Chatty

AI compliance

How Chatty helps Shopify store owners meet GDPR and EU AI Act requirements — from data collection and security to what we never do.

Last updated: 7 August 2026

Understanding compliance requirements

GDPR Overview

The General Data Protection Regulation (GDPR) is Europe’s primary data protection law. For Chatty users, this means:

  • Collecting only necessary customer data
  • Being transparent about data usage
  • Protecting user privacy rights
  • Ensuring secure data handling

EU AI Act Overview

The EU AI Act is Regulation (EU) 2024/1689, which entered into force on 1 August 2024. It classifies AI systems by risk level.

  • Chatty is a limited-risk AI system. It is not a high-risk system under the Regulation, so the high-risk obligations (conformity assessment, risk management system, registration in the EU database) do not apply.
  • Transparency obligations under Article 50 apply from 2 August 2026. These require that people are told when they are interacting with an AI system.
  • Article 50(1) puts this obligation on us as the provider, and today the widget does not carry a built-in notice. The assistant ships with the display name “Chatty AI”, which is what tells a shopper an AI is answering, but that name is freely editable and there is no separate banner or disclaimer. Until we ship one, keep a name or welcome message that makes the AI plain, and state it in your storefront privacy notice. That is also the safer position for you as deployer.
  • Asking for a human works by default. A customer who asks to speak to a person is handed to a human agent. This trigger is switched on when the assistant is set up, and the app gives no button to turn it off.

Accuracy and human oversight

AI-generated answers can be wrong, incomplete, or out of date. The assistant answers from the content a merchant gives it — products, policies, help articles and order data — and it can still misread a question or state something the source material does not support. Merchants should review the answers their assistant gives and keep the underlying content current. Nothing Chatty generates is legal, medical, or financial advice.

A human agent can take over any conversation at any moment, and an end customer can ask for one. Chatty does not make decisions that produce legal effects or similarly significant effects on an end customer within the meaning of Article 22 GDPR: it answers questions and suggests products, it does not decide credit, pricing eligibility, refunds, or account status on its own.

What we are in this context

Shopify store owners (data controller)

As a Shopify store owner using Chatty, you are the data controller. This means you:

  • Decide how customer data is used
  • Set purposes for data collection
  • Ensure proper customer notification
  • Maintain an updated privacy policy

Chatty (data processor)

We act as the data processor, meaning we:

  • Process data according to your instructions
  • Implement security measures
  • Handle data per GDPR requirements
  • Provide necessary compliance tools

How Chatty supports your compliance

Data collection

✓ Minimal data collection

  • We collect what the assistant needs to answer in context — chat content, order details, browsing on the store, and technical identifiers such as IP address, browser and session. The full list is below
  • Every data point has a stated purpose
  • Nothing the assistant collects is used for advertising or resale

✓ Transparent processing

  • The assistant is named so a shopper can tell it is an AI — see the Article 50 note above for what this does and does not cover today
  • Explicit data usage explanations
  • No hidden data collection

Security measures

✓ Data protection

  • Encrypted in transit with TLS 1.2+ and at rest with AES-256, provided by Google Cloud and AWS at the storage layer
  • Data separated by store identifier, so one store cannot read another store’s data
  • Merchant authentication through Shopify OAuth and Firebase Authentication — we never hold merchant passwords
  • No payment card data is collected or stored. Billing is handled entirely by Shopify.

✓ Access controls

  • Production access through Google Cloud IAM on a least-privilege basis
  • Every administrative action is written to Google Cloud Audit Logs, which cannot be disabled or deleted
  • Personal data breaches are reported within 72 hours of us becoming aware of them

✓ What we don’t claim

Chatty does not hold SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27701 or PCI DSS certification. We would rather say so plainly than imply an audit that has not happened.

AI providers

Chat content is sent to four AI providers to generate answers and to screen content.

  • Google LLC (Gemini API) — generates AI replies. United States
  • OpenAI, L.L.C. — content moderation and embeddings. United States
  • Anthropic PBC (Claude API) — answers in the product demo on chatty.net, and builds the store knowledge memory. United States
  • Hangzhou DeepSeek Artificial Intelligence Co., Ltd. (DeepSeek API) — generates replies for selected stores, and builds the store knowledge memory. China

Under the API terms of Google and OpenAI, data sent through their APIs is not used to train or fine-tune their models. We have not verified an equivalent term for Anthropic or DeepSeek and will not claim one until we can produce it on request.

Where your data lives

Every server and store that holds your data is located in the United States: database, application runtime, file storage, transactional email, backups and search index all run in United States regions. Real-time chat delivery runs on a global edge network, with the data itself stored in the United States. One vendor processes outside that footprint: the DeepSeek API named above, which answers messages in China. Our team in Vietnam accesses the infrastructure remotely to run and support the service; no data is stored in Vietnam.

  • Primary database (Firestore): Google Cloud, US multi-region (nam5)
  • Application runtime and cache: Google Cloud, us-central1
  • File storage, CDN and transactional email: AWS (S3, CloudFront, SES), United States
  • Real-time chat delivery: Cloudflare Workers, global edge, stored in the United States
  • Analytics: Google BigQuery, United States
  • Backup (change history): Google Cloud, US multi-region
  • Search index: Meilisearch Cloud (Meili SAS), us-central1

International data transfers

  • EEA and Switzerland to the United States: Standard Contractual Clauses, Commission Implementing Decision (EU) 2021/914, Module Two and Module Three.
  • United Kingdom to the United States: the UK International Data Transfer Addendum, version B.1.0, in force since 21 March 2022.
  • Switzerland: the same Clauses with FADP adaptations; the supervisory authority is the FDPIC.
  • To China: nothing yet. Those Clauses cover the route to the United States, not the transfer to the DeepSeek API in China, and we will not name a mechanism we cannot produce on request. The paperwork is being settled and we will publish it, with the date, as soon as it is signed. Merchants who want no processing outside the United States can write to [email protected] and we will keep their store off that routing.

Retention and deletion

  • Order data synced from your store: kept for as long as it is needed to answer order and shipping questions, and deleted when you ask us to delete it.
  • Conversations you delete: removed from production immediately, kept in a recovery store for 3 months in case of accidental deletion, then permanently deleted.
  • Conversations while you use the service: retained for as long as you remain a customer. They are not deleted on a timer. Your plan may limit how far back you can browse your own history; that limits what the plan displays, not how long we keep the data.
  • Written deletion requests: data is deleted or returned within 30 days, confirmed in writing.
  • Backups: data removed from production is purged from backup change history within 30 days.
  • Accounting and invoice records: retained as required by Vietnamese accounting law. These contain merchant business details and amounts only — no end-customer data.

What data we collect & why

For Merchants (Shopify store owners)

  • Chat messages & conversations: Stored so merchants keep their support history and so the AI can use earlier context within the same store. We do not train any model of our own on conversation content. Under their API terms, neither do Google or OpenAI on what we send them. We have not verified an equivalent term for Anthropic or DeepSeek and will not claim one until we can produce it on request
  • Store information: Basic store data from Shopify to enable app functionality
  • Customer service settings: Your configuration preferences for the chatbot
  • Usage analytics: product usage data from the Chatty admin, used to improve app performance

For end users (store customers)

  • Chat content: Messages sent through the chat widget
  • Order information:order records synced from the merchant’s store so the assistant can answer order status and shipping questions, plus any order or tracking number a customer types into the chat. Synced order data is kept only for as long as it is needed to answer those questions
  • Browsing activity on the storefront: the address of the pages viewed, what kind of page it is, the site the customer arrived from, and the products the assistant suggested, so it can answer in context
  • Technical identifiers: a session ID, plus whether the device is mobile or desktop. For a shopper who is logged in to the store, the session ID exists from the moment the widget loads, so page views are recorded from then. For a shopper who is not logged in, it is created when they open the chat, and nothing is recorded before that. The IP address, approximate city, browser and device type are added once a conversation starts
  • Nothing beyond this: The chatbot does not ask for or collect any other personal data on its own. Anything else reaches us only because a customer types it into the chat

For visitors to chatty.net

  • Website analytics and advertising:Google Analytics 4 stores a client identifier and the Meta Pixel stores advertising identifiers — neither is anonymous. If you are in the European Economic Area, the United Kingdom, Switzerland, Brazil, or California, nothing non-essential loads before you accept; elsewhere it loads with the page and stops when you reject it. The video and the interactive demo are the exception everywhere: they load only when you press the button that starts them. See our Cookie Policy for the full list.

How we use your data

Primary uses

  • Providing customer support functionality
  • Generating answers and suggestions within the merchant’s own store context
  • Maintaining chat history for merchants
  • Processing order tracking requests

What we don’t do

  • No data selling to third parties
  • No advertising use of merchant or end-customer data. The one advertising tool we run is the Meta Pixel on this marketing website, which sees visitors to chatty.net and never touches data from a merchant’s store — see our Cookie Policy
  • No unauthorized data sharing

Privacy Notice Template

Quick reminder: Add this privacy text to your site before turning on the chatbot. Feel free to modify it for your store.

Our site uses Chatty AI for customer support, provided to us by AVADA GROUP COMPANY LIMITED (Vietnam), which acts as our processor. Here’s what you should know:

  • • The assistant is an AI. It stores data on your device, which needs your consent under Article 5(3) of the ePrivacy Directive as implemented where you are — section 25 TDDDG in Germany, the equivalent rule elsewhere — and we rely on that consent as our legal basis under Article 6(1)(a) GDPR. You can withdraw it at any time. Store owner: gate the widget behind your own cookie banner so it loads only after a visitor agrees — Chatty does not do this for you, and this line is only accurate once you have set that up
  • • Once you send a message, we use it to answer your question, to screen it for abuse, and to keep a support history for this store — nothing else. Our legal basis for that is our legitimate interest in running customer support for this store (Article 6(1)(f) GDPR)
  • • The assistant can also see your order details, the pages you view on this store, and technical details such as your IP address, browser and session, so it can answer in context
  • • Your messages are sent to Google or OpenAI in the United States, or to DeepSeek in China, to generate a reply. Google and OpenAI do not use them to train their models. AVADA GROUP has not verified an equivalent term for DeepSeek
  • • Your conversations are stored with Google LLC (Google Cloud) in the United States; uploaded files are stored with Amazon Web Services and the search index is held by Meili SAS, both in the United States; chat delivery runs through Cloudflare’s global edge network with the data stored in the United States. Staff at AVADA GROUP in Vietnam can access them to run and support the service. Every one of these transfers to the United States relies on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), and transfers from the UK on the UK International Data Transfer Addendum, version B.1.0. The transfer to DeepSeek in China is not yet covered by those clauses; AVADA GROUP is settling that paperwork. Email us at [insert your support email] and we will obtain a copy from AVADA GROUP for you
  • • Chats are encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • • Your data is never used for ads
  • • Answers are AI-generated and can be wrong — check anything important with us
  • • Order data pulled from our store is kept only for as long as it is needed to answer order and shipping questions; your chat history, along with the browsing and technical details attached to it, is kept for as long as we use Chatty. Both are deleted if you ask us to
  • • You can ask us for a copy of your data, ask us to correct or delete it, ask us to restrict how we use it, object to our using it, or ask for it in a portable format. You can also complain to your data protection authority — contact [your email]
  • • You are talking to an AI assistant and can ask for a human at any time

Contact

For anything involving personal data — access, deletion, a copy of our Data Processing Agreement, or a question about this page — email [email protected]. Our Privacy Policy sets out the legal bases we rely on, your rights under Articles 15–22 GDPR, and how to complain to a supervisory authority.

Chatty is operated by AVADA GROUP COMPANY LIMITED (CÔNG TY TNHH AVADA GROUP), Business Registration No. 0109524114, 102 Tran Phu, Ha Dong, Hanoi, Vietnam.