Buzzchat
Legal

Privacy Policy

Plain answers about what we store, where it lives (the EU) and how to get it out. Last updated 11 June 2026.

1. Who's responsible

Buzzchat is operated by Hola Money Sociedad Limitada (Hola Money S.L.), C/ Granada 7, 04820 Vélez-Rubio, Almería, Spain. For your account data we are the controller. For the conversations your workspace has with its own customers, your organisation is the controller and we act as your processor. Privacy questions: privacy@buzzchat.test.

2. What we process

  • Account data - your name, email, password hash (or Google/Microsoft SSO identifiers), workspace membership and billing records.
  • Conversation data - messages, attachments and contact details flowing through your inboxes across all channels (chat, email, WhatsApp, SMS, Messenger, Teams), plus metadata such as page URL, browser and locale that the widget collects to give agents context.
  • Video calls - call lifecycle metadata (who, when, how long). The audio/video itself flows peer-to-peer between browsers and is never stored on our servers; calls are not recorded.
  • Usage & logs - standard server logs and aggregate usage needed to run, secure and bill the service. No advertising trackers, ever.

3. AI features

Optional AI features (drafted replies, summaries, auto-tagging, sentiment detection, the first-line chatbot) send the relevant conversation text and your help-centre articles to Anthropic for processing at the moment you (or your automation) use them. AI outputs are suggestions stored with the conversation. These features are off whenever no AI key is configured for the platform.

4. Sub-processors

ProviderPurposeRegion
Hetzner Online GmbHApplication & database hostingEU (Germany)
Buzzmark (Hola Money S.L.)Inbound & outbound ticket emailEU (Spain)
Mollie B.V.Subscription paymentsEU (Netherlands)
AnthropicOptional AI features (when used)See section 3

5. Cookies

The dashboard uses strictly-necessary cookies for sign-in sessions and CSRF protection. The widget stores an opaque session token in the visitor's browser so their conversation survives reloads. Our marketing pages use self-hosted, cookieless analytics (Umami) that we run ourselves - no third-party advertising or analytics cookies are ever set, and no analytics run inside the dashboard or the widget on your website.

6. Retention & deletion

  • Workspace data is retained while the workspace exists. Deleting a workspace cascades all of its inboxes, conversations, contacts and files.
  • Built-in GDPR tools let owners and admins export a full workspace, export a single contact's data, and erase a contact and all their conversations.
  • Billing records are kept as long as Spanish tax law requires.

7. Your rights

Under the GDPR you can request access, correction, export, restriction or erasure of your personal data, and you may complain to your supervisory authority (in Spain, the AEPD). If your data lives in a customer's workspace, we'll route your request to that workspace's owner - they're the controller.

8. Security

All traffic is encrypted in transit. Secrets are stored hashed, API tokens are shown once, two-factor authentication is available (and enforceable per workspace), and access within a workspace is governed by roles and per-inbox permissions. Found something? Email support@buzzmark.chat and we'll respond fast.

9. Changes

We'll notify workspace owners of material changes to this policy by email or in-app before they take effect.

Ready to start chatting?

Create your workspace, paste the snippet, and talk to your first customer today.

Get started free