Widget privacy notice

If you embed the Oshu chat widget, add the following to your website's privacy policy. Replace the [bracketed] parts and have it reviewed.

privacy notice
AI chat assistant (Oshu) Template — replace the [bracketed] parts with your details and have your own counsel review this text before publishing. On [WEBSITE] we use an embeddable AI chat assistant operated on our behalf by BeyondSimulations GmbH, Am Eich 9d, 22113 Hamburg, Germany ("Oshu") as our processor. A data processing agreement under Art. 28 GDPR is in place with Oshu. Purpose: the assistant answers visitor questions based on content we have provided. Data processed: when you use the chat, the messages you enter, the generated responses, and a conversation identifier are processed. Technical data such as your IP address is processed only transiently for security and abuse prevention and is not stored permanently with the conversation. Please do not enter special categories of personal data (Art. 9 GDPR) into the chat. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in answering enquiries efficiently). If the chat forms part of a contractual service, Art. 6(1)(b) GDPR. Hosting and inference: data is processed on servers of Hetzner Online GmbH in Falkenstein, Germany. Responses are generated via the EU API of Mistral AI SAS in Paris, France. There is no transfer to a third country, and the content is not used to train AI models. Cookies: the widget sets two strictly necessary first-party cookies so a conversation can be resumed — "cw_conv_<agent>" (conversation identifier) and "cw_conv_session_<agent>" (signed session token to retrieve the conversation history). Both last approximately 24 hours, with SameSite=Lax and the Secure flag. No tracking, marketing, or third-party cookies are set. Legal basis: § 25(2) TTDSG (strictly necessary cookies). Retention: conversation logs are automatically deleted after at most 12 months. If "private mode" is enabled, the content of visitor messages is not stored. Your rights: you have the rights under Art. 15–21 GDPR (access, rectification, erasure, restriction, portability, objection). To exercise them, contact us as the controller: [COMPANY], [CONTACT EMAIL].