Privacy Policy
What we collect, why we collect it, who else sees it, and how you get it back or get it deleted. Written plainly and in full, including the parts most policies leave vague.
Last updated 11 September 2026 · No Names Collective (Pvt) Ltd
1. Who this policy is about
This policy is issued by No Names Collective (Pvt) Ltd, of No 561, Sirimadura, Gangarama Road, Werahara, Boralasgamuwa, Sri Lanka, the operator of chassia and the controller of the personal data described below.
It covers two different groups of people, and it says which is which throughout:
- Our customers: the businesses that buy chassia, and the people at those businesses who deal with us.
- Website visitors: the people who talk to an assistant on one of our customers’ websites. For that data the customer is the controller and we act on their instructions; we still explain it here because you deserve to know what happens to it.
2. What we collect, and when it is collected
When you enquire or order (our customers)
- Your name, your business name, email address, telephone number and website address, collected at the moment you contact us or place an order, because you give them to us.
- The information about your business you give us for your assistant: services, prices, opening hours, policies and similar. This is business information, though it may contain the names and contact details of your staff.
- Billing details: the name and address the invoice is issued to, and a record of payments made. We do not collect or store card numbers (see section 4).
When you use your assistant’s admin (our customers)
- Your login email address and a securely hashed password, never the password itself.
- A log of administrative actions taken in your account (who changed what and when), kept for security and for answering “who did this?”.
When someone talks to an assistant (website visitors)
- The messages typed into the assistant and the assistant’s replies, collected as the conversation happens, because that is what a conversation is.
- Contact details a visitor chooses to give so the business can get back to them: typically a name and an email address or phone number. This is only ever collected because the visitor offers it.
- The page the conversation started on, and technical details of the request (see below).
Assistants are instructed not to ask for sensitive personal information, such as health details, card numbers or national identity numbers, and our customers are contractually required not to use them for that. Please do not type such information into a chat assistant, here or anywhere else.
Automatically, on every request
- IP address, browser and device type, the page requested, and the date and time. Collected at the moment of the request, and used to keep the service running and to detect abuse such as automated attacks.
On this website (chassia.com)
This site sets no cookies, runs no analytics and loads nothing from any other company: no fonts, no scripts, no tracking pixels. The only thing it stores in your browser is your light-or-dark theme preference, kept in your browser’s own local storage and never sent to us. Loading a page of this site makes no request to any third party at all.
3. Why we collect it, and what we do with it
- To provide the service you bought: building and running your assistant, answering your visitors, and passing you the enquiries it captures.
- To bill you: issuing invoices, taking the setup fee and the monthly subscription, and keeping the accounting records the law requires.
- To support you: answering your questions, investigating problems you report, and telling you about changes to the service, its prices or these policies.
- To keep the service secure and working: detecting abuse, blocking attacks, diagnosing faults and maintaining backups.
- To meet legal obligations: tax and company record-keeping, and responding to lawful requests from authorities.
We do not use your data, or your visitors’ conversations, for advertising, for profiling, or to train AI models, ours or anyone else’s. We never sell personal data and we never rent or share contact lists. We send no marketing email to your website visitors.
4. Who else sees it, and how far
We share personal data only with the service providers we need in order to run chassia, only to the extent each of them needs, and only under contracts that require them to protect it and to use it for nothing else. Those providers fall into these categories:
- Cloud hosting and content delivery. The companies whose servers and network the platform runs on. They hold the data at rest and in transit; they do not use it.
- AI model providers. When your assistant answers a question, the conversation is sent to an AI model provider to generate the reply. We only use providers who are contractually bound not to train their models on what we send and to state how long they retain it. The conversation is not used to improve anyone’s model.
- Our payment provider, PAYable. Card payments are processed entirely by them: your card number is entered on their secure page and never reaches our systems. They receive the amount, the currency and the details needed to process the payment, and they are the controller of the card data they hold.
- Email delivery. The provider that delivers transactional email: password resets, invoices, notifications of an enquiry. They see the recipient address and the content of that message.
- Professional advisers and authorities: our accountants and lawyers where needed, and a public authority where we are legally required to disclose.
Named rather than described, because a category is not a disclosure — this is the current list, and the two rows marked “not in use today” are routes an assistant may be moved onto, which we would tell the customer about first:
| Who | What they do | Where |
|---|---|---|
| Anthropic PBC | Runs the AI model that answers your visitors. Contractually excluded from training on our data. | United States |
| Amazon Web Services | Sends the email the platform generates — invitations, notifications and password resets. | Singapore (ap-southeast-1) |
| DigitalOcean | Hosts the managed database your content and conversations are stored in. | Singapore |
| Contabo | Hosts the servers the platform runs on. | Singapore |
| Cloudflare | Serves the site through its network and stores uploaded files. | Singapore and its global network |
| PAYable | Takes card payments. Card details are entered on their page and never reach us. | Sri Lanka |
| Google LLC (not in use today) | An alternative AI model. Not used for live assistants today. | United States |
| A Western cloud host running the DeepSeek open-weights model (not in use today) | An alternative AI model, reached only through a host with a no-training, stated-retention posture. Not used for live assistants today. | United States or European Union |
If we are ever party to a sale or merger of the business, personal data may transfer with it; we would tell you before that happened. If this list is ever out of date, the authority is the copy in our terms of service, and you can ask us at info@nonames.lk.
5. Where your data is held
The platform and its databases run on servers in Singapore, and backups are held in the same region. AI model providers and our payment and email providers may process data in other countries; where they do, we require contractual protections for the transfer. We are domiciled in Sri Lanka.
6. How long we keep it
- Assistant conversations: a conversation that produced no enquiry is deleted after the period set for that assistant — 90 days by default, up to 365 days if the customer asks. A conversation that produced an enquiry is kept while the enquiry is open and for 12 months after it is closed. In every case a transcript is deleted no later than 24 months after its last message; that ceiling is ours and no customer can extend it.
- Enquiries captured by an assistant: kept for the customer for as long as their account is active, because they are the customer’s business records.
- Account and business information: for as long as your account is active, and for 90 days after it closes, so an account can be restored if it closed in error.
- Invoices and payment records: for as long as tax and company law requires us to keep them.
- Technical and security logs: a rolling period, typically no more than 90 days.
7. How you can see, correct, restrict or delete your data
You can ask us at any time to: give you a copy of the personal data we hold about you; correct it if it is wrong; delete it; stop using it for a particular purpose; or restrict our use of it while a dispute about it is resolved. You can also withdraw consent where our use of the data rests on your consent.
Email info@nonames.lk with what you want. We will confirm we have received it, may ask you to confirm who you are, and will respond within 30 days. There is no charge.
If you are a website visitor who talked to an assistant on a business’s site and want that conversation deleted: contact that business, since the data is theirs. If you cannot reach them, or you do not know who they are, write to us at the address above and we will identify the business and pass your request on.
If you are a customer, three routes are open to you without asking us for anything:
- Delete a conversation, or an enquiry, yourself. Both are records in your workspace and both carry a Delete control. They are separate records on purpose — deleting a transcript leaves the enquiry it produced standing, so honouring an erasure request in full means deleting both, and the panel beside each control says so.
- See the retention period that applies to your assistant on its dashboard. Changing it is a request to us rather than a switch, because the period is a floor we enforce as your processor.
- Ask us to delete your whole account from your account settings. The request goes to a person, we confirm it with you, and we then remove your workspace and its data — except the records tax and company law require us to keep, which are the invoices and payment records named above.
8. How it is protected
Data is encrypted in transit (HTTPS with TLS 1.2 or higher) and at rest. Access to production systems is limited to the people who operate the platform, individually authenticated with two-factor authentication, and every administrative action is logged. Each customer’s data is isolated from every other customer’s, and that isolation is checked by an automated test suite that must pass before any change reaches production. The fuller description is in section 8 of our terms of service.
9. Children
chassia is sold to businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child’s data has reached us, tell us and we will delete it.
10. Changes to this policy
If we change this policy we update the date at the top of this page, and where a change materially affects our customers we email them about it beforehand.
11. Contact and complaints
Write to us first; we would rather fix it than have you complain about it:
No Names Collective (Pvt) Ltd
No 561, Sirimadura, Gangarama Road, Werahara, Boralasgamuwa, Sri Lanka
Email: info@nonames.lk
Telephone: +94 77 699 9318
We handle personal data in line with Sri Lanka’s Personal Data Protection Act No. 9 of 2022. If you are not satisfied with how we have handled your request, you may complain to the Data Protection Authority of Sri Lanka.