πŸ”’ Legal Document

Privacy Policy

At ChatBucket, privacy is a foundational design principle not an afterthought. This Privacy Policy governs the collection, processing, storage, and lawful disclosure of personal data across every surface of the ChatBucket platform: our web and mobile applications, conversational AI infrastructure, REST and Webhook APIs, SDKs, and all associated services. We operate under a data-minimisation philosophy: we collect only what is necessary, retain it only as long as required, and never monetise it through third-party advertising.

πŸ“… Effective: April 2026
🏒 ChatBucket Technologies Pvt. Ltd.
βš–οΈ GDPR Β· CCPA Β· PIPL Β· DPDP Act 2023 Β· ISO 27001-aligned
1

Who We Are and How to Contact Us

Who we are: ChatBucket Technologies Pvt. Ltd. ("ChatBucket", "we", "us", or "our") is an AI-native communication infrastructure company incorporated in India. We develop and operate the ChatBucket platform a conversational AI substrate that enables businesses to deploy intelligent chat agents across WhatsApp, web, mobile, SMS, and email channels from a single unified configuration.

Registered address: Plot No. 106, Shalivahana Nagar Road, Srinagar Colony, SBH Colony, Yousufguda, Hyderabad, Telangana 500073, India.

Privacy contact: For data subject requests, regulatory inquiries, or privacy-related correspondence, reach our Privacy team at hello@chatbucket.business. We acknowledge all requests within 72 hours and resolve them within the statutory 30-day window.

This Privacy Policy fulfils our transparency obligations under the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), China's Personal Information Protection Law (PIPL), and India's Digital Personal Data Protection Act 2023 (DPDP Act). Material revisions are published on this page with a revised effective date.

2

Our Relationship to You

The legal character of our data relationship depends on how you interact with ChatBucket's infrastructure:

  • Visitor / Prospect: Interacts with our public-facing surfaces without an authenticated account. ChatBucket operates as an independent data controller for all session, analytics, and contact data collected in this context.
  • User (Developer / Merchant Admin / Operator): Holds an authenticated ChatBucket account and interacts directly with the platform, APIs, or dashboard. ChatBucket is the data controller for account, usage, telemetry, support, and billing data.
  • Customer (Merchant / Developer Organisation): A business entity under a commercial agreement with ChatBucket. ChatBucket is the data controller for personal data we independently collect about the Customer's authorised representatives.
  • End User (processed on behalf of a Customer): A natural person whose personal data is ingested into ChatBucket's processing infrastructure by a Customer through our platform interfaces or APIs. In this context, ChatBucket operates exclusively as a data processor acting under the Customer's documented instructions, governed by our Data Processing Agreement (DPA). The Customer retains the role of data controller and bears primary compliance accountability for the lawfulness of that processing.
3

Your Rights Relating to Your Personal Data

Depending on your jurisdiction of residence, you hold enforceable rights over personal data that ChatBucket controls. These rights are exercisable through a verified data subject request submitted to hello@chatbucket.business. We do not condition access to our services on the waiver of any privacy right.

πŸ‘Right of Access

Obtain a structured copy of your personal data and verify that it is being processed lawfully and on a valid legal basis.

✏️Right to Rectification

Compel correction of inaccurate or incomplete personal data held within our systems without undue delay.

πŸ—‘οΈRight to Erasure

Request permanent deletion of your personal data where no overriding legal obligation or legitimate interest exists to justify continued retention.

🚫Right to Object

Object to processing operations grounded in legitimate interest or direct marketing, including AI-driven profiling derived from your interactions.

⏸️Right to Restrict Processing

Request a processing moratorium on your data while accuracy is contested or an objection is pending adjudication.

πŸ“¦Right to Data Portability

Receive your personal data in a machine-readable, interoperable format (JSON / CSV) for transmission to another controller.

↩️Right to Withdraw Consent

Revoke any consent-based processing at any time; withdrawal is prospective and does not invalidate prior lawful processing.

βš–οΈNon-Discrimination Β· Grievance (CCPA / DPDP) ✦

California residents are protected against discriminatory service denial for exercising CCPA rights. Indian residents may additionally lodge a grievance with our Grievance Officer under DPDP Act Section 13, with escalation rights to the Data Protection Board of India.

To exercise any right, write to hello@chatbucket.business. We will verify your identity before processing requests and respond within 30 days. Requests are processed free of charge unless manifestly unfounded or excessive.

4

Whose Personal Data We Collect

  • Visitors / Prospects: Individuals browsing our website, developer documentation, or marketing surfaces
  • Users: Authenticated individuals operating ChatBucket's platform, SDKs, APIs, or mobile applications
  • Customers (Merchant / Developer Orgs): Authorised company contacts administrators, developers, billing contacts, and technical liaisons
  • End Users of Customer Deployments: Natural persons whose conversational data traverses ChatBucket's AI processing infrastructure via a Customer's integration. ChatBucket processes this data strictly as a sub-processor; the originating Customer remains the data controller accountable under applicable law.
  • Enquirers: Any individual who submits data via a contact form, support ticket, or direct privacy correspondence
  • Candidates: Job applicants whose personal data is provided in the context of a recruitment process
  • Third-party sourced data: Identity verification results from authorised KYC partners, enriched contact data from B2B intelligence services where lawfully permitted, and telemetry signals relayed by cloud infrastructure, CDN, and communications sub-processors bound by data processing agreements.
5

When We May Process Your Personal Data

ChatBucket processes personal data only when a valid lawful basis under GDPR Article 6 (and equivalent provisions of the DPDP Act, CCPA, and PIPL) applies. We rely on the following bases across our processing activities:

  • Consent (Art. 6(1)(a)): Where you have freely given, specific, informed, and unambiguous consent for example, when subscribing to marketing communications or enabling optional analytics integrations.
  • Contractual Necessity (Art. 6(1)(b)): Where processing is required to perform a contract to which you are party, including account provisioning, platform delivery, billing, and API access management.
  • Legal Obligation (Art. 6(1)(c)): Where we are subject to a binding legal duty including KYC/AML obligations, tax record-keeping, court orders, or regulatory disclosure requirements.
  • Legitimate Interests (Art. 6(1)(f)): Where processing is necessary for purposes that are not overridden by your fundamental rights including fraud prevention, platform security, abuse detection, and service analytics. We conduct a Legitimate Interests Assessment (LIA) / balancing test before relying on this basis for any non-trivial processing activity.
6

What Personal Data We Collect

ChatBucket's data collection architecture operates across three ingestion pathways: data you actively provide during account lifecycle events; data generated automatically as a by-product of your interaction with our platform's runtime and infrastructure layers; and data received from authorised third-party sub-processors that support secure, compliant service delivery.

Data You Actively Provide

  • Identity & Contact: Full name, verified email address, phone number, postal address, organisation name, and professional role
  • Account & Credential Data: Username, hashed authentication credentials, MFA configuration, and user preference state
  • KYC / AML (when mandated): Government-issued identity document details, biometric liveness samples, proof-of-address documentation, and sanctions-screening outcomes
  • Financial / Billing: Billing contact details, invoice records, and payment instrument metadata. ChatBucket does not store Primary Account Numbers (PANs) or full card credentials at any layer of its infrastructure.
  • Developer & Integration Configuration: API key identifiers, Webhook endpoint URIs, OAuth scopes, and third-party channel integration settings
  • Conversational & Content Data: Messages, media attachments, and structured data payloads transmitted through your ChatBucket-powered agents. ChatBucket does not use Customer or End User conversational data to train shared foundation models without explicit, opt-in contractual consent.
  • Support & Communications: Helpdesk tickets, feature requests, survey responses, and inbound correspondence

Data Generated Automatically

  • Log & Device Telemetry: IP address, device fingerprint, OS and application version, screen/page views, HTTP referrers, error traces, and crash diagnostics
  • Platform Observability Data: API call volumes and latency distributions, SDK initialisation events, authentication event streams, agent resolution rates, and infrastructure reliability metrics collected to maintain the operational integrity and performance SLAs of the platform.
  • Security & Fraud Signals: Anomalous access pattern indicators, brute-force detection events, IP reputation signals, and immutable audit trail records
  • Approximate Location: Coarse geolocation inferred from network IP or device locale settings, where permitted by user configuration
  • Voice / Media Streams (feature-specific): When voice, video transcription, or accessibility features are active, we transiently process the media payload necessary to deliver the feature.

Data Received from Authorised Sub-Processors

  • Identity Verification Partners: KYC verification outcomes, document authenticity scores, and AML screening results
  • Payment & Financial Infrastructure: Transaction status signals and reconciliation metadata (never full PANs)
  • Cloud, Security & CDN Providers: Service delivery telemetry from AWS (primary compute), Cloudflare (edge security), and Google Workspace
  • Connected Third-Party Integrations: Data exchanged with messaging platforms, CRM systems, and e-commerce connectors that you explicitly authorise

ChatBucket may derive aggregated, irreversibly de-identified analytics from platform usage data for product development and performance benchmarking.

Children's Data: The ChatBucket platform and its APIs are not designed for or directed to individuals under the age of 18. We do not knowingly ingest personal data from minors. If you believe a child under 18 has submitted personal data, please notify us at hello@chatbucket.business immediately.

7

How We Use Cookies and Tracking Technologies

ChatBucket deploys cookies and analogous client-side persistence mechanisms to enable core platform functionality, maintain authenticated session state, and collect anonymised behavioural analytics. We operate a consent-first cookie governance model: non-essential tracking technologies are not activated until you have granted explicit, granular consent via our cookie preference interface.

Cookie Classification

CategoryPurposeRetention
Strictly NecessaryPrerequisite for platform operation. Maintains authenticated session state, CSRF protection tokens, and security controls. Cannot be disabled without degrading core functionality.Session
Analytics & PerformanceCaptures anonymised interaction telemetry to drive evidence-based product improvements. No cross-site tracking.Up to 2 years
Functional / PreferencePersists user-configured preferences including locale, accessibility display settings, and dashboard layout state across sessions.Up to 1 year
Security & IntegritySupports bot detection, credential-stuffing prevention, and platform integrity monitoring. Signals are not shared with advertising networks.Session – 1 year
AI Personalisation ✦Stores anonymised agent interaction signals to tune response quality for your account. Opt-out available in account settings without service degradation.Up to 90 days

You may configure browser-level cookie controls or use our in-platform preference manager at any time. Disabling non-essential cookies does not affect your ability to use core ChatBucket features. Visit allaboutcookies.org for independent guidance.

8

How We Use Your Personal Data and Why

Every processing purpose below is tied to a defined lawful basis. We do not repurpose personal data for secondary uses materially incompatible with the original collection context without notifying you and, where required, obtaining fresh consent.

  • Provisioning, operating, and continuously improving the ChatBucket platform and its conversational AI runtime
  • Managing account lifecycles, subscription entitlements, and platform access authorisation
  • Delivering timely, context-aware technical and customer support
  • Conducting quantitative and qualitative research including A/B experimentation, agent resolution benchmarking, and model quality assessments to advance the reliability and intelligence of the platform
  • Verifying user and merchant identity and operationalising fraud prevention, abuse detection, and AML compliance controls
  • Discharging legal and regulatory obligations including KYC/AML requirements, tax record-keeping, and mandatory regulatory reporting
  • Asserting and enforcing contractual rights under our Terms of Service and Data Processing Agreements
  • Transmitting service-critical communications including security incident notifications, API deprecation alerts, policy change disclosures, and platform status updates through authenticated, permission-scoped notification channels

ChatBucket does not engage in solely automated individual decision-making that produces legal or equivalently significant effects without implementing mandatory human-review safeguards. Where AI-driven signals influence a consequential outcome, you may request human oversight of the automated determination where applicable law so provides.

9

Who We Share Your Personal Data With

  • With Your Explicit Consent: We disclose personal data to third parties only where you have provided a clear, affirmative, and freely revocable authorisation.
  • Authorised Sub-Processors: Cloud compute infrastructure (AWS India ap-south-2, Hyderabad), edge security and CDN (Cloudflare), and internal productivity tooling (Google Workspace). All sub-processors are vetted, contractually bound by a Data Processing Agreement, and listed in our public Sub-Processor Register. We provide 30-day advance notice of material sub-processor changes.
  • KYC / Identity Verification Partners: Verification data is transmitted exclusively to RBI-authorised identity verification providers for the limited purpose of identity authentication and AML screening.
  • Payment & Financial Infrastructure Partners: Only tokenised payment status signals and reconciliation metadata are exchanged. Full card PANs are never transmitted to or stored within ChatBucket's systems.
  • Legal & Regulatory Authorities: Disclosure to competent legal authorities where compelled by valid court order, statutory obligation, or to protect the life, safety, or fundamental rights of individuals.
  • Corporate Transactions: In the event of a merger, acquisition, restructuring, or divestiture, personal data may be transferred as part of the transaction subject to (i) advance notice to affected users, (ii) data continuity assurances, and (iii) the successor entity's assumption of equivalent privacy obligations.

ChatBucket maintains a strict zero-data-sale policy: we do not sell, rent, broker, or otherwise monetise your personal data to any third party for advertising, targeting, or profiling purposes under any commercial arrangement or jurisdiction.

10

How Long We Store Your Personal Data

ChatBucket applies a tiered data retention architecture calibrated to processing purpose, contractual necessity, and statutory obligation. Retention periods are automatically enforced through our data lifecycle management pipeline.

  • Active Service Tenure: Personal data is retained for the full duration of your active account or subscription relationship and for the period required to deliver contracted services.
  • Post-Termination Operational Buffer: A minimum 60-day retention window applies following account termination, providing a recovery period for dispute resolution, final billing reconciliation, and statutory audit trails.
  • KYC / AML Records: Identity verification records are retained for a statutory minimum of 5 years post-account closure, in compliance with PMLA and equivalent requirements.
  • Conversational Payload Data: End-user message data processed through the ChatBucket runtime is subject to a 90-day rolling retention window by default, configurable by the Customer in their DPA supplement. End-to-end encrypted messaging payloads are not stored server-side beyond the in-flight processing window.

At the expiry of each applicable retention window, personal data is subject to secure, irreversible deletion or technical anonymisation through a verified data destruction protocol.

11

Where We Store Your Personal Data

ChatBucket's production workloads are deployed on AWS India (ap-south-2 Hyderabad) as the primary compute and storage region, with DigitalOcean as a secondary compute substrate. All data-at-rest is encrypted using AES-256. All data-in-transit is protected by TLS 1.3. Automated encrypted backups are replicated within the same sovereign boundary. Edge traffic is routed through Cloudflare's global network for DDoS mitigation and WAF protection.

Cross-Border Transfer Mechanisms

  • EU / UK: Transfers to third countries rely on European Commission-approved Standard Contractual Clauses (SCCs, 2021 edition) and the UK International Data Transfer Addendum (IDTA).
  • California (CCPA): Downstream sub-processors serving California residents are contractually required to honour all CCPA consumer rights and maintain equivalent privacy standards.
  • India (DPDP Act 2023): KYC and sensitive personal data is stored exclusively within Indian sovereign territory. All other processing adheres to data-minimisation and proportionality principles under DPDP Act obligations.
  • China (PIPL): Where ChatBucket processes personal information of Chinese data subjects, we obtain required statutory consents and rely on PIPL-compliant cross-border transfer mechanisms, including standard contracts approved by the CAC.

✦ Data Protection Impact Assessments (DPIAs)

  • ChatBucket conducts DPIAs for all high-risk processing activities, including large-scale processing of sensitive data, systematic automated profiling, and deployment of new AI inference capabilities.
  • DPIA outcomes inform architectural design decisions and are reviewed annually or upon material change to the processing context.
  • Where a DPIA identifies a high residual risk that cannot be mitigated, we consult the relevant supervisory authority prior to commencing processing.
12

How We Protect Your Personal Data

ChatBucket implements a defence-in-depth security posture aligned with ISO/IEC 27001 principles and OWASP best practices. Our controls span the full technology stack from network perimeter to application layer to data persistence.

  • Encryption in Transit: TLS 1.3 is enforced across all API endpoints, dashboard interfaces, and Webhook delivery channels. Downgrade attacks to TLS 1.2 or below are blocked at the edge.
  • Encryption at Rest: AES-256 encryption is applied to all persistent data stores, encrypted backup volumes, and KYC document archives.
  • Zero-Trust Access Controls: Production system access is governed by role-based access control (RBAC) implemented on a principle of least privilege. Privileged access requires just-in-time (JIT) authorisation, session recording, and mandatory MFA including hardware security keys for engineering staff with database access.
  • Continuous Security Assurance: We conduct quarterly penetration testing by independent security researchers, monthly automated vulnerability scanning, and continuous SAST within our CI/CD pipeline.
  • Incident Response & Breach Notification: ChatBucket maintains a documented incident response plan with defined escalation paths. In the event of a personal data breach meeting the GDPR notification threshold, we notify the relevant supervisory authority within 72 hours of confirmed detection and affected individuals without undue delay.
  • Privacy by Design: New platform features and infrastructure changes undergo mandatory privacy impact review before deployment, ensuring that data protection obligations are embedded at the architectural level.
  • Employee Security Training: All staff with access to personal data complete annual data protection and information security training.

User Responsibility: ChatBucket cannot guarantee the security of your personal data if you share your authentication credentials, API keys, or session tokens with any unauthorised third party. Enable MFA on your account. Report suspected credential compromise to security@chatbucket.business immediately.

13

Links to External Platforms

The ChatBucket platform, developer documentation, and dashboard may contain hyperlinks or embedded integrations that route to external services not owned or operated by ChatBucket Technologies Pvt. Ltd. including third-party channel platforms, payment gateways, identity verification portals, and partner developer ecosystems. Once a data subject navigates beyond ChatBucket's infrastructure perimeter, this Privacy Policy ceases to govern the collection and processing of their personal data. ChatBucket assumes no liability for the data practices, accuracy, or security posture of external platforms. We strongly recommend reviewing the privacy policy and terms of service of any third-party service before submitting personal data.

14

Customer Obligations to Respect Individual Users' Rights

Customers who integrate ChatBucket's APIs and platform infrastructure to process the personal data of their own end users assume the role of data controller under GDPR, DPDP Act, and equivalent frameworks. ChatBucket operates exclusively as a data processor in this context, acting under documented Customer instructions and governed by a binding Data Processing Agreement (DPA).

  • Customers are independently responsible for establishing and maintaining a valid lawful basis for all personal data processing activities they orchestrate through ChatBucket's infrastructure.
  • Where ChatBucket acts as data processor, our obligations including sub-processor management, security controls, breach notification timelines, and data subject request facilitation are codified in the executed Data Processing Agreement (DPA). Customers who require a DPA should contact hello@chatbucket.business.
  • Customers must implement privacy notices that accurately describe ChatBucket's role as a processing sub-contractor and obtain all legally mandated consents from their end users before routing personal data through the platform.
  • ChatBucket accepts no liability for a Customer's independent data controller obligations, including non-compliant data collection, unlawful secondary processing, inadequate notice provision, or failure to honour data subject rights arising outside the scope of our contracted services.
15

Changes to Our Privacy Policy

ChatBucket reserves the right to revise this Privacy Policy at any time to reflect changes in our processing activities, legal obligations, or platform capabilities. All revisions are published on this page with an updated effective date and incremented version identifier.

Material Changes: Where a proposed revision materially affects how we process your personal data, we will provide advance notice via (i) an in-platform banner, (ii) an email notification to your registered address, and (iii) a highlighted changelog entry on this page, no fewer than 30 days before the change takes effect.

Acceptance: Continued use of the ChatBucket platform following the effective date of any revision constitutes your acknowledgement and acceptance of the updated terms. If you do not agree to a material change, you may terminate your account before the effective date and submit a data deletion request to hello@chatbucket.business.

πŸ“¬ Privacy Inquiries & Data Subject Requests

βœ‰οΈEmail: hello@chatbucket.business all requests acknowledged within 72 hours
πŸ“Plot No. 106, Shalivahana Nagar Road, Srinagar Colony, SBH Colony, Yousufguda, Hyderabad, Telangana 500073, India
⏱We resolve all verified data subject requests within 30 days of confirmed receipt (or within the shorter statutory window mandated by your jurisdiction).
πŸ›‘Grievance Officer (DPDP Act, India): Indian residents may address grievances to our designated Grievance Officer at grievance@chatbucket.business. Unresolved grievances may be escalated to the Data Protection Board of India upon its constitution under the DPDP Act 2023. ✦
πŸ”—EU/UK residents may also lodge a complaint with their local data protection supervisory authority (e.g., ICO for UK, relevant DPA for EU Member States) if they are dissatisfied with our response.

Upgrade your reality

Join the waitlist and get priority access

@2026 ChatBucket. All rights reserved