Draft — pending legal review. This document was prepared to reflect the actual data flows in the product and has not yet been reviewed by a lawyer. Do not treat it as final until reviewed by qualified counsel, particularly regarding GDPR representative/DPO requirements if EU visitor volume becomes significant.
This policy explains how Agent AI Chat, operated by Zihad Hosan (Bangladesh), handles personal data. It covers two groups differently:
When someone chats with an embedded widget, we process the messages they send and the AI-generated replies in order to run the conversation and generate grounded answers. This includes sending message content to our LLM provider (see Section 6) to generate a response. We do not knowingly use end-visitor chat content to train models, and we do not sell it.
We do not sell personal data, and we do not use it for third-party advertising.
Application data (accounts, content, chat sessions and messages) is stored in a managed Postgres database hosted in the AWS eu-west-2 (London) region. Application hosting runs on Vercel's global infrastructure.
We use the following sub-processors to operate the Service:
The full list with roles is in the Data Processing Addendum. We'll update this list if sub-processors change.
Depending on where you're located, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. Customers can exercise these rights for their own account data via their dashboard or by contacting us. End visitors should direct data requests about their chat data to the website operator (the Customer) they chatted with, who can in turn request deletion or export from us as their processor. You can also contact us directly at hello@zihadhosan.dev and we will route the request appropriately.
Deleting a Customer account triggers erasure of that tenant's data — content, FAQs, chat sessions and messages, and account records — from our production database. This is a manual, verified process today pending fuller self-service tooling.
Passwords are hashed, not stored in plain text. Access to production data is limited to the operator. Data in transit is encrypted (HTTPS/TLS). No method of storage or transmission is 100% secure, and we can't guarantee absolute security.
The Service is not directed at children under 16, and we do not knowingly collect personal data from them. If a Customer configures a widget for a website directed at children, they are responsible for ensuring that use complies with applicable law (e.g. COPPA, GDPR-K).
Data may be processed in Bangladesh (by the operator) and in the hosting regions of our sub-processors (primarily the EU/UK for database storage, and the US for some sub-processors). Where required, we rely on our sub-processors' own transfer safeguards (e.g. Standard Contractual Clauses).
We may update this policy from time to time. Material changes will be notified by email or in-app notice before taking effect.
Questions or data requests: hello@zihadhosan.dev.