HyperChat privacy notice
Effective 17 July 2026 · Last updated 18 July 2026
1. Who we are
HyperChat is provided by Clone Centre Ltd, a company registered in England and Wales under company number 16536248. Our registered office is 145 Moorhey Road, Liverpool, England, L31 5LF. Contact us at clone@clonecentre.ai.
2. Our role
We act as controller for information used to operate customer accounts, secure the service, handle enquiries and manage our commercial relationship. When a visitor chats with a HyperChat assistant on a customer's website, that customer normally decides why the visitor's information is processed. In that situation the customer is the controller and Clone Centre Ltd processes the information on its behalf. The customer's privacy notice also applies.
3. Information we process
- Customer account and project details, including business name, email address, website URL, configuration and subscription references.
- Public website content supplied for building a knowledge base, including pages, services, FAQs and branding information.
- Chat messages, timestamps, a pseudonymous session identifier, referring page, browser type, device type and a one-way hash of the network address used for abuse prevention.
- Lead details submitted voluntarily, such as name, organisation, email address, telephone number, enquiry and the consent wording accepted.
- API-key metadata, webhook configuration, event and delivery logs, response codes and security records. Full API keys are not retained after issue.
- For agency workspaces: agency contact and plan details, credential scopes, website-authority references and attestations, domain-verification state, build jobs, project ownership, usage limits and an activity audit log.
- Support correspondence and information required to investigate a fault, complaint or security incident.
4. Why we use information and our lawful bases
- Contract: to create, host and support chatbots, manage accounts, deliver integrations and provide purchased services.
- Legitimate interests: to keep HyperChat secure, prevent abuse, diagnose faults, improve reliability, understand service usage and protect legal rights. We balance these interests against the rights of affected people.
- Consent: where a visitor asks to be contacted or where consent is otherwise presented as the basis. Consent can be withdrawn by contacting the relevant website owner or us.
- Legal obligation: where records must be retained or disclosed to comply with applicable law.
Visitors do not have to provide contact details, but without an email address or telephone number the website owner cannot follow up through the lead form.
5. Agency website authority and automation
Before an agency build can run, HyperChat records the agency's confirmation that it has permission from the website owner and verifies the domain by DNS, an HTTPS well-known file or our internal contract review. Verification tokens are stored only as keyed hashes. We retain the authority reference, verification outcome and related audit history to perform the service, enforce access boundaries, investigate misuse and protect legal rights. Technical domain verification does not establish that an agency holds every copyright, confidentiality or data-protection permission required for its intended use.
6. AI processing and automated decisions
HyperChat uses generative AI to retrieve relevant website material and draft conversational responses. Messages and relevant knowledge-base content may be sent to the configured AI provider. HyperChat is not intended to make solely automated decisions that produce legal or similarly significant effects. AI responses can be incomplete or incorrect and should not replace qualified professional or human review.
7. Who receives information
Information is shared only as needed with the HyperChat customer whose assistant a visitor uses; hosting, database and content-delivery providers including Railway and its infrastructure suppliers; configured AI providers including OpenAI and Moonshot AI; payment providers where checkout is enabled; professional advisers and authorities where legally required; and integration destinations such as CRMs, Zapier, Make or n8n that the customer deliberately connects.
A customer controls its own connected destinations. Their separate privacy terms apply once information is delivered to them.
8. International transfers
Some suppliers or connected services may process information outside the United Kingdom. Where restricted transfers apply, we use an applicable adequacy regulation or contractual safeguards recognised under UK data-protection law. Contact us for information about the safeguard relevant to a particular service.
9. Retention and deletion
There is no single retention period for customer-controlled chatbot content. We retain it according to the customer's instructions, while the relevant project or account remains active, and afterwards only for as long as reasonably needed for backup recovery, disputes, security and legal obligations. The criteria include account status, contractual requirements, the sensitivity of the information and applicable limitation periods. Deleting a HyperChat project removes its active conversations, leads, API credentials, webhooks and integration events; residual backup copies expire through the provider's backup cycle.
10. Cookies and local storage
HyperChat uses an essential signed cookie to keep authorised administrators logged in. The embedded widget uses browser local storage to remember a random chat-session identifier and whether lead details were already submitted. These are operational features, not advertising trackers. Customer websites may use their own cookies and should explain them separately.
11. Security
We use access controls, encryption in transit, hashed or encrypted integration credentials, signed webhooks, request limits and logging designed to protect information. No internet service can guarantee absolute security. Customers must protect private portal links and integration keys and promptly report suspected compromise.
12. Your rights
Depending on the circumstances, UK data-protection law may give you rights of access, correction, erasure, restriction, portability and objection, and the right to withdraw consent without affecting earlier lawful processing. To exercise a right, contact the website owner whose chatbot you used or email us. We may need to verify identity and identify the relevant customer and session.
Your right to object: where processing is based on legitimate interests, you may object based on your particular situation. You may always object to direct marketing.
13. Complaints and changes
Please contact us first so we can investigate. You may also complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint. We may update this notice when the service or law changes; the current version and effective date will remain on this page.