This Policy applies to specteron.com, Specteron accounts, the application panel, contact forms and the operation of Specteron services.
For a widget installed on a customer’s website, that customer is usually the controller of visitor data and should provide its own privacy information.
Controller and privacy contact
The controller of personal data used to operate Specteron accounts, the website, billing, support and direct customer relationships is Bartosz Plichta, a natural person responsible for the Specteron project before registration of a separate business entity.
Privacy requests and all data-protection questions may be sent to [email protected]. No Data Protection Officer has been appointed.
Controller and processor roles
For Specteron users who create an account and use the panel, Bartosz Plichta is the controller of account, security, subscription, support and related operational data.
For people who communicate through a Specteron widget embedded on a customer’s website, the customer is, as a rule and in the typical scenario, the controller. Specteron provides the tool and processes messages, conversation data, forms and leads as needed to deliver the service. The exact allocation of roles may depend on the customer’s configuration and purpose.
Customers must inform their visitors, establish an appropriate legal basis and handle data-subject requests relating to their own use of the widget.
Data we may process
-
01
Account data: email address, hashed password, name, company name, phone number, roles and account settings.
-
02
Technical and security data: IP address, browser and device information, timestamps, session data, security events and technical logs.
-
03
Chatbot data: messages, prompts, conversation history, bot configuration, feedback and handoff information.
-
04
Knowledge Base data: uploaded files, URLs, extracted content, source metadata and indexing information.
-
05
Contact and lead data: contact-form contents, names, email addresses, phone numbers and information collected through customer bots.
-
06
Subscription data: plan, usage, billing status, subscription history and Stripe customer, payment or transaction identifiers.
-
07
Communications: support messages, legal or privacy requests and system-email delivery information.
We do not ask users to upload special-category or highly sensitive data. Do not provide sensitive data, secrets or third-party information unless it is necessary, lawful and appropriately protected.
Purposes and legal bases
-
01
To create and operate accounts, authenticate users, provide the panel, bots, conversation history, Knowledge Base, forms, leads and subscriptions — performance of the service agreement.
-
02
To generate AI answers and retrieve relevant Knowledge Base content — performance of the service agreement and, where applicable, the customer’s documented use of the tool.
-
03
To process payments, subscription status, invoices or legally required billing information — performance of the agreement and compliance with legal obligations.
-
04
To send account, security, payment and service messages and respond to submitted requests — performance of the agreement or legitimate interests in communication and support.
-
05
To protect accounts, prevent fraud and abuse, diagnose faults, maintain logs and defend claims — legitimate interests in security, reliable operation and legal protection.
-
06
To improve product reliability and understand use of features through limited operational analytics — legitimate interests or consent where consent is legally required.
-
07
To run Google Ads measurement and load optional external media — consent where required.
Where processing is based on consent, you may withdraw it at any time without affecting processing already carried out. We do not operate an email newsletter. We may contact you about your account, service, payment, security or a request you submitted.
OpenAI and AI processing
Specteron uses the OpenAI API to generate answers and related AI output. The content of messages, prompts, bot configuration and relevant fragments of Knowledge Base content may be transmitted to OpenAI for this purpose.
OpenAI may process prompts, outputs and service metadata under its applicable API terms and data controls. Depending on the API feature and account configuration, limited retention for abuse monitoring or application state may occur.
Do not upload unnecessary sensitive data
Users should not upload sensitive personal data, trade secrets or data they have no right to process unless there is a clear need, a lawful basis and suitable safeguards.
Payments and Stripe
Stripe processes card payments and subscription transactions. Full card details are entered into and handled by Stripe’s payment environment; Specteron does not independently store full card numbers or card security codes.
Specteron may receive the payment status, selected plan, billing details, subscription status, and Stripe customer, checkout, invoice or transaction identifiers needed to operate the subscription and resolve payment issues. Stripe processes data under its own privacy terms.
Service providers and data transfers
-
01
awhost — VPS hosting and database infrastructure located in the European Union.
-
02
hoste.pl — email and SMTP delivery.
-
03
OpenAI — AI generation and related API processing.
-
04
Stripe — checkout, card payments and subscription billing.
-
05
Cloudflare — network delivery, traffic protection and security-related technical data.
-
06
Google — Google Ads tag and YouTube embedded video services, when enabled or loaded.
Some providers may process data outside the European Economic Area or be subject to non-EEA laws. Where required, the provider’s available transfer mechanism, such as an adequacy decision or standard contractual clauses, may apply. The exact data-processing agreements and transfer settings with providers are subject to ongoing verification; this Policy does not claim that a separate DPA has been signed where that has not been confirmed.
Data may also be disclosed where required by law, to protect rights and security, or in connection with a future lawful transfer of the Specteron project. Users will be informed where the law requires it.
Retention periods
-
01
Account data: until the account is deleted or as long as needed to provide the service and meet legal obligations.
-
02
Chatbot conversations: 30 days by default, unless the user changes the retention setting; conversations may be deleted earlier.
-
03
Leads: 30 days by default, unless the user changes the retention setting; leads may be deleted earlier.
-
04
Technical logs: normally 30 days, unless longer retention is necessary for security, fault investigation or legal claims.
-
05
Contact forms: up to 12 months after the request, unless a longer period is needed to handle an ongoing matter or claim.
-
06
Knowledge Base files and URLs: while the account remains active and until the user deletes them, unless another user-selected retention setting applies.
-
07
Subscription and billing information: for the subscription lifecycle and as long as needed for accounting, tax, dispute or other legal obligations. Full card data remains with Stripe.
Backups and security copies may take additional time to cycle out. Data may be retained longer if required by law, a dispute, a security investigation or the establishment, exercise or defence of legal claims.
Your data-protection rights
Depending on the circumstances and applicable law, you may request access, correction, deletion, restriction, portability, object to processing and withdraw consent where consent is the legal basis. You may also lodge a complaint with a supervisory authority. In Poland, this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
-
01
Contact [email protected] to exercise a right or ask a privacy question.
-
02
Use account deletion in the Security section to request removal of your account.
-
03
Use GDPR export in the Security section to obtain available account data.
-
04
Delete conversations and leads, or change their retention, using the available panel controls.
We may need to verify your identity. Some rights are not absolute and may be limited by other people’s rights, security requirements or legal duties. If a request concerns a customer’s widget, it may need to be directed to that customer as the controller.
Security
We apply reasonable technical and organisational measures intended to protect data, including hashed password storage, access controls, session security, backups and technical logging appropriate to the service.
No system can guarantee absolute security. Users should protect credentials, restrict workspace access, configure retention, avoid unnecessary sensitive data and report suspected incidents to [email protected].
Users requiring consent and policy changes
Specteron does not apply a fixed 18+ requirement. A person using the service must have the capacity or consent required under the law applicable in their country. Customers using widgets should take particular care if their service is directed to children.
We may update this Policy when the product, providers, legal requirements or the operator’s status changes. The current effective date is shown above. Material changes will be communicated where required.