Skip to main content
EzyConn

GDPR

GDPR Compliance

Last updated: August 19, 2026

This page explains how EzyConn handles personal data under the EU General Data Protection Regulation (GDPR) and the UK GDPR. It sits alongside our Privacy Policy and Terms of Service.

1. Controller and processor

When you visit ezyconn.com or sign up for an account, EzyConn is the data controller for your account and billing data.

When you install the EzyConn widget and your visitors chat with you, EzyConn is a data processor acting on your instructions. You are the controller for your visitors' personal data, and you decide what is collected, why, and for how long it is kept.

2. Data Processing Agreement

If you process EU or UK personal data through EzyConn, you need a Data Processing Agreement (DPA) with us. Request one at privacy@ezyconn.com and we will send the current version, including the Standard Contractual Clauses where they apply.

3. What we process on your behalf

  • Chat transcripts and attachments your visitors send
  • Names, email addresses, and phone numbers visitors choose to provide
  • Technical data such as IP address, browser, and pages viewed
  • Agent activity needed for routing, assignment, and reporting

4. Lawful basis

For your account and billing data, we rely on performance of a contract. For product analytics and security logging we rely on legitimate interests. For anything you send us outside those purposes, such as marketing email, we rely on consent, which you can withdraw at any time.

For your visitors' data, the lawful basis is yours to determine as the controller. Most customers rely on legitimate interests for support conversations, and consent for any marketing follow-up.

5. Data subject rights

Under GDPR, individuals have the right to:

  • Access the personal data held about them
  • Have inaccurate data corrected
  • Have data erased (the "right to be forgotten")
  • Restrict or object to processing
  • Receive their data in a portable format
  • Not be subject to solely automated decisions with legal effects

If you are an EzyConn account holder, email privacy@ezyconn.com and we will respond within 30 days. If you are a visitor who chatted on someone else's website, contact that website's owner: they are the controller, and we will assist them in responding to you.

6. AI processing and your data

EzyConn runs on third-party AI models to generate answers. Content you send is used to answer your customers, not to improve anyone's models.

7. Sub-processors

We use a small set of sub-processors for hosting, AI inference, email delivery, and payments. The current list, including each provider's location and purpose, is available on request at privacy@ezyconn.com. We will give notice before adding a new sub-processor so you can object.

8. International transfers

Where personal data leaves the EEA or UK, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with a transfer risk assessment. Enterprise customers can request specific data residency arrangements.

9. Retention

Conversation history is retained according to your plan: 30 days on the Free plan, 90 days on Lite and Starter, one year on Basic and Pro, and unlimited on Business. Enterprise customers can set custom retention and deletion policies per region. When you close your account, we delete or anonymise your data within 90 days, except where we are legally required to keep records.

10. Security

Data is encrypted in transit and at rest. Access is role-based and logged. See our security page for how each control works. We will notify affected customers of a personal data breach without undue delay and within 72 hours where the regulation requires it.

11. Breach notification and complaints

If you believe your data has been mishandled, contact us first at privacy@ezyconn.com. You also have the right to lodge a complaint with your local supervisory authority, such as the ICO in the United Kingdom or your national Data Protection Authority in the EU.

Please note: this page describes how EzyConn approaches GDPR. It is not legal advice, and it is not a substitute for a signed Data Processing Agreement. Have your own counsel review your obligations as a controller before relying on it.