GDPR

Last updated: July 2026

This is a placeholder document. It has not been reviewed by legal counsel or a data protection professional and must be replaced before any commercial launch. It does not constitute legal advice.

1. Controller and processor roles

For conversations that happen on your website, you (the account holder) are the data controller and ForeverChat acts as a data processor on your behalf. For your own account data — the details of the people on your team — ForeverChat is the controller.

2. Lawful basis

You are responsible for establishing a lawful basis (such as legitimate interest or consent) for operating chat on your site and for informing your visitors. ForeverChat provides the tooling; the customer relationship with the visitor is yours.

3. Data subject requests

Visitors who wish to access, correct, or delete their conversation data should contact the website they chatted on — that business is the controller. Account owners can action these requests from the dashboard or by contacting support, and can request deletion of their account and associated data.

4. Sub-processors

ForeverChat uses a small set of sub-processors to deliver the service (for example, transactional email and, when enabled, SMS and payment providers). A current list will be published here before launch, and material changes will be communicated in advance where reasonably possible.

5. Data location and transfers

Where data is processed and any safeguards for international transfers (such as Standard Contractual Clauses) will be documented here. This section in particular requires counsel review before it can be relied upon.

6. Data processing agreement

A Data Processing Agreement will be made available to customers who require one. In the meantime, questions can be directed to privacy@foreverchat.co.

See also our Privacy Policy and Cookie Policy.