Privacy Policy
How Sinchao handles personal data, both the data we decide the purposes for and the support conversations we process on behalf of our customers.
Last updated 23 September 2026.
01Who we are
Sinchao is a customer support service operated by Overflow Labs Ltd, a company registered in England and Wales under number 13324827, with its registered office at Suite 201, 16 Pepper Street, London E14 9RP, United Kingdom ("we", "us", "our").
For any question about this policy, or to exercise a data protection right, write to [email protected].
02The two roles we act in
This policy covers personal data we decide the purposes and means for — visitors to this website and people who hold a Sinchao account. For that data we are the controller.
Separately, Sinchao processes support conversations that our business customers bring into the service from their own stores and helpdesks. That material belongs to the customer, who decides why and how it is processed. For it we are a processor acting on that customer’s documented instructions under our agreement with them.
If you contacted a shop and want to know how your message was handled, the shop is the controller and your request goes to them. We will pass on any request we receive to the customer concerned.
03Data we hold as controller
- Account data — your email address, a hash of your password, the organizations you belong to and your role in each, and sign-in timestamps.
- Session data — a session token issued when you sign in. It is kept in your browser’s local storage, not in a cookie. See our Cookies Policy.
- Technical logs — IP address, user agent, requested paths, response codes and timestamps, recorded when your browser or the workspace calls our servers.
- Usage counters — the number of tickets and responses processed by each organization, used to bill and to enforce limits.
- Correspondence — messages you send us and our replies.
04Data we process as processor
On behalf of a customer organization, the service handles:
- support conversations ingested from the customer’s store or helpdesk, including the message text, sender details and order or account references contained in them;
- the customer’s knowledge base — facts, instructions, policies, response templates and case studies;
- responses written by the service, their translations, follow-up questions asked by agents, and the reply finally sent, by an agent or, in takeover, by the service;
- the differences between a response and the sent reply, and the knowledge enhancements derived from them.
Whether this material contains personal data, and whose, is determined by the customer. We do not use it for our own purposes.
05Why we process it, and on what basis
- To provide the service and your account — performance of our contract with you or your organization.
- To bill for usage and keep accounting records — performance of a contract and compliance with a legal obligation.
- To keep the service secure, prevent abuse and investigate incidents — our legitimate interest in protecting the service and its users.
- To send service messages about availability, changes and security — our legitimate interest in keeping customers informed.
- To measure and improve the service using aggregated counts that do not identify anyone — our legitimate interest in improving what we sell.
- To comply with law and respond to lawful requests — compliance with a legal obligation.
We do not sell personal data, we do not use it for advertising, and we do not build profiles for third parties.
06Automated processing and human review
The service writes a response to each conversation that matches one of the customer’s skills, in one of two modes the customer chooses skill by skill:
- Copilot — the default. The response is published to the customer’s helpdesk as a draft or an internal note, and a human agent approves, edits, regenerates or rejects it before anything is sent.
- Takeover — the service sends the response itself, after checking it against the customer’s data, policies and the limits the customer set. Anything outside those limits, such as a refund above the amount the customer allows, is held for a human agent instead of being sent.
Takeover replies are sent without a person reviewing each one. The customer decides which conversations and which actions takeover may handle, and remains the controller responsible for those replies. If you wrote to a shop and want a person to look at a reply you received, ask the shop, and we will support them in answering.
To draft and translate a response, the text of the conversation and the relevant knowledge base excerpts are sent to a large language model provider acting as our sub-processor. We contract for that content not to be used to train the provider’s models and for it to be retained only as long as needed to return the result.
07Who else is involved
We use a small set of sub-processors, each bound by written terms and permitted to act only on our instructions:
- Beepflow — the platform this service runs on, operated by us.
- Cloudflare — content delivery, object storage, TLS for our custom domains, and delivery of the fonts and interface assets a page loads. Loading a page makes your browser request files from Cloudflare, which discloses your IP address and user agent. It sets no cookies for us.
- Large language model providers — drafting and translation of responses.
- Email delivery providers — sign-in and service messages.
A current list of sub-processors is available on request from [email protected]. We give customers notice of material changes before a new sub-processor starts work.
08How long we keep it
- Account data — for as long as the account exists, then up to 12 months.
- Technical logs — up to 12 months.
- Conversations, responses and knowledge base content — for the term of the customer’s agreement. On termination we return or delete it within 30 days, unless the customer asks otherwise or we must keep it by law.
- Billing and accounting records — six years, as UK tax law requires.
- Correspondence — up to 24 months.
09Where data goes
We are based in the United Kingdom. Some sub-processors operate outside the UK and the EEA. Where they do, transfers rely on UK adequacy regulations, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum, plus any additional safeguards the transfer requires.
10How we protect it
- Traffic is encrypted in transit with TLS, and stored data is encrypted at rest.
- Passwords are stored only as salted hashes.
- Every record is scoped to an organization, and access is checked on every request so one organization cannot read another’s data.
- Access by our staff is limited to what their work requires and is logged.
No service can promise perfect security. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the Information Commissioner’s Office and, where required, you.
11Your rights
Under the UK GDPR and the Data Protection Act 2018 you may ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. Where we rely on consent, you may withdraw it at any time without affecting earlier processing.
Send requests to [email protected]. We respond within one month and may ask you to confirm your identity first. Exercising these rights is free unless a request is manifestly unfounded or excessive.
If you are unhappy with our answer you may complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. If you are in the EEA you may also complain to your local supervisory authority.
12Children
Sinchao is a business tool. It is not directed at children and we do not knowingly create accounts for anyone under 16. If you believe a child’s data has reached us, tell us and we will delete it.
13Changes to this policy
We update this policy when the service or the law changes. The date at the top shows the current version, and we tell account holders about material changes before they take effect. This version is dated 23 September 2026.