Privacy policy
Effective date: 2026-04-24
1. General
This privacy policy explains how we process personal data when you use the Daisoras Chat platform, the website, and related services. Processing is carried out in accordance with the General Data Protection Regulation (GDPR), the law of the Republic of Lithuania, and other applicable EU privacy requirements.
By using the Platform you confirm that you have read this policy. If you do not agree with it, you must not use the Platform.
2. Data controller and contact
Data controller: Daisoras Chat (the service provider).
For questions about personal data processing, contact us by email at support@b-mod.com or via the contact page.
3. Data we process
We ask the user for the minimum amount of personal data — only an email address is required at registration (along with a password, which is stored only as a cryptographically protected hash). All other data is either optional or generated automatically while the service is operating.
In summary, we process the following categories:
- Account data: email (required), password hash, optional name or organisation name (only if you provide them), subscription plan information, organisation membership (where applicable), and dates on which the terms of use and privacy policy were accepted.
- Authentication data: active session identifiers, OAuth provider access tokens (if you sign in via OAuth), email verification codes.
- Usage data: technical logs, IP address (for security and abuse prevention), action history (audit records), browser/user-agent information, error reports.
- Billing data: Stripe customer and subscription identifiers, plan status, invoice history. We do NOT store payment card numbers, CVV codes, or bank account details — these are handled by Stripe under their privacy and PCI DSS policies.
- Content you upload: chatbot configuration, knowledge base documents, instructions.
- Conversation data: chatbot conversations with end users (visitors of the customer’s website). This may include text entered by end users, and the customer is responsible for what information is collected through their chatbot widget.
- Support data when you contact us for help (correspondence content, account context).
What we do NOT collect
- identity document data (passports, ID cards);
- payment card numbers, expiration dates, or CVV codes (these are processed by Stripe in its own environment);
- biometric data (face, fingerprint, voiceprint);
- precise geolocation data (we may infer an approximate region from the IP address only for security purposes);
- special-category data (Art. 9 GDPR — health, religious or political beliefs, etc.), unless the user themselves chooses to upload such data into the chatbot knowledge base (in which case processing happens under the user’s own responsibility).
4. Purposes and legal bases
We process personal data for the following specific purposes:
- account creation, identity verification, and sign-in;
- providing the service and performing the contract (GDPR Art. 6(1)(b));
- sending technical notifications about service operation, security events, or material changes via email;
- responding to enquiries, customer support, and technical assistance;
- billing administration and compliance with statutory accounting obligations (GDPR Art. 6(1)(c));
- legitimate interests — security, fraud prevention, and service improvement (GDPR Art. 6(1)(f));
- where applicable, on the basis of your consent (GDPR Art. 6(1)(a)), e.g. for optional marketing communications.
We do NOT sell personal data to any third party and we do not use it for marketing without your separate, clear, and voluntary consent. Consent can be withdrawn at any time using the same channels through which it was given.
We do not make automated decisions producing legal or similarly significant effects on the user within the meaning of Art. 22 GDPR. AI responses in the chatbot widget are informational and are not, in themselves, considered such decisions.
5. Recipients and processors
We share data only to the extent necessary to provide the service and meet legal duties:
- Stripe Payments Europe, Ltd. — payment processing, subscription management, invoice generation. Stripe privacy policy: stripe.com/privacy.
- OpenAI, L.L.C. — the AI model service used to generate chatbot responses. Only the chatbot conversation context (messages, knowledge-base extracts) is sent to the OpenAI API to the extent needed to produce an answer. The user’s email address, password, and other account data are NOT transferred to the AI model service. OpenAI privacy policy: openai.com/policies/privacy-policy.
- Hosting and infrastructure providers (servers, databases, caches), with whom we have signed data processing agreements.
- Email delivery providers (transactional emails: registration codes, password resets, invoices, system notifications).
- Professional advisers (lawyers, auditors, accountants) where necessary and proportionate.
- Public authorities and law enforcement when required by applicable law or lawful orders.
Each processor has its own privacy policy and is responsible for the data it processes. We sign data processing agreements compliant with Art. 28 GDPR and apply appropriate contractual, technical, and organisational safeguards.
6. International transfers
If data is transferred outside the European Economic Area, we ensure a lawful transfer and appropriate safeguards (e.g. European Commission standard contractual clauses or other lawful transfer mechanisms).
7. Retention
We keep data for as long as needed for the purposes in this policy, to perform our contracts, and to meet legal obligations.
- account data for the life of the account and a reasonable period after closure;
- accounting and payment data for periods required by law;
- security logs for as long as needed for incident prevention and investigation.
8. Your rights
Under the GDPR you have the following rights:
- the right to access your data;
- the right to rectification of inaccurate data;
- the right to erasure (“right to be forgotten”) where applicable;
- the right to restrict processing;
- the right to data portability where applicable;
- the right to object to processing based on legitimate interests;
- the right to withdraw consent where processing is based on consent.
To exercise your rights, write to us at support@b-mod.com.
9. Cookies and similar technologies
The Platform uses only essential technical cookies and similar technologies required for authentication, maintaining a signed-in session, remembering the user’s language choice, and core security and service features. Under the ePrivacy Directive these cookies do not require consent.
We do not use advertising, profiling, or third-party marketing cookies. If we ever introduce analytics cookies, they will be enabled only with the user’s prior consent through a cookie banner, and consent will be revocable at any time.
All data transmitted between your browser and the Platform’s servers is encrypted using HTTPS / TLS.
10. Security and liability
We use reasonable technical and organisational measures, but we cannot guarantee absolute security of data on the internet.
You are responsible for the security of your login credentials, access control, the lawfulness of data you upload, and your own backups. To the extent permitted by the law of the Republic of Lithuania and the European Union, we are not liable for damage caused by unlawful third parties, your errors, or improper use of the Platform.
11. Complaints and supervisory authority
If you believe we process your data unlawfully, please contact us first so we can try to resolve the issue promptly.
You also have the right to lodge a complaint with the State Data Protection Inspectorate of Lithuania (VDAI) or another competent EU supervisory authority in your place of residence.
12. Policy changes
We may update this privacy policy from time to time. The updated version is published on this page with a new effective date.
Where the law requires, we will inform you of material changes via the Platform or by email.