- Home
- Privacy
Privacy policy
Written to be read. If anything here is unclear, email privacy@openline.ai and we'll answer in plain language.
1. Who this covers
This policy covers two different groups of people, and the difference matters:
- Customers — businesses and their team members who hold an Openline account and configure an AI website agent.
- Visitors — people who talk to an Openline agent installed on a customer's website.
For customer account data, Openline is the data controller. For conversations between a visitor and an agent, the customer is the controller and Openline acts as a processor on their instructions. If you are a visitor and want your conversation deleted, the fastest route is usually the business whose website you were on — though you can also write to us and we will pass the request on and act on it.
2. What we collect
Account and billing data
- Name, work email, password hash, and company name
- Billing contact, billing address and tax identifiers
- Payment card details are handled by our payment processor. We never see or store full card numbers.
Configuration and knowledge data
- The website addresses you connect and the pages retrieved from them
- Documents, FAQs, product information and instructions you upload or write
- Agent settings — tone, branding, qualification questions, escalation rules
Please don't upload personal data about your customers into the knowledge base. It is designed to hold the information you would happily publish on your own website.
Conversation data
- Messages exchanged between a visitor and the agent
- Any details the visitor chooses to give — typically name, email, phone, company and requirement
- Page the conversation started on, referring source, approximate location derived from IP, browser and device type, and timestamps
Product and website usage
- Log data — IP address, pages requested, errors, and performance timings
- Dashboard usage, so we can see which features are actually used
- Cookies as described in section 8
3. Why we use it
| Purpose | Data used | Basis |
|---|---|---|
| Providing the service — running agents, generating replies, capturing leads | Configuration, knowledge, conversation | Performance of contract |
| Billing and account administration | Account, billing | Performance of contract |
| Support and troubleshooting | Account, logs, conversation (on request) | Legitimate interests |
| Security, fraud and abuse prevention | Logs, account | Legitimate interests |
| Improving reliability and product quality | Aggregated usage, error data | Legitimate interests |
| Product and marketing email to customers | Account | Consent or legitimate interests, with opt-out in every message |
| Meeting legal and tax obligations | Billing, account | Legal obligation |
4. What we do not do
- We do not sell personal data, and we do not share it with advertising networks.
- We do not use one customer's conversations or knowledge base to answer another customer's visitors.
- We do not allow third-party model providers to train their models on your content. Content sent for processing is submitted under agreements that prohibit training use.
- We do not read your conversations for curiosity. Access by our staff is limited to the cases in section 6.
5. Who we share it with
We use a small number of sub-processors to run the service. Each is bound by a data processing agreement and receives only what it needs:
- Cloud hosting and databases — storage and compute for the application
- AI model providers — generating replies from your knowledge and the visitor's message
- Payment processing — subscriptions, invoices and card handling
- Transactional email — verification, alerts and notifications
- Error monitoring and analytics — reliability and performance
A current, named list with locations is available at privacy@openline.ai on request, and we give notice of material changes to customers. We also share data where an integration you configured requires it — if you connect a CRM, leads and transcripts go to that CRM because you told us to.
6. Staff access
Openline staff access customer content only when: you ask us to as part of a support request; we are investigating a security incident or suspected abuse; or the law requires it. Access is role-restricted and logged.
7. How long we keep it
- Conversations and leads — retained for as long as your account is active, with a configurable retention window. You can set automatic deletion after 30, 90, 180 or 365 days.
- Knowledge sources — until you delete them or close your account.
- Account and billing records — kept for as long as required by tax and accounting law after the account closes.
- Server logs — a rolling short-term window for security and debugging.
When an account is closed, content is deleted or irreversibly anonymised within 30 days, other than records we must keep by law. Backups age out on their own cycle.
8. Cookies
On this website we use cookies that are strictly necessary for it to work, and privacy-respecting analytics to understand which pages are useful. The chat widget on a customer's site sets a first-party identifier so a visitor's conversation survives a page refresh — it is not used for cross-site tracking or advertising.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to receive a portable copy, and to withdraw consent. Customers can do most of this themselves in the dashboard — export and deletion are built in. For anything else, write to privacy@openline.ai and we will respond within 30 days. If you're unhappy with our response you can complain to your local data protection authority.
10. International transfers
Our infrastructure and sub-processors may process data in countries other than yours. Where that happens, transfers are covered by appropriate safeguards such as standard contractual clauses. Enterprise customers can discuss data residency options with us.
11. Security
Encryption in transit and at rest, role-based access control, tenant isolation and logged administrative access. The detail is on the security page. No system is perfectly secure; if we become aware of a breach affecting your data we will tell you promptly and tell you what we know.
12. Children
Openline is a business product and is not directed at children. We do not knowingly collect personal data from children. If a customer's agent is likely to be used by minors — a school or coaching institute, for example — that customer is responsible for handling consent under their local law.
13. Changes to this policy
We'll update this page when the product changes, and note the date at the top. For material changes affecting customers, we give notice by email before they take effect.
14. Contact
Privacy questions, data requests and complaints: privacy@openline.ai. Security matters: security@openline.ai. Anything else: contact us.