Privacy Policy
Your privacy matters. Learn how we protect your data.
1. Introduction and Data Controller
We appreciate your interest in our website and services. The protection of your personal data is of particular importance to us. We therefore process your data exclusively on the basis of legal provisions (GDPR, Austrian TKG 2003).
Data Controller:
Thomas Schärer
Ebentaler Straße 100A
9020 Klagenfurt am Wörthersee
Austria
Email: contact@sbotify.com
2. What Data We Collect
2.1 When Using Our Website
When you visit our website, the following data is automatically collected:
- IP address (anonymized)
- Date and time of access
- Browser type and version
- Operating system
- Referrer URL
- Pages visited
2.2 During Registration
When you create an account, we collect:
- First and last name
- Email address
- Password (stored encrypted)
- Company name (optional)
2.3 When Using Our Services
To provide our chatbot services, we process:
- Website URLs you want to scan
- Scraped content from your website (for knowledge base)
- Third-party API keys (OpenAI, Claude, Gemini)
- Chat histories and conversations
- Usage statistics
3. Purpose of Data Processing
We process your data for the following purposes:
- Providing and improving our services
- Creating and managing your user account
- Technical support and customer service
- Security and fraud prevention
- Fulfilling legal obligations
- Billing and payment processing (for paid plans)
4. Legal Basis
The processing of your data is based on the following legal grounds:
- Art. 6(1)(a) GDPR: Consent (e.g., for cookies, newsletters)
- Art. 6(1)(b) GDPR: Contract performance (using our services)
- Art. 6(1)(c) GDPR: Legal obligation
- Art. 6(1)(f) GDPR: Legitimate interest (website optimization, security)
5. Storage Duration
We store your data only as long as necessary for the stated purposes:
- Account data: Until account deletion
- Chat histories: 12 months (or until deletion upon request)
- Invoice data: 7 years (legal retention requirement)
- Server logs: 30 days
6. Data Sharing
We only share your data in the following cases:
- AI Services: When using our chatbots, requests are forwarded to your chosen AI providers (OpenAI, Anthropic, Google). These are subject to their own privacy policies.
- Payment Providers: Stripe for billing purposes
- Hosting Provider: Our server host for technical provision
- Legal Requirement: In response to official requests
7. Cookies and Tracking
Our website uses the following types of cookies:
- Necessary Cookies: Required for website functionality
- Preference Cookies: Store your language settings
- Analytics Cookies: For website improvement (only with consent)
You can change your cookie settings at any time.
8. Your Rights
As a data subject, you have the following rights:
- Access (Art. 15 GDPR): Information about your stored data
- Rectification (Art. 16 GDPR): Correction of inaccurate data
- Erasure (Art. 17 GDPR): "Right to be forgotten"
- Restriction (Art. 18 GDPR): Restriction of processing
- Data Portability (Art. 20 GDPR): Export of your data
- Objection (Art. 21 GDPR): Objection to processing
- Complaint: To the data protection authority
Austrian Data Protection Authority
Barichgasse 40-42, 1030 Vienna
Tel: +43 1 52 152-0
Email: dsb@dsb.gv.at
Web: www.dsb.gv.at
9. Data Security
We implement the following security measures:
- SSL/TLS encryption for all data transfers
- AES-256 encryption for API keys
- Regular security updates
- Access controls and authentication
- Regular backups
10. International Data Transfer
When using AI services, data may be transferred to third countries (USA). We ensure that your data is adequately protected through standard contractual clauses and appropriate safeguards.
11. Changes to This Privacy Policy
We reserve the right to adapt this privacy policy as needed. The current version is always available on this page.
Last updated: February 2026