← Back to ClientRelay

Privacy Policy

Last updated: July 10, 2026

ClientRelay is operated by ClientRelay Technologies, based in Norway. We are committed to protecting your privacy and handling your data transparently.

1. Data Controller

ClientRelay Technologies
Molde, Norway
Email: contact@clientrelay.tech

2. Data We Collect

Data Type Source Purpose
Email address Google OAuth Authentication, account identification, hub membership
Display name Google OAuth UI personalization
Profile photo URL Google OAuth Avatar display in dashboard
Knowledge base content User uploads Training AI chatbot responses
Chat logs End-user conversations Analytics, quality monitoring, lead capture
Lead form submissions End-user chat interactions Business lead generation for hub owners
IP address hash Automatic (rate limiting) Security - rate limit enforcement. The actual IP address is never stored.
Landing page visit data (anonymous) Automatic (landing page script) Anonymous visitor counting - page path, referrer domain, browser language, device type (mobile/desktop). No IP addresses, no cookies, no user identifiers.

Optional browser dictation

On supported browsers, a visitor may choose to dictate a chat-message draft. The first microphone click displays a disclosure. Dictation starts only after the visitor clicks again and grants any microphone permission requested by the browser.

Raw microphone audio is processed by the speech-recognition service provided or selected by the visitor's browser or operating system. Depending on that browser or device, audio may be transmitted to the browser or operating-system provider. ClientRelay does not receive, record, or store the raw audio. The resulting transcript remains in the message field for review and is handled as a chat message only if the visitor presses Send.

The speech-service provider controls its processing location, security measures, and any provider-side retention. Visitors should consult their browser or operating-system provider's privacy information. A visitor can avoid this processing by not enabling dictation or by denying microphone permission.

3. How We Use Your Data

3a. Legal Basis (GDPR)

Processing Legal Basis GDPR Article
Dashboard login (Google OAuth) Contract — necessary for service delivery Art. 6.1(b)
Chat messages (anonymous) Legitimate interest — service improvement Art. 6.1(f)
IP hash (rate limiting) Legitimate interest — security Art. 6.1(f)
Lead data (name, email, phone) Consent — voluntarily submitted by end-user Art. 6.1(a)
Landing page analytics (anonymous) Legitimate interest - aggregate visitor statistics Art. 6.1(f)
Optional browser dictation Consent - activated by the visitor after disclosure and browser permission Art. 6.1(a)

4. Data Storage and Location

Application data stored by ClientRelay is hosted on Supabase infrastructure within the European Union. Authentication is handled by Supabase Auth (Google OAuth provider).

5. Third-Party Services

Service Purpose Data Shared Location
Supabase Inc. Database, auth, serverless functions All application data EU region
Google LLC Gemini AI (chatbot), OAuth (dashboard) Knowledge base content, chat messages, email USA (EU-US Data Privacy Framework)
GitHub Inc. Static website hosting (GitHub Pages) No user data (static files only) USA (EU-US Data Privacy Framework)
Resend Inc. Email notifications for lead capture Recipient email address, lead name USA (EU-US Data Privacy Framework)
Google LLC (Analytics) Website traffic analytics (GA4) Anonymous usage data (page views, device type, traffic source) USA (EU-US Data Privacy Framework)
Visitor's browser or operating-system speech provider (optional) Speech-to-text dictation initiated by the visitor Microphone audio; ClientRelay does not receive the raw audio Determined by the provider and may be outside the EU/EEA

Some data handled by ClientRelay's listed service providers may be transferred to countries outside the EU/EEA (USA). Such transfers are protected by the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs). Optional browser dictation is governed separately by the visitor's browser or operating-system speech provider.

6. Chat Log Data

When end-users interact with chatbots created on the platform:

6a. Shared Data Responsibility

When a business uses a ClientRelay chatbot widget on their website with lead capture enabled, both ClientRelay (as data processor) and the business (as data controller) share responsibility for personal data collected. The business is responsible for informing their end-users about data collection.

Businesses that offer optional dictation should also ensure their own privacy information accurately covers any browser or operating-system speech service available to their visitors.

7. Data Retention

Data Retention Period
Chat logs (anonymous) 30 days, then automatically deleted
Lead data (name, email, phone) 2 months, then automatically deleted
Dashboard account Until account is deleted
Knowledge base Until you delete it or account is terminated
IP hash (rate limiting) 24 hours (in-memory, not permanently stored)
Landing page analytics 12 months, then automatically deleted
Optional dictation audio Not retained by ClientRelay; any provider-side retention is governed by the visitor's browser or operating-system provider
After account deletion All data deleted within 30 days

8. Your Rights (GDPR)

Under the General Data Protection Regulation (GDPR), you have the right to:

For chat data: since chat logs are anonymous, there is no personal data to delete. For lead data: contact us or the website owner for deletion.

We respond to all requests within 30 days. Contact us at contact@clientrelay.tech.

9. California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

We do not sell personal information. We do not share personal information with third parties for their marketing purposes.

10. Cookies and Local Storage

The Service uses:

11. Security

We implement industry-standard security measures including:

12. Children's Privacy

The Service is not intended for use by individuals under the age of 16. We do not knowingly collect data from children.

13. Supervisory Authority

If you believe we are processing your personal data in violation of GDPR, you have the right to lodge a complaint with the supervisory authority:

Datatilsynet (Norwegian Data Protection Authority)
Phone: +47 22 39 69 00
Email: postkasse@datatilsynet.no
Website: datatilsynet.no

14. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of the Service constitutes acceptance of the updated policy.

15. Contact

For privacy-related questions or requests:

ClientRelay Technologies
Email: contact@clientrelay.tech
Location: Molde, Norway