EU & EEA
Data Residency
BotNira provides a dedicated European data environment designed to keep EU/EEA vendor data and backups within the European region.
Storage & backups
EU vendor data stays in the EU/EEA environment.
Businesses using BotNira in the European region are assigned to the European data environment. BotNira stores and backs up their BotNira-retained vendor and customer data within the EU/EEA.
This regional architecture is designed to separate European customer data from the storage environments used for other BotNira regions.
EU storage does not mean every third-party processing operation occurs inside the EU.
BotNira stores and backs up its EU/EEA vendor data within the European environment. However, certain communication and AI functions involve third-party service providers.
These providers may operate infrastructure or process information outside the EEA. The exact processing location depends on the applicable service, provider configuration and functionality.
BotNira is currently formalizing its contractual and international-transfer framework for EU/EEA customers, including appropriate data-processing and transfer mechanisms.
How data moves through BotNira.
Different communication channels use different transport providers, while BotNira remains the application layer and regional storage environment.
Channel-by-channel data flow.
BotNira uses different infrastructure depending on how a customer communicates with a business.
Phone Calls
Twilio provides the telecommunications transport layer. BotNira manages the application layer and uses OpenAI for applicable AI processing.
WhatsApp provides the messaging transport layer. BotNira manages the application and applicable AI processing after the communication reaches BotNira.
Email communications are handled through the BotNira application. AI processing is performed through OpenAI where required by the configured functionality.
Website Chat
Website chat connects with BotNira's application environment and uses OpenAI where AI functionality is required.
SMS
Twilio provides SMS transport while BotNira manages application processing and applicable AI functionality.
Designed around European data protection principles.
BotNira's European environment is designed to support businesses handling personal data under the General Data Protection Regulation.
Controller & Processor
Where BotNira processes personal data on behalf of an EU/EEA customer, the customer generally determines the purposes and means of processing, while BotNira performs processing on the customer's behalf, subject to the actual arrangement.
Data Minimization
BotNira is designed to process information needed to provide configured communication and AI functionality.
Technical & Organizational Measures
Encryption, access controls, vulnerability scanning, penetration testing, backups and incident response controls form part of BotNira's security program.
Data Subject Rights
BotNira provides privacy support through its Data Protection Officer for requests concerning personal information processed through the platform.
Our current contractual status.
BotNira currently does not have a dedicated Data Processing Agreement in place for its EU/EEA customer onboarding process.
This means we do not represent on this Trust Center that every EU/EEA customer currently has a completed Article 28 data-processing agreement with BotNira.
BotNira is working toward formalizing the appropriate contractual framework for customers requiring processor-specific GDPR documentation.
Transparency about data leaving the EEA.
EU/EEA data remains protected by GDPR requirements when transferred outside the EEA. BotNira therefore distinguishes between regional storage and third-party processing.
EU Storage
BotNira-retained EU/EEA vendor data is stored within the European environment.
EU Backups
Backups for EU/EEA vendor environments are maintained within the European environment.
SCC Framework
BotNira does not currently maintain a completed public SCC framework for EU customer relationships.
Transfer Impact Assessment
BotNira does not currently have a documented Transfer Impact Assessment published for its EU environment.
EU data-protection rules provide mechanisms for transferring personal data to third countries, including adequacy decisions and Standard Contractual Clauses. BotNira will not claim that a particular transfer mechanism applies until it has been formally implemented for the relevant processing relationship.
Privacy questions?
BotNira has a Data Protection Officer responsible for privacy matters across BotNira's supported regions.
kamal@botnira.comPrivacy rights supported by BotNira.
EU/EEA individuals may have rights under GDPR depending on the circumstances and legal basis for processing.
Access
Request access to personal information.
Correction
Request correction of inaccurate information.
Deletion
Request deletion where the applicable conditions are satisfied.
Restriction
Request restriction of processing in applicable circumstances.
Portability
Request personal data in a portable format where the GDPR right applies.
Objection
Object to certain processing where the GDPR provides that right.
Security controls protecting the EU environment.
SSL / TLS
Secure transport encryption protects communications.
Encryption at Rest
Stored information is protected with encryption.
Encryption in Transit
Data is protected during transmission.
2FA
Two-factor authentication provides an additional account security layer.
Database Backups
Regular backups support operational resilience.
Firewall
Network controls help protect infrastructure.
DDoS Protection
Infrastructure protections help mitigate attacks.
Vulnerability Scanning
Regular vulnerability scanning identifies potential security weaknesses.
Penetration Testing
Penetration testing has been completed.
Restricted Employee Access
Routine BotNira team members do not have access to customer data.
Incident Response
A security team handles security incidents and potential security events.
Data Deletion
Applicable data is permanently deleted following the 45-day post-closure period.
A defined customer data lifecycle.
Vendor actively uses BotNira.
Vendor stops using BotNira.
Applicable data remains during the closure period.
Applicable customer data is permanently deleted.
BotNira compliance documentation.
The following documentation represents BotNira's available security and compliance evidence.
SOC 2 Type II
Security and trust-services control assessment.
View document →ISO/IEC 27001
Information security management certification.
View document →ISO/IEC 27701
Privacy information management certification.
View document →GDPR Compliance
GDPR compliance documentation.
View document →HIPAA
HIPAA-related compliance documentation.
View document →Penetration Testing
Security testing documentation.
View document →Know which external providers participate.
BotNira uses specialized third-party services for certain communication and AI functions.
We are currently preparing a formal public subprocessor register containing provider names, processing purposes, processing locations and applicable transfer information.
View SubprocessorsFrequently asked questions.
Is EU vendor data stored in Europe?
Does BotNira use OpenAI?
Does EU data ever involve third-party providers?
Does BotNira currently have an EU DPA?
Does BotNira currently use SCCs?
Who handles privacy questions?
kamal@botnira.com
How long is data retained after account closure?
Questions about EU data protection?
Contact BotNira's Data Protection Officer for privacy and data-protection questions.
Contact Data Protection Officer