Documentation/Update your privacy policy

Update your privacy policy

Before your widget goes live, tell visitors how you use LeadReply. Start with the checklist, then copy and adapt the wording below.

What you need to add

Add a section about your website chat to your existing privacy policy, and update your cookie or browser-storage notice. Your business is the controller of visitor data; LeadReply processes it on your behalf. Linking to our policy is useful, but visitors also need to understand your business's use of their data.

  • Who to contact: your business's legal name, address and privacy contact.
  • What is collected and why: messages, volunteered contact details, visitor identifiers, page visits, chat activity and lead-source information; explain enquiry follow-up and analytics. Include order data if you enable order tracking.
  • AI and providers: say the chat uses AI, that conversation content reaches AI providers, and that LeadReply processes data for you. Explain recipients and any international transfers using confirmed processing terms.
  • Legal basis: state the basis for each purpose. Answering an enquiry, analytics and marketing are separate purposes; receiving a phone number or email is not a marketing opt-in.
  • Retention: give your actual retention period or criteria and arrange deletion to match it.
  • Storage and rights: explain cookies and similar storage, how consent is managed, and how visitors can exercise their rights or contact their supervisory authority.

Note

These are starting points, not a complete policy or a guarantee of compliance. Replace every bracketed field and review the wording for your location and actual use.

Copy and adapt: English

Add this section to your policy after completing the business details, legal bases, retention and provider information. Keep your cookie-policy link accessible to visitors.

Wording to adapt

Website chat and enquiries [Business legal name], contactable at [business address and privacy email], is responsible for the personal data collected through our website chat. We use LeadReply to provide an AI assistant, answer questions, record conversations and receive enquiries so our team can follow up. We process the messages you send and any name, email address, phone number or other information you choose to share. LeadReply also records a browser identifier, pages visited, timestamps, chat interactions and visit-source information (such as referring pages and campaign tags) to help us understand widget use and where enquiries come from. [If you use order tracking, explain the order reference, amount and currency sent to LeadReply and why. Otherwise remove this sentence.] LeadReply processes this data on our behalf. Conversation content is sent to AI service providers to generate replies; hosting and other service providers support delivery of the service. [Identify the relevant providers or recipient categories and explain any international transfers and the applicable safeguards, based on the current processing agreement.] Our legal basis for responding to enquiries is [state the applicable basis and, if relevant, the legitimate interest]. Our basis for visitor analytics is [state the applicable basis]. We obtain consent for browser storage where required. Providing contact details is optional; without them we may be unable to contact you about your enquiry. Sharing them does not subscribe you to marketing. The widget uses cookies, local storage and session storage to recognise returning browsers, resume chats, remember widget behaviour and record visit sources. The visitor-ID cookie lasts up to 400 days and is refreshed on visits; some local-storage values have no automatic expiry. See [your cookie-policy URL] for purposes, storage periods and how to manage consent. We keep enquiries and chat records for [your retention period or criteria, and how deletion is carried out]. You can contact [your privacy email] to request access, correction, deletion, restriction or portability, or to object where applicable. You can withdraw consent through [your consent settings or contact method] and complain to [your local data-protection authority]. More information about LeadReply: https://leadreply.xyz/privacy.

Replace every bracketed field.

Texto para adaptar: español

Añade esta sección a tu política. Completa todos los campos entre corchetes, revisa las bases jurídicas y confirma los proveedores, las transferencias y la conservación antes de publicarla. Actualiza también tu política de cookies y el consentimiento cuando corresponda.

Texto para adaptar

Chat y consultas de la web [Razón social del negocio], con dirección [dirección del negocio] y contacto [email de privacidad], es responsable de los datos personales recogidos a través del chat de nuestra web. Utilizamos LeadReply para ofrecer un asistente de IA, responder preguntas, registrar conversaciones y recibir consultas para que nuestro equipo pueda atenderlas. Tratamos los mensajes que envías y el nombre, email, teléfono u otros datos que decidas compartir. LeadReply también registra un identificador del navegador, páginas visitadas, fechas y horas, interacciones con el chat y el origen de las visitas (como páginas de referencia y etiquetas de campañas) para ayudarnos a entender el uso del widget y de dónde vienen las consultas. [Si utilizas seguimiento de pedidos, explica la referencia, el importe y la moneda enviados a LeadReply y su finalidad. Si no, elimina esta frase.] LeadReply trata estos datos por nuestra cuenta. El contenido de las conversaciones se envía a proveedores de IA para generar respuestas; proveedores de alojamiento y otros servicios permiten prestar el servicio. [Identifica los proveedores o categorías de destinatarios y explica las transferencias internacionales y sus garantías según el acuerdo de tratamiento vigente.] La base jurídica para atender consultas es [indica la base aplicable y, si corresponde, el interés legítimo]. La base para las analíticas de visitantes es [indica la base aplicable]. Solicitamos consentimiento para el almacenamiento en el navegador cuando sea necesario. Facilitar datos de contacto es opcional; sin ellos quizá no podamos responder a tu consulta fuera del chat. Compartirlos no supone suscribirse a comunicaciones comerciales. El widget utiliza cookies, almacenamiento local y de sesión para reconocer navegadores que vuelven, retomar chats, recordar el comportamiento del widget y registrar el origen de las visitas. La cookie del identificador dura hasta 400 días y se renueva con las visitas; algunos valores del almacenamiento local no caducan automáticamente. Consulta [URL de tu política de cookies] para conocer las finalidades, los plazos y cómo gestionar el consentimiento. Conservamos las consultas y conversaciones durante [plazo o criterio de conservación y cómo se realiza la eliminación]. Puedes escribir a [tu email de privacidad] para solicitar acceso, rectificación, supresión, limitación o portabilidad, o para oponerte cuando corresponda. Puedes retirar el consentimiento en [configuración de consentimiento o medio de contacto] y reclamar ante [autoridad de protección de datos; en España, la AEPD]. Más información sobre LeadReply: https://leadreply.xyz/privacy.

Sustituye todos los campos entre corchetes.

Cookies, browser storage and consent

Describe storage by its purpose. The widget remembers chats and also measures visitor journeys and lead sources. First-party storage is not automatically exempt from consent. Where consent is required, your site must obtain it before the relevant storage or tracking starts and support withdrawal.

The current widget starts storing identifiers and tracking visits when it loads; it does not wait for your cookie banner. Have your website provider or developer connect script loading to your consent manager where required. Test both acceptance and rejection before publishing.

Storage to cover in your cookie notice
PurposeStorage and lifetime
Recognise returning browsersVisitor ID in a first-party cookie (up to 400 days, refreshed on visits), local storage (no built-in expiry) and session storage.
Resume and protect conversationsA local conversation reference is usable for 30 days after saving; a local conversation security token has no built-in expiry.
Remember the first visit sourceLocal source data is reused for up to 90 days. That reuse limit does not automatically erase the stored value.
Group visits and remember widget behaviourSession storage lasts for the tab session; visit sessions reset after 30 minutes of inactivity. Local page counters and trigger history have no built-in expiry.

Browser-storage lifetimes are different from server retention. The LeadReply policy describes keeping conversations and leads while the account is active, archiving older conversations and deletion on verified requests or account closure. Archiving is not deletion. If you promise a shorter period, arrange deletion with your team and LeadReply support.

Before you publish

  1. Publish the completed chat section and cookie notice on your own website.
  2. Make your policy accessible where visitors start chatting or share details, and clearly tell them they are interacting with AI.
  3. Confirm the processing agreement, current sub-processors and transfer information with admin@leadreply.xyz before filling in those fields.
  4. Check your consent setup on a fresh visit, including rejecting consent and withdrawing it after acceptance.
  5. Confirm your privacy contact and deletion process work, then install and test your widget.

Further reading

The European Commission's transparency guidance covers explaining data use. For Spain, see the AEPD's privacy-notice guidance and cookie guidance.

Questions & answers

Ask about this page — the LeadReply team and other readers can answer and upvote.

Log in to ask a question, reply, or upvote. Reading is open to everyone.

Loading discussion…