Effective from: 7 May 2026 Version: 1.0
This document describes how VEMART Distribution s.r.o., Company ID: 11763426, VAT ID: CZ11763426, with registered office at Světova 523/1, Libeň, 180 00 Prague 8, processes personal data in connection with the Inflo Shopping Assistant service.
Contact for data protection questions: [email protected] Web: inflo.cz
VEMART Distribution s.r.o. has not appointed a data protection officer.
This document is divided into several parts:
- Part A – Principles of personal data processing, where VEMART Distribution s.r.o. acts as the controller of personal data.
- Part B – Data Processing Agreement / DPA, where VEMART Distribution s.r.o. acts as the processor of personal data for the client.
- Part C – List of further processors, suppliers and recipients of data.
- Part D – Cookies, localStorage, sessionStorage and similar technologies.
- Part E – Sample information for clients to use on their website.
Part B of this document constitutes a data processing agreement within the meaning of Art. 28 GDPR and is part of the contractual relationship between the provider and the client.
Part A – Principles of personal data processing
1. When we act as the controller of personal data
VEMART Distribution s.r.o. acts as the controller of personal data in particular in the following situations:
- visiting the inflo.cz website,
- registration and use of the client portal,
- management of clients' user accounts,
- ordering the service, billing and payments,
- communication with a client or a person interested in the service,
- providing customer and technical support,
- security, abuse prevention and protection of the service,
- keeping business records,
- marketing, newsletters, traffic measurement and business communication,
- asserting legal claims and fulfilling statutory obligations.
In these cases we determine the purposes and means of processing personal data ourselves.
2. When we act as the processor of personal data
If the client uses the Inflo Shopping Assistant on its website and data of the client's visitors, customers or potential customers is processed via the widget, the client typically acts as the controller of personal data and VEMART Distribution s.r.o. as the processor.
This processing is governed in detail in Part B – Data Processing Agreement / DPA.
An end customer who communicates with the widget on the client's website is not a customer of VEMART Distribution s.r.o. In such a case they have a contractual relationship with the client, i.e. the operator of the relevant website or e-shop.
3. What personal data we process as a controller
To the extent necessary for the purposes set out below, we may process in particular the following categories of data:
3.1 Identification and contact data
- first and last name,
- company name,
- Company ID, VAT ID,
- billing address,
- registered office or place of business,
- e-mail address,
- telephone number,
- job position,
- the client's contact person.
3.2 Account and access data
- the e-mail used for login,
- password hash or external login data,
- user roles and permissions,
- assignment to an organization, workspace or website,
- account creation date,
- login history,
- security records,
- account settings.
3.3 Billing and payment data
- the chosen plan,
- billing period,
- payment history,
- issued invoices,
- data required for tax documents,
- payment identifiers at the payment provider,
- the customer identifier at the payment provider,
- the last four digits of the payment card, the card brand and the payment-method status, where available via the payment provider.
We do not store the full payment card number or the card security code.
3.4 Operational, technical and security data
- IP address,
- user agent,
- device type,
- operating system,
- browser,
- language settings,
- access time,
- URL and referrer,
- system logs,
- error records,
- security events,
- information about use of the service,
- limit consumption,
- the number of AI answers,
- data about the widget and client-portal settings.
3.5 Communication data
- e-mail communication,
- messages sent via the contact form,
- communication with support,
- requests, complaints and grievances,
- internal notes on handling a request,
- feedback and service ratings.
3.6 Marketing and analytics data
- website traffic,
- visit source,
- interaction with the website,
- consents given or withdrawn,
- campaign information,
- interest in the service,
- business communication history,
- newsletter sign-up,
- e-mail opens and clicks in an e-mail, where this feature is used.
3.7 Reference data
- the client's name,
- the client's logo,
- publicly available information about the client,
- ratings, reviews or a case study, where provided or approved by the client.
4. Purposes and legal bases of processing
| Purpose of processing | Categories of data | Legal basis |
|---|---|---|
| Creating and managing an account | identification, contact, access and operational data | performance of a contract / pre-contractual steps |
| Providing the Inflo Shopping Assistant service | account data, service settings, technical and operational data | performance of a contract |
| Billing, accounting and tax records | identification, billing and payment data | compliance with a legal obligation / performance of a contract |
| Payments and subscription management | billing and payment data | performance of a contract |
| Technical support | contact, communication, technical and operational data | performance of a contract / legitimate interest |
| Service security and abuse prevention | IP address, logs, security events, technical data | legitimate interest |
| Improving the service and developing features | operational, statistical and analytics data | legitimate interest |
| Website traffic measurement | analytics data | consent, or legitimate interest for necessary technical measurement |
| Marketing and business communication | contact and marketing data | consent / legitimate interest |
| References and promotion of the service | client name, logo, reviews | legitimate interest / consent depending on the nature of use |
| Protection of legal claims | contractual, billing, communication and operational data | legitimate interest |
| Fulfilling obligations toward public authorities | data required by legal regulations | compliance with a legal obligation |
5. Marketing communication
We may send clients and persons interested in the service commercial communications concerning the Inflo Shopping Assistant service, new features, operational notices, offers, case studies or similar services.
We send commercial communications on the basis of consent or legitimate interest, where the law allows us to do so. You can unsubscribe from commercial communications at any time via the link in the e-mail or by sending a message to [email protected].
We may send service, security, billing and contractual messages even without consent, because they are necessary for providing the service or performing the contract.
6. Retention period for personal data
We retain personal data only for the time necessary for the given purpose, or for the time required by law.
| Category of data | Retention period |
|---|---|
| Client account and contractual data | for the duration of the contract and subsequently usually up to 5 years for the protection of legal claims |
| Invoices and tax documents | for the period set by accounting and tax regulations, usually 10 years |
| Payment identifiers | for the duration of the subscription and subsequently according to the payment provider's rules and legal claims |
| Communication with support | for the period of handling the request and subsequently usually up to 3 years |
| Security and operational logs | usually 30 to 180 days, unless longer retention is necessary for security or an incident |
| Marketing contacts | until consent is withdrawn or unsubscribed, or for the duration of the legitimate interest |
| Analytics data | according to the analytics tool settings; for Google Analytics 4 no longer than 14 months, unless set otherwise |
| Trial accounts and inactive accounts | usually anonymization or deletion after 90 days of inactivity, unless longer retention is necessary |
| Backups | deletion takes place within the normal backup cycle |
Aggregated and anonymized data from which a specific person can no longer be determined may be retained longer for statistical, security, analytics and development purposes.
7. Who has access to the data
Only persons who need it for the performance of their activity have access to personal data, in particular administrators, technical support, the provider's authorized persons and necessary suppliers.
Access to production data is restricted on a need-to-know basis and by permission. Persons with access to personal data are bound by confidentiality.
We may also disclose personal data to public authorities where such an obligation is imposed on us by a legal regulation or a binding decision.
8. Automated decision-making
We do not use clients' personal data for automated decision-making that would have legal or similarly significant effects on data subjects.
The Inflo Shopping Assistant generates automated responses to end users' queries. These responses serve as assistance in communication on the client's website and do not in themselves constitute automated decision-making with legal effects on the part of the provider.
9. Rights of data subjects
Under the conditions set by the GDPR, a data subject has in particular the following rights:
- the right of access to personal data,
- the right to rectification of inaccurate data,
- the right to erasure,
- the right to restriction of processing,
- the right to data portability,
- the right to object to processing based on legitimate interest,
- the right to withdraw consent, where processing is based on consent,
- the right to lodge a complaint with the Office for Personal Data Protection.
Requests can be sent to [email protected].
If a request concerns data processed via the widget on the client's website, where we act as a processor, we may forward the request to the relevant client or refer the data subject to the client as the controller of personal data.
10. Office for Personal Data Protection
A data subject has the right to lodge a complaint with the supervisory authority:
Office for Personal Data Protection (Úřad pro ochranu osobních údajů) Pplk. Sochora 27, 170 00 Prague 7 Web: uoou.gov.cz
Part B – Data Processing Agreement / DPA
11. Purpose and position of the parties
11.1. This part of the document governs the processing of personal data that VEMART Distribution s.r.o. carries out as a processor for the client as the controller of personal data in connection with the use of the Inflo Shopping Assistant service.
11.2. The client determines the purposes and means of processing the personal data of end users on its website. The provider processes this personal data only for the purpose of providing the service and according to the client's instructions.
11.3. This data processing agreement is concluded at the moment the client accepts the terms and conditions, orders the service, creates an account, uses the client portal or inserts the widget on its website.
11.4. If the client concludes a separate written data processing agreement with the provider, that separate agreement prevails over this part of the document.
12. Subject of the processing
The subject of the processing is the processing of personal data of end users, website visitors, customers or potential customers of the client via the Inflo Shopping Assistant service.
Processing occurs in particular during:
- displaying the widget on the client's website,
- starting and conducting a conversation,
- generating AI answers,
- recommending products,
- using the client's data sources,
- handover of the conversation to an operator,
- storing conversation history,
- measuring use of the service,
- securing operation,
- resolving incidents and support.
13. Duration of processing
Processing lasts for the duration of the contractual relationship between the client and the provider and subsequently for the time necessary for erasure, anonymization, export, incident resolution or protection of legal claims.
We usually retain the content of conversations for 90 days. After this period, the conversation content is anonymized or removed. The technical records of the session and messages without text content may be retained usually for 1 year for statistical, security, operational and billing purposes.
Backups are deleted within the normal backup cycle.
14. Nature and purpose of the processing
The nature of the processing is the automated processing of personal data via an online SaaS service.
The purpose of the processing is in particular:
- to enable the end user to communicate via the widget,
- to answer the end user's query,
- to recommend relevant products or information from the client's data sources,
- to hand a more complex query to the client's operator,
- to show the client the history and context of the conversation,
- to allow the client to evaluate the assistant's performance,
- to measure the use of limits and the plan,
- to protect the service against misuse,
- to ensure secure and stable operation of the service.
15. Categories of data subjects
The processing may concern in particular the following categories of data subjects:
- visitors to the client's website,
- the client's customers,
- the client's potential customers,
- persons communicating via the widget,
- persons whose data is mentioned in a conversation,
- operators and staff of the client communicating via the service.
16. Categories of personal data processed for the client
Depending on the client's settings and the end user's behavior, the following data may be processed in particular:
16.1 Conversation data
- the end user's queries,
- the assistant's answers,
- the operator's answers,
- conversation history,
- message timestamps,
- the internal state of the conversation,
- information about handover to an operator,
- answer ratings or feedback, where the feature is available.
16.2 Session and visitor identifiers
- session ID,
- visitor ID,
- conversation identifier,
- message identifier,
- widget identifier,
- identifier of the client, workspace, website or e-shop,
- data stored in cookies, localStorage or sessionStorage, where used.
16.3 Technical and operational data
- IP address,
- user agent,
- device type,
- operating system,
- browser,
- language,
- page URL,
- referrer,
- visit time,
- approximate country or region based on technical data,
- logs and diagnostic data.
16.4 Product and commercial context
- the visited product page,
- product ID,
- product name,
- category,
- price,
- availability,
- product variant,
- relevant cart contents, where connected by the client,
- information about shipping, payment, returns, complaints and other commercial terms of the client.
16.5 Contact data of the end user
If the client activates this feature or if the service offers it in the future, the widget may process in particular:
- name,
- e-mail,
- phone,
- order number,
- preferred contact method,
- other data provided by the end user to handle a request.
16.6 The client's data sources
The service may process data contained in the client's data sources, in particular:
- product feeds,
- product descriptions,
- FAQ,
- the client's terms and conditions,
- information about shipping and payment,
- information about complaints and returns,
- the client's own documents,
- content of the client's web pages obtained using a web scraper,
- the client's knowledge base,
- metadata of documents and sources.
Data sources may also be stored in a vector database for the purpose of retrieving the relevant context for the assistant's answer.
17. Prohibited and inappropriate data
The service is not intended for processing special categories of personal data or highly sensitive data.
The client must not intentionally process via the service in particular:
- birth numbers,
- numbers of ID cards, passports or other documents,
- full payment card data,
- payment card security codes,
- passwords and access credentials,
- health data,
- biometric data,
- genetic data,
- data on religion, political opinions, sexual orientation or trade-union membership,
- data about children, unless there is an explicit legal reason and agreement of the parties,
- other data that is not necessary for the purpose of the service.
If an end user enters such data into a conversation, the provider may carry out automated or regular checks of the database in order to remove, anonymize or restrict further processing of it.
18. Instructions of the controller
18.1. The client instructs the provider to process personal data to the extent necessary for providing the Inflo Shopping Assistant service.
18.2. The client's instructions are considered to be in particular:
- these terms,
- the service's terms and conditions,
- the service settings in the client portal,
- the widget settings,
- connected data sources,
- retention settings, where available,
- operator-handover settings,
- other written or electronic instructions of the client accepted by the provider.
18.3. If the provider concludes that the client's instruction violates legal regulations, it will notify the client of this, unless prevented from doing so by a legal regulation or security reasons.
19. Obligations of the provider as processor
The provider undertakes in particular to:
- process personal data only on the basis of the client's instructions,
- process personal data only for the purposes of providing the service,
- ensure that persons authorized to process personal data are bound by confidentiality,
- adopt reasonable technical and organizational security measures,
- engage further processors only under the conditions set out in this DPA,
- reasonably assist the client in fulfilling its obligations under the GDPR,
- reasonably assist the client in handling data subjects' requests,
- inform the client of a security incident concerning personal data,
- after the end of providing the service, delete, anonymize or return the personal data according to the service terms,
- provide the client with reasonable information needed to demonstrate compliance with this DPA.
20. Obligations of the client as controller
The client is responsible in particular for:
- the lawfulness of processing end users' personal data,
- determining the purpose and legal basis of processing,
- fulfilling information obligations toward end users,
- setting up cookie consents and similar mechanisms on its website,
- the content of data sources,
- the accuracy, currency and lawfulness of the data provided to the service,
- configuring the assistant and permitted topics,
- assessing the suitability of the service for a specific use,
- ensuring that prohibited or excessive personal data is not inserted into the service,
- handling the rights of end users as data subjects,
- the lawfulness of operators' communication.
21. AI processing and transfer of data to AI providers
21.1. The service uses artificial-intelligence elements to generate answers, retrieve relevant context and recommend information or products.
21.2. In order to generate an answer, the following may be transferred to AI providers or via an AI gateway, in particular:
- the end user's query,
- relevant conversation history,
- relevant parts of the client's knowledge base,
- product information,
- information about shipping, payment, availability or returns,
- the assistant's instructions and settings,
- page or session metadata, where necessary for the answer.
21.3. The provider does not use client data or end users' conversations to train the provider's or third parties' general AI models, unless the client gives explicit consent or it is expressly agreed in a separate agreement.
21.4. The provider may use anonymized or aggregated data for security, analytics, statistical and development purposes, provided the client, the end user and a specific conversation cannot reasonably be identified from it.
21.5. Where technically available and configured, the provider uses limited-retention, no-training or zero-data-retention modes with the AI gateway or AI providers. The specific processing rules at AI providers may be governed by their current contractual and technical terms.
22. Further processors
22.1. The client grants the provider general authorization to engage the further processors listed in Part C – List of further processors, suppliers and recipients of data.
22.2. The provider may update the list of further processors on an ongoing basis, in particular when changing infrastructure, service features, AI providers, payment tools, e-mail services or other suppliers.
22.3. The provider will inform the client of a material change to further processors in a reasonable manner, for example by publishing the updated list, by notice in the client portal or by e-mail.
22.4. If the client disagrees with the engagement of a new further processor, it may raise a reasoned objection. If the objection cannot be reasonably resolved, the client may terminate use of the service at the end of the current billing period.
22.5. The provider is responsible for concluding appropriate contractual data-protection arrangements with further processors to the extent required by law.
23. Transfers outside the EEA
23.1. The provider seeks to use European regions and European data locations where this is technically and contractually available.
23.2. However, some of the service's suppliers are global companies or companies based outside the European Economic Area. In such a case, personal data may be transferred outside the EEA.
23.3. Where personal data is transferred outside the EEA, the provider uses available legal mechanisms, in particular adequacy decisions, the EU-U.S. Data Privacy Framework, standard contractual clauses or other appropriate safeguards under the GDPR.
23.4. The provider does not recommend claiming that all processing takes place exclusively in the EU when global suppliers such as AI model providers, payment services, cloud infrastructure, analytics or e-mail services are used.
24. Security measures
The provider adopts reasonable technical and organizational measures to protect personal data. These measures may include in particular:
- encrypted data transfer using HTTPS/TLS,
- role-based access control,
- restricting production access to authorized administrators,
- separating individual clients' data using a tenant model,
- security logging,
- audit records,
- backups,
- operation monitoring,
- regular system updates,
- reasonable infrastructure security,
- checking for unauthorized or excessive personal data in the database,
- anonymization of conversation content after the retention period,
- contractual confidentiality obligations of persons with access to data.
Security measures may change over time according to the development of the service, risks, technologies and legal requirements.
25. Security incidents
25.1. If the provider detects a personal data breach concerning personal data processed for the client, it will inform the client without undue delay after it learns of the incident and assesses its basic nature.
25.2. The notification will contain the information available to the provider, in particular the nature of the incident, the categories of data affected, the measures taken or proposed and a contact point for further communication.
25.3. The client is responsible for assessing whether to report the incident to the supervisory authority or to data subjects, where it has this obligation as the controller of personal data.
25.4. The provider will give the client reasonable cooperation needed to fulfil these obligations.
26. Data subjects' requests
26.1. If a data subject contacts the provider with a request concerning data processed for the client, the provider may refer them to the client as controller or forward the request to the client.
26.2. The provider will give the client reasonable technical and organizational cooperation in handling data subjects' requests, where possible and proportionate to the nature of the service.
26.3. If handling a request would require disproportionate work or an individual technical intervention outside the normal functionality of the service, the provider may request reasonable reimbursement of costs, unless the parties agree otherwise.
27. Audit and demonstrating compliance
27.1. The provider will give the client reasonable information needed to demonstrate fulfilment of obligations under this DPA.
27.2. An audit by the client is possible only by prior agreement, to a reasonable extent, under conditions protecting the security of the service, the provider's confidential information, other clients' data and the operation of the service.
27.3. The client must not carry out penetration tests, vulnerability scans or other security tests without the provider's prior written consent.
27.4. Instead of an individual audit, the provider may provide reasonable documentation, a security summary, certifications, supplier attestations or other materials, where available.
28. Return, erasure and anonymization of data
28.1. After the contract ends, the provider will delete, anonymize or enable export of the personal data processed for the client, where the service's features allow it and where legal regulations or legitimate interests do not require longer retention.
28.2. The content of conversations is usually retained for 90 days. After this period, the conversation content is anonymized or removed.
28.3. Technical records of the session and messages without text content may be retained usually for 1 year for operational, security, analytics and billing purposes.
28.4. Backups are deleted gradually within the normal backup cycle and it may not be technically possible to remove a specific record immediately from every backup copy. Backups are protected and used only for system recovery or security purposes.
Part C – List of further processors, suppliers and recipients of data
This part lists the main suppliers, further processors and recipients of data that the provider may use in operating the service. The specific scope of involvement may vary depending on the features used, the plan, the client's settings and the technical architecture.
| Supplier / service | Purpose of use | Type of data | Role | Location / transfer |
|---|---|---|---|---|
| Vercel | application hosting, frontend, serverless functions, AI Gateway, operational infrastructure | technical data, operational logs, possibly data passed through the AI Gateway | processor / infrastructure supplier | EU regions where configured; possible global transfer per the supplier's terms |
| Supabase | database, authentication, storage, vector database / pgvector | accounts, configuration, conversations, sessions, data sources, embeddings, operational data | processor | EU region where the project is configured; possible global transfer per the supplier's terms |
| OpenAI | generating AI answers, embeddings, prompt processing | queries, conversation history, relevant knowledge base, product context, embeddings | further processor / AI provider | possible transfer outside the EEA, contractual and technical safeguards per the supplier's terms |
| Google / Gemini | generating AI answers or AI features | queries, conversation history, relevant knowledge base, product context | further processor / AI provider | EU or global infrastructure per the service used; possible transfer outside the EEA |
| Anthropic | alternative or supplementary AI provider | queries, conversation history, relevant knowledge base, product context | further processor / AI provider | possible transfer outside the EEA, contractual and technical safeguards per the supplier's terms |
| Stripe | payments, billing, subscription management, payment methods | billing and payment data, customer and payment identifiers | payment provider, independent controller or processor depending on context | EU / USA / global infrastructure, transfer mechanisms per Stripe's terms |
| Google Workspace / Gmail | e-mail communication, internal document management, work e-mail | contact data, e-mail communication, internal documents | processor / independent controller depending on context | EU or global infrastructure per Google Workspace settings |
| Resend | transactional and service e-mails | e-mail, name, e-mail content, technical delivery data | processor | possible transfer outside the EEA per the supplier's terms |
| Cloudflare R2 | file and object storage | documents, files, metadata, technical data | processor / infrastructure supplier | per the configured region and Cloudflare's terms; possible global transfer |
| Axiom | operational and application logs | technical logs, diagnostics, errors, security records | processor | per the supplier's settings and terms; possible transfer outside the EEA |
| GitHub | source-code management, development, issue tracking | source code, technical documentation, development information; normally not production personal data of end users | development-tool supplier | global infrastructure, possible transfer outside the EEA |
| CookieScript | managing cookie consents and user preferences | cookie preferences, technical identifiers, consents | processor / CMP supplier | EU / EEA or per the supplier's terms |
| Google Tag Manager | managing scripts on the website | technical data per the deployed tags | tool supplier / per the tags used | EU or global infrastructure per Google's terms |
| Google Analytics 4 | analytics of website traffic and behavior | analytics identifiers, traffic, events, technical data | processor / independent controller per settings and Google's terms | EU or global infrastructure, possible transfer outside the EEA |
The provider may update the list on an ongoing basis. The current list should always be available on the provider's website or in the client portal.
Part D – Cookies, localStorage, sessionStorage and similar technologies
29. General
The inflo.cz website, the client portal and the Inflo Shopping Assistant widget may use cookies, localStorage, sessionStorage and similar technologies.
These technologies may serve in particular to:
- ensure the basic functioning of the website and service,
- maintain the session,
- security,
- remember settings,
- the smooth flow of a conversation,
- traffic measurement,
- analytics,
- marketing and remarketing, where the user gives consent.
30. Overview of technology categories
| Type | Purpose | Validity | Legal basis |
|---|---|---|---|
| Necessary / technical | Maintaining the session, session ID, security, basic functions of the website and service | for the session / short-term | legitimate interest / performance of a contract |
| AI Assistant – sessionStorage | Conversation state in the browser for a smooth query flow and conversation continuity | for the duration of the browser session | legitimate interest / performance of a contract |
| AI Assistant – localStorage, where used | Storing the widget state, conversation continuity, technical identifiers or user preferences | per the widget settings, typically short-term | legitimate interest / performance of a contract |
| Google Tag Manager | Managing analytics and marketing scripts. GTM itself typically serves as a container for other tools | per settings | legitimate interest for technical container management / consent for the contained scripts per their purpose |
| Analytics cookies, e.g. Google Analytics 4 | Measuring traffic, behavior on the website, visit sources and website performance. Activated only with consent, unless it is necessary measurement | up to 14 months per settings | consent |
| Marketing cookies | Ad personalization, remarketing and campaign measurement. Activated only with consent | per the provider | consent |
31. The widget on the client's website
The Inflo Shopping Assistant widget may use technical identifiers and browser storage in order to conduct a conversation and maintain its continuity.
The client, as the website operator, is responsible for ensuring that the use of the widget is correctly described in its own privacy policy and cookie policy.
If the use of a specific technology requires the end user's consent, the client is responsible for obtaining it.
32. Cookie preferences
The user can manage their cookie preferences via the cookie bar or the consent settings, where available on the website.
Some technical cookies and similar technologies are necessary for the functioning of the service and cannot be turned off without limiting the functionality of the website or widget.
Part E – Sample information for clients to use on their website
This part is only a recommended sample text that the client may adjust according to its specific use of the service, legal basis, website settings and its own privacy policy.
33. Short notice near the widget
On our website we use the AI assistant Inflo Shopping Assistant, which helps you choose products, answers questions and may connect you with our operator. Communication with the assistant may be stored and processed in order to handle the query, improve customer support, security and evaluate the quality of the service.
34. Sample for the client's privacy policy
On our website we use the Inflo Shopping Assistant service provided by VEMART Distribution s.r.o. This service allows website visitors to communicate with an AI assistant and get answers to questions about our range, shipping, payments, returns or other topics related to our website.
As part of using the assistant, the conversation content, technical session identifiers, device and browser data, the page URL, the time of communication and possibly contact data may be processed, where the visitor provides it voluntarily for the purpose of further communication or handover to an operator.
The controller of personal data processed via the assistant is us, as the operator of this website. VEMART Distribution s.r.o. acts in this respect as our processor.
The purpose of the processing is to handle the visitor's query, provide customer support, recommend relevant products, ensure conversation continuity, service security and evaluate its use.
The legal basis of the processing may be performance of a contract, taking pre-contractual steps, a legitimate interest in providing customer support and improving services, or consent where it is required for certain technologies or marketing purposes.
The content of conversations is usually retained for a limited time and subsequently anonymized or removed according to the service settings and our retention rules.
35. Sample for the client's cookie policy
The Inflo Shopping Assistant chat widget may be used on the website. The widget may use technical cookies, sessionStorage, localStorage or similar technologies in order to maintain the session, preserve conversation continuity, remember the widget state, security and the correct functioning of the service.
These technologies are used in particular for technical and functional purposes. If analytics or marketing processing were to take place via the widget or related tools, such processing would be activated only according to the consent settings on this website.
36. Recommended notice for the end user
We recommend that the client state clear information near the widget that the user is communicating with an AI assistant. For example:
"You are communicating with an AI assistant. For more complex queries the conversation may be handed to our operator."
Final provisions
This document may be updated on an ongoing basis, in particular when the service changes, new suppliers are engaged, legal regulations change, the technical solution changes or the purposes of processing change.
The provider may inform clients of material changes by e-mail, by notice in the client portal or by publishing a new version of the document on the website.
This document should be read together with the terms and conditions of the Inflo Shopping Assistant service.