Privacy policy
Last updated 16 August 2026
ConGreeto(“ConGreeto”, “we”, “us”) is a product of Brillnex Systems. This policy explains what personal data we handle, why, and what you can do about it.
1. Two different relationships
Read the section that applies to you, because our role is different in each.
If you are a ConGreeto customer
You hold an account with us. For your account, billing and usage data we are the data controller — we decide why and how it is processed, and this policy governs it.
If you chatted with an assistant on someone else's website
The business whose website you were on is the data controller. They chose to run an assistant, they decide what it asks and how they follow up. We are their data processor: we handle that conversation on their instructions. To exercise your rights over that conversation, contact that business. If you cannot reach them, write to us at congreeto@gmail.com and we will pass it on.
2. What we collect
Account data
- Name and email address.
- A one-way hash of your password. We never store the password itself and cannot read it.
- Your timezone preference, your role in each workspace, and whether two-factor authentication is enabled.
- Email verification and two-factor codes, which are short-lived.
Billing data
Payments are processed by Stripe. Card numbers never reach our servers — we store only your subscription state, plan, billing period, invoice history and the last four digits and expiry of the card, as returned to us by Stripe.
Content you give the assistant
- Pages we crawl from website addresses you provide.
- Documents you upload, including text extracted from scanned files by OCR.
- Manual text and question-and-answer entries you write.
- Portfolio records you add, import from a spreadsheet, or have crawled.
You are responsible for having the right to supply this material. Please do not upload special-category personal data (health, biometric, political and similar) as assistant training material.
Conversation and lead data
- The full transcript of what a visitor and the assistant said to each other.
- Contact details a visitor chooses to give during a conversation — typically name, email address and phone number.
- Material derived by AI from the conversation: a summary, the topics raised, a sentiment reading, an engagement score, a lead score and a tier.
- The page address the visitor was on, and campaign attribution parameters such as UTM tags.
- An anonymous visitor identifierstored in the visitor's browser. It lets us count unique visitors, opens and interactions rather than raw page loads. It is not linked to a name unless the visitor volunteers one in the conversation.
- Notes, tags, follow-up dates, deal values and stage changes recorded by the customer's team.
Usage data
Counts of conversations, AI tokens, documents and pages crawled, measured against your plan limits, plus an activity log of who changed what inside a workspace.
3. Why we process it, and on what basis
| Purpose | Lawful basis |
|---|---|
| Providing the service you signed up for | Performance of a contract |
| Taking payment and issuing invoices | Performance of a contract; legal obligation |
| Generating summaries, scores and tiers from conversations | Legitimate interests of the customer operating the assistant |
| Counting unique visitors and measuring engagement | Legitimate interests; consent where local law requires it |
| Security, fraud prevention and abuse handling | Legitimate interests |
| Service, billing and security notifications | Performance of a contract |
| Optional daily and weekly digest emails | Consent — you can switch these off at any time |
4. Automated processing
The assistant generates replies, summaries, scores and tiers automatically. These are assessments to help a human decide who to follow up — they do not by themselves produce a legal or similarly significant effect on anyone, and a person on the customer's team can change or override any of them. Assistant output can be wrong; it should not be relied on as professional advice.
5. Who we share it with
We do not sell personal data. We share it only with:
- Our AI model provider, to generate replies and analysis. Content sent for this purpose is not used to train their public models.
- Stripe, for payment processing.
- Our hosting and database providers, to run the service.
- Our email delivery provider, to send verification codes, lead alerts and digests.
- Our analytics providers, to measure how this marketing site is found and used. This applies to congreeto.com only — it is not running inside your dashboard.
- Authorities, where we are legally required to, and a buyer or successor if the business is sold — in which case this policy continues to apply until you are told otherwise.
A current list of sub-processors is available on request from congreeto@gmail.com.
6. Support access
Our support staff can, when helping you, view your workspace. When that is happening a banner is shown in your dashboard for the whole session, so you always know. These sessions are recorded in the activity log.
7. How long we keep it
- Account and workspace data: for as long as your account is open.
- Conversations, leads and portfolio records: for as long as the workspace holds them. Archiving a lead hides it from the working views but retains it.
- Deleting a chatbot is a soft delete — it is removed from your dashboard but recoverable by support for a limited period before permanent erasure.
- Invoices and billing records: as long as tax and accounting law requires.
- After an account is closed, remaining data is deleted or irreversibly anonymised within a defined period; contact us for the current window.
8. Security
- Two-factor authentication by one-time code sent to your email address.
- Sessions built on HttpOnly refresh cookies with CSRF protection. Access tokens are held in memory and never written to browser storage.
- Passwords must be at least 12 characters with upper case, lower case, a number and a symbol.
- Domain allow-listing — an assistant only loads on the domains its owner has listed.
- Role-based access enforced on the server, not merely hidden in the interface. Agents cannot see revenue figures; viewers cannot change anything.
No system is perfectly secure. If you believe an account has been compromised, contact us immediately.
9. International transfers
Your data may be processed in countries other than your own. Where it is transferred out of the UK, EEA or another region with transfer restrictions, we rely on an appropriate legal transfer mechanism. Details are available on request.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to our use of your personal data, to withdraw consent, and to receive a portable copy. Customers can export their leads to CSV or Excel from the dashboard at any time.
To exercise any of these, write to congreeto@gmail.com. We will respond within the period your local law requires. You also have the right to complain to your data protection regulator.
11. Cookies and similar technologies
Our dashboard uses cookies that are strictly necessary to keep you signed in securely. The website assistant stores an anonymous visitor identifier in the browser so that engagement can be counted per person rather than per page load. We do not use advertising cookies.
This marketing site additionally uses Google Analytics, which sets its own cookies to measure how visitors arrive and which pages they read, and Vercel Web Analytics, which is cookieless and stores nothing on your device. Neither runs inside the dashboard.
12. Children
ConGreeto is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has provided personal data through an assistant, contact us and we will delete it.
13. Changes
If we make a material change we will update the date at the top of this page and, for customers, notify you by email or in the dashboard.
14. Contact
Brillnex Systems, operator of ConGreeto — congreeto@gmail.com