Arty Privacy Policy

Version: 1.0, May 2025

Introduction

Welcome to Arty, a multi-specialization AI agent platform developed by Artfultec. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable laws. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our services, including our chat widget, website (https://artyagent.com), and upcoming features (e.g., email, messaging apps, mobile app, voice interactions). By using Arty, you agree to the practices described below.

Who We Are

Arty is operated by Artfultec, a technology company providing among others, AI-driven solutions for professionals. For GDPR purposes, Artfultec is the data controller responsible for your personal data. You can contact us at:

  • Email: privacy@artfultec.com

Data We Collect

We collect and process the following personal data to provide and improve our services:

  • Chat Interactions:
    • Messages you send and receive via the chat widget
    • Conversation IDs and timestamps to manage sessions.
    • Example: Questions about services or form data (e.g., email, name, or conversations with our AI chat widget).
  • Account Information:
    • Name, email, and password when you sign up or update your account.
    • Organization details (e.g., billing email, phone number) for administrative purposes.
  • Configuration Data:
    • Agent settings, such as business name and website URLs, entered during agent creation.
  • Usage Data:
    • Technical data (e.g., IP address, browser type) logged for server management.
    • No tracking cookies are used unless explicitly stated.
  • Future Channels (Planned for 2025):
    • Email: Email content and metadata (e.g., sender address, subject) for inquiry responses.
    • Messaging Apps: Messages sent via WhatsApp, Telegram, or Facebook Messenger (e.g., phone numbers).
    • Voice: Speech transcripts from voice interactions (e.g., via mobile app or widget).
    • Mobile App: Device data and push notification IDs for app-based interactions.

How We Use Your Data

We process your data for the following purposes, based on our legitimate interest to provide and enhance Arty’s services or your implied consent (via widget usage or sign-up):

  • Service Delivery:
    • Process chat messages to enable AI agents (e.g., Sales/Secretary, UX Wizard) to respond.
    • Manage user accounts and agent configurations for personalized interactions.
  • Improvement:
    • Analyze messages (anonymized after 90 days) to improve AI performance and response accuracy.
  • Security:
    • Detect and prevent unauthorized access or fraud (e.g., via IP logs).
    • Log incidents to ensure data integrity.
  • Communication:
    • Send account-related emails (e.g., confirmations, password resets).
    • Respond to support inquiries via privacy@artfultec.com.
  • Future Channels (Planned for 2025):
    • Process emails, messaging app messages, or voice inputs for agent interactions.
    • Store voice transcripts to support voice-enabled features.

Legal Basis for Processing

  • Legitimate Interest: We process chat messages and usage data to deliver our core service (AI agent interactions) and maintain platform security.
  • Implied Consent: By using the chat widget or submitting data, you consent to our processing as described. Future explicit consent may be required for email, messaging, or voice channels.
  • Contractual Necessity: Account and configuration data are processed to fulfill our agreement with you (e.g., providing agent functionality).

Data Retention

  • Chat Messages: Retained for 90 days to maintain conversation history and improve services, then automatically deleted.
  • Account Information: Kept for as long as your account is active. Deleted upon request or account closure.
  • Configuration Data: Agent settings are stored until you delete the agent.
  • Usage Data: Technical logs (e.g., IP addresses) are deleted after 12 months or when no longer needed.
  • Future Channels: Email, messaging, and voice data will follow the same 90-day retention policy unless otherwise specified.

Your Rights

Under GDPR, you have the following rights regarding your personal data:

  • Access: Request a copy of your data (e.g., chat history, account details).
  • Rectification: Correct inaccurate or incomplete data.
  • Erasure (“Right to be Forgotten”): Request deletion of your data.
  • Restriction: Limit how we process your data.
  • Portability: Receive your data in a structured, machine-readable format.
  • Objection: Object to processing based on legitimate interest.
  • Withdraw Consent: Revoke consent for future processing (if applicable).

To exercise these rights, contact us at privacy@artfultec.com with your account details (e.g., email). We will respond within 30 days, as required by GDPR. Admins can also delete data via our admin interface.

Data Sharing

We do not sell or share your personal data with third parties, except in the following limited cases:

  • Service Providers:
    • OpenAI (gpt-4o) processes chat messages to generate responses. OpenAI is GDPR-compliant and acts as a data processor.
    • Future providers (e.g., Gmail API, WhatsApp Business API, Google Cloud Speech-to-Text) may process data for email, messaging, or voice features.
  • Legal Obligations:
    • We may disclose data if required by law (e.g., court orders) or to protect our rights.
  • Internal Use:
    • Data is accessible to authorized Artfultec staff (e.g., admins) for support and maintenance.

Data Security

We implement the following measures to protect your data:

  • Encryption: Data is transmitted via HTTPS (https://artyagent.com), database encryption and signed URLs for additional channels.
  • Access Controls: CSRF tokens and various middleware prevent unauthorized access.
  • Logging: Security incidents are logged to detect and address potential breaches.

Despite these measures, no system is 100% secure. We will notify you and authorities of any data breaches within 72 hours, as required by GDPR.

International Data Transfers

Arty is hosted in [Your Hosting Location, e.g., AWS US-East-1]. If you’re an EU user, your data may be transferred outside the EU (e.g., to OpenAI’s servers). We ensure such transfers comply with GDPR using:

  • Standard Contractual Clauses (SCCs): Agreements with providers like OpenAI to protect your data.
  • Adequacy Decisions: Where applicable, relying on EU-recognized safe jurisdictions.

Children’s Privacy

Arty is not intended for users under 16. We do not knowingly collect data from children. If you believe we have such data, contact us at privacy@artfultec.com to request deletion.

Changes to This Policy

We may update this Privacy Policy to reflect changes in our services (e.g., new channels like email or voice) or legal requirements. Updates will be posted at https://artyagent.com/en/privacy, with the “Version” and date revised. Significant changes will be communicated via email or website notice.

Contact Us

For questions, concerns, or to exercise your GDPR rights, contact us at:

  • Email: privacy@artfultec.com

You also have the right to lodge a complaint with an EU supervisory authority.

Effective Date

This Privacy Policy is effective as of May 28, 2025.