BotNira Trust Center Visit BotNira.com →
🇪🇺 EUROPEAN UNION & EEA

EU & EEA
Data Residency

BotNira provides a dedicated European data environment designed to keep EU/EEA vendor data and backups within the European region.

EU / EEA ENVIRONMENT
🇪🇺
European Residency

Storage & backups

Primary storage EU / EEA
Backup storage EU / EEA
AI processing OpenAI*
Voice transport Twilio
✓

EU vendor data stays in the EU/EEA environment.

Businesses using BotNira in the European region are assigned to the European data environment. BotNira stores and backs up their BotNira-retained vendor and customer data within the EU/EEA.

This regional architecture is designed to separate European customer data from the storage environments used for other BotNira regions.

How data moves through BotNira.

Different communication channels use different transport providers, while BotNira remains the application layer and regional storage environment.

01 Customer Voice / Message
→
02 Communication Provider Twilio / Meta*
→
03 BotNira Application Layer
→
04 OpenAI* AI Processing
→
05 BotNira Application Layer
→
06 EU Storage EU Backup
Important: Third-party transport and AI providers may process information according to their own infrastructure, contractual terms and applicable data-processing arrangements.

Channel-by-channel data flow.

BotNira uses different infrastructure depending on how a customer communicates with a business.

☎
VOICE

Phone Calls

Customer → Twilio → BotNira → OpenAI* → BotNira → EU Storage
TRANSPORT Twilio
AI OpenAI*
STORAGE EU / EEA

Twilio provides the telecommunications transport layer. BotNira manages the application layer and uses OpenAI for applicable AI processing.

◇
MESSAGING

WhatsApp

Customer → Meta / WhatsApp → BotNira → OpenAI* → BotNira → EU Storage
TRANSPORT Meta / WhatsApp
AI OpenAI*
STORAGE EU / EEA

WhatsApp provides the messaging transport layer. BotNira manages the application and applicable AI processing after the communication reaches BotNira.

@
MESSAGING

Email

Customer → BotNira → OpenAI* → BotNira → EU Storage
APPLICATION BotNira
AI OpenAI*
STORAGE EU / EEA

Email communications are handled through the BotNira application. AI processing is performed through OpenAI where required by the configured functionality.

◌
WEB

Website Chat

Visitor → BotNira → OpenAI* → BotNira → EU Storage
APPLICATION BotNira
AI OpenAI*
STORAGE EU / EEA

Website chat connects with BotNira's application environment and uses OpenAI where AI functionality is required.

#
MESSAGING

SMS

Customer → Twilio → BotNira → OpenAI* → BotNira → EU Storage
TRANSPORT Twilio
AI OpenAI*
STORAGE EU / EEA

Twilio provides SMS transport while BotNira manages application processing and applicable AI functionality.

* OpenAI processing BotNira uses OpenAI API/business services for applicable AI functionality. BotNira is currently confirming the precise regional processing options applicable to its OpenAI configuration.

Designed around European data protection principles.

BotNira's European environment is designed to support businesses handling personal data under the General Data Protection Regulation.

ROLE

Controller & Processor

Where BotNira processes personal data on behalf of an EU/EEA customer, the customer generally determines the purposes and means of processing, while BotNira performs processing on the customer's behalf, subject to the actual arrangement.

PRIVACY

Data Minimization

BotNira is designed to process information needed to provide configured communication and AI functionality.

SECURITY

Technical & Organizational Measures

Encryption, access controls, vulnerability scanning, penetration testing, backups and incident response controls form part of BotNira's security program.

RIGHTS

Data Subject Rights

BotNira provides privacy support through its Data Protection Officer for requests concerning personal information processed through the platform.

Transparency about data leaving the EEA.

EU/EEA data remains protected by GDPR requirements when transferred outside the EEA. BotNira therefore distinguishes between regional storage and third-party processing.

IMPLEMENTED

EU Storage

BotNira-retained EU/EEA vendor data is stored within the European environment.

IMPLEMENTED

EU Backups

Backups for EU/EEA vendor environments are maintained within the European environment.

BEING FORMALIZED

SCC Framework

BotNira does not currently maintain a completed public SCC framework for EU customer relationships.

NOT COMPLETED

Transfer Impact Assessment

BotNira does not currently have a documented Transfer Impact Assessment published for its EU environment.

Why this matters

EU data-protection rules provide mechanisms for transferring personal data to third countries, including adequacy decisions and Standard Contractual Clauses. BotNira will not claim that a particular transfer mechanism applies until it has been formally implemented for the relevant processing relationship.

👤

Privacy questions?

BotNira has a Data Protection Officer responsible for privacy matters across BotNira's supported regions.

kamal@botnira.com

Privacy rights supported by BotNira.

EU/EEA individuals may have rights under GDPR depending on the circumstances and legal basis for processing.

01

Access

Request access to personal information.

02

Correction

Request correction of inaccurate information.

03

Deletion

Request deletion where the applicable conditions are satisfied.

04

Restriction

Request restriction of processing in applicable circumstances.

05

Portability

Request personal data in a portable format where the GDPR right applies.

06

Objection

Object to certain processing where the GDPR provides that right.

Privacy requests and questions can be directed to: kamal@botnira.com

Security controls protecting the EU environment.

01

SSL / TLS

Secure transport encryption protects communications.

02

Encryption at Rest

Stored information is protected with encryption.

03

Encryption in Transit

Data is protected during transmission.

04

2FA

Two-factor authentication provides an additional account security layer.

05

Database Backups

Regular backups support operational resilience.

06

Firewall

Network controls help protect infrastructure.

07

DDoS Protection

Infrastructure protections help mitigate attacks.

08

Vulnerability Scanning

Regular vulnerability scanning identifies potential security weaknesses.

09

Penetration Testing

Penetration testing has been completed.

10

Restricted Employee Access

Routine BotNira team members do not have access to customer data.

11

Incident Response

A security team handles security incidents and potential security events.

12

Data Deletion

Applicable data is permanently deleted following the 45-day post-closure period.

A defined customer data lifecycle.

01 Active Account

Vendor actively uses BotNira.

02 Account Closure

Vendor stops using BotNira.

03 45 Days

Applicable data remains during the closure period.

04 Permanent Deletion

Applicable customer data is permanently deleted.

During an active subscription Vendors can manage and delete applicable customer calls, messages and other available data through BotNira's platform controls.

Know which external providers participate.

BotNira uses specialized third-party services for certain communication and AI functions.

We are currently preparing a formal public subprocessor register containing provider names, processing purposes, processing locations and applicable transfer information.

View Subprocessors

Frequently asked questions.

Is EU vendor data stored in Europe?
Yes. BotNira stores EU/EEA vendor data within the European environment and maintains backups within the European environment.
Does BotNira use OpenAI?
Yes. BotNira uses OpenAI API/business services for applicable AI functionality. BotNira is currently confirming the precise regional processing configuration applicable to its OpenAI implementation.
Does EU data ever involve third-party providers?
Yes. Depending on the communication channel, BotNira uses Twilio, Meta/WhatsApp and OpenAI for specialized communication or AI functions.
Does BotNira currently have an EU DPA?
BotNira does not currently have a dedicated DPA in place for its EU/EEA customer onboarding process. The contractual framework is being formalized.
Does BotNira currently use SCCs?
BotNira does not currently maintain a completed public SCC framework for its EU customer relationships. We do not claim that SCCs have already been implemented where they have not.
Who handles privacy questions?
BotNira's Data Protection Officer handles privacy matters across BotNira's supported regions.

kamal@botnira.com
How long is data retained after account closure?
Applicable data is retained for 45 days following account closure and then permanently deleted.

Questions about EU data protection?

Contact BotNira's Data Protection Officer for privacy and data-protection questions.

Contact Data Protection Officer

Have a security or compliance question?

Our team can help with security documentation, compliance information, data residency questions, enterprise reviews and security questionnaires.