Scope and roles
This Privacy Policy describes how Chatoner may handle information across the website and the public experiences for Chatoner AI Conversations, Chatoner AI Systems, and Chatoner AI Academy—including Chatoner AI Labs at labs.chatoner.com where this notice applies. Separate platform, direct-subscriber, client, learner, organization, institution, employment, or service agreements and notices may apply.
Depending on the activity and applicable law, Chatoner may act as a controller, processor, service provider, contractor, educational provider, or another legally defined role. Service records document the relevant role for each processing activity.
Information we may collect
Information may include names, email addresses, phone numbers, organization details, role, region, preferred language, time zone, contact and booking content, application or admissions information, billing contacts, consent choices, device information, security events, and analytics events.
Platform-specific services may also involve customer conversations, CRM information, workflow logs, AI outputs, approvals, documents, knowledge sources, learning records, projects, assessments, credentials, support records, guardian information, academic-integrity information, or highly restricted safeguarding information.
- Do not submit passwords, private keys, payment credentials, or unnecessary sensitive data through general website forms.
- Access to service records follows role, tenant, field, purpose, and minimum-necessary controls.
How information may be used
Chatoner may use information to respond to enquiries, route requests, schedule calls, deliver resources, manage applications, provide services, operate platforms and Labs workspaces, enforce direct plan or Academy Program entitlements, administer learning, process payments, issue credentials, support users, protect security, meet legal obligations, and improve authorized products and experiences.
Marketing communication should be separated from a request for service where required, recorded, withdrawable, and subject to channel and jurisdiction rules.
AI, automation, and human review
Chatoner may use approved AI and automation to classify, summarize, route, draft, retrieve, monitor, or support work. The relevant workflow should define the approved purpose, data, sources, permissions, limitations, human checkpoints, escalation, retention, and evidence.
AI should not be treated as the sole decision-maker for high-impact, legal, financial, employment, healthcare, academic, safeguarding, disciplinary, credential, or similarly consequential decisions.
Analytics, cookies, and local preferences
The public website uses essential local storage for theme, language, currency display, time zone, consent, form state, and similar functional preferences. Optional analytics should load only after the relevant consent.
The contact form may use a country-level network lookup to preselect a region and phone calling code. It does not request precise device coordinates, and the visitor can change the suggested values. Browser locale is used as a fallback or when a recognized privacy signal blocks the network lookup.
General analytics should not intentionally include names, email addresses, phone numbers, form narratives, payment information, credentials, learner answers, private messages, accessibility information, or safeguarding information.
Vendors, subprocessors, and transfers
Services may use vendors for hosting, identity, database, storage, email, messaging, calendar, video, payments, CRM, automation, AI, analytics, search, support, monitoring, credentials, and file processing. Chatoner reviews contracts, security, data locations, retention, subprocessors, incident terms, and deletion capability as appropriate to the service.
International transfers and regional hosting requirements are assessed based on the users, clients, institutions, services, and jurisdictions involved.
Retention, security, and rights
Information should be retained only for the period required by the documented purpose, legal obligations, contracts, legitimate operational needs, dispute handling, credential verification, safeguarding, or approved archival requirements. Retention may vary by record category.
Subject to applicable law, individuals may have rights to access, correct, delete, restrict, object, withdraw consent, receive a copy, or complain to a regulator. Requests should be verified and routed through the appropriate process.
Contact and policy changes
Privacy enquiries can be sent to info@chatoner.com. Platform-specific or contractual contacts may also apply.
Chatoner may update this policy as the platform, services, vendors, or legal requirements change. Material changes should be communicated appropriately and version history should be retained.
This policy provides general information and is not legal advice. Additional privacy notices or agreements may apply to specific services, jurisdictions, sectors, users, communication channels, and data categories.
