1. Scope and identity
This Privacy Policy explains how Chatoner AI Systems (“Chatoner,” “we,” “us,” or “our”) handles personal information through systems.chatoner.com, public forms, resource downloads, booking intake, contact requests, and related pre-sales communications.
Separate agreements, privacy notices, or data processing terms may govern client projects, authenticated workspaces, employee data, customer data processed on a client’s instructions, or a specific service. Where Chatoner acts only on a client’s documented instructions, the client generally determines the purpose of that processing and should provide the relevant notice to its own users or customers.
Entity notice: the final operating legal entity, registration details, and postal address must be inserted and legally reviewed before public launch. Privacy requests may be sent to privacy@chatoner.com.
2. Information we collect
Information you provide
- Names, business email addresses, phone numbers, job titles, company or venture names, websites, industries, locations, and—where relevant—company size.
- Selected pathway, delivery route, initiative type, intended audience, first credible outcome, stage, non-confidential evidence, high-level asset categories, milestone, risk flags, and decision-owner context submitted through booking or contact forms.
- Operational bottlenecks, current tools, lead volume, workflow descriptions, estimated values, project goals, and requested services.
- Consent choices, communication preferences, and records of requests.
- Files or documents you intentionally upload through an enabled project or form.
- Messages, call notes, support content, survey responses, and feedback.
Information collected automatically
- Essential browser storage used for language-region formatting, display currency, booking time zone, consent preferences, form state, and site operation.
- Technical information such as page path, browser/device category, approximate timestamps, referral/source category, selected locale/currency/time zone, and interaction events when the applicable analytics consent is active.
- Security and delivery logs such as submission time, status, error code, and generated event identifiers.
Public forms must not be used for source code, repository access, credentials, private URLs, confidential documents, customer records, or other secrets. AI Labs and AI Academy do not automatically receive Systems intake or project information.
3. How we use information
- Provide requested resources, reports, booking intake, answers, and service information.
- Respond to sales, support, partnership, billing, privacy, or other inquiries.
- Qualify requests, prepare calls, estimate projects, and route work to the appropriate team.
- Operate, secure, debug, monitor, and improve the website and its forms, including formatting dates, indicative pricing, and booking previews according to selected display preferences.
- Send optional educational or commercial follow-up when a separate opt-in or another lawful basis applies.
- Maintain records of consent, communication, requests, and operational activity.
- Protect against misuse, fraud, unauthorized access, spam, or security incidents.
- Comply with applicable law, enforce agreements, establish or defend claims, and respond to authorized requests.
4. Processing grounds and choices
The legal basis or permitted ground depends on the activity and jurisdiction. It may include performing a requested step before a contract, providing contracted services, consent, legitimate business interests balanced against individual rights, or compliance with legal obligations.
Where consent is relied upon, you may withdraw it for future processing. Withdrawal does not necessarily affect processing already completed or information retained for another valid reason. Optional marketing or nurture messages should include an unsubscribe path.
5. Forms, booking, and lead routing
When you submit a form, the information may be sent to a configured automation endpoint, approved lead-management or business-record system, scheduling provider, email provider, internal notification channel, or task system. The purpose is to deliver the requested item, route the inquiry, prevent duplicates, record status, and create an appropriate follow-up task.
Do not submit passwords, secret keys, payment-card data, government identifiers, health records, legal case files, or other sensitive information through general public forms unless Chatoner has explicitly approved a secure collection method for that purpose.
6. Analytics and cookies
Essential storage may operate without optional consent where necessary for basic site functionality, security, locale, display currency, booking time zone, consent state, and requested interactions. Optional analytics providers are designed to load only after an affirmative analytics choice and only when production identifiers have been configured.
Configured providers may include Google Analytics, Microsoft Clarity, Plausible, Fathom, or PostHog. The actual provider set, configuration, region, retention, and data fields must be reviewed before launch. See the Cookie Policy and the on-site cookie preference control.
7. Email and communication follow-up
Requested transactional messages—such as a checklist, ROI report, booking confirmation, or response—may be sent because you asked for them. Optional educational or promotional follow-up should be separately identified where required and may be stopped through the unsubscribe mechanism or by contacting us.
Phone, SMS, WhatsApp, or automated calling should only be used under a project-specific consent and compliance plan. General website submission does not automatically authorize every communication channel or purpose.
9. AI-assisted processing
Chatoner may use approved commercial AI services to classify, summarize, extract, draft, retrieve, or support operational work. Public form content should not be routed into an AI service unless needed for the disclosed purpose and the production workflow has been approved.
AI output may be inaccurate or incomplete. Consequential actions should use validation, source review, permission controls, and human approval appropriate to the impact. Chatoner does not use public consumer chat interfaces as a default channel for sensitive client workflows.
10. Data retention
Information should be retained only as long as reasonably necessary for the stated purpose, legal obligations, dispute management, security, backup, or documented client instructions. Different records may have different periods.
- Unconverted inquiry and marketing records: retain according to the approved sales and consent schedule.
- Contract and billing records: retain according to applicable accounting, tax, and limitation requirements.
- Operational and security logs: retain long enough to detect, investigate, and evidence system activity.
- Uploaded documents: retain according to the project agreement and approved deletion process.
Final production periods must be defined in an internal retention schedule rather than inferred from this website template.
11. Security
Chatoner uses administrative, technical, and organizational measures intended to protect information, such as access controls, scoped credentials, MFA for privileged access, encryption offered by approved providers, environment separation, logging, monitoring, and documented incident response. No system can be guaranteed completely secure, and visitors should use the appropriate secure channel for sensitive information.
12. International processing
Website and service providers may process information in more than one country. Where cross-border restrictions apply, Chatoner and its clients should select appropriate regions, contractual mechanisms, and supplementary measures. The actual transfer analysis depends on the final legal entity, providers, data, and affected individuals.
13. Your privacy rights
Depending on location and context, individuals may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or information about certain disclosures. Rights are not absolute and may be subject to verification, exceptions, or the role Chatoner plays.
Send a request to privacy@chatoner.com with enough information to identify the relevant interaction. Do not send unnecessary identity documents by ordinary email. If the request concerns a Chatoner client’s customer data, we may refer it to that client.
14. Children
The public website and business services are not intentionally directed to children. Do not submit children’s information through public forms. Any project involving minors requires explicit scoping, heightened safeguards, and legal review.
15. Third-party websites and tools
The site may link to schedulers, client portals, social sites, or other third-party services. Their privacy practices are governed by their own notices. A link does not mean Chatoner controls that service.
16. Changes to this Policy
We may update this Policy when the website, providers, services, or legal requirements change. The effective and review dates should be updated, and material changes should be communicated as appropriate. Previous versions should be retained internally when required.
17. Contact
Privacy questions and requests: privacy@chatoner.com
General inquiries: hello@chatoner.com
Website: systems.chatoner.com
Related documents: Privacy Policy · Terms of Use · Cookie Policy · Legal & Compliance Readiness