When visitors chat, conversations and often IP addresses or email are stored. To be GDPR-compliant you need to know what is saved and for how long.
What is typically stored: Chat messages, timestamps and possibly email or phone if the visitor provides them. Some solutions also log IP addresses.
Retention period: Set a policy (for example 12 or 24 months) and configure the system so that older data is deleted automatically. Mention in your privacy policy that chat logs are stored for this period.
Right to erasure: If someone requests that their data be deleted, you must be able to remove their conversation and identifying information. Verify that your provider supports this and that you have a process for handling such requests.