Legal
Data Processing Agreement
Effective from 1 August 2026
When LiveBot runs on your website, we process your visitors' personal data on your behalf. This document describes what we do with them and how we protect them. It forms part of the terms of service, no separate signature is needed, but if your company requires one, we will send it.
1. Who is who
You are the controller, you decide what the chat on your website is used for and what material goes into it. We are the processor: ITex Services s.r.o., IČO 08886164, registered office at Knapovec 180, 56201 Ústí nad Orlicí.
We process the data only for you and on your instructions. Instructions include how you configure the service in the portal.
If we were to process the data otherwise than as instructed, we would do so only where the law requires it, and we would tell you beforehand unless the law forbids it.
2. What we process
Purpose: running the chat assistant and live chat on your website, including statistics and the conversation overview.
Whose data: visitors to your website and the people who operate the chat on your side.
Which data: the content of conversations; name, email and message text where a visitor leaves them; technical conversation metadata (IP address, browser and device, the page they are writing from); for operators, name, email and sign-in credentials.
For how long: for the duration of the contract and 30 days after it ends. Then we delete the data.
The service is not meant to process special categories of data (health, beliefs and the like). They do not belong in a chat and the assistant asks visitors not to enter them.
3. How we protect them
Only people who need the data for their work have access, and they are bound by confidentiality.
Data are transferred encrypted, access is protected by passwords and two-factor authentication, and databases are separated at the level of individual sites, so nobody but you can reach your data.
We review and adjust our security as technology develops. We will describe the specific measures in more detail on request.
4. Who else is involved
We use further processors. We have contracts with all of them binding them to the same level of protection:
- Vercel — running the application (hosting).
- Supabase — database and file storage.
- Anthropic — the Claude language model that generates the answers.
- OpenAI — the GPT language model and knowledge base indexing; used depending on the site's configuration.
- Email gateway provider — sending messages and notifications.
Language model providers receive the conversation text and relevant excerpts of your knowledge base. They do not use data from us to train their models.
If we want to add or replace a processor, we will tell you at least a month in advance. If you do not agree, you may terminate the contract.
5. Where the data sit
The application runs on servers in Frankfurt; the database and file storage are likewise in the European Union. Sign-in details, billing data and operational records never leave the European Union.
Only one thing is processed outside the European Union: the text of the conversation and the relevant excerpts from your knowledge base. These go to the language model providers, Anthropic and OpenAI, both based in the United States, and without them the bot would have nothing to answer from.
Transfers to the United States are covered by the standard contractual clauses approved by the European Commission. The model providers do not use our data for training and do not keep it beyond processing the request.
6. When someone asks about their data
When a visitor asks you for access to their data, for correction or for deletion, you handle it as the controller. We will help, you can find and delete conversations directly in the portal, and if you are unsure, get in touch.
If such a request reaches us by mistake, we will pass it to you and will not answer it ourselves.
We will also assist you with a data protection impact assessment and in dealing with the supervisory authority, should you need it.
7. If something goes wrong
If we discover a security breach affecting your data, we will tell you without undue delay, at the latest within 48 hours of becoming aware of it.
We will describe what happened, which data are affected, what the consequences may be and what we are doing about it. Reporting to the authority and informing the people concerned is then up to you as the controller.
8. Evidence and audits
On request we will demonstrate that we comply with what is written here. If you want to carry out an audit, we will agree the date and scope in advance so that it does not disrupt other clients.
You bear the cost of the audit, unless it reveals that we have breached our obligations.
9. End of processing
After the contract ends we keep the data for 30 days so you can request them, then delete them. We will prepare an export on request.
The exception is data we must keep by law, typically accounting documents.
Need the DPA signed or in another format? Write to info@livebot.cz.

