Privacy Policy
Last Updated: August 6, 2026
At Eteon ("we," "our," or "us"), we are committed to protecting the privacy and security of our workspace owners ("Customers") and the visitors who interact with AI chat widgets powered by Eteon ("End-Users").
1. Information We Collect
A. Information Provided by Workspace Owners (Customers)
- Account Information: Name, email address, password credentials, business details, and billing details when registering an account.
- Knowledge Base Content: Public website URLs, text, FAQs, and documents uploaded by Customers to train customized AI bots.
- Workspace Settings: Office hours, notification email preferences, and live support agent credentials.
B. Information Captured via Chat Widgets (End-Users)
- Lead Data: Information explicitly submitted by visitors during chat sessions (e.g., Name, Phone Number, Email Address, Custom Query fields).
- Conversation Logs: Complete transcripts of interactions between End-Users, AI bots, and live human support agents.
- Technical Metadata: IP address, browser type, device specifications, referrer URL, and timestamp of the interaction.
- Site Analytics: Pages visited on eteon.net, along with a first-party cookie identifier, the browser's reported timezone and language, and a derived device identifier. These are used to distinguish repeat visits from new ones, to identify automated and proxied traffic, and to approximate a visitor's location. They are visible only to Eteon operators and are deleted after 30 days.
2. How We Use Your Information
We use the collected information strictly for the following business purposes:
- Service Delivery: Generating AI responses, routing live support tickets, displaying captured leads in Customer dashboards, and sending lead alerts to business owners.
- Platform Optimization: Monitoring performance, fixing technical bugs, preventing spam/abuse, and refining AI accuracy.
- Transactional Communications: Dispatching lead notifications, password resets, and system updates.
Notice: We do NOT sell, rent, or trade personal data or customer leads to third-party advertisers or data brokers.
3. Third-Party Service Providers & AI Processing
To deliver our services, we process data using trusted cloud infrastructure and AI processing vendors:
- Artificial Intelligence (LLM) Processors: Chat prompts and document excerpts are processed via secure AI APIs. The models we route to are DeepSeek-V4 (served by DeepInfra and by DeepSeek), and, when those are unavailable, open-weight models served by OpenRouter (Google Gemma, Z.ai GLM). We do not send your data to OpenAI or Anthropic. Our paid providers (DeepInfra, DeepSeek) use request data to generate the response. The OpenRouter fallback and image questions use free-tier models, whose upstream providers may log prompts under their own terms; we route to them only when the paid providers are unavailable or for images.
- Database & Hosting Infrastructure: Account and workspace data is stored in Supabase, encrypted in transit and at rest. The application runs on our own virtual private server; knowledge bases and transcripts kept there are protected by server access controls, not by per-file encryption.
- Email Transports: Transactional emails and lead notifications are dispatched via secure SMTP/Email processors.
- Messaging and alerts: When a workspace owner turns on live-support alerts, visitor messages are relayed to them through Telegram and through WhatsApp (via our self-hosted WhatsApp gateway).
- Payments, bot protection and lookups: Razorpay processes subscription payments. Cloudflare (including Turnstile) screens traffic for automated abuse. When a visitor asks how a product compares with a named rival, that rival's name is sent to public search engines (such as Brave and Yahoo). IP addresses may be looked up with IP-geolocation services (ipinfo.io, ipwho.is) for abuse prevention, and default avatars are drawn by DiceBear.
4. Data Ownership & Retention
- Customer Ownership: Workspace owners retain full ownership of all captured leads, knowledge base inputs, and chat transcripts stored in their workspace.
- Data Control: Customers may delete entire bots at any time from the Eteon Dashboard. Deletion of individual lead records or chat transcripts is handled on request: email us from the account address and we will erase them.
5. Data Security
We implement enterprise-grade security measures to protect your data:
- Encryption: All data in transit is encrypted using TLS 1.2+ (HTTPS). Database storage is encrypted at rest.
- Role-Based Access Control (RBAC): Support agents can only view chats and tickets assigned to their workspace.
- Abuse Protection: Automated rate-limiting and IP blocking prevent unauthorized automated scraping or abuse.
6. Your Rights (GDPR & Data Protection)
Depending on your location, you have rights regarding your personal data:
- Right to Access & Export: Request an export of all personal data held in your account.
- Right to Erasure: Request complete deletion of your account and lead records.
- Right to Correction: Update account details at any time in your dashboard settings.
7. Contact Information
If you have any questions or privacy inquiries, please contact us:
Email: [email protected]
Phone: +91 8269297289