may be transferred outside the EU. These activities are subject to Google's own data protection practices and are governed by Standard Contractual Clauses. Where required, we obtain user consent before enabling analytics cookies.
5. Retention Periods
We retain personal data only for as long as necessary to fulfill the purpose for which it was collected.
In general, demo requests and other contact submissions are kept for up to 12 months. Data collected through chatbot usage is retained according to the agreements we have with our clients, typically for 6 to 12 months following the end of the client’s subscription or the last recorded interaction, unless otherwise required by law. Anonymous or aggregated data may be retained longer for analytics or product improvement, provided it cannot be linked back to an individual.
You may request earlier deletion of your data at any time, and we will process such requests in accordance with GDPR.
6. Your Rights Under GDPR
As a data subject, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of your data (“right to be forgotten”), where applicable.
- Restrict or object to processing in certain situations.
- Request a portable copy of your data.
- Withdraw consent for processing where consent was the legal basis.
To exercise your rights, please contact us at chatnav@chatnav.ai. You also have the right to lodge a complaint with your national data protection authority. In Croatia, this is the AZOP (www.azop.hr). We do not use your personal data for profiling or automated decision-making that produces legal or similarly significant effects.
7. Security Measures
We take appropriate technical and organizational measures to protect personal data, including encryption of stored and transmitted data, secure authentication and access controls, and ongoing monitoring of our systems.
In the event of a data breach affecting your personal data, we will notify you and relevant authorities in accordance with our legal obligations.
8. Cookies and Tracking
Our website may use cookies to ensure basic functionality and security. If we introduce analytics or marketing cookies in the future, we will display a cookie banner and obtain your explicit consent before setting any non-essential cookies. For more details, please refer to our Cookie Policy.
9. Changes to This Policy
We may update this Privacy Policy from time to time, for example to reflect changes in legislation or our business practices. If we make material changes, we will post the updated policy on our website with a revised effective date.
10. Contact Information
For all questions or requests related to this Privacy Policy or your personal data, please contact:
ChatNav d.o.o.
Ulica Erazma Barčića 13
10000 Zagreb, Croatia
Email: chatnav@chatnav.ai