A live chat privacy policy is the part of your privacy notice that explains what happens to the words, e-mail addresses and technical details visitors give you through a chat widget. Most websites add a chat tool and never touch the policy, which leaves a gap: visitors are typing personal information into a box that the notice does not mention. This guide lists what the widget collects, the sections to add, and wording you can adapt.
One caveat first. This is practical guidance from a software vendor, not legal advice. Privacy law differs by country, and your lawyer or data protection officer should approve the final text. What follows is meant to make that conversation shorter.
What a Chat Widget Actually Collects
You cannot describe data you have not listed, so start with an inventory. For a typical AI live chat setup, that includes:
- Message content. Everything the visitor types, and every reply, from the human team or the AI assistant.
- Contact details. A name and e-mail address when a pre-chat form asks for them, or when the team is offline and the visitor leaves an e-mail so you can reply.
- Technical context. In Talkmio, the visitor’s IP, country, city, device, browser, source and the pages they viewed are used to show context in the Inbox.
- Identifiers for continuity. Something has to let the widget recognise a returning visitor and restore the conversation. That is usually a cookie or local storage entry.
- Attachments and anything volunteered. Visitors sometimes paste order numbers, screenshots or details you never asked for.
- Ratings and ticket data. Feedback scores, status, priority and notes your team adds.
Write your own list from what you actually enabled, not from a template. If you never ask for a phone number, do not mention one. If you switched the pre-chat form to required, say so.
Where the Chat Section Fits in Your Policy
You do not need a separate document. A short, clearly headed section inside the privacy policy is enough, linked from the widget where practical. GDPR sets out what people must be told when you collect their data, in Article 13: who you are, why you process the data, on what legal basis, who receives it, how long you keep it and what rights people have. Your chat section should answer each of those for chat specifically.
The Sections to Add
1. Who is responsible
Name your company and contact details. If you have a data protection officer, list them. This is usually already in your policy; the chat section can refer back to it.
2. What data the chat collects and why
Be specific about purposes: answering questions, providing support, following up on an enquiry, improving answers, and keeping records of the conversation. Do not list “marketing” if you do not use chat data for it.
3. The legal basis
Answering a visitor’s question typically rests on your legitimate interest in providing support, or on steps taken before a contract when the question is about a purchase. If you use non-essential cookies or tracking in the widget, consent may be the basis for that part. Your lawyer decides this; the article on chat widget cookies and consent explains where the line usually falls.
4. Who processes the data
Your chat vendor is a processor acting on your instructions. If it uses an AI model provider, that is a sub-processor, and visitors should be told AI is involved. For Talkmio, conversation data is stored in the EU (Germany), and only the conversation text plus relevant knowledge base excerpts are sent to the AI model provider. Whichever vendor you use, you need a signed agreement; see what to check in a data processing agreement and Article 28 for the legal requirements.
5. Retention
Say how long chats are kept. Plans differ: Talkmio’s Free plan keeps 30 days of history, Pro 365 days and higher plans unlimited, and you can export or delete data at any time. Your policy should reflect the period you actually choose, not the maximum the software allows. Read how long to keep chat logs before deciding.
6. Transfers outside the EU
If any processor handles data outside the EU or EEA, describe the safeguard, such as standard contractual clauses. Ask your vendor and its AI provider for this in writing and repeat it accurately.
7. Visitor rights
Access, correction, deletion, restriction, objection and portability, plus the right to complain to a supervisory authority. Give a working contact route and note that requests are answered within the legal deadline. The process is explained in responding to data subject access requests.
8. Cookies and local storage
List the widget’s storage entries, their purpose and lifetime. Cross-check with your cookie banner so both documents say the same thing.
9. AI involvement
State that visitors may be talking to an AI assistant, that it answers from your website and documents, and that a person can take over. The reasons to say so plainly are covered in AI chatbot disclosure.
Sample Wording You Can Adapt
Treat the paragraphs below as a draft to edit, not text to paste.
Chat on our website. When you use the chat on our website, we process the messages you send, your name and e-mail address if you provide them, and technical information such as your approximate location, device, browser and the pages you viewed. We use this to answer your questions, provide support and follow up on your request. Our legal basis is our legitimate interest in providing support, or steps at your request before a contract.
AI assistant. Some replies in the chat are written by an AI assistant that answers from information on our website and documents we provide. If it cannot help, or you ask for a person, a member of our team takes over. To generate replies, your messages and relevant excerpts of our information are sent to our AI service provider, which processes them on our behalf.
Storage and retention. Chat data is stored on servers in the European Union (Germany). We keep conversations for [period] and then delete them. You can ask us to access, correct or delete your data at any time by writing to [your address].
Replace the bracketed items with facts. A retention period you do not follow is worse than none.
Comparison: What Each Setup Needs to Disclose
| Setup | Extra disclosure needed | Watch out for |
|---|---|---|
| Human-only chat, no form | Message content, IP, cookie for session | Visitors volunteering sensitive detail |
| Chat with required pre-chat form | Name and e-mail, purpose of collection | Collecting more fields than needed |
| AI assistant answering visitors | AI involvement, AI provider as recipient, excerpts sent | Vague “third parties” wording |
| E-mail channel creating tickets | Mail content, addresses, ticket notes | Mail retention differing from chat |
| Facebook, Instagram, WhatsApp channels | Platform operator as a separate controller | Two privacy notices apply |
| Live visitor tracking view | Pages viewed, country, device shown to agents | Cookie consent for the tracking part |
Practical Steps Beyond the Text
A policy only helps if the product matches it. Go through this list once per quarter.
- Test the widget with a fresh browser. See what it stores before and after consent.
- Link the policy from the widget. A short line in the welcome text or pre-chat form, such as “By chatting you agree to our privacy notice”, makes it findable. Only use “agree” wording if your legal basis supports it; a plain “Read our privacy notice” link is safer.
- Reduce what you collect. Talkmio’s pre-chat form can be none, optional or required. Choose the lightest option that still gets you what you need.
- Tell the AI what to avoid. Business instructions can say never to ask for payment card numbers, passwords or health details. A related guide covers keeping payment data out of chat.
- Set your retention. Delete or export old conversations on the schedule your policy states.
- Keep a record of the agreement with your vendor, including the sub-processor list.
Special Cases Worth a Sentence
Sensitive information typed by visitors
Visitors of clinics, law firms and insurers regularly type health, legal or financial details into a chat box, whether or not you asked. You cannot stop people from typing, but your policy can say that visitors should not share sensitive information in chat, and your welcome message can repeat it in one line. If your sector routinely handles such data, involve your compliance lead before switching on an AI assistant. The sector guides for medical clinics and law firms discuss what that looks like in practice.
Children and minors
If your site is aimed at young people, or a minor could plausibly start a chat, check the age thresholds that apply in your country. A generic sentence that the chat is not intended for children below a certain age is common, but it only helps if it is accurate for your audience.
Contacts, tickets and exports
Chat data does not stay in the chat. A conversation can become a numbered ticket, the visitor becomes a contact with a history, and reports or CSV exports may copy fragments into spreadsheets. Your retention and deletion promises have to cover those copies as well. When someone asks for deletion, search by name, e-mail or text so that you find the ticket and the contact record, not only the original chat.
Team access
Agents handle conversations, while Admins also manage websites, Mio and settings, and the Owner handles billing. Give people the lowest role that lets them do their job, and remove leavers promptly. Your policy does not need to name roles, but your internal procedures should.
Common Mistakes
- Copying a generic policy that talks about “forms” and “newsletters” and never mentions chat.
- Saying data stays in the EU without checking whether the AI provider processes elsewhere.
- Promising deletion “immediately” when backups take longer.
- Forgetting that ticket notes and e-mail replies are personal data too.
- Leaving out the AI. If a bot writes replies, say so.
- Never updating the text after changing tools.
For the wider legal background, the overview of GDPR and live chat is the natural companion. The official summaries at gdpr.eu are also useful for plain-language definitions.
Frequently Asked Questions
Do I need to mention live chat in my privacy policy?
Yes, if your chat widget collects any personal data, and almost all of them do: message content, an e-mail address, IP address or a cookie. Visitors should be told what is collected, why, who processes it, how long it is kept and how to exercise their rights. A short dedicated section is usually enough.
Do I have to tell visitors that an AI is answering?
You should. Many jurisdictions expect transparency when automated systems interact with people, and it builds trust. Say in the policy and, ideally, in the widget that some replies come from an AI assistant answering from your content, and that a person can take over. Ask your lawyer about the rules in your market.
How long should I keep chat transcripts?
Keep them only as long as you need them for support, follow-up and any legal obligations, and state that period in your policy. A common approach is a fixed number of months, then deletion or export. The right period depends on your business and local law, so decide deliberately instead of accepting the software default.
Is the AI model provider a separate recipient I must name?
If your chat vendor sends conversation text to an AI provider, that provider acts as a sub-processor, and your privacy notice should describe the category of recipient and the purpose. With Talkmio, only the conversation text and relevant knowledge base excerpts are sent to the model provider. Get the current sub-processor details in writing.
Does the chat widget need a cookie banner entry?
If the widget stores or reads anything on the device that is not strictly necessary for the service the visitor asked for, consent rules can apply. Session storage that restores an ongoing conversation is often treated as necessary, but tracking features are not. Check the widget’s storage list and align your banner and policy.
Can visitors ask me to delete their chat history?
Yes. Under GDPR people can request access, correction and deletion of their personal data, subject to limits. You need a working contact route and a process to find the conversation. Talkmio lets you search by name, e-mail or text and lets you export or delete data, or you can write to [email protected].
The Bottom Line
A good live chat privacy policy is short, specific and true. List what your widget really collects, explain the purpose, legal basis, processors including any AI provider, retention period and visitor rights, and say plainly when an AI assistant is answering. Then make sure the product matches the words. Talkmio stores data in the EU (Germany), lets you export or delete conversations, and hands over to a person when Mio cannot answer from your content, which makes the honest version of this section easy to write. You can try it free at app.talkmio.com, and for anything legally binding, ask your own counsel to review the final text.
