GDPR

What is GDPR?

The General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy for all individuals within the European Union. GDPR also addresses the export of personal data outside the EU. It aims to give control to citizens and residents over their personal data and to simplify the regulatory environment for international business by unifying the regulation within the EU. We take the GDPR very seriously at Chatway and apply all the following changes and features to all of our users around the world. This article describes the GDPR compliance status of Chatway.

What Chatway did about it

1. AWARENESS OF THE GDPR

All managers and employees responsible of software development, design and infrastructure maintenance of Poptin LTD (the company that operates the Chatway app), an Israeli limited company (and the owner company of Poptin inc.), are aware of the GDPR requirements.

Tests and code reviews are performed by our development team and Data Protection Officers before any code deployment to the platform. We always take data protection and privacy by design into consideration when developing a new feature, infastructure, integration or any processing activities. We also made sure our 3rd parties we use are GDPR compliant and aware, as mentioned below.

2. INFORMATION WE STORE ON OUR CUSTOMERS

When a user registers and opts-in, he/she needs to fill out their:

We also collect the country of the user to make sure he/she gets their account's interface in the right language.

A user can also fill out more information, also with his/her consent, such as:

Live Visitors feature Using our live visitor feature, website owners can view real-time data about visitors currently on their site. The information displayed includes:

This feature is designed to enhance user engagement and support. Visitors have the option to disable tracking by toggling off the feature, ensuring their browsing activity is not monitored in real-time.

Website owners are responsible for obtaining necessary consents from their visitors for this data collection and ensuring compliance with applicable data protection laws.

E-commerce Integrations and GDPR Compliance Chatway’s integrations with WooCommerce and Shopify allow access to certain customer data (such as cart contents, orders, and coupon codes) to improve customer support experiences during live chats.When using these integrations, Chatway acts as a data processor and you, as the Chatway user and store owner, remain the data controller for any personal data processed via WooCommerce or Shopify. The processing of this data is based on legitimate interest in providing support services or consent, depending on how you inform and obtain permission from your visitors. Chatway only processes this data as necessary to provide our services and does not retain the data longer than required. You are responsible for ensuring GDPR compliance regarding your customers’ data, including providing proper notices and obtaining consent where necessary.

3. INFORMATION WE STORE ON OUR CUSTOMERS' END-USERS (VISITORS)

4. INDIVIDUAL RIGHTS

5. UPDATED OUR TERMS OF SERVICE AND PRIVACY POLICY

You can read our updated terms of service and privacy policy by click on the following links:

6. DPA

Ask us for our DPA (Data Processing Agreement) and we will send it to you via email. You can email it back to us once you signed it to [email protected]

7. WE REVIEWED THE GDPR STATUS OF ALL THE 3RD PARTIES WE USE

We use platforms and tools like Stripe, Amazon Web Services, Google, Facebook, Elastic Email, CloudFlare, Profitwell

8. DATA BREACHES

A personal data breach refers to a breach of security that can lead to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.

Our duty is to keep our users’ information safe, and report certain types personal data breach to the relevant supervisory authority within 72 hours. We also understand we must inform affected individuals without undue delay.

We take our users’ personal data, business information and our system security very seriously. These are a few implemented procedures and methods that we take:

We use 2-Factor-Authentication on our sensitive accounts (eg. hosting provider, etc.) Isolated servers for the application and for sensitive data

Access to our server systems is allowed only from specific IP addresses Daily backups

Always adding more automatic security tests to monitor the system. And more

Data protection officer Name: Gal Dubinski
Address: Street 18 Jerusalem Blvd
Postal code: 7752311
City: Ashdod
Country: Israel
Telephone: +97235248444
Email: [email protected]

WHAT SHOULD YOU DO TO GO ALONG WITH THE GDPR?

9. Consent Checkbox in Widget side contact form

You can now add a consent checkbox to any Chatway widget form. This allows you to request explicit visitor agreement before submitting their personal details. Use this checkbox to ask visitors to accept your Terms & Conditions or Privacy Policy before starting a conversation.

10. User Data Retention & Deletion Controls

We’ve introduced flexible data retention settings that let you control how long visitor data is stored.

From the Chatway dashboard, you can now:

These tools help ensure you're only retaining data for as long as needed and respecting your visitors’ right to be forgotten.