Last updated 06/09/2026
Privacy Notice
This notice explains how VIMI Co., Ltd., operator of b2blead.ai, collects, uses, stores, discloses, and protects personal data across the b2blead.ai chat widget, embedded forms, CRM, knowledge base, billing, account services, and connected integrations.
We process personal data in accordance with Thailand's Personal Data Protection Act B.E. 2562 (2019) (PDPA). Where our processing is subject to the EU General Data Protection Regulation, UK data protection law, or another applicable privacy law, we also apply the requirements of that law.
Who we are
VIMI Co., Ltd., Atlas Parkworks, Room 310, 302 Ratchadaphisek Road, Khlong Toei, Bangkok 10110, Thailand. Privacy enquiries and data-rights requests can be sent to privacy@b2blead.ai.
Our controller and processor roles
We act as a data controller for platform account, signup, billing, security, support, and our own optional marketing data. We generally act as a data processor for visitor chats, form submissions, leads, CRM data, knowledge-base content, connected inbox data, and other customer data processed on a client's documented instructions. The client is normally the controller of that data and must provide its own visitor privacy notice, choose a lawful basis, configure appropriate retention, and ensure its collection and outreach are lawful.
Our Data Processing Addendum applies when we process customer personal data as a processor.
Account, signup, support, and billing data
We process names, business contact details, company and website information, login identifiers, encrypted credentials and session data, roles, preferences, support communications, invitation and password-reset records, integration identifiers, and audit/security events. For billing, Stripe processes payment-card details directly; we receive customer and subscription identifiers, checkout email, tier, invoice links, status, and payment-event metadata rather than full card numbers.
Website visitor chats and lead capture
When a person uses a b2blead.ai widget on a client website, we may process chat messages and bot replies; lead fields such as name, email, phone, company, country, website, and message; thread and interaction history; sentiment and topic labels; referrer and source; language; user agent; device type; and approximate country, region, and city. Current native widget routes hash network addresses for the application record. Historical session records created before September 2026 may retain a raw IP until verified deletion.
We use this data to run the conversation, retrieve relevant client knowledge, capture requested enquiries, support the client's customer-service conversations, prevent abuse, create CRM records, notify authorized client users, and provide reporting. The client whose website displays the widget controls the business purpose and should identify b2blead.ai in its own notice.
Where the client enables marketing consent in native chat, an optional, unticked checkbox appears below “Talk to a person.” The visitor's choice is recorded when they submit their contact details, together with the wording, privacy-notice versions and time. Simply starting a chat does not record marketing consent. Clients can review recorded choices in CRM contact cards and lead CSV exports. Existing unsubscribe and do-not-contact restrictions take precedence over a recorded opt-in.
Embedded forms and CRM
Embedded forms may collect name, email, phone, company, country, URL, messages, client-defined fields, and uploaded files. We also process the form and source URL, document referrer, hashed IP, user agent, spam and validation results, consent receipt, and interaction events. Unsaved form drafts may remain in the visitor's browser local storage for up to 30 days. Accepted submissions can become CRM records containing stage, owner, notes, reminders, contact history, ratings, and integration status.
Clients can configure a privacy-notice URL and consent text on their forms. Where a client sends leads to Telegram, respond.io, HubSpot, email, or a custom webhook, that destination receives the fields selected for the client-authorized workflow.
Sensitive personal data
The service is not designed to intentionally collect sensitive personal data. Clients must not configure chats, forms, CRM workflows, uploads, or integrations to collect or process sensitive personal data unless they have assessed the risks, established a valid lawful basis, provided any required notices, obtained any required explicit consent or authorization, and confirmed that the service is appropriate for the use case. If sensitive personal data is incidentally included in customer content, we process it according to the client's documented instructions and the controls described in this notice and the DPA.
Knowledge-base and integration data
We process uploaded and crawled documents, files, extracted text, page URLs and titles, public website content, crawl logs, embeddings, and vector metadata to build and operate a client's knowledge base. Personal data can appear incidentally in customer-selected content. Google Drive delivery may process the connected account email, OAuth scopes, app-created file and folder identifiers, filenames, uploaded files, and delivery metadata. OAuth refresh tokens are encrypted at rest.
Gmail data
For enabled Gmail features, we may process the connected email address, message and thread identifiers, sender and recipient details, subject, snippet, message body, attachments, timestamps, and draft/send results. We use this data to identify inbound enquiries, create and manage CRM leads, display review history, and create or send follow-up messages initiated by an authorized workflow. Email-to-lead processing is off by default.
Support, security, and operational data
We process support communications, request and authentication events, error reports, security and audit events, email delivery records, crawl logs, integration sync records, and system diagnostics. Depending on the event, these records may contain an email address, account or bot identifier, domain, network or device metadata, timestamp, action, delivery or integration status, and error details. We use this data to provide support, confirm delivery and integration activity, prevent abuse, investigate incidents, troubleshoot the service, and maintain its security, reliability, and performance.
AI and automated processing
The service uses third-party AI providers to generate chat replies, retrieve knowledge, create embeddings, classify messages, summarize content, and perform configured enrichment. Depending on the selected feature, visitor questions, recent chat history, lead details, CRM context, client knowledge snippets, or document text may be sent to Groq or an approved alternative inference provider. OpenAI processes query and document text for embeddings and selected content-processing tasks. Firecrawl and, where needed, Anthropic may use a domain derived from a business email address to retrieve and summarize public company information.
Cerebras is used only for configured or fallback paths. Mandarin and other configured interface translations use the Anthropic AI-assistance path, subject to the applicable tenant approval controls. Current providers and controls are listed in our Subprocessor Register.
Under our DPA, we will not use, or authorize an AI subprocessor to use, customer personal data to train or improve a general or shared model without the client's prior written authorization. Provider retention depends on the service, applicable business/API terms and account settings. The register identifies providers and the information they process. AI outputs and lead classifications may be inaccurate and should be reviewed by an authorized person. We do not use solely automated processing to make decisions that produce legal or similarly significant effects about an individual.
Where technically and operationally appropriate, we minimize data sent to AI providers by selecting recent or relevant conversation content, truncating retrieval context, and limiting accompanying metadata. Company enrichment generally uses a domain derived from a business email address, and we exclude personal or free-email domains where feasible. We do not intentionally send sensitive personal data to an AI provider unless the use case has been specifically assessed and approved, the client has instructed the processing, and an appropriate lawful basis and provider safeguards are in place.
Purposes and lawful bases
- Contract and requested steps: creating accounts, providing client-configured chats, forms, CRM, billing, integrations, and support.
- Legitimate interests: securing and improving the service, preventing abuse, troubleshooting, measuring service performance, and managing business relationships, after considering individual rights.
- Legal obligations: tax, accounting, regulatory, law-enforcement, and dispute requirements.
- Consent: optional marketing and any feature or client collection that specifically asks for consent. Consent can be withdrawn without affecting earlier lawful processing.
- Client instructions: where we are a processor, the client determines and documents the lawful basis for its visitor, lead, form, CRM, and outreach processing.
Recipients and subprocessors
Personal data may be disclosed to authorized client users; hosting, database, storage, security, email, billing, AI, crawling, vector-search, and integration providers; professional advisers; regulators and law enforcement where legally required; and customer-selected destinations. The named providers, purposes, data categories, status, and processing locations are maintained in our Subprocessor Register.
We do not sell personal data or disclose it to advertising data brokers.
Google Workspace Limited Use
Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Our handling of Google Workspace user data also complies with the Google Workspace User Data and Developer Policy. We use Google user data only for prominent user-facing features requested by the connected client.
- We do not transfer Google user data except to provide the requested feature with user consent, for security, to comply with law, or as part of a merger or asset sale with the required prior consent.
- We do not use or transfer Google user data for advertising, retargeting, lending, or sale to data brokers.
- Humans do not read Google user data unless the user has affirmatively authorized access to specific data, access is necessary for security or legal compliance, or the data is aggregated and anonymized for lawful internal operations.
- We do not use Google user data to create, train, or improve a general or shared AI model beyond a specific user-facing feature permitted by Google's policy.
International transfers
Our primary application, database, vector, and object-storage regions are in Singapore. VIMI is established in Thailand, while provider control planes, support, security, logs, AI services, and subprocessors may process data in the United States, European Economic Area, United Kingdom, and other listed locations. A legacy Supabase database remains in the United States during retirement. Provider-held copies and backups follow their own retention and deletion processes.
Where required, we use contractual and organizational safeguards such as data processing agreements, contractual transfer clauses including EU Standard Contractual Clauses and the UK Addendum where applicable, access controls, encryption, regional configuration, and transfer reviews. B2Blead is responsible for the required provider and transfer safeguards. A service listing or saved client permission does not establish that these reviews are complete. Automatic provider-review blocking depends on the bot's compliance configuration.
Retention and deletion
Clients choose retention periods that reflect the purpose of each record. Business-to-business sales cycles can exceed five years, so relevant CRM contact details, enquiry history, and relationship records may be needed throughout a continuing sales opportunity or customer relationship. Clients should review whether those records remain necessary; their age alone does not establish that the purpose has ended.
Chat history can support ongoing customer service, including recurring issues, previous troubleshooting and service commitments. The default ten-year retention period is intended to support this continuity; clients can select a shorter period appropriate to their needs.
The current platform default is 3,650 days (about ten years) for each configurable category: raw chat content, rejected form submissions, form interaction events, raw integration payloads, email logs, raw crawl and knowledge-base artifacts, and CRM contacts. CRM retention is measured from the last recorded activity. Client settings may specify different periods. These are configurable product defaults, not a requirement to keep every record for ten years.
Choose retention periods for each type of information according to its purpose. A long sales cycle or ongoing support need does not by itself justify keeping rejected submissions or technical logs for as long as relevant chat and CRM history.
Automatic retention deletion is off by default. With it off, saved periods support review and preview; they do not cause records to be deleted when a period ends. Records may remain until a reviewed manual action or another applicable deletion process is completed. When a client enables automatic deletion, eligible records are deleted or identifying details removed in scheduled batches, subject to applicable processing safeguards. This can include deleting CRM contacts beyond their last-activity retention period. Clients should review continuing opportunities and required records before enabling it.
Retiring a bot starts a separate 90-day period, after which its database records become eligible for deletion even if automatic retention deletion is off. External files and knowledge-base vectors require separate cleanup; deleting the bot's database records does not establish that all copies have been erased. Clients should arrange any required export or continued retention before retiring a bot.
Browser form drafts expire after 30 days. Account, billing, security, consent, and legal records are retained for the applicable relationship and any required limitation, tax, audit, or dispute period. Privacy rights and legal retention obligations continue to apply regardless of a configured period. Clients and individuals may request review or deletion at the contact address above. On termination, customer personal data is returned or deleted as described in the DPA, subject to legal requirements and backup cycles.
Cookies and local storage
The portal uses essential Supabase authentication and session cookies for access and security. It also uses functional browser storage for interface preferences, including the last selected bot. The chat widget uses session storage for the current chat reference, a protected resume token, and language choice so the conversation can continue in the same browser tab. These items are needed to provide the requested service, secure it, or remember a choice; they are not used for advertising or cross-site profiling.
If a client enables form draft saving, an embedded form can store the visitor's entered values and current page in that browser for up to 30 days. The widget can also remember an animation-dismissal choice for the configured period. B2Blead may record limited form-view, form-start, and widget-animation events to measure operation and use. A client using the PDPA Framework can suppress those optional public events, host-page form analytics hooks, and form draft storage while keeping essential service and security features available.
We do not place third-party advertising or cross-site analytics cookies. A client website may independently use its own analytics, cookies, or consent platform and must describe and manage them under its own Privacy Notice. Cloudflare Turnstile may be loaded when the client enables that anti-abuse option.
Security and incidents
We use encrypted transport, role-based access, tenant isolation, private storage, audit controls, and AES-256-GCM encryption for stored OAuth refresh tokens. No service can be guaranteed completely secure. We investigate suspected incidents and notify affected clients, individuals, or regulators where required by applicable law and our contractual obligations.
Your privacy rights
Subject to applicable law and exceptions, an individual may request:
- access to and a copy of personal data;
- correction of inaccurate or incomplete data;
- deletion, anonymization, restriction, or objection to processing;
- data portability where the legal conditions apply;
- withdrawal of consent and objection to direct marketing; and
- information about safeguards used for international transfers.
Where we act as processor, we may refer the request to the relevant client controller. Email requests to privacy@b2blead.ai. Our privacy team reviews each request manually and may verify identity before acting. We aim to respond within 30 days of receiving a valid request, unless applicable law permits or requires a different period. Individuals may also complain to the Thailand Personal Data Protection Committee or another competent supervisory authority.
Account holders may also request closure of their account and deletion or anonymization of personal data associated with it by emailing the address above. We will confirm the scope and process. We may retain data where required by law, for accounting, security, fraud prevention or dispute handling, at the instruction of the relevant client controller, or during limited backup cycles. Customer personal data is returned or deleted in accordance with the client's instructions and the DPA.
Optional marketing communications
Marketing consent is optional and separate from accepting our Terms or receiving the service. A recipient can withdraw at any time by contacting us. We may retain a minimal suppression record to honor the opt-out. We will not send optional marketing emails until each message has a working unsubscribe mechanism.
Children
The platform is a business service and is not directed to children. Clients must not intentionally use it to collect children's personal data unless they have an appropriate lawful basis, provide required notices, obtain any required parental authorization, and receive our prior written approval for the use case.
Changes
We may update this policy when our services or legal obligations change. We will update the date above and provide additional notice where required.