Privacy Policy
Privacy Policy
Last updated: 11/22/2025
This Privacy Policy explains how SUMPLER (“we”, “us”, “our”) processes personal data when you access or use AnsrFast, our SaaS web application available at https://www.ansrfast.com (“Service”).
We aim to comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and globally recognized privacy best practices.
We also comply with the Google API Services User Data Policy, including the Limited Use requirements, for all Google OAuth data.
Using AnsrFast means you accept this Privacy Policy. If you disagree, please discontinue your use of the Service.
1. Who We Are
Data Controller:
SUMPLER
Country: France
Email: contact@ansrfast.com
SUMPLER develops and operates AnsrFast, a platform that enables customer-facing teams to create and manage AI chatbots for help centers and websites.
2. Scope
This Privacy Policy covers all personal data processed through:
- The AnsrFast website
- The web application
- Authentication flows (including Google Sign-In)
- Support and communication channels
- Embedded widgets
It applies to all users, including business users from the EU, EEA, UK, US, and other regions.
3. Personal Data We Collect
3.1. Account Data
Collected when you create or manage your account:
- Name
- Email address
- Password hash (never the plain password)
- Company name (optional)
- Profile picture (if provided)
If you sign up via Google, certain items come from Google OAuth (see section 3.2).
3.2. Google OAuth Data
If you choose Google Sign-In, we receive:
- Google account email
- Basic profile information (name, profile photo)
- Google user ID
- OpenID Connect tokens strictly necessary for login
We do not access or read:
- Gmail content, Drive files, Calendar events, Contacts, Photos, YouTube data, or any sensitive Google scope.
Scopes requested:
openid, email, profile (minimum needed for authentication only).
Purpose:
Authentication, account creation, session management, and security.
We do NOT:
- Sell Google user data
- Use Google OAuth data for advertising
- Combine Google data with third-party data for profiling
- Share Google data with unauthorized third parties
We fully comply with the Google API Services User Data Policy and Limited Use restrictions.
3.3. Usage Data
Collected automatically when you access the Service:
- IP address
- Device information (browser, OS)
- Pages viewed and actions performed
- Timestamps, logs, and error reports
- Referrer information
- Approximate location (country-level) derived from IP
This helps ensure security, improve performance, and understand how the product is used.
3.4. Content & Knowledge Base Data
To configure your chatbot, you may upload or enter:
- Help center articles
- Documentation or FAQs
- Text snippets
- Structured or unstructured content
This data belongs to you. We process it only to operate, improve, and deliver your chatbot features.
3.5. Payment & Billing Data
Payments are processed by Stripe. We may receive:
- Billing name
- Billing email
- Billing address (if required for invoicing)
- Subscription status and payment history
- Last 4 digits of your card (from Stripe)
All sensitive payment information is stored by Stripe, not by us.
3.6. Cookies & Analytics
We may use:
- Plausible Analytics (privacy-friendly)
- or Google Analytics depending on configuration
These tools collect anonymous or pseudonymous metrics to help us improve the product.
We do not use analytics for targeted advertising.
4. How We Use Personal Data
4.1. To Provide and Operate the Service
- User account creation and authentication (incl. Google Sign-In)
- Delivering the chatbot features
- Processing payments and subscriptions
- Ensuring platform reliability and security
4.2. To Provide Support
- Respond to support tickets
- Assist with onboarding and troubleshooting
- Communicate important service messages
4.3. To Improve the Product
- Analyze feature usage
- Identify usability or performance issues
- Enhance user experience and reliability
4.4. Communications
We may send:
- Transactional communications (e.g. receipts, password resets)
- Product updates
- Security alerts
- Onboarding tips or educational content
You can unsubscribe from non-essential emails at any time.
5. Legal Bases for Processing (GDPR)
We rely on the following legal bases:
Performance of a contract:
To provide, maintain, and support the Service.
Legitimate interests:
To improve the product, ensure security, prevent fraud, and ensure stable operation.
Consent:
For optional analytics, cookies, and marketing communications where required.
6. Data Sharing & Sub-Processors
We share data only with service providers who act on our behalf and only for necessary operational purposes.
Sub-processors include:
6.1. Hosting & Infrastructure
- Vercel – application hosting
- Cloudflare – CDN, security, performance
- Neon (on AWS Frankfurt) – database hosting
6.2. Payment Processor
- Stripe – billing and invoicing
6.3. Analytics & Monitoring
- Plausible Analytics / Google Analytics
- Logging and error tracking via infrastructure providers
6.4. Other Providers
We may use email, support, or operational tools as needed.
Each provider processes data under strict confidentiality and data protection agreements.
We do not sell or rent personal data.
7. International Data Transfers
Your data may be processed in countries outside the EU/EEA, including the United States.
When this occurs, we rely on safeguards such as:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions where available
- Additional technical and organizational measures
We aim to ensure your data benefits from a level of protection consistent with EU standards.
8. Data Retention
We retain personal data only for as long as necessary to:
- Provide the Service
- Comply with legal obligations
- Resolve disputes
- Enforce agreements
Typical retention examples:
- Account data: kept until your account is deleted
- Google OAuth data: kept only as long as needed for authentication
- Logs: retained for security and diagnostics for a limited period
- Billing data: retained as required by accounting law
You may request deletion at any time.
9. Security Measures
We take appropriate technical and organizational measures, including:
- HTTPS encryption
- Secure password hashing
- Access control and permissions
- Continuous security monitoring
- Data minimization and strict access logs
- Use of reputable infrastructure providers
While no security system is infallible, we continuously work to protect your data.
10. Your Rights
10.1. GDPR Rights (EU/EEA/UK Users)
You have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your data
- Restrict or object to processing
- Request a portable copy of your data
- Withdraw consent at any time
- File a complaint with a data protection authority
10.2. CCPA/CPRA Rights (California Users)
You have the right to:
- Request to know what personal information we collect
- Request deletion of your personal data
- Request correction of inaccurate data
- Access your personal information
- Opt out of “sale” or “sharing” (we do not sell personal data)
- Non-discrimination for exercising your rights
To exercise your rights, contact: contact@ansrfast.com
11. Children’s Privacy
AnsrFast is not intended for children under 13 (or 16 where applicable under GDPR).
We do not knowingly collect data from children.
If you believe data was collected from a child, contact us immediately.
12. Third-Party Links
Our Service may link to third-party websites or services. Their privacy practices are governed by their own privacy policies, not ours.
13. Changes to This Policy
We may update this Privacy Policy from time to time.
We will publish updates on this page, and for significant changes, we may notify users by email.
14. Contact Us
For questions or privacy requests, contact:
Email: contact@ansrfast.com
Website: https://www.ansrfast.com