Security and data
Understand where your data goes and what you can control.
Chatyx processes your sources and conversations to run your chatbots. Here are the main services involved, available controls and points to consider before deployment.
How a question is processed
- A visitor writes through the widget or a connected channel. Their message and relevant context are sent to Chatyx.
- Depending on your configuration, the service retrieves source passages or queries a business integration, then uses an AI provider to prepare an answer.
- The answer is returned to the channel. Conversations and collected contacts can be reviewed in the app; notifications depend on your settings.
Only add sources needed for your intended use. Tell visitors which data you request and how it will be used, especially before collecting contact details.
Primary storage and external processing
The primary Chatyx database is located in Supabase’s Paris region. This does not mean every processing operation stays in France or the European Union: AI providers, channels and other services operate under their own infrastructure and terms.
- Supabase
- Accounts, database and stored sources. The project’s primary region is Paris (eu-west-3).
- Cloudflare
- Public website delivery and Turnstile protection for the contact form.
- OpenAI · Cohere
- AI processing: answer generation, source retrieval and ranking of relevant passages, depending on the workflow.
- Railway · n8n
- Chatyx automations run on Railway using self-hosted n8n software.
- Stripe
- Payments and paid subscription management.
- Brevo · Resend
- Delivery of service emails, notifications or communications, according to their purpose and your choices.
- Meta / WhatsApp · Telegram · Shopify
- Messages or business data required when you connect these services.
- Google Analytics
- Public website audience measurement after consent to the relevant cookies.
This overview describes the main services used and does not replace applicable contractual terms. Contact us before uploading content subject to data residency or industry-specific requirements.
Controls available to you
- Account authentication and access checks for your chatbot resources.
- HTTPS connections and settings for domains allowed to embed your widget.
- Communication preferences and consent controls for public website cookies.
- A JSON export of supported account data from privacy settings and an account deletion option.
The account export covers profile information, preferences, subscriptions, chatbot configuration and source references. It is not a complete archive of every conversation and file. For a broader request, email privacy@chatyx.fr.
Sources, models and retention
Adding a document lets the chatbot retrieve useful passages. This retrieval process does not train a model exclusively for your business. Messages and relevant excerpts may be sent to the AI services used to answer.
Deletion in the app does not guarantee immediate erasure of every technical log or backup across all providers. Requests need to account for their scope, applicable retention rules and any legal obligations.
Exercise your rights or discuss your requirements
Send your request to privacy@chatyx.fr. Identify the relevant account, chatbot or channel. For a chatbot operated by another business, its operator is also your contact for the data they collect.
A response is provided within one month. An extension may be necessary in cases allowed under the GDPR; you will be informed within that first month.