Legal
Privacy Policy
Last updated 1 October 2026 · Effective 1 October 2026
This policy explains what Quantum Market Hub LLC (“Advizz”, “we”), 8 The Green, Suite R, Dover, DE 19901, United States, does with personal data in the Advizz service — this website, the client cabinet, and the chat assistant our customers install on their own sites. The commercial terms are in the User Agreement.
Contents
1. Two roles, two situations
If you are a visitor who chatted with an assistant on some company’s website: that company decides what the assistant does and why it keeps your conversation. It is the controller of your data; we process the conversation on its behalf and under its instructions. Requests about such data are handled through that company — write to us and we will route your request to it and tell you we have done so.
If you are our customer — a business with an Advizz account — we are the controller of your account data: who you are, how you reached us, which plan you use and what happened in your cabinet.
2. What we hold
| Data | Where it comes from |
|---|---|
| Conversations: the messages exchanged with the assistant, their time, the page the visitor was on (address and title), the detected language, a random session identifier, and the rating if one is given | The chat widget, the demo chats on this site, and the email channel |
| Contact details a visitor gives: name, email address, phone number — with the moment and the way they were given (a form, or recognised in the text) | Entered by the visitor in the conversation |
| Inbound email: the sender’s address, subject and body of a message sent to the support address we route for a brand | Email sent by the visitor |
| Account data: company name, website, the names and work email addresses of the users invited to the cabinet, plan and usage counters, and a log of account events | Given by the customer, or recorded as the cabinet is used |
| Sign-in sessions: IP address, browser user-agent and a short device label (“Chrome · macOS”), so a cabinet user can see and end sessions on other devices | Recorded at sign-in |
| Product analytics: counted events such as a dialogue started, an answer sent, a lead captured, a handoff requested, a question left unanswered — tied to a brand and, where relevant, to a conversation | Recorded by the service as it runs |
| Knowledge base: text taken from the customer’s own website, catalogue and documents, with a revision history | Read on the customer’s instruction, or uploaded by the customer |
We do not ask for and do not want special-category data — health, beliefs, biometrics and the like. Do not put it into a conversation. We do not collect or store card details: payment, where it applies, is arranged outside the service.
3. Why we hold it
- To run the assistant — answer the question in front of it, keep the thread of the conversation, hand it to a human operator, and let the customer see the conversation in their cabinet. Legal basis: performance of our contract with the customer, and the customer’s own basis towards its visitors.
- To provide the account — sign-in, plan limits, invoices, support correspondence. Legal basis: contract.
- To keep the service safe and working — rate limits, abuse prevention, error diagnosis, isolation between brands. Legal basis: legitimate interest.
- To improve the product — counted events and aggregate quality measurements. Legal basis: legitimate interest.
4. Cookies and local storage
This site carries no advertising or analytics trackers — no Google Analytics, no advertising pixels, no third-party profiling scripts. What is used:
- a session cookie for the client cabinet and the admin area, so a signed-in person stays signed in, plus a token that protects forms against cross-site submission. Both are strictly necessary and set only once you sign in;
- in the chat widget, a random conversation identifier kept in the browser’s local storage, so a visitor who returns within 30 days continues the same thread instead of starting from nothing. It carries no name and no profile, and clearing site data removes it;
- web fonts loaded from Google Fonts on the public pages, which means your browser requests a file from Google’s servers.
5. Who else processes it
| Who | What they get |
|---|---|
| Our model provider (OpenAI) | The question, the relevant part of the knowledge base and the recent turns of the conversation, sent through its API to produce an answer |
| Cloudflare | DNS for advizz.io and the routing of email sent to our addresses, which passes the message through on the way to the service |
| Our hosting provider | Operates the server the service and its database run on; no separate access to the content |
| Our mail relay | Sends outgoing notifications — a sign-in link, a lead alert, a reply from a conversation |
| The customer whose assistant was used | Sees the conversations on its own brand, and the contacts collected in them |
We do not sell personal data and we do not share it for anyone’s advertising. Beyond the processors above, we disclose data only where the law requires it, or to a professional adviser under a duty of confidence. If our business is transferred, this policy follows the data and we will say so before anything changes.
6. AI models and training
Answers are generated by a third-party large language model called through its API. We do not train models of our own on customer content or on visitors’ conversations, and the provider’s API terms do not allow it to train on data sent that way. Prompts are not sent to any other model provider than the one configured for the account.
Automated answers are not a decision about a person: the assistant explains, compares and quotes what the customer has published. It does not score, profile or decide anything with a legal effect on a visitor.
7. How long we keep it
- Conversations, contacts and analytics events — while the customer’s account is active, because they are its own support history. A customer can delete an individual contact from the cabinet at any time, and we delete a conversation on the customer’s or the visitor’s request.
- After an account closes — its data is deleted within 30 days, except where we must keep an invoice or correspondence for accounting or legal reasons. Ask for an export before you close.
- Sign-in sessions — a session row is kept while the session is live and for a short period after it is revoked, so that “log out everywhere” can be audited.
- Knowledge base revisions — the most recent revisions of each entry are kept so a change can be rolled back; older ones are pruned automatically.
8. Security
- Everything travels over HTTPS; the service is not served over plain HTTP.
- Sign-in to the cabinet is by one-time link to a work mailbox — there is no client password to leak — and each live device is a row that can be revoked on its own.
- Model-provider keys are stored encrypted at rest; only the last four characters are ever shown back in the interface.
- Brands and accounts are isolated from each other in the data model, and that isolation is covered by automated tests that run on every deployment.
- Access to the production database is limited to the people who operate the service.
No system is perfectly secure. If a breach affects your data, we will inform the affected customers without undue delay and, where the law requires it, the competent authority.
9. Your rights
Depending on where you live, you may have the right to ask for a copy of your data, to have it corrected or deleted, to restrict or object to its processing, to receive it in a portable form, and to withdraw consent you have given. You can also complain to your data-protection authority.
Write to hello@advizz.io. We answer within 30 days. If the data belongs to a conversation on someone else’s website, we pass the request to that company, because the decision is theirs — and we tell you who it is.
10. Children
The service is built for business use and is not directed at children. We do not knowingly collect data from a child; if you believe a child’s data reached us, write to us and we will delete it.
11. International transfers
We are a United States company, and our processors operate in the United States and in Europe, so your data may be processed outside the country you are in. Where that transfer needs a legal basis, it rests on the standard contractual clauses of the processor concerned and on the agreement we have with it.
12. Changes to this policy
The current version always lives at this address, dated at the top. If a change materially affects how we handle personal data, we will tell the contact addresses of active accounts before it takes effect.
13. Contact
Quantum Market Hub LLC
8 The Green, Suite R, Dover, DE 19901, United States
hello@advizz.io