# Chatbot Security and Privacy
Document360 is committed to handling chatbot data securely and in compliance with global privacy regulations.
Data Handling
- Conversation Logs – Stored on Document360's secure cloud infrastructure.
- User Identification – By default, conversations are anonymous. You can enable user identification for logged-in portal visitors.
- Query Data – User queries are processed to generate answers and may be logged for analytics purposes.
Data Encryption
- All data transmitted between the user's browser and Document360 servers is encrypted using TLS 1.2+.
- Data at rest is encrypted using AES-256.
Compliance
Document360's Chatbot is designed to support compliance with:
- GDPR (General Data Protection Regulation)
- CCPA (California Consumer Privacy Act)
- SOC 2 Type II
Access Controls
- Only project Admins and Owners can access conversation history and analytics.
- Role-based access controls prevent unauthorized configuration changes.
Data Retention
| Plan | Retention Period |
|---|---|
| Business | 90 days |
| Enterprise | Configurable (up to 2 years) |
Anonymization
You can enable Query Anonymization to strip personally identifiable information (PII) from conversation logs before storage.
Summary
Document360's security-first approach ensures that chatbot interactions remain private, encrypted, and compliant with industry standards.
