All legal documents

AI data handling

What our AI features do with the content you and your customers type — which model providers can receive it, the difference between using your own key and ours, and what we will and will not claim.

Effective
19 June 2026
Version
v1.0

What this covers

Tóg offers an AI-chat plugin (the “AI front desk”): a tenant switches it on, configures it (assistant name, persona, greeting, business knowledge, a hand-off email), and embeds a chat widget on their own website. This page explains, plainly and accurately, what that feature does with conversation content. It applies to the AI-chat plugin specifically; other plugins (loyalty, reviews, bookings) do not send content to AI model providers and are covered by the Privacy Policy.

What content is sent to a model

When a website visitor sends a message to a tenant’s AI-chat widget, the following is sent to whichever model provider is active for that request (see below):

  • The conversation. The visitor’s message and the recent turns of the conversation, together with the tenant’s configured instructions and business knowledge that form the assistant’s system prompt.
  • An attached image, if the visitor sends one. If the visitor attaches an image to a message, that image is included with the request to the model so it can be answered.

We bound this for cost and safety: only the most recent turns are kept, each turn is length-limited, and an oversized payload is rejected. We do not send the tenant’s private hand-off email address to the model, and the system instructions are designed so the assistant answers only from the tenant’s own business knowledge.

What is NOT sent to a model

The AI-chat model call carries the conversation for that request. It does not include the tenant’s stored secrets or API keys, other tenants’ data, billing data, or our audit logs. Account sign-in credentials are never sent to a model provider.

Which provider receives it — and who pays

A single request goes to exactly one model provider, chosen in this fixed order of priority:

1 · Your own OpenAI key (bring-your-own-key)

If the tenant has stored their own OpenAI API key, that always takes priority: the request is sent to OpenAI on the tenant’s key, against the tenant’s own OpenAI account, quota and billing. In this case the relationship with OpenAI — including OpenAI’s data-use, retention and any model-training terms — is governed by the agreement between the tenant and OpenAI, not by Tóg. We use the key only to make that call; it is stored encrypted at rest and is never logged or returned.

2 · Anthropic Claude, via the Vercel AI Gateway (Tóg-paid default)

If no tenant key is set, the default path routes the request through the Vercel AI Gateway to Anthropic Claude. Tóg pays for this path. The conversation transits Vercel (the gateway) and is processed by Anthropic to generate the reply.

3 · Google Vertex (Gemini) (Tóg-paid)

If the gateway is not configured, the request is sent to Google Vertex AI (a Gemini model), which Tóg pays for and which runs in the EU (europe-west1 by default).

4 · No provider configured — an honest non-answer

If none of the above is configured, the assistant does not fabricate a business answer. It replies honestly that it isn’t available right now and invites the visitor to leave their details for the team to follow up. The same graceful, honest fallback is used if a model call fails for a technical reason — we never present a made-up reply as if it came from the business.

The model providers we engage on the Tóg-paid paths are listed as our sub-processors:

Sub-processorPurposeData processedRegion
Google Cloud / Firebase (Google LLC)Primary application data store and identity: Cloud Firestore (database), Firebase Authentication (account sign-in), and Cloud Storage. Also Vertex AI (Gemini) when the Tóg-paid AI model path is used.All tenant account data, configuration, and plugin-collected end-shopper data (loyalty members, reviews, bookings); authentication credentials; AI prompt/response content when the Vertex path serves a request.Firestore: europe (eur3, EU multi-region). Vertex AI: europe-west1 by default.
Vercel Inc.Application hosting and edge delivery for the marketplace, and the Vercel AI Gateway that routes AI-chat requests to the configured model.HTTP request/response data and operational logs; for AI-chat via the gateway, the chat prompt and the model's reply transit Vercel.United States (with global edge). Transfers governed by SCCs — see the DPA.
OpenAI, L.L.C.Used only when AI-chat is enabled and OpenAI is the active model provider.Large-language-model responses for the AI-chat plugin when OpenAI is the selected provider — either on the tenant's own (BYO) OpenAI key or the Tóg-paid path.The chat conversation content (end-shopper messages and any image a shopper attaches) for the request being answered.United States. Transfers governed by SCCs — see the DPA.
Anthropic, PBCUsed only when AI-chat is enabled and the gateway (Claude) path is active.Claude large-language-model responses for the AI-chat plugin, served through the Vercel AI Gateway (the default Tóg-paid model path).The chat conversation content for the request being answered.United States. Transfers governed by SCCs — see the DPA.

The full, dated sub-processor list is on the Sub-processors page.

Training and retention

We want to be precise here rather than make a promise we cannot keep on every path:

  • Tóg does not use AI-chat conversations to train our own models. We do not operate or train our own large language models; the AI-chat feature calls third-party providers to generate replies.
  • Whether a provider uses content to train its models depends on that provider. For the Tóg-paid paths, this is governed by the provider’s terms for the API/service we use; for a bring-your-own-key path, it is governed by the tenant’s own account and settings with that provider. We therefore state it as provider-dependent and do not present “no training” as a blanket Tóg guarantee.
  • Retention by the provider (for example, short-term retention for abuse monitoring) is likewise set by the provider’s terms and may vary by provider and over time.

Owner verification needed

[OWNER: Verify the current data-use, model-training and retention terms for each Tóg-paid provider used by AI-chat (OpenAI API, Anthropic via the Vercel AI Gateway, Google Vertex AI) and confirm the wording above matches those terms; update if a provider offers a contractual no-training commitment we can rely on]

On our side: Tóg keeps a conversation only as needed to provide the feature. When the assistant hands a visitor to a person, the conversation is emailed to the tenant’s own hand-off address (via our email provider, Resend) so the tenant’s team has the context — it is not sent to any other third party. The tenant controls what they then do with that record. Any conversation data stored in our systems lives in the EU (see Data residency below) and is covered by the tenant’s data-subject and deletion rights in the Privacy Policy. [OWNER: Confirm the specific retention period for AI-chat conversation records held by Tóg (e.g. hand-off email delivery only vs a stored transcript window)]

Data residency for AI

Our own storage is in the EU. The Tóg-paid Vertex path runs in the EU (europe-west1). The Vercel AI Gateway and the OpenAI and Anthropic services are operated by US-established providers, so a request routed to them is an international transfer governed by the safeguards described on the Data Residency page and our Data Processing Addendum.

Tenant responsibilities

The tenant is the controller of the end-shopper data their AI-chat assistant collects. We recommend tenants:

  • tell their website visitors that an AI assistant is in use and that messages are processed by a model provider (a notice in the tenant’s own privacy policy);
  • keep sensitive personal data out of the assistant’s configured knowledge base, and not invite visitors to share sensitive data in chat;
  • where they use their own provider key, review that provider’s data-use and training settings on their account.

Questions about how AI-chat handles data? Email support@togs.ie.

Questions about this document? Email support@togs.ie.