Privacy Policy
1. Who we are
CastorChat ("we", "us") is an AI assistant platform operated by PANDORA G.P., a Greek software development company — Komaithous 21 & Aretha, 26443 Patras, Greece · VAT: EL801214481 · GEMI: 151912016000. We provide businesses with AI-powered chat and voice assistants that answer their customers' questions, book appointments, and hand conversations to humans when needed.
For privacy questions or requests, contact us at [email protected].
2. Our two roles
How we handle your data depends on how you interact with us:
- When you talk to an assistant on a business's website or phone line (as a visitor or caller), that business is the data controller of your conversation, and CastorChat acts as its data processor. Requests about that data are best addressed to the business you interacted with; we support them in fulfilling your rights, and you can always reach us directly too.
- When you are our customer (a business with a CastorChat account) or you visit castorchat.com, CastorChat is the data controller of your account and contact data.
3. What we process
When you chat with an assistant
- The messages you type, and the assistant's replies.
- A pseudonymous visitor identifier (stored in your browser — see section 8).
- If you choose to leave your contact details (for example to be called back): the name, email, phone number and message you provide.
- Technical processing records (which knowledge was retrieved to answer you, timing) used to operate and improve the service.
When you call an assistant by phone
- Your phone number (caller ID), the call transcript, and an automatic call summary.
- Call audio is recorded only when the business has turned recording on. Recording is off by default for new assistants. Where recording is active, the assistant's greeting discloses it at the start of the call.
- Every voice assistant identifies itself as an AI at the start of the call.
When you are our customer
- Account data: email address, authentication data, organization details.
- The content you upload to your assistant's knowledge base.
- Usage and billing-related records.
4. Why we process it (legal bases)
- Performing the service — answering the questions you ask, booking the appointments you request, passing your callback request to the business (contract / the controller-business's legitimate interest).
- Operating and securing the platform — abuse prevention, rate limiting, diagnostics (legitimate interest).
- Legal obligations — for example the EU AI Act's transparency requirements (see section 9).
- Consent, where a business has configured a consent step before collecting your contact details.
5. How long we keep it
| Data | Retention |
|---|---|
| Chat conversations & processing records | Deleted by automated retention sweeps; default horizon 180 days after a session is archived. |
| Voice call records (number, transcript, summary) | Deleted by an automated sweep; default horizon 180 days. Erasure requests scrub the personal data immediately (see section 7). |
| Call audio (held by our voice subprocessor) | Bounded vendor-side retention of 30 days, after which it is deleted automatically. |
| Contact details you leave (leads) | Kept per the receiving business's configured retention window. |
| Customer account data | For the life of the account and as required afterwards for legal/accounting purposes. |
| Backups | Encrypted backups may persist for a limited period after deletion before they are rotated out. |
6. Who we share it with (subprocessors)
We use a small set of service providers to run the platform. We do not sell personal data, and we do not use your conversations to train foundation AI models.
| Provider | Purpose | Location / transfer basis |
|---|---|---|
| Google (Gemini API, paid tier) | Generating assistant replies. Prompts and outputs are not used by Google to train its models on the paid tier. | EU/US — EU-US Data Privacy Framework + SCCs |
| ElevenLabs | Voice: speech recognition, speech synthesis, call handling, recording (when enabled) | EU/US — DPA with bounded retention (30 days) and transcript redaction of phone numbers |
| Hosting provider | Application and database hosting | EU (servers located in the EU) |
| Cloudflare | Network security, content delivery | Global edge — SCCs |
| Telephony carrier (e.g. DIDWW) | Phone numbers and call routing | EU |
| Google Cloud Translation | Multilingual knowledge-base answers | EU/US — DPF + SCCs |
| Resend | Transactional email (notifications, summaries) | US — SCCs |
Business customers receive our Data Processing Agreement, which includes this subprocessor list and a notification mechanism for changes to it.
7. Your rights
Under the GDPR you can ask for access to, correction of, deletion of, or a portable copy of your personal data, and you can object to or ask us to restrict certain processing. It works like this:
- Deletion is real. When a conversation is erased, voice-call personal data (caller number, transcript, summary) is scrubbed immediately and durably — a late-arriving copy of the call data cannot restore it. Bounded copies held by the voice subprocessor age out within its 30-day retention window.
- If you interacted with a business's assistant, you can contact that business (the controller) or us at [email protected] — we will route and support the request either way.
- You also have the right to complain to a supervisory authority — in Greece, the Hellenic Data Protection Authority (dpa.gr).
8. Cookies and local storage
The chat widget stores a small set of strictly necessary items in your browser's local storage: a pseudonymous visitor identifier, your open session, and preferences such as language. These are required for the chat to function (for example, so your conversation survives a page reload). We do not use advertising cookies or cross-site tracking, which is why you don't see a cookie consent banner.
9. AI transparency
CastorChat assistants are artificial intelligence, and we tell you so — in line with Article 50 of the EU AI Act:
- Chat responses are labeled as AI-generated (including a machine-readable marker).
- Voice assistants disclose at the start of a call that you are speaking with an AI — and, where recording is on, that the call is recorded.
- Each assistant links to an AI transparency page describing how it works.
10. Security
Data is encrypted in transit (TLS) and sensitive stored secrets are encrypted at rest (AES-GCM). Access to production systems is restricted, tenant data is strictly isolated, and the platform's release process runs an extensive automated test suite — including security-focused tests — before any change reaches production.
11. Children
Our services are aimed at businesses and their adult customers. We do not knowingly collect data from children under 15. If you believe a child has provided us personal data, contact us and we will delete it.
12. Changes to this policy
We will post any changes on this page and update the date at the top. Material changes affecting business customers are additionally notified per the DPA.
13. Contact
PANDORA G.P. · Komaithous 21 & Aretha, 26443 Patras, Greece
VAT: EL801214481 · GEMI: 151912016000
[email protected]