; Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content
Skip to main content

Privacy Policy

Effective date: September 29, 2026
This Privacy Policy explains how RUBIKON TECHNOLOGIES LLP (“ChatRex”, “we”, “us”) collects, uses, stores, and shares personal data when you visit ChatRex websites, create an account, use the ChatRex platform, or connect ChatRex to a supported third-party service. This Policy applies to the entire ChatRex Service and every supported channel and integration that a customer connects. Provider-specific disclosures supplement, and do not limit, the general rules in this Policy.
1. Who we are
The data controller for ChatRex account and website information is:
RUBIKON TECHNOLOGIES LLP
BIN 221140012450
12 Saryarka Avenue, Saryarka District
Astana 010000, Republic of Kazakhstan
Email: info@chatrex.pro
When we process personal data from a merchant’s store, CRM, communication channel, or customer conversations on the merchant’s instructions, the merchant is normally the controller and ChatRex acts as its processor or service provider.
2. Information we collect
Depending on how the Service is used, we may process:
Account information
  • name;
  • email address and telephone number;
  • company name and role;
  • authentication and account-security information;
  • language, plan, and account settings.
Billing information
  • selected plan and billing history;
  • transaction and invoice identifiers;
  • subscription status;
  • marketplace contract identifiers.
Payment card details may be collected directly by the applicable payment provider or marketplace and may not be stored by ChatRex.
Connected service data
  • store URL and technical identifiers;
  • plugin version and connection status;
  • API credentials, access tokens, and webhook identifiers;
  • product names, descriptions, categories, prices, images, and inventory;
  • order identifiers, contents, amounts, statuses, and delivery information;
  • customer names, contact details, billing and shipping information;
  • information required to execute merchant-configured actions.
ChatRex requests only permissions reasonably necessary for enabled functionality.
Connected channels and integrations
Depending on the services selected by the customer, ChatRex may process authorized account or workspace identifiers, connection settings, messages and attachments, lead and contact fields, CRM records, catalog and order fields, appointment or calendar details, spreadsheet data, and the results of permitted actions. The exact data depends on the connected provider, granted permissions, and enabled workflow. These general rules apply to messaging channels, CRM systems, websites, e-commerce platforms, booking services, calendars, spreadsheets, and other supported integrations.
Website and catalog integration data
When a customer authorizes a supported website or catalog integration, ChatRex receives and processes:
  • an encrypted OAuth access token and the read permissions granted by the customer;
  • the selected site ID, display name, published domain, primary locale, Ecommerce SKU collection ID, connection status, and authorization timestamps;
  • the list of sites available to the authorizing provider account and basic publication and domain metadata used to let the customer select a site;
  • published Ecommerce product and SKU data, including identifiers, names, descriptions, slugs and public URLs, prices, compare-at prices, currencies, variant options, product images, publication state, and inventory type and quantity.
ChatRex uses the read-only scopes sites:read, cms:read, and ecommerce:read. The current integration does not request write scopes and does not read form submissions, orders, customer accounts, or site-visitor data.
Chatbot and conversation data
  • messages and conversation history;
  • names and contact details included in messages;
  • chatbot prompts, instructions, goals, and configuration;
  • AI-generated responses;
  • operator notes and escalation information;
  • files and knowledge-base materials uploaded by the merchant.
Technical and usage data
  • IP address;
  • browser, device, and operating-system information;
  • access dates and times;
  • diagnostic, security, and audit logs;
  • pages and features used;
  • errors and performance information.
Support and communications
  • support requests;
  • correspondence and call details;
  • information provided during demonstrations, onboarding, or troubleshooting.
3. How we obtain information
We obtain information:
  • directly from account holders and website visitors;
  • from authorized connected services;
  • from customers and other individuals communicating with a configured chatbot;
  • from payment providers and marketplaces;
  • automatically through logs, cookies, and similar technologies;
  • from authorized employees or representatives of a customer.
4. Purposes and legal bases
We process personal data to:
  • create and administer accounts;
  • provide requested chatbot and integration functionality;
  • synchronize permitted business, site, and catalog information from authorized connected services;
  • generate responses and perform configured actions;
  • process subscriptions and payments;
  • provide support and troubleshoot errors;
  • secure the Service and prevent abuse;
  • comply with legal and accounting obligations;
  • improve Service performance and usability;
  • send service-related communications;
  • send marketing communications where permitted.
Depending on the circumstances, our legal basis may be:
  • performance of a contract;
  • compliance with a legal obligation;
  • our legitimate interests in operating, securing, and improving the Service;
  • consent;
  • documented instructions from a merchant acting as controller.
Where we rely on consent, it may be withdrawn at any time without affecting prior lawful processing.
5. Artificial intelligence processing
Customer Content may be sent to AI technology providers, including OpenAI, to generate responses, analyze instructions, retrieve relevant knowledge, or perform other enabled features.
For a website or catalog integration, this may include the customer’s question, the relevant conversation excerpt, bot instructions, and only the product, SKU, price, image, public URL, variant, or inventory fields needed to answer that question. OAuth access tokens and app client secrets are not sent to AI providers. AI providers process this information as service providers for the requested ChatRex functionality and subject to applicable contractual and data-protection obligations. Merchants should not configure ChatRex to send information that is unnecessary for the requested purpose.
ChatRex does not make legally binding or similarly significant decisions about individuals solely through AI unless a customer separately establishes a lawful basis, provides required notices, and implements appropriate safeguards and human review.
6. How we share information
We may share information with:
  • hosting, database, storage, and content-delivery providers;
  • AI technology providers, including OpenAI;
  • payment and subscription providers;
  • email, support, monitoring, and security providers;
  • third-party services connected by the customer;
  • professional advisers and auditors;
  • government authorities where disclosure is legally required;
  • a buyer or successor in connection with a merger, financing, restructuring, or sale of assets.
Service providers may process information only for contracted purposes and subject to appropriate confidentiality and data-protection obligations.
We do not sell personal data for monetary consideration.
7. International transfers
ChatRex and its service providers may process information in countries other than the country where it was collected.
Where required, we use appropriate transfer mechanisms and safeguards, which may include contractual protections, adequacy decisions, consent, or other mechanisms recognized by applicable law.
By enabling integrations involving international providers, merchants instruct ChatRex to perform transfers necessary to provide those integrations, subject to applicable law.
8. Data retention
We retain personal data only for as long as necessary to:
  • provide the Service;
  • follow documented customer instructions;
  • maintain security and audit records;
  • resolve disputes;
  • enforce agreements;
  • comply with accounting, tax, and legal obligations.
After account closure or a valid deletion request, Account Data and Customer Content are deleted or anonymized from active systems within 30 calendar days, unless continued retention is required by law.
Security and audit logs are retained for up to 12 months, unless longer retention is required by law or an ongoing security investigation.
Residual encrypted backup copies are placed beyond use and overwritten through the normal backup cycle within 30 calendar days. If a backup is restored, applicable deletion requests are reapplied.

Integration disconnection and deletion. The provider OAuth access token remains encrypted in active systems only while the integration is connected. When the customer disconnects the integration, ChatRex requests revocation from the provider where available, removes the token from the active ChatRex integration record, and stops new provider API requests. Temporary catalog responses normally expire from the operational cache within 60 seconds. Remaining site and connection metadata, and any integration-derived product facts already included in Customer Content, follow the retention periods above. A customer may request deletion when disconnecting by contacting info@chatrex.pro; applicable active-system data will be deleted or anonymized within 30 calendar days, subject to legal exceptions. Security and audit logs remain subject to the 12-month period above.

9. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal data, including access restrictions, authentication controls, encryption where appropriate, logging, monitoring, and backup procedures.
No online service can guarantee absolute security. Customers are responsible for protecting their credentials, reviewing connected services and granted permissions, and keeping their websites, extensions, and integration software updated where applicable.
10. Merchant responsibilities
Merchants using ChatRex must:
  • provide their own customers with an accurate privacy notice;
  • identify ChatRex and relevant AI or integration processing where required;
  • establish a lawful basis for processing;
  • collect valid consent where required;
  • limit data to what is necessary;
  • respond to data-subject requests;
  • configure retention and access appropriately;
  • avoid submitting prohibited or unnecessary sensitive information.
If you are an end customer communicating with a merchant through ChatRex, requests concerning your store, order, or conversation data should normally be sent first to that merchant.
11. Your rights
Depending on applicable law, you may have the right to:
  • request access to your personal data;
  • correct inaccurate information;
  • request deletion;
  • restrict or object to processing;
  • receive certain data in a portable format;
  • withdraw consent;
  • object to direct marketing;
  • complain to a competent data-protection authority;
  • request information about automated processing and applicable safeguards.
To exercise a right concerning your ChatRex account, contact info@chatrex.pro.
We may need to verify your identity. If ChatRex processes the relevant data solely for a merchant, we may forward the request to that merchant or ask you to contact it directly.
12. Cookies
ChatRex websites may use necessary cookies for authentication, security, language preferences, and core functionality.
Analytics or marketing cookies will be used only where permitted and, where required, after consent. Available cookie choices may be managed through the website’s cookie controls.
13. Children
The Service is intended for businesses and is not directed to children. ChatRex does not knowingly allow children to create business accounts.
Merchants must not use ChatRex to collect children’s personal data unless they have established a valid legal basis and implemented all required safeguards.
14. Changes to this policy
We may update this Privacy Policy when the Service, law, or our processing practices change.
The effective date will be updated, and additional notice will be provided where required.
15. Contact and complaints
Privacy questions and requests may be sent to:
RUBIKON TECHNOLOGIES LLP
Email: info@chatrex.pro
You may also lodge a complaint with the competent data-protection authority in your jurisdiction.