Version dated 6 September 2026.
1.1. This Policy explains what personal data Watbot, LLC collects when you visit https://watbot.org/ or use our services, why we process it, on what legal basis, who we share it with, how long we keep it and what rights you have.
1.2. It covers visitors to the website, registered users of the chatbot builder, the AI features and the Knowledge Base, users of the Online Schools module, and the people whose data those users process through our services. It does not cover third-party websites or messaging platforms you reach from our services; those are governed by their own notices.
1.3. Terms defined in the Terms of Service have the same meaning here. Where this Policy uses "controller", "processor", "personal data" and "processing", it uses them as defined in Regulation (EU) 2016/679 (the "GDPR") and, for the United Kingdom, in the UK GDPR and the Data Protection Act 2018.
1.4. Cookies and similar technologies are described in a separate Cookie Policy, which forms part of this Policy.
2.1. We are the controller of the personal data of our own users and website visitors: the data you give us when you register, pay and contact support, and the technical data our systems record when you use the service. Sections 4 to 13 describe that processing.
2.2. We are a processor of the personal data that our users bring into the service and process through it: the contacts and message histories of their chatbots, the recipients of their mailings, the respondents to their forms, the Students of their Online Schools and the people whose information they place in a Knowledge Base or in a dialogue with a Model. For that data the user is the controller (under US state privacy laws, the business), decides why and how it is processed and is responsible for the legal basis, the notices and the consents. We process it only on the user's documented instructions and only to run the service. Section 14 sets out the data processing terms required by Article 28 GDPR.
2.3. If you are an End User of a chatbot, a mailing, a form or an Online School and you want to know how your data is used, or you want to exercise your rights, contact the business that operates it. If you contact us instead, we will pass your request to that user and help them answer it, but we cannot decide it ourselves.
3.1. We are established outside the European Union and the United Kingdom.
3.2. Article 27 GDPR requires a controller established outside the Union to designate a representative in the Union, unless the exemption in Article 27(2)(a) applies: where the processing is occasional, does not include the large-scale processing of special categories of personal data or of personal data relating to criminal convictions and offences, and is unlikely to result in a risk to the rights and freedoms of natural persons.
3.3. We have not currently designated a representative in the Union or in the United Kingdom and rely on that exemption. Our assessment is that: our offer is not directed at the market of any particular Member State (the international website is published in English and German, prices are quoted in US dollars and euros, and we do not run country-specific campaigns, local payment methods or local-language sales); we do not monitor the behaviour of individuals in the Union on any significant scale; we do not process special categories of personal data or data relating to criminal convictions, and we ask users not to place such data in the service; and the data we do process about individuals in the Union is limited to what is needed to run a business software subscription.
3.4. We keep this assessment under review and re-examine it whenever our activity in the Union or the United Kingdom changes. As soon as the processing of personal data of individuals there ceases to be occasional or low-risk — in particular if we begin to target Member State markets directly, or if the volume, the nature or the sensitivity of the data changes — we will designate a representative under Article 27 GDPR and under the UK GDPR and publish their name and address in this Policy before continuing.
3.5. Until then, individuals in the Union and the United Kingdom and the supervisory authorities may contact us directly at support@watbot.kz, in English or German. We do not require you to go through any intermediary and we answer within the time limits set by the GDPR. This does not affect your right to lodge a complaint with your supervisory authority (clause 13.6).
4.1. Data you give us.
4.2. Data we generate or receive when you use the service.
ref_id) and the UTM parameters of the campaign you arrived from, stored in cookies as described in the Cookie Policy.4.3. Data we do not want. We do not seek special categories of personal data — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, data concerning health, sex life or sexual orientation — and we do not seek data relating to criminal convictions. Please do not place such data in the service, including in dialogues with Models and in a Knowledge Base. If you must process it for your own business, you remain the controller of it and are responsible for the additional conditions your law imposes.
4.4. Sources. We collect data from you directly, from your use of the service, from the payment service that processes your payment, from the sign-in provider you choose, and from the partner whose referral link you followed.
5.1. To provide the service you asked for — creating and running your account, giving you access to the builder, the AI features, the Knowledge Base and the Online Schools module, storing your content, providing support. Legal basis: performance of a contract (Article 6(1)(b) GDPR).
5.2. To bill you — calculating the cost of plans and of AI usage, taking payments, issuing invoices and receipts, keeping accounting records. Legal basis: performance of a contract and compliance with a legal obligation (Article 6(1)(b) and (c)).
5.3. To send you service messages — confirmations, security alerts, notices about renewals, limits, incidents and changes to our documents. Legal basis: performance of a contract, and our legitimate interest in keeping you informed (Article 6(1)(b) and (f)). You cannot turn these off while you have an account, because they are needed to operate it.
5.4. To keep the service secure and prevent abuse — logging access, detecting fraud, spam and attacks, enforcing limits, investigating breaches of the Terms. Legal basis: our legitimate interest in protecting the service, our users and third parties (Article 6(1)(f)). We have weighed that interest against your rights and limited the data to what security requires.
5.5. To improve the service — aggregated statistics on how features are used, and website analytics. Legal basis: your consent for analytics cookies (Article 6(1)(a)) and, for aggregated and anonymised statistics, our legitimate interest (Article 6(1)(f)).
5.6. To tell you about our products — news about features, offers and events. Legal basis: your consent, or our legitimate interest in marketing our own similar services to existing customers where the law allows (Article 6(1)(a) or (f)). Every marketing message contains an unsubscribe link, and you can also opt out at any time by writing to support@watbot.kz with "Unsubscribe" in the subject line. Opting out of marketing does not stop service messages.
5.7. To comply with the law and to establish or defend legal claims — tax and accounting duties, responding to lawful requests from competent authorities, handling complaints and disputes. Legal basis: compliance with a legal obligation and our legitimate interest in defending claims (Article 6(1)(c) and (f)).
5.8. If we ever want to use your data for a new purpose that is not compatible with the ones above, we will tell you and, where the law requires it, ask for your consent first.
6.1. The AI features give access to Models that are developed and operated by third parties. We do not develop the Models and do not generate responses on our own systems.
6.2. When you use an AI feature, the provider of the Model you selected receives what is needed to produce a response: the text of the request, the dialogue, attached files and images, retrieved fragments of the Knowledge Base and, where the "AI Agent" block is running, the exchange between your chatbot and its End User. Model Providers are located in several countries, including the United States and the European Union, so this may be an international transfer — see Section 10.
6.3. What happens to that data on the Model Provider's side is governed by that provider's own terms. We select providers whose terms match the nature of the service, including terms that exclude the use of submitted data for training their models by default, but we do not control their infrastructure. The current list of Models is shown in the interface, and the provider of each Model is identified there.
6.4. We do not use the content of your dialogues or your Knowledge Base materials to train Models, and we do not disclose them to anyone other than as described in this Policy.
6.5. The content of AI chat dialogues is stored in your account and visible only to you and to the people you have given access to the project. Consumption records (model, Tokens, cost, date) are kept for billing and are shown to you in the "Logs" section.
6.6. When the web search and page retrieval tools are used, the query or the link is sent to the external search service or to the owner of the site being retrieved.
6.7. Please do not send Models more personal data than the task needs, and do not send information that you are not allowed to disclose. If your request contains other people's personal data, you are the controller of it and must have a legal basis for that transfer.
7.1. When you build a chatbot, run a mailing, publish a form or open an Online School, you collect and process the personal data of other people. For that data you are the controller and we are your processor, as described in clause 2.2 and Section 14.
7.2. You decide what data to collect, why, for how long and to whom to disclose it. You are responsible for the notice given to those people, for their consent where consent is required, for their opt-outs and for answering their requests.
7.3. We do not use the data of your End Users for our own purposes, including marketing, and we do not sell it.
7.4. We ask you not to use the service to collect special categories of personal data or children's data unless you have made your own assessment of the additional conditions that apply and have implemented them.
8.1. Roles. The Online Schools module lets a user create a school, publish courses and give Students access to them. For Students' personal data, the user who owns the school is the controller: they set the content of the courses, the terms and price of access and the way Students are contacted. We process Students' data solely on that user's instructions, to the extent needed to run the module, and we do not decide the purposes. Section 14 applies to that processing in full.
The school owner must publish their own terms, privacy notice and consent forms, reference them in the Student Portal settings, and make sure Students accept them at registration. Our documents do not govern the relationship between a school and its Students.
8.2. What we process on the school's behalf.
8.3. Purposes. Registering the Student and giving access to the portal; delivering courses and learning materials; running the learning process, reviewing assignments and communicating with curators; issuing and verifying certificates; recording orders and payments; sending service and learning notifications; protecting learning materials from unauthorised copying; keeping the portal secure.
8.4. Video protection: e-mail overlay and key issuance log. Video lessons are stored encrypted, and the decryption key is issued to the Student's player for the duration of playback. While a lesson plays, the Student's e-mail address is displayed over the image; the Student always sees this overlay and is told in the interface that it cannot be removed. Each key issuance is recorded in a log holding the video identifier, the Student identifier, the IP address, an irreversibly transformed (hashed) browser identifier and the date and time.
The only purpose is to protect the exclusive rights in the school's materials and to detect access being shared. The log is not used to monitor a Student or to evaluate them: we do not collect what they watch beyond the lesson identifier, camera images, sound, geolocation or information about other programs and websites. A sharp discrepancy between the networks a key is requested from may temporarily restrict playback. Because this involves processing Students' personal data, the school owner must describe it in the documents given to Students.
8.5. Notifications. Students receive service e-mails (address confirmation, password recovery, access information) and learning notifications (assignment reviews, curator replies, lesson releases). Learning notifications can be turned off in the portal profile; service e-mails needed to operate and secure the account cannot.
8.6. Linking a messenger. A Student may link a messenger account to receive school notifications and to open the portal as a mini app. Linking is voluntary, is not required for study and can be cancelled at any time in the portal profile. When an account is linked and when notifications are sent, the Student's chat identifier and the notification text are transmitted to the messenger operator, which processes them under its own rules and may be located outside the EEA — see Section 10.
8.7. Certificate verification. If a school issues certificates, the verification page is open without authorisation to anyone with a direct link (including from a QR code) or with the certificate number, and shows the Student's name, the names of the course and the school, and the number and date of issue. The page is public by design: that is what makes a certificate verifiable. A Student who does not want that disclosure may ask the school not to issue a certificate, or to revoke one.
8.8. School access and exports. The school owner and the curators they appoint can see their Students' data in the interface — name, e-mail address, profile picture, progress, submitted work, correspondence and payment information — and can export reports, including as CSV. From the moment of export that data is processed by the school outside our service, and the school is responsible for its storage, use, transfer and destruction.
8.9. Payments for courses. Courses are sold to Students by the school. Payment goes through a payment service the school connects itself, and the funds reach the school. Card details are entered on the payment service's side and are never transmitted to us. On the school's behalf we process order information (amount, currency, status, date, payment identifier) to the extent needed to open access and record payments.
8.10. Retention and deletion. A Student's data is kept while their portal account exists. A Student may delete the account themselves; for 30 calendar days afterwards it can be restored by signing in, and after that the account and its data, including uploaded files, are irreversibly deleted. A Student account exists within a single school and gives no access to other schools. Learning materials, including video, are kept while the school owner pays for the relevant plan; when payment stops the school is restricted and, after the period set in the Terms of Service, we may delete the materials and data of the unpaid school. Entries in the key issuance log are kept no longer than needed for the purpose in clause 8.4 and are deleted with the video or the Student's account.
8.11. Student requests. Requests about the processing of a Student's data, the content of courses, payments and refunds go to the school, using the contact details shown in the Student Portal. We help the school answer them where technical assistance is needed. If a request reaches us directly, we forward it to the school and tell the Student we have done so.
9.1. We do not sell personal data and do not share it with anyone for their own purposes. We disclose it only to the categories of recipients below, and only as far as the service requires.
9.2. Everyone acting for us is bound by a written contract, may process the data only on our instructions, must keep it confidential and must apply appropriate security measures.
9.3. A current list of the sub-processors we use to run the service is available on request at support@watbot.kz.
10.1. Our providers are located in several countries, including in the United States and the European Union. Using the service therefore involves transferring personal data across borders.
10.2. Where we transfer personal data out of the EEA or the United Kingdom to a country that is not covered by an adequacy decision of the European Commission or of the United Kingdom, we rely on:
10.3. Where we act as a processor for our users (Section 14), the same safeguards apply to the onward transfers we make to run the service, and the Standard Contractual Clauses are incorporated into our contract with you.
10.4. You may ask us for a copy of the safeguards used for a specific transfer by writing to support@watbot.kz; we may redact commercial terms.
11.1. We keep personal data only as long as needed for the purpose it was collected for, and then delete or anonymise it.
11.2. Where we must keep data to defend a legal claim, we keep only what the claim requires and delete the rest.
12.1. We apply technical and organisational measures appropriate to the risk, including: encryption of traffic in transit; storage of passwords in an irreversibly transformed form; role-based access control and least-privilege access for our staff; access logging; segregation of environments; regular backups; monitoring of infrastructure security; encryption of learning video and short-lived access keys; and confidentiality obligations for everyone with access.
12.2. No system can be guaranteed secure. You help by choosing a strong unique password, not sharing your credentials, and reviewing active sessions in your account.
12.3. If a personal data breach occurs, we investigate, contain it, and notify the competent supervisory authority within 72 hours of becoming aware where the breach is likely to result in a risk to individuals, and notify the individuals concerned without undue delay where the risk is high, in accordance with Articles 33 and 34 GDPR. Where we act as processor, we notify the controller without undue delay after becoming aware, as required by clause 14.7.
13.1. If the GDPR or the UK GDPR applies to the processing of your data, you have the right to:
13.2. Much of this you can do yourself: your account lets you view and edit your data, download your content, manage sessions and delete the account.
13.3. To exercise a right, write to support@watbot.kz from the address registered in your account. We reply within one month; where a request is complex or you have made several, we may extend that by up to two further months and will tell you why within the first month. There is no charge, unless a request is manifestly unfounded or excessive.
13.4. We may ask for information needed to confirm your identity, so that we do not disclose your data to someone else. We ask for no more than is necessary and do not keep it beyond the request.
13.5. Requests about data we process for one of our users — including Students of an Online School — are forwarded to that user, who decides them as controller. We tell you when we have done so.
13.6. Complaints. If you think we have not handled your data properly, please tell us first at support@watbot.kz so that we can put it right. You also have the right to lodge a complaint with a supervisory authority — in the EEA, the authority of the Member State of your habitual residence, place of work or of the alleged infringement; in the United Kingdom, the Information Commissioner's Office. Because we have not designated a representative (Section 3), you may complain to the authority of your own country.
13.7. Automated decisions. We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you. Automated checks are used to detect fraud and abuse and to enforce the limits of your plan; where such a check results in a restriction, you can ask for it to be reviewed by a person by writing to support@watbot.kz.
This Section is the data processing agreement between you as controller and us as processor for the personal data you process through the service. It applies automatically to every user and needs no separate signature; if your organisation requires a signed agreement, write to support@watbot.kz.
14.1. Subject matter and duration. We process personal data to provide the services described in the Terms of Service, for as long as your account exists and, after it ends, for the deletion period in clause 14.9.
14.2. Nature and purpose. Hosting, storage, transmission, structuring, retrieval, display, backup and deletion of the data, and its transmission to the third-party services you connect, in each case in order to run the features you use.
14.3. Types of personal data. Identifiers and contact details, message content and attachments, profile and progress data, order and payment records, technical and log data, and any other data you choose to place in the service.
14.4. Categories of data subjects. Your chatbots' users, the recipients of your mailings, the respondents to your forms, the Students of your Online Schools, your team members, and any other individuals whose data you enter.
14.5. Our obligations. We process the data only on your documented instructions, including for transfers to a third country, unless the law we are subject to requires otherwise, in which case we inform you before processing unless that law prohibits it. Your instructions are given through your use of the service, its settings and the integrations you connect. We tell you if, in our opinion, an instruction infringes data protection law.
14.6. Confidentiality and security. Everyone we authorise to process the data is bound by confidentiality. We implement the measures described in Section 12, taking account of the state of the art, the cost of implementation and the risk to individuals.
14.7. Assistance. Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures in fulfilling your obligation to respond to data subject requests, and we assist you with security, breach notification, data protection impact assessments and prior consultation, taking into account the information available to us. We notify you without undue delay after becoming aware of a personal data breach affecting your data, and give you the information you need to notify your authority and the individuals concerned.
14.8. Sub-processors. You give us general authorisation to engage the sub-processors needed to run the service — the categories listed in Section 9. Each is bound by data protection obligations no less protective than these, and we remain fully liable to you for their performance. We maintain a current list, available at support@watbot.kz, and we inform you of intended changes in advance so that you can object; if you object on reasonable data protection grounds and we cannot offer an alternative, you may terminate the affected service and receive back the unused prepaid amount.
14.9. Deletion and return. On termination, at your choice, we delete or return the personal data we process for you. Deletion takes place within 30 calendar days of the end of your account, except where the law requires us to keep the data and except for copies in backups, which are deleted in the ordinary rotation. During those 30 days you may export your data from the interface or ask us for an export.
14.10. Audits. We make available the information needed to demonstrate compliance with this Section and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits take place no more than once a year (unless an incident or an authority requires more), on at least 30 days' notice, during business hours, without disrupting the service, subject to confidentiality, and at your cost. We may satisfy an audit request by providing existing documentation and answers where they address it.
14.11. Transfers. Where we transfer personal data processed for you outside the EEA or the United Kingdom, we do so under the safeguards in Section 10, and the Standard Contractual Clauses (module controller-to-processor) are incorporated into this Section by reference, with you as data exporter and us as data importer. In case of conflict, the Clauses prevail over this Policy and the Terms of Service.
14.12. US state privacy laws. Where those laws apply, we act as your service provider or processor. We do not sell or share the personal information you entrust to us, do not retain, use or disclose it for any purpose other than performing the service, and do not combine it with personal information from other sources except as those laws permit. We comply with the applicable obligations and give you the same level of protection they require.
15.1. This Section applies to residents of US states with comprehensive privacy laws, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana. Terms such as "personal information", "sell", "share", "sensitive personal information" and "targeted advertising" have the meanings given in the law of your state.
15.2. Categories of personal information we collect as a business. Over the past 12 months we have collected the categories below from you, from your use of the service, from payment services and from sign-in providers, for the purposes described in Section 5, and we keep each category for the periods in Section 11:
15.3. Sensitive personal information. We collect account credentials in a hashed form because access to your account requires it. We do not use or disclose sensitive personal information for purposes other than those permitted without a right to limit, and we do not infer characteristics from it.
15.4. Sale and sharing. We do not sell personal information and we do not share it for cross-context behavioural advertising. We have not done so in the past 12 months, and we do not knowingly do so for anyone under 16.
15.5. Disclosure for a business purpose. We disclose the categories above to the recipients listed in Section 9, each under a contract that limits them to performing the service for us.
15.6. Your rights. Subject to the law of your state, you may: know what personal information we have collected, used and disclosed and obtain a copy of it; correct inaccurate information; delete it; opt out of any sale, sharing or targeted advertising (we do none, but the request is honoured as an instruction); limit the use of sensitive personal information; and obtain a copy in a portable format. We do not discriminate against you for exercising a right — no denial of service, no different prices, no lower quality.
15.7. How to exercise them. Write to support@watbot.kz with "US privacy request" in the subject line, or use the controls in your account. We confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days where reasonably necessary, and we will tell you if we need the extension. We verify your identity against the data we hold before acting; for a copy of specific pieces of information we apply a higher standard of verification.
15.8. Authorised agents. You may use an authorised agent. We ask for written permission signed by you and may still contact you to confirm the request, unless the agent provides a valid power of attorney.
15.9. Appeals. If we refuse a request, we explain why. Where your state's law provides a right of appeal, you may appeal within 45 days by replying to our decision with "Appeal" in the subject line; we respond within 45 days, and if we deny the appeal we tell you how to contact your state Attorney General.
15.10. Opt-out preference signals. We honour the Global Privacy Control signal for the browser that sends it, in respect of the analytics cookies covered by the Cookie Policy. We do not respond to Do Not Track signals, for which there is no common standard.
15.11. California "Shine the Light". We do not disclose personal information to third parties for their own direct marketing purposes, so there is nothing to report under California Civil Code section 1798.83. You may still ask us to confirm this at the address above.
15.12. Data we process for our customers. Where our customer collects your information through their chatbot, form, mailing or online school, they are the business or controller and we are their service provider. Send your request to them; if you send it to us, we forward it and assist them in answering it.
16.1. The service is a business tool. It is not directed to children, and we do not knowingly collect personal data from children under 16 (under 13 in the United States) as a controller.
16.2. If you use the service to process children's data — for example if your online school teaches minors — you are the controller of that data and are responsible for the additional requirements that apply, including verifiable parental consent where the law requires it, and for the age at which a child can consent in their country, which in the European Union is between 13 and 16 depending on the Member State.
16.3. If you believe a child has given us personal data as a controller, write to support@watbot.kz and we will delete it.
17.1. We may update this Policy. The version date at the top always shows the current version, and the current text is published at https://watbot.org/privacy.
17.2. Where a change materially affects how we handle your data, we notify you by e-mail or in the interface at least 30 days before it takes effect. Where a change requires your consent, we ask for it before relying on it.
Controller: Watbot, LLC.
Privacy questions, data subject requests and complaints: support@watbot.kz.
General enquiries: info@watbot.kz. Telephone: +7 747 699 45 19.
We have not appointed a data protection officer, because the criteria in Article 37 GDPR are not met. Requests sent to the address above reach the person responsible for data protection at our company.