Privacy policy
Last updated October 2026
Governed Assistant processes two kinds of personal data: about our customers (the businesses and their team members) and, on their behalf, about the visitors who chat with their assistant.
Visitors to our customers' websites
- Chat messages are stored with email addresses, phone numbers and card numbers removed, and are deleted after the business's retention period (30 to 180 days).
- Contact details are only collected when a visitor fills in the form and ticks the consent box. Names, emails, phone numbers and messages are encrypted at rest.
- Messages that contain card or ID numbers are refused before any AI model sees them.
- The business that runs the assistant decides how these details are used; we process them on its behalf.
Our customers
We keep account details (name, email, workspace, role), an audit log of admin actions, and billing records (handled by Stripe; we never see full card numbers).
Business data you upload
Columns that look like personal details (emails, phone numbers, addresses, account numbers) are left out on import. Analytics return totals and breakdowns, never individual rows.
Where data goes
See the sub-processor list. AI providers receive only the question and the approved knowledge needed to answer it.
Your rights
Workspace owners can export or delete all their data at any time from Workspace settings. Visitors can ask the business that runs the assistant to access or delete their details.
Draft text. Have it reviewed before launch.
Terms · Privacy · Sub-processors · Pricing