Privacy Policy

Last updated: October 7, 2026

1. Data controller and data processor

Uneven Bits ApS, CVR no. DK30487842, domiciled in Denmark, has two roles depending on the data being processed. For data about account holders — meaning the individuals who create an account and use the Asktopus dashboard — we are the data controller. For chat data from visitors on a website using the Asktopus widget, our customer is the data controller and we act as a data processor on the customer's behalf under GDPR Article 28. All processing is carried out in accordance with the EU General Data Protection Regulation (GDPR) and Danish data protection legislation.

2. What information do we process?

We process two categories of personal data. Account data (we are the controller): name, email address, company name, payment information (handled via Stripe; we do not store card data), technical data (IP address, browser type, cookies), and usage data (log files, dashboard interaction, support communications). Website statistics (we are the controller): on asktopus.com we count visits with Umami, which we run ourselves on our own server. It sets no cookies, stores nothing on your device and doesn't keep IP addresses; we see which pages are viewed, the referring site, campaign tags, country, browser and device type, without identifying you. When you create an account, we also store how you found us: the campaign or referring site and the pages you arrived on and signed up from. Visitor data (we are the processor on our customer's behalf): chat messages written by visitors on a website using the Asktopus widget, the name, e-mail address and phone number a visitor enters in the chat's contact form to be contacted by the customer's team, plus technical metadata such as IP address and browser type. What visitors write in the chat may contain personal data — it is our customer's responsibility to inform visitors of this in their own privacy notice. Shopify stores (we are the processor on the merchant's behalf): when a merchant installs the Asktopus app, we read the store's name, currency and web address, and the products, collections, stock levels, pages, blog posts and policies the store publishes, so the assistant can answer from them. On the Pro and Business plans, if the merchant allows it, we also read the store's metaobjects (its own content, such as FAQs or size charts) of the kinds the merchant chooses, and on Business its markets and each market's prices. The app can only read these: it reads no orders and no customer records, and changes nothing in the store. Messages a shopper sends with "Talk to a person" go to the merchant through the store's own contact form; we don't store them.

3. Purpose of processing

We process account data to: deliver and administer the Asktopus service, create and maintain your account, process payments and invoicing, provide customer support, send service messages, comply with legal requirements, and improve and develop the platform. We use the website statistics and how an account found us to see which pages and channels bring visitors and customers. We process visitor data solely to deliver the chat assistant on the customer's behalf — including retrieving relevant content via vector search and generating answers via language models — and to give the customer insight into conversations and usage patterns.

4. Legal basis

For account data we process personal data on the following legal bases in the GDPR: Performance of a contract (Article 6(1)(b)) — necessary to fulfill the agreement for delivery of the service. Legal obligation (Article 6(1)(c)) — necessary to comply with legislation, including bookkeeping and tax laws. Legitimate interests (Article 6(1)(f)) — necessary to operate, secure, and develop the service, including website statistics and knowing how customers find us, provided your interests do not take precedence. For visitor data we process information solely on the documented instructions of our customer (the data controller) under the data processing agreement.

5. Data retention

We retain personal data for as long as necessary for the purposes for which it was collected. Account information is retained while you have an account, including on the free plan. When you ask us to delete your account, account data is deleted within 30 days, unless we are required to retain it under applicable legislation (e.g., the 5-year bookkeeping requirement). Payment information is retained in accordance with bookkeeping requirements. Log files and technical data are retained for up to 12 months. The content of chat conversations from the widget (questions, answers and messages passed on to the customer's team) is deleted automatically 90 days after the conversation's last activity. After that we keep only a record that the conversation took place (time, site, number of messages and technical usage data), without its content. Our backups are kept for up to 30 days, so deleted data can remain in backups for up to 30 days after deletion before it is overwritten. When a merchant uninstalls the Shopify app, we keep the store's data for 48 hours in case the app is installed again; Shopify then asks us to erase it, and we delete the store's site, its knowledge and its conversations.

6. Sub-processors and international transfers

To deliver the service we use the following sub-processors: Contabo (France — hosting of servers and databases), Hetzner (Germany/Finland — hosting of servers and databases, if we move or add servers there), OpenAI (USA — embeddings for search across customer content), Anthropic (USA — the Claude language model for generated answers), xAI (USA — the Grok language model for generated answers), Cloudflare (EU/USA — network delivery and security, website crawling, file storage and backups), Stripe (EU/USA — payment processing), Brevo (EU — sending service emails), and Sentry (EU — error monitoring). Transfers to the USA are made on the basis of the European Commission's adequacy decision (EU-US Data Privacy Framework) or, where applicable, the European Commission's Standard Contractual Clauses. We notify customers before adding or replacing sub-processors that process visitor data.

7. Your rights

Under the GDPR and Danish data protection legislation, you have the following rights against the data controller: right of access, right to rectification, right to erasure, right to restriction of processing, right to data portability, and right to object. Where we are the controller (account data), you can exercise your rights by writing to [email protected]. Where the matter concerns visitor data and our customer is the controller, you should contact that customer directly — we will gladly forward the request if you contact us first in case of doubt. You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) if you believe we are processing your information in breach of the GDPR.

8. Contact

If you have questions about our processing of personal data or wish to exercise your rights, please contact us at [email protected].