DM Butler
Legal

Privacy Policy

Version 2026-10-09

1. Controller

DM Butler

This policy covers our website and your DM Butler account. For the messages of your customers that DM Butler handles for you, you are the controller and we are your processor under the Data Processing Agreement.

2. What we process and why

3. Cookies

We only use cookies that are strictly necessary: the session cookie, a security token, your language choice and your light/dark preference. We use no advertising or analytics cookies, so no consent banner is needed.

4. Artificial intelligence

Customer messages and your approved knowledge are sent to the AI providers listed below to generate replies. They may not use this data to train their models. Your customers are told that they are talking to an AI assistant.

5. Recipients and transfers

We use these service providers (sub-processors). Transfers outside the EU/EEA are based on an adequacy decision or the EU Standard Contractual Clauses.

6. Your rights

You have the right of access, rectification, erasure, restriction, data portability and objection, and to withdraw consent at any time with effect for the future. You can export your data and delete your workspace yourself under Settings → Data, or contact us. You may also complain to a data protection supervisory authority, in particular in your EU country of residence.

7. Children

DM Butler is a service for businesses and is not directed at anyone under 18. We do not knowingly collect data of children for our own purposes.

8. Security

Data is encrypted in transit; channel tokens and payment keys are also encrypted at rest. Access is limited to staff who need it and is logged.