PluginChatBot
Home
Integrations
HubSpot Integration WhatsApp Integration Messenger & Instagram Live Chat Handoff Explore All Integrations
Installation Pricing
Contact Us Login Start Free Trial→
Dashboard
Home
Integrations HubSpot Integration WhatsApp Integration Messenger & Instagram Live Chat Handoff Explore All Integrations
Installation Pricing Contact Login Start Free Trial→
Dashboard

Legal document

Privacy Policy

How PluginChatBot and NAFCORP TECHNOLOGIES collect, use, disclose, secure and manage personal information.

Version 1.0 | Effective 21 September 2026

1. Who we are and how to contact us

PluginChatBot is provided by NAFCORP PTY LTD (ACN 660 556 203; ABN 53 660 556 203), trading as NAFCORP TECHNOLOGIES, Victoria, Australia. In this policy, “we”, “us” and “our” mean that company. Our websites include pluginchatbot.com and app.pluginchatbot.com. Contact our privacy officer at sales@pluginchatbot.com, using “Privacy request” in the subject line. You may ask for this policy in an accessible format or request an alternative way to communicate with us.

This policy explains how we handle information about identifiable or reasonably identifiable people when providing our websites, accounts, chatbot platform, support and related services. It covers information that is recorded in text, documents, messages, technical records and other supported formats, including information generated or inferred by an AI system.

2. Our role and the role of the business using a chatbot

When you create a PluginChatBot account, contact us, purchase a subscription or visit our own websites, we determine how your information is used for those activities. When a business installs a PluginChatBot widget or connects a messaging service, that business ordinarily determines why it collects its visitors' information and how it uses their conversations and leads. We process that information to provide the platform and carry out the business's authorised instructions.

The business operating the chatbot should identify itself and provide its own privacy notice. Its staff and authorised administrators may access conversations, leads and connected records. Its choices may determine what is collected, whether an integration receives the information and how long it needs the records. The business's policy does not replace this policy, and neither party can transfer away responsibilities imposed on it by law. Our Data Processing Addendum sets out our processing commitments to customers.

For a request about a chatbot on someone else's website, contact that business first where practicable. You may also contact us with the website address and approximate time of your interaction. We will assist, identify the appropriate business where reasonably possible, and address any responsibilities we have directly. You do not have to obtain that business's permission to raise a concern with us or a regulator.

3. Information we collect and hold

Accounts and administration. Names, email addresses, telephone numbers supplied at registration, business and workspace details, membership and permissions, account identifiers, authentication and verification records, password hashes, account preferences and records of the terms accepted. We do not need your ordinary password in a support message.

Subscriptions and payments. Plan, price, currency, billing periods, invoices, subscription status, payment-provider references and transaction outcomes. Stripe handles payment information entered into its hosted payment interfaces. We receive information necessary to administer purchases, not a general entitlement to inspect your full card details.

Conversations and leads. Messages, answers, contact details entered by visitors, visitor and conversation identifiers, channels, relevant website addresses, timestamps, attachments where supported, conversation summaries, handoff records and staff replies. A message may contain personal information even without a name, particularly when combined with a visitor identifier or other records.

Customer content and integrations. Website content submitted for retrieval, uploaded knowledge documents, bot configuration and instructions, permitted connected-system records, integration identifiers and credentials necessary to operate authorised connections. Where text-to-speech is enabled, text selected for speech is sent for audio generation. A new voice-recording or transcription feature requires its own collection notice before audio is collected; this policy is not permission to record calls secretly.

Technical and support information. IP-related security information, device and browser details, cookies and browser storage, page or feature interactions, service errors, resource usage, support correspondence and incident records. Some security and analytics records use hashes or internal identifiers. Those records are not necessarily anonymous.

We do not require identity documents, tax file numbers, full payment-card numbers, medical records or other sensitive information in ordinary chatbot conversations. Do not enter passwords, private keys or confidential information into a public widget. Customers must not configure the platform to collect restricted information contrary to our Acceptable Use Policy.

4. How we collect information and your choices

We collect information directly when you register, complete a form, communicate with a chatbot or support team, upload content, configure the platform or buy a service. We also receive information from the customer operating a chatbot, authorised workspace users, connected services you or the customer enable, payment providers and automatically generated service and security records.

Some registration details are required to create, secure and administer an account. Where a field is required, the interface identifies it. Without necessary information we may be unable to provide that function. Optional information should be identified as optional. You may make a general enquiry anonymously or under a pseudonym where practicable. An authenticated account or reasonable verification may be necessary for billing, access to private records or an account change.

An enquiry or acceptance of service terms is not blanket consent to marketing, sensitive-information collection, unrelated AI training or every possible overseas disclosure. Where consent is the appropriate basis for an activity, we seek a specific, informed choice and provide a way to withdraw it. Withdrawal does not undo handling that was lawful before withdrawal and may prevent a function that needs the information from continuing.

If we receive information we did not request, we assess whether we could lawfully have collected it. Where appropriate and lawful, we delete, de-identify or restrict it rather than incorporating it into routine processing. A warning not to submit sensitive information does not remove our obligations when it is submitted.

5. Why we use information

We use information to create and secure accounts; supply chatbot, knowledge retrieval, lead capture and human-handoff functions; carry out authorised integrations; administer trials, subscriptions and payments; provide support; investigate misuse and incidents; maintain reliability; respond to privacy requests; and comply with applicable legal requirements.

Customer conversations and knowledge content are used to supply the customer's configured service, not as a general licence to sell visitor data, publish private conversations or build unrelated advertising profiles. Access by our personnel must have a legitimate service, security, support or legal purpose and be limited accordingly.

We may analyse operational measures such as feature usage, response failures and resource consumption to improve reliability and plan capacity. Reusing identifiable conversation content for a materially different purpose requires a separate assessment and any notices, permissions or consent the law requires. De-identification requires an assessment of re-identification risk; merely removing a name is not enough.

6. AI processing and generated information

PluginChatBot uses third-party AI services, including OpenAI, to generate responses and support enabled knowledge and speech functions. Relevant messages, instructions, selected conversation context and retrieved material may be sent to the AI provider. The provider and the business operating the chatbot may receive information contained in that context.

Making documents available for retrieval is different from training the underlying general-purpose model. Under the standard OpenAI API arrangements reviewed for this policy, API content is not used to train OpenAI's models by default unless sharing is explicitly enabled. We do not authorise optional general-model training on customer content as part of the ordinary service. This is not a promise that no provider stores information: abuse monitoring, response state, uploaded files and retrieval stores may have different retention rules, including legal preservation requirements.

AI responses can contain mistakes, unfair inferences or invented personal information. Do not rely on them as verified facts about a person. Contact the business or us to request correction or review. The AI Usage and Safety Provisions explains permitted uses and the need for human oversight. We do not authorise customers to use the standard service as the sole decision-maker for significant decisions about an individual's rights or interests.

7. Who information may be shared with

We share information with the relevant customer and its authorised users; cloud infrastructure, security and AI providers; transactional email providers; Stripe and relevant payment participants; and connected CRM or messaging providers when the relevant connection is enabled. Our Subprocessor and Recipient Register identifies providers and distinguishes service processors from recipients that may act for their own purposes.

Account details may also be passed to NAFCORP's signup and customer-administration system to administer the relationship. This is not a separate marketing opt-in. Access by another business, contractor or external provider supporting that system must be assessed and disclosed appropriately.

We may disclose information to professional advisers, insurers, regulators, courts or law-enforcement bodies where reasonably necessary and permitted or required by law. We assess the scope and legal basis of requests. We may disclose limited information for a genuine business transfer subject to appropriate confidentiality and privacy safeguards, with notice of material changes where required. This does not permit selling private conversations as a standalone dataset.

8. Overseas handling

Our providers and authorised personnel may handle information in Australia and overseas. Overseas locations that may be involved include the United States and New Zealand, together with countries identified in our Subprocessor and Recipient Register where practicable. A provider's headquarters is not necessarily where it stores information, performs inference, provides support or operates backups.

The location and retention of information depend on the service, account settings, selected features and applicable provider arrangements. We do not promise that all information remains in Australia or that Australian storage also means Australian-only processing. Customers requiring a particular location must obtain an expressly agreed service arrangement before providing the affected information.

We assess overseas handling and take reasonable steps required by applicable law, including reviewing provider terms, security, access and onward handling. Accepting this policy is not an agreement to waive APP 8 protections or an acknowledgement that we are relieved of accountability for overseas recipients.

9. Cookies, tracking and marketing

Our Cookie Policy explains cookies, local storage, session storage and relevant third-party technologies. Necessary authentication and security technologies are different from optional advertising or analytics. The choices available in our consent interface apply to the technologies it controls. Rejecting optional tracking does not prevent unavoidable network processing needed to deliver a requested service.

We send promotional electronic messages only where permitted by applicable marketing law. A service enquiry, chatbot conversation or paid account does not automatically authorise unrelated promotional messages. You may use the unsubscribe facility or email us to withdraw marketing permission. We action unsubscribe requests within five working days and do not require payment or an account login to unsubscribe. We may retain a minimal suppression record to respect your choice.

Essential notices about a service you use, security incidents, billing and requested support are not treated as marketing permission. Customers using integrations to send messages are responsible for their own lawful recipient permissions and notices; we remain responsible for our own sending practices.

10. Retention, deletion and closure

We retain personal information for the purposes described in this policy while it is reasonably needed, and for any period required by applicable law or a court or tribunal order. We consider the nature of the information, the customer's ongoing service needs, security, dispute handling and legal recordkeeping. We restrict information retained only for a legal obligation rather than continuing to use it for ordinary service or marketing purposes.

The current platform does not automatically expire conversation and lead records solely because they reach a particular age. Account closure or subscription cancellation is not a representation that every stored copy has been erased. Customers must review the continuing need for identifiable conversation records and give appropriate deletion instructions; we must also meet our own applicable retention duties. Neither an indefinite database setting nor a customer's preference permits retaining information when the law requires its destruction or de-identification.

You may request deletion through the privacy contact above. For customer-controlled records, we verify the request, coordinate with the customer where appropriate and identify applicable restrictions. We explain the scope, expected process and any material delay. Removing a record from the dashboard is not necessarily erasure from every database, provider store or backup.

Necessary billing and company financial records may be retained after closure; Australian company financial-record requirements generally require at least seven years. This does not justify retaining complete chat histories for seven years. Backup copies and provider-held records require their own restricted-access and deletion processes. Where information cannot immediately be removed from a protected backup, it must not be restored to ordinary use without reapplying the relevant deletion or restriction.

11. Security and incidents

We use technical and organisational measures appropriate to the information and risks, including access restrictions, authentication, protected transport, credential handling, operational logging and incident management. Customer administrators must manage their authorised users, protect credentials, configure integrations carefully and notify us promptly of suspected compromise.

No system is completely secure. We do not claim that a third-party provider's certification automatically certifies PluginChatBot, or that a security feature prevents every breach. If an incident occurs, we assess and contain it, cooperate with affected customers and notify individuals and authorities where the applicable law requires. A customer agreement may require notice before the legal threshold for regulatory notification is reached.

12. Access, correction, complaints and other requests

Email sales@pluginchatbot.com with enough information to locate the relevant records. For a customer widget, include the website address, relevant dates and the contact details or identifier you used. Do not send identity documents unless we explain why a limited verification method is necessary. An authorised representative may act for you.

We aim to acknowledge a request within five business days and respond within 30 calendar days, or explain why further time is reasonably needed. These are our service targets, not a statement that every Australian law has the same deadline. We follow any shorter applicable legal requirement. We do not charge to make a request or correct information. If a lawful access charge is proposed, we explain it first and keep it reasonable; we do not use charges to obstruct your rights.

Where we lawfully refuse access or correction, we provide reasons to the extent permitted and explain available complaint options. Where appropriate, we can associate your statement of disagreement with the record and notify relevant recipients of a correction as required by law.

Raise a privacy complaint through the same contact, describing the issue and desired outcome. We investigate fairly and communicate our response. You may complain to the Office of the Australian Information Commissioner where it has jurisdiction, or the relevant state or territory privacy or health-complaints regulator. Information is available at oaic.gov.au. Our process does not prevent you from using legal rights or approaching a regulator.

13. Children, sensitive information and changes

The account-management service is intended for adults acting for a business. Visitors to a customer's website may include children; an adult-only account rule does not mean that every widget visitor is an adult. Customers must assess their audience and obtain required notices, safeguards and permissions. Do not use the standard service for child-directed, sensitive-health or other restricted processing without our prior written approval and an appropriate implementation assessment.

We update this policy when our practices or applicable requirements change. The published page identifies its version and effective date. We provide additional notice of material changes where appropriate and obtain fresh consent where required. A policy update does not retrospectively authorise an incompatible new use of information.

Legal documents

Privacy Policy Terms of Service Acceptable Use Policy Data Processing Addendum Subprocessors Cookie Policy AI Usage & Safety
PluginChatBot

Build a free chatbot for your business in minutes, no code or technical expertise needed. Capture HubSpot leads and manage Messenger, Instagram, and WhatsApp conversations in one place with ease.

Start your free PluginChatBot trial Start Free Trial

Platforms

WordPress ChatbotWooCommerce ChatbotShopify ChatbotWix ChatbotWebflow ChatbotSquarespace ChatbotCustom Website Chatbot

Solutions

Customer Support AI ChatbotEcommerce AI ChatbotSales AI ChatbotMarketing AI ChatbotHealthcare AI ChatbotLead Generation ChatbotLocal Business AI ChatbotSmall Business AI Chatbot

Features

AI ChatbotLead CaptureKnowledge BaseIntegrations

Integration

WhatsAppHubSpotMessenger & InstagramLive Chat handoff

Company

AboutContactPricingLegal

Resource

Chatbot TrainingSecurity and control24/7 supportBlogFAQsBook a Demo
© 2026 PluginChatBot · A product of NAFCORP TECHNOLOGIES