Security and data

    Understand where your data goes and what you can control.

    Chatyx processes your sources and conversations to run your chatbots. Here are the main services involved, available controls and points to consider before deployment.

    How a question is processed

    1. A visitor writes through the widget or a connected channel. Their message and relevant context are sent to Chatyx.
    2. Depending on your configuration, the service retrieves source passages or queries a business integration, then uses an AI provider to prepare an answer.
    3. The answer is returned to the channel. Conversations and collected contacts can be reviewed in the app; notifications depend on your settings.

    Only add sources needed for your intended use. Tell visitors which data you request and how it will be used, especially before collecting contact details.

    Primary storage and external processing

    The primary Chatyx database is located in Supabase’s Paris region. This does not mean every processing operation stays in France or the European Union: AI providers, channels and other services operate under their own infrastructure and terms.

    Supabase
    Accounts, database and stored sources. The project’s primary region is Paris (eu-west-3).
    Cloudflare
    Public website delivery and Turnstile protection for the contact form.
    OpenAI · Cohere
    AI processing: answer generation, source retrieval and ranking of relevant passages, depending on the workflow.
    Railway · n8n
    Chatyx automations run on Railway using self-hosted n8n software.
    Stripe
    Payments and paid subscription management.
    Brevo · Resend
    Delivery of service emails, notifications or communications, according to their purpose and your choices.
    Meta / WhatsApp · Telegram · Shopify
    Messages or business data required when you connect these services.
    Google Analytics
    Public website audience measurement after consent to the relevant cookies.

    This overview describes the main services used and does not replace applicable contractual terms. Contact us before uploading content subject to data residency or industry-specific requirements.

    Controls available to you

    • Account authentication and access checks for your chatbot resources.
    • HTTPS connections and settings for domains allowed to embed your widget.
    • Communication preferences and consent controls for public website cookies.
    • A JSON export of supported account data from privacy settings and an account deletion option.

    The account export covers profile information, preferences, subscriptions, chatbot configuration and source references. It is not a complete archive of every conversation and file. For a broader request, email privacy@chatyx.fr.

    Sources, models and retention

    Adding a document lets the chatbot retrieve useful passages. This retrieval process does not train a model exclusively for your business. Messages and relevant excerpts may be sent to the AI services used to answer.

    Deletion in the app does not guarantee immediate erasure of every technical log or backup across all providers. Requests need to account for their scope, applicable retention rules and any legal obligations.

    Read the privacy policy

    Exercise your rights or discuss your requirements

    Send your request to privacy@chatyx.fr. Identify the relevant account, chatbot or channel. For a chatbot operated by another business, its operator is also your contact for the data they collect.

    A response is provided within one month. An extension may be necessary in cases allowed under the GDPR; you will be informed within that first month.

    Contact us before deployment