Data Protection & Privacy

How MultipleChat collects, processes, stores, protects, and deletes your data. This is a binding legal document.

Operated by NLP GmbH  ·  Küsnacht, Switzerland  ·  CHE-232.104.780  ·  Last Updated: March 1, 2026  ·  Version 1.2

Before You Begin — Why This Document Exists

This Data Protection & Privacy Policy ("Policy") is a legally binding document that forms part of your agreement with NLP GmbH ("MultipleChat," "we," "us," or "our"), the Swiss-registered company that operates the MultipleChat artificial intelligence platform. It should be read together with our Terms of Service and Refund Policy. Together, these three documents form your complete legal agreement with MultipleChat.

MultipleChat is a multi-model AI platform that routes your queries to third-party AI providers including OpenAI, Anthropic, Google, Meta, Mistral, and Perplexity. This means your data moves through multiple systems, and you deserve to know exactly what happens at every step. That is what this document explains — in full, in plain language, and without evasion.

We wrote this document to be exhaustive because we believe data protection is not a checkbox exercise — it is a contractual commitment. Every statement in this Policy is enforceable under Swiss law. If we say we don't sell your data, that is a binding legal promise, not a marketing slogan.

This Policy applies to all users of the MultipleChat platform worldwide — whether on the free plan or any paid subscription, whether accessing the platform via web, mobile, API, or any other interface, and whether located in Switzerland, the European Union, the United Kingdom, the United States, or any other jurisdiction.

Section 1 — Definitions and Interpretation

The following definitions apply throughout this Policy. Where these terms conflict with definitions in the Terms of Service, the definitions in this Policy take precedence for data protection matters.

Interpretation: Where this Policy uses "including" or "includes," this means "including but not limited to." References to any statute or regulation include all amendments, re-enactments, and subordinate legislation. Headings are for convenience only. The singular includes the plural and vice versa. References to "you" and "your" mean the User. References to "we," "us," and "our" mean NLP GmbH trading as MultipleChat.

Section 2 — Data Controller and Legal Entity

Section 3 — Our Core Data Protection Commitments

Before detailing the specifics of how we handle your data, we want to state our core commitments clearly. These are not aspirational goals — they are operational facts and contractual promises enforceable under Swiss law.

MultipleChat's Eight Data Protection Commitments

Commitment 1 — Zero AI Training. We do not use your Conversation Data, User Content, uploaded files, or any other Personal Data to train, fine-tune, improve, or develop any AI model — not our own, and not any third party's. This is absolute and unconditional.

Commitment 2 — No Data Sales. We will never sell, rent, lease, trade, barter, or otherwise commercially transfer your Personal Data to any third party for any purpose, under any circumstances. Our revenue comes exclusively from Subscription Fees. Your data is not our product.

Commitment 3 — No Advertising. We do not serve advertisements on the MultipleChat platform. We do not share your data with advertising networks, data brokers, analytics companies, or any third party for advertising or marketing purposes.

Commitment 4 — Swiss Jurisdiction. MultipleChat is a Swiss company operating under Swiss law — one of the strongest privacy frameworks in the world. Switzerland holds a European Commission adequacy decision under GDPR Article 45, meaning your data receives equivalent protection to intra-EU transfers.

Commitment 5 — Encryption Everywhere. All data is encrypted with AES-256 at rest and TLS 1.3 in transit. There are no exceptions. Every conversation, every file, every record is encrypted before it is written to any storage system.

Commitment 6 — Your Control. You can delete individual conversations, individual files, or your entire account at any time. You can export your data in machine-readable formats. We honour all data subject rights under GDPR, the Swiss FADP, and equivalent legislation.

Commitment 7 — Transparency. Every data flow in and out of the MultipleChat platform is documented in this Policy. We do not process your data for undisclosed purposes. If we change how we process data, we will update this Policy and notify you.

Commitment 8 — Accountability. We maintain detailed records of all Processing activities as required by GDPR Article 30. We conduct Data Protection Impact Assessments where required. We cooperate with supervisory authorities. We take responsibility for our data handling practices.

Section 4 — Personal Data We Collect

We are transparent about every category of data we collect. The table below identifies each category, what it includes, when it is collected, and why. Detailed legal bases for each category are set out in Section 5.

Category Specific Data Elements When Collected
Account Data Full name, email address, profile picture (if provided), language preference, timezone, account creation date, subscription tier, account status At registration and when updated by User
Authentication Data OAuth tokens (via Auth0/Okta), session identifiers, login timestamps, login IP addresses, MFA status, device identifiers used for authentication At each login and session initiation
Conversation Data All messages sent to AI models (User Content), all AI responses (Generated Content), conversation titles, timestamps, model selection per message, token consumption per request, file references within conversations Each time you interact with an AI model
Uploaded Files Documents, images, spreadsheets, PDFs, and any other files uploaded through the platform for AI processing When you upload a file
Billing Data Subscription plan, billing cycle dates, transaction amounts, payment status, invoice records, Stripe customer ID. Note: full card numbers, CVVs, and bank account details are processed and stored exclusively by Stripe — MultipleChat never sees or stores these At subscription creation and each billing event
Usage Data Feature usage patterns (which features you use and how often), session duration, number of conversations created, number of messages sent, models used, token consumption per billing cycle Continuously during platform use
Technical Data Browser type and version, operating system, screen resolution, device type (desktop/mobile/tablet), anonymized IP address, referring URL, HTTP headers Automatically on each page load or API request
Support Data Email correspondence with our support team, any information you provide in support requests, screenshots or attachments sent to support When you contact support
Cookie Data Session cookies, authentication cookies, preference cookies, analytics cookies, advertising pixels, and conversion tracking cookies. Full details including each specific tool and its data collection practices are set out in Section 21 and our Cookie Policy When you visit the platform
Log Data Server access logs, error logs, API request logs, security event logs. These are primarily used for security monitoring, debugging, and abuse prevention Automatically during platform operation

Section 5 — Legal Bases for Processing (GDPR Article 6)

Under the GDPR, every Processing activity must have a valid legal basis. Below, we identify the specific legal basis for each category of Processing we perform. This section is particularly relevant for Users in the EU, EEA, Switzerland, and the UK, but the principles apply to all Users.

Processing Activity Legal Basis (GDPR Art. 6(1)) Explanation
Account creation and management (b) Contract Performance Necessary to provide the Services you have requested
Processing AI queries and delivering responses (b) Contract Performance The core service delivery — routing your queries to AI models and returning responses
Storing Conversation Data and chat history (b) Contract Performance Enables conversation continuity and history features you expect from the platform
Processing file uploads (b) Contract Performance Necessary to process files you submit for AI analysis
Subscription billing and payment processing (b) Contract Performance Necessary to fulfil the subscription agreement
Retention of billing and tax records (c) Legal Obligation Required by Swiss tax law and financial regulations (7-year retention)
Security monitoring and abuse prevention (f) Legitimate Interest Protecting the platform and all Users from security threats, fraud, and abuse
Anonymized analytics and service improvement (f) Legitimate Interest Improving platform performance, features, and reliability using aggregated, anonymized data
Error logging and debugging (f) Legitimate Interest Identifying and fixing technical issues to maintain service quality
Responding to support requests (b) Contract Performance Providing customer support as part of the Service
Compliance with legal requests (c) Legal Obligation Responding to valid court orders, subpoenas, or regulatory demands
EU right of withdrawal processing (c) Legal Obligation Required by EU consumer protection directives

Legitimate Interest Balancing Test: Where we rely on legitimate interest as a legal basis, we have conducted a balancing test to ensure that our interests do not override your fundamental rights and freedoms. The results of these assessments are available upon request by contacting [email protected]. You have the right to object to Processing based on legitimate interest at any time — see Section 16.

Section 6 — How We Use Your Data

We use your Personal Data only for the purposes described below. We do not process your data for any undisclosed purpose.

Section 7 — AI Training — We Do Not Use Your Data

Critical — Read This Section Carefully

MultipleChat does not use your data to train AI models. Period. This section explains what that means in practice and how it differs from consumer AI products.

Section 8 — Third-Party AI Providers — Data Handling

When you use MultipleChat, your queries are transmitted to Third-Party AI Providers for processing. This section details what each provider does — and does not do — with your data.

Provider Uses API Data for Training? Temporary Data Retention API Tier Used Headquarters
OpenAI (GPT-4o, o1, o3, DALL-E) No Up to 30 days for abuse monitoring, then deleted Commercial API San Francisco, USA
Anthropic (Claude Sonnet, Opus, Haiku) No Up to 30 days for safety evaluation, then deleted Commercial API San Francisco, USA
Google (Gemini Pro, Ultra, Flash) No Per Google Cloud Data Processing terms Vertex AI / Commercial API Mountain View, USA
Meta (Llama series) No Not retained by provider when accessed via API Commercial API Menlo Park, USA
Mistral AI (Mistral Large, Medium, Small) No Per commercial API terms Commercial API Paris, France (EU)
Perplexity AI (Sonar, search models) No Per commercial API terms Commercial API San Francisco, USA
xAI (Grok series) No Per commercial API terms Commercial API USA

Section 9 — Sub-Processors and Data Sharing

MultipleChat engages a limited number of Sub-Processors to provide the Services. We do not share your data with any party not listed below, except as required by law.

Sub-Processor Purpose Data Accessed Location
Microsoft Azure Cloud hosting and infrastructure (Swiss region) All platform data (encrypted at rest and in transit) Switzerland (primary), EU (backup)
Auth0 (Okta) Authentication and identity management Email, authentication tokens, login metadata EU / USA
Stripe Payment processing Billing data, card details (Stripe only — not MultipleChat) USA / Ireland
Cloudflare CDN, DDoS protection, WAF, edge security IP addresses, HTTP headers, request metadata Global edge network
Third-Party AI Providers AI model inference (see Section 8) User Content and conversation context for AI processing See Section 8 table
Google LLC Analytics (Google Analytics 4), tag management (GTM), advertising conversion tracking (Google Ads) Page views, session data, conversion events, device metadata, anonymized IP, click identifiers USA
Microsoft Corporation Session replay and heatmaps (Microsoft Clarity), advertising conversion tracking (Microsoft/Bing Ads UET), retargeting (LinkedIn Insight Tag) Mouse movements, clicks, scroll behaviour, page views, conversion events, device metadata USA
Hotjar Ltd Session recording, heatmaps, user behaviour analysis Mouse movements, clicks, scroll depth, page navigation, device type (IP anonymized; sensitive fields suppressed) Malta (EU)
Meta Platforms Inc. Advertising conversion tracking (Meta Pixel for Facebook/Instagram) Page views, conversion events, click identifiers (fbclid), device metadata USA
X Corp. Advertising conversion tracking (X/Twitter Pixel) Page views, conversion events, click identifiers (twclid), device metadata USA
Reddit Inc. Advertising conversion tracking (Reddit Pixel) Page views, conversion events, click identifiers (rdt_cid), device metadata USA
Cheq AI Technologies Ltd (ClickCease) / ClickGuard Click fraud prevention and invalid traffic detection IP addresses, click patterns, user agent strings, referral data, device fingerprints Israel / USA

Section 10 — Security Architecture and Measures

MultipleChat implements comprehensive technical and organisational security measures to protect your data. This section describes our security architecture in detail — not as marketing, but as a technical specification that enterprise security teams can evaluate.

Section 11 — Encryption Standards

Section 12 — Access Controls and Internal Security

Section 13 — Data Residency and Infrastructure

Section 14 — International Data Transfers

Because MultipleChat routes queries to Third-Party AI Providers — some of which are headquartered in the United States — your data may cross international borders. This section explains when, how, and under what legal safeguards those transfers occur.

Section 15 — Data Retention Schedule

We retain data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law. The following table sets out our specific retention periods.

Data Category Retention Period Basis for Retention Period
Conversation Data and Chat History While account is active; deletable by User at any time Contract performance — service feature
Uploaded Files While account is active; deletable by User at any time Contract performance — service feature
Account Data While account is active; 30 days after account deletion request Contract performance, then grace period for accidental deletion
Authentication Logs 12 months from creation Security monitoring and abuse prevention
Anonymised Analytics Up to 2 years Service improvement (data cannot identify individuals)
Billing and Tax Records 7 years from transaction date Swiss tax law and financial regulations (mandatory)
Support Correspondence 3 years from last contact, or while account is active Service quality and dispute resolution
Server and Error Logs 90 days Debugging, security monitoring, abuse prevention
Security Incident Logs 3 years from incident Regulatory compliance and forensic analysis
Legal Hold Data Until legal hold is released Legal obligation — preservation of evidence

After Retention Expiry: When a retention period expires, data is permanently deleted or irreversibly anonymised within 30 days of the expiry date. "Permanently deleted" means the data is overwritten and removed from all live systems and backups. "Irreversibly anonymised" means the data is transformed in a way that makes it impossible to re-identify the Data Subject, even using all reasonably available means.

Section 16 — Your Rights Under Data Protection Law

Under the GDPR, the Swiss FADP, the UK DPA 2018, the CCPA/CPRA, and equivalent legislation, you have the following enforceable rights regarding your Personal Data. These rights are not conditional on your subscription tier — they apply equally to free and paid Users.

Section 17 — Right to Erasure — Detailed Procedures

Section 18 — Data Portability

Section 19 — Automated Decision-Making and Profiling

Section 20 — Children's Privacy

Section 21 — Cookies, Analytics, and Tracking Technologies

MultipleChat uses a range of cookies, analytics tools, and tracking technologies on its marketing website and platform. We are committed to full transparency about what runs on your browser. This section discloses every third-party tracking technology currently deployed, the data it collects, and why we use it.

Important — Consent and Control

Non-essential cookies and tracking technologies — including analytics, marketing, and advertising pixels — are activated only with your consent, which you can grant or withdraw at any time through our cookie consent banner or the cookie settings accessible on the platform. Essential cookies (authentication, session management, security) are required for the platform to function and cannot be disabled.

21.1 — Essential Cookies (No Consent Required)

21.2 — Analytics and Performance Tools (Consent Required)

The following analytics and performance tools are used to understand how visitors interact with the MultipleChat website, identify usability issues, and improve the platform experience. They are activated only with your consent.

Tool Provider Purpose Data Collected Provider Location
Google Analytics 4 Google LLC Website traffic analysis, user journey mapping, conversion tracking, audience demographics Page views, session duration, bounce rate, referral source, device type, browser, geographic region (anonymized IP), events and conversions USA (EU data processing available)
Google Tag Manager Google LLC Tag management system that controls the deployment of all other tracking scripts. GTM itself does not collect Personal Data — it manages the tags that do GTM processes tag firing rules; data collection is performed by the individual tags it manages USA
Hotjar Hotjar Ltd Session recording, heatmaps, and user behaviour analysis to identify usability issues and improve the platform interface Mouse movements, clicks, scroll depth, page navigation, screen size, device type. Hotjar's recordings automatically suppress sensitive input fields (passwords, payment fields). IP addresses are anonymized Malta (EU)
Microsoft Clarity Microsoft Corporation Session replay, heatmaps, and behavioural analytics to understand how users interact with the platform interface Mouse movements, clicks, scroll behaviour, page views, session duration, device and browser metadata. Clarity masks sensitive content by default. IP addresses are not stored by Clarity USA

21.3 — Advertising and Conversion Tracking Pixels (Consent Required)

The following advertising pixels and conversion tracking tools are used to measure the effectiveness of our advertising campaigns on third-party platforms, to attribute sign-ups and subscriptions to specific campaigns, and to build remarketing audiences. These tools place cookies on your browser and may transmit data to the respective advertising platform. They are activated only with your consent.

Tool Provider Purpose Data Collected Provider Location
Google Ads Conversion Tracking Google LLC Measures conversions (sign-ups, subscriptions) from Google Search and Display ads. Enables remarketing to visitors who have previously visited the MultipleChat website Conversion events, page visits, Google click identifiers (GCLID), device and browser data USA
Microsoft Advertising UET Microsoft Corporation Universal Event Tracking for Microsoft/Bing Ads. Measures conversions from Bing search ads and enables audience targeting on the Microsoft Advertising network Page views, conversion events, Microsoft click identifiers, device and browser metadata USA
Meta Pixel (Facebook/Instagram) Meta Platforms Inc. Tracks conversions from Facebook and Instagram ads. Enables custom audience creation and lookalike audience targeting on Meta platforms Page views, conversion events (e.g., sign-up, subscription), Meta click identifiers (fbclid), browser and device metadata, hashed User identifiers (where applicable) USA
LinkedIn Insight Tag LinkedIn Corporation (Microsoft) Tracks conversions from LinkedIn ads. Enables website demographic analysis and retargeting on the LinkedIn advertising platform Page views, conversion events, LinkedIn member identifiers (anonymized), company demographic data (industry, company size, job function), device and browser metadata USA
X (Twitter) Pixel X Corp. Tracks conversions from X (Twitter) ads. Enables tailored audience creation and remarketing on the X advertising platform Page views, conversion events, X click identifiers (twclid), browser and device metadata USA
Reddit Pixel Reddit Inc. Tracks conversions from Reddit ads. Enables audience targeting and campaign optimisation on the Reddit advertising platform Page views, conversion events, Reddit click identifiers (rdt_cid), browser and device metadata USA

21.4 — Click Fraud Prevention (Legitimate Interest)

21.5 — How to Control Tracking Technologies

21.6 — Data Transfers by Tracking Technologies

Most of the tracking technologies listed above are operated by US-based companies. When you consent to non-essential cookies, data may be transferred to servers in the United States. These transfers are governed by the EU-US Data Privacy Framework (where applicable), Standard Contractual Clauses, and the individual provider's data processing terms. If you do not consent to non-essential cookies, no data is transmitted to these providers.

21.7 — Cookie Policy

Section 22 — Data Breach Notification

Section 23 — Regulatory Compliance Framework

MultipleChat's data protection practices are designed to comply with multiple overlapping regulatory frameworks. This section identifies each framework and our compliance status.

Framework Scope Status
GDPR (EU) 2016/679 EU/EEA data subjects Compliant
Swiss FADP (revised 2023) Swiss data subjects and all processing in Switzerland Compliant
UK GDPR and DPA 2018 UK data subjects Compliant
CCPA/CPRA California residents Compliant
PIPEDA Canadian data subjects Compliant
SOC 2 Type II Security, availability, and confidentiality controls Independently audited
ISO 27001 Information security management system Aligned
PCI DSS Level 1 Payment card data (via Stripe) Compliant (Stripe-managed)
EU AI Act (2024/1689) AI system obligations for EU market Monitored — compliance in progress as requirements phase in

CCPA-Specific Disclosures for California Residents: Under the CCPA/CPRA, you have additional rights including: the right to know what Personal Information we collect, use, and disclose; the right to delete Personal Information; the right to opt-out of the sale of Personal Information (we do not sell Personal Information); the right to non-discrimination for exercising your rights; and the right to limit use of sensitive Personal Information. MultipleChat does not sell Personal Information as defined by the CCPA. MultipleChat does not use or disclose sensitive Personal Information for purposes beyond those permitted by the CCPA. To exercise your CCPA rights, contact [email protected].

Section 24 — Data Processing Agreement (Enterprise)

Section 25 — Special Categories of Data

Important — Do Not Submit Special Category Data

MultipleChat is not designed to process special categories of Personal Data as defined by GDPR Article 9. You must not submit such data to the platform.

Section 26 — Data Protection Impact Assessments

Section 27 — Third-Party Links and Integrations

Section 28 — Changes to This Policy

Section 29 — Supervisory Authorities and Complaints

Section 30 — Governing Law and Jurisdiction

Section 31 — Severability

Section 32 — Entire Agreement

Section 33 — Contact Information

A Final Note — From Us to You

If you've read this entire document, thank you. We know it's long. We wrote it this way on purpose — because we believe that the companies and individuals who trust us with their data deserve to know exactly what happens to it, explained thoroughly and without evasion.

Data protection is not a feature we bolt on after the fact. It is built into every layer of the platform — from the infrastructure we chose (Swiss-hosted), to the providers we integrate with (commercial API tiers only), to the way we structure our business model (subscriptions, not data monetisation). Your trust is the foundation of everything we do, and this document is our way of demonstrating that it is well placed.

If you have questions that this document doesn't answer, please write to us at [email protected]. We genuinely want to hear from you, and we'll do our best to give you a clear, honest answer.

— The MultipleChat Team, NLP GmbH, Küsnacht, Switzerland