ProductUse casesPricingBlogContact
Dashboard Sign in Start free
Artificial Intelligence in Business

What a Chatbot Privacy Notice Should Tell Your Customers

What a Chatbot Privacy Notice Should Tell Your Customers

A chatbot privacy notice tells visitors who runs the chat, what they may type into it, why those messages get processed, who else receives them, how long they’re kept and how to use their rights. Plenty of small companies add a chat widget first and only later realise their privacy policy covers contact forms and newsletters but says nothing about conversations. Sound familiar? What follows is a practical checklist with example wording you can adapt. It isn’t legal advice, though, so have the final text reviewed by someone who knows your setup.

What does a chatbot actually collect?

Messages visitors type, anything personal they decide to share, and technical data about the device and session. Map this before you write a single sentence of the notice. In practice, personal data in chatbot conversations tends to land in a few buckets:

  • the text of questions and answers, stored as transcripts
  • details visitors volunteer, such as names, email addresses, order numbers, health or financial information
  • technical data: IP address, browser type, timestamps
  • cookie or session identifiers that link messages to one visitor

And yes, technical data counts. Recital 30 of the GDPR names IP addresses and cookie identifiers as online identifiers that can be combined to profile and identify people. People also type things you never asked for (they always do), so the notice has to cover free text, not just the fields you designed. Ask your chatbot provider exactly what gets logged, where it’s stored and for how long. If you’re still evaluating a tool, you can ask us about data handling before you sign up.

The chatbot privacy notice checklist

A complete chatbot privacy notice covers the same core points as any GDPR notice, just applied to chat data. Start with the controller, meaning the company that decides why and how the data is processed. That’s you. Not the chatbot vendor. Then go down this list:

  • identity and contact details of the controller
  • contact details of your data protection officer, if you have one
  • purposes for processing chat data
  • the legal basis for each purpose
  • recipients and processors
  • transfers outside the EU, if any
  • the retention period or the criteria used to set it
  • data subject rights, such as access, rectification and erasure
  • the right to lodge a complaint with a supervisory authority
  • whether any automated decision-making takes place

How you say it matters as much as what you say. The transparency principle in recital 39 expects information that’s easy to access, easy to understand and written in clear, plain language. So drop the legalese. Describe what your chat really does, the way you’d explain it to a customer on the phone.

Which legal basis fits chatbot conversations under the GDPR?

Most support chats rest on steps taken at the visitor’s request or on legitimate interest. Consent comes in for the extras, like marketing use or non-essential cookies. Each purpose needs its own basis, and the notice should pair them explicitly rather than lumping everything together.

Consent sets a high bar. The GDPR recitals 32 and 40 explain that consent requires a clear affirmative act (silence or pre-ticked boxes don’t count), and that processing needed for a contract or for pre-contract steps requested by the person is a separate lawful basis. Which is exactly why a lone, vague line like “by using the chat you agree to our terms” falls flat. It names no purpose and it doesn’t get you valid consent either.

Example wording: “We use your messages to answer your question about our products. The legal basis is taking steps at your request before a possible contract.”

How long are chat logs kept and who sees them?

State a concrete chatbot data retention period, or at least the rule you use to set one. The GDPR’s transparency principle asks controllers to set time limits for erasure or for periodic review. “As long as necessary” on its own? Too thin.

Then list who can read transcripts, at minimum by category: your own staff, the chatbot provider acting as processor, and any hosting or AI model subprocessors it relies on. A short word on security helps too, for example whether you use HTTPS encryption of conversations in transit. If someone on your team follows up a chat by email or phone, say so in the notice, because the data then moves into another channel. If your process includes that step, the wider topic of passing chats to humans is worth a read.

Example wording: “We delete chat transcripts after [period]. Our chatbot provider processes them on our behalf under a data processing agreement.”

Where should privacy information for chat users appear?

Layers work best here. A short line inside the widget before the first message, plus a link to the full notice. Visitors get the essentials right when they start typing, and the details sit one click away for anyone who cares.

Example widget text: “This assistant answers from our website content. Do not share sensitive data. How we handle your messages: [privacy notice link]”. Spell out what not to type, such as health details or card numbers. A generic warning is easy to scroll past. To publish the change:

  1. Add a chatbot section to your main privacy policy.
  2. Place the short notice line in the widget.
  3. Check that your cookie banner covers any cookies the chat sets.
  4. Record the date of the change in the policy.

Common gaps in chatbot privacy notices

The usual gaps involve data nobody thought of as chat data. Documents uploaded as bot sources can contain personal details of employees or customers, so clean documents before uploading them and strip out anything the bot should never repeat.

A few other repeat offenders:

  • using transcripts to improve answers or train models without saying so
  • copying the vendor’s policy instead of describing your own processing
  • leaving the notice unchanged after switching the bot, the provider or the purposes

A good chatbot privacy notice mirrors what the chat really collects and who touches it. Nothing more. Review it whenever the setup changes, not once a year out of habit.

FAQ

Do I need a separate privacy notice just for the chatbot?

Not necessarily. A dedicated section in your main privacy policy plus a short notice inside the widget usually does the job. What counts is that the chat processing is described specifically, not buried under general website language.

Is a chatbot vendor responsible for my GDPR obligations?

No. The company running the chat on its website is the controller and has to inform users. The vendor is a processor, working on your instructions under a data processing agreement.

What if a visitor shares sensitive data in the chat?

Your notice should ask users not to share that kind of information, and your team needs a clear rule for deleting those messages when they show up anyway. Health data is a special category under the GDPR, so treat it with extra care even when it arrives unrequested.