Version of 26 August 2026

Privacy policy

What the service does with the data of account owners and of the visitors of their sites: what reaches us, why, where it is kept, who receives it and how to have it removed.

Who runs the service

The data controller is Pavel Ulitin, sole proprietor, tax number 732812384867, Russia. WidgetChat is a BOZEX service.

Write to info@bozex.ru about anything related to personal data: the same address takes requests to correct, block or delete data and to withdraw consent.

Where this policy applies

It covers widgetchat.ru, the dashboard, the api.widgetchat.ru gateway, the chat widget on customer sites, the WordPress plugin, the amoCRM application, the service bots in Telegram and the public API.

The service takes messages from site visitors, brings them to the operator in Telegram, WhatsApp, MAX or a CRM, and returns the reply into the chat window on the site.

Who is the controller of what

For the data of account owners, their staff and the visitors of widgetchat.ru itself, we are the controller.

Conversations that happen on your site we process on your behalf: there you are the controller and we are the processor. Telling your visitors about the chat and about the data it passes on is your job, in your own privacy policy.

What data is processed

  • Account — Email address, name, sign-in identifiers from Google, Yandex, VK or Telegram, the list of connected sites and the widget appearance settings.
  • Connection keys — Bot tokens and channel keys that the owner entered in the dashboard. They are stored encrypted and are never returned to the outside.
  • Conversations — Message text, attached files and screenshots, voice messages and their transcripts, read marks.
  • Chat visitor — The identifier the widget keeps in the browser so that a returning visitor sees their own history; the address of the page they wrote from; the IP address and browser details.
  • Messages from marketplaces and messengers — The name or nickname in that channel, the ticket or order number, the phone number — exactly as the channel itself sends them.
  • Technical logs — Date and time of actions, errors, security events, request identifiers.

Why

  • To deliver the message — Carry the message from the visitor to the operator and bring the reply back into the chat window.
  • To show the history — A returning visitor sees the earlier conversation, and the operator sees one thread instead of scattered fragments.
  • To notify — Sound, unread counter and the tab title in the browser, notifications in Telegram.
  • To support and to fix — Handle the account owner's request to our support and find the cause of a fault.
  • To protect the service — Cut off abuse, key guessing and load that gets in the way of other customers.
  • To comply with the law — Answer lawful requests from authorities.

On what grounds

The account owner's data is processed to perform the contract with them, that is the terms of use. The conversations of their site visitors we process on their instructions, as a processor.

Analytics on widgetchat.ru runs only after the consent given in the cookie banner; refusing it does not prevent you from using the site or the dashboard.

Who receives the data

Only the services without which the message would not arrive: Telegram, so that the operator receives it and replies; WhatsApp (Meta), MAX, Wildberries and the site owner's CRM — if the owner connected that channel themselves.

We do not sell data, do not pass it to advertising networks and do not use conversations to train models. Apart from the channels listed above and cases directly required by law, conversations go nowhere.

Where the data is stored

The service databases are hosted on servers in Russia. Part of the technical infrastructure — the Telegram gateway and the attachment storage — runs on servers in Germany, so a cross-border transfer takes place.

In both cases the recipient is the service's own infrastructure, not an outside company.

How long it is kept

  • Conversations and attachments — Until the site owner deletes the site in the dashboard: deleting the site deletes its conversations.
  • Account data — While the account exists; after deletion up to thirty days, until backups expire.
  • Technical logs — Up to twelve months; security event records up to three years.
  • Backups — No longer than thirty days; what was deleted is not restored from them.

Cookies and analytics

The widget keeps a technical identifier in the visitor's browser — without it there is no way to show a person their own conversation on the next visit. That is a technical necessity and needs no separate consent.

Yandex Metrica runs on widgetchat.ru. It starts only after the visitor accepts analytics in the cookie banner; before that the counter is not loaded at all.

How the data is protected

Database access is closed, keys and tokens are stored encrypted, and traffic between the widget, the gateway and the channels goes over TLS. Staff access to conversation content happens only on the account owner's request and only to fix a fault.

If a breach affects customer data, we inform the account owner and the supervisory authority within the time limits set by law.

Your rights

You may ask which of your data is processed, have inaccurate data corrected and unnecessary data deleted, withdraw your consent and complain to the supervisory authority or to a court.

Send the request to info@bozex.ru; we answer within thirty days. If the request concerns a conversation on someone else's site, we forward it to the owner of that site: there they are the controller.

Children

The service is not meant for children and does not knowingly collect their data. We do not ask for special categories of data or biometrics; if such details end up in a conversation by accident, they are used for nothing except answering that message.

Changes to this policy

The page carries a version date. Significant changes are announced in the dashboard; continuing to use the service after the announcement means you accept the new version.

Frequently asked questions

Who is responsible for the data of my site's visitors?

You are, as the site owner: the chat sits on your page and works on your instructions. We process the conversations on your behalf and follow your deletion requests.

Do I need to mention the chat in my own privacy policy?

Yes. The widget keeps an identifier in the visitor's browser and passes us what the person wrote — your policy has to say so.

How do I delete the conversations?

Delete the site in the dashboard: its conversations go with it. A single conversation can be deleted on request to info@bozex.ru.

Is data transferred abroad?

Yes, part of the technical infrastructure — the Telegram gateway and the attachment storage — runs on servers in Germany. The recipient is our own infrastructure, not an outside company.

Read next

Add the chat to your website

Sign up with email or Telegram, set it up in the dashboard, paste one line of code. Free right now.