BotNira Trust Center Visit BotNira.com →
INDIA

India Data Residency

BotNira provides Indian vendors with regional data storage and backups in India while delivering AI-powered voice, messaging, email and website communication services.

INDIA DATA RESIDENCY
🇮🇳
Indian Region

Customer data is stored in India.

Primary storage India
Backups India
AI processing OpenAI
Phone provider Twilio

Indian vendor data stays in India

When a business located in India signs up for BotNira, that business is treated as an Indian vendor for data-residency purposes.

BotNira stores the vendor's BotNira data within its Indian regional infrastructure. Backups for Indian vendor data are also maintained in India.

This means that the primary BotNira application data belonging to an Indian vendor is maintained within the Indian region.

Regional storage does not mean that every technical processing operation necessarily occurs inside India. Certain BotNira functionality uses external service providers, including OpenAI for applicable AI processing.

What Indian vendors' data can include

Depending on how a vendor uses BotNira, the platform may handle different categories of business and customer information.

Vendor Information

Business information, account information, configuration data and information required to operate the BotNira account.

Customer Information

Information submitted by or exchanged with customers communicating with the vendor through BotNira.

Call Data

Depending on the configured service, voice conversations and related call information may be processed through BotNira.

Messaging Data

Messages exchanged through supported communication channels may be handled by BotNira.

Email Data

Email communication handled through BotNira may be stored within the vendor's regional environment.

Website Chat Data

Conversations conducted through BotNira website chat functionality may be stored and managed through BotNira.

How Indian data moves through BotNira

BotNira keeps regional storage separate from external communication and AI services used to deliver specific functionality.

☎
VOICE

Phone Calls

Customer → Twilio → BotNira → OpenAI
TELEPHONY PROVIDER Twilio

Twilio provides telephone connectivity and acts as the communication bridge between the customer's telephone network and BotNira.

AI PROCESSING OpenAI

Applicable voice and AI processing may be performed through OpenAI services.

◉
MESSAGING

WhatsApp

Customer → Meta → BotNira → OpenAI
MESSAGING PROVIDER Meta / WhatsApp

Meta provides the WhatsApp communication infrastructure used to transmit messages between customers and BotNira.

AI PROCESSING OpenAI

Where an AI-powered response is required, applicable message content may be processed through OpenAI services.

@
MESSAGING

Email

Customer → BotNira → OpenAI*
PLATFORM BotNira

Email communication is handled through BotNira infrastructure without a separate messaging intermediary.

AI PROCESSING OpenAI*

OpenAI may be involved when an AI-powered feature requires processing of email content.

◇
WEB

Website Chat

Customer → BotNira → OpenAI*
PLATFORM BotNira

Website chat is provided and managed directly through BotNira infrastructure.

AI PROCESSING OpenAI*

OpenAI may process content when an AI-powered website chat feature requires it.

* AI processing: OpenAI is used as an AI service provider for applicable BotNira AI functionality. BotNira remains responsible for the overall application, data handling and Indian regional storage environment.

Digital Personal Data Protection framework

India's Digital Personal Data Protection Act, 2023 establishes a framework for processing digital personal data while recognizing individuals' rights and lawful purposes for processing.

FRAMEWORK

DPDP Act, 2023

The Digital Personal Data Protection Act, 2023 provides India's principal framework for the processing of digital personal data.

NOTIFIED

DPDP Rules, 2025

The Government of India notified the Digital Personal Data Protection Rules, 2025 on November 14, 2025.

APPLICABLE

Data Fiduciary

The DPDP framework establishes obligations for organizations determining the purpose and means of processing digital personal data.

APPLICABLE

Data Principal Rights

The framework provides individuals with rights concerning their personal data, subject to the applicable provisions and implementation timeline.

Key privacy principles relevant to BotNira

BotNira's Indian data handling approach is designed to support responsible processing of digital personal data.

Lawful Processing

Personal data should be processed for lawful purposes and in accordance with the applicable requirements of the DPDP framework.

Notice & Transparency

Individuals should receive appropriate information about the processing of their personal data as required by applicable law.

Purpose-Based Processing

Personal data should be processed for legitimate and disclosed purposes rather than used without an appropriate basis.

Data Security

Appropriate safeguards are used to protect personal data against unauthorized access, misuse, loss and security threats.

Data Deletion

Data should not be retained longer than necessary for the applicable purpose or legal requirements, subject to BotNira's documented retention policy.

Individual Rights

The DPDP framework provides rights to Data Principals, including rights relating to access, correction and grievance redressal, subject to applicable provisions.

Data protection contact

BotNira maintains a dedicated data protection contact responsible for privacy and data protection matters across its regions.

Data Protection Contact

Kamal

kamal@botnira.com

Indian storage and international AI processing

Indian vendor data is stored and backed up within BotNira's Indian regional infrastructure.

However, some BotNira functionality requires processing through OpenAI services. Relevant information may therefore be processed outside India when an AI-powered feature is used.

This distinction is important: data residency refers to where BotNira stores the vendor's data, while AI processing refers to where a particular operation required to provide an AI feature may occur.

BotNira does not represent that every processing operation involving an Indian vendor occurs exclusively inside India.

Indian cybersecurity requirements

BotNira considers applicable Indian cybersecurity requirements as part of its regional security architecture.

SECURITY

CERT-In Directions

The Indian Computer Emergency Response Team (CERT-In) has issued directions under the Information Technology Act addressing cybersecurity incident reporting, logging and related controls for covered entities.

LOGGING

ICT System Logs

Applicable CERT-In requirements include maintaining ICT system logs securely for a rolling period of 180 days within Indian jurisdiction.

INCIDENT RESPONSE

Security Incident Response

BotNira maintains a security team responsible for responding to security incidents and coordinating appropriate response activities.

MONITORING

Security Monitoring

BotNira performs regular vulnerability scanning and maintains security controls intended to identify and address potential threats.

Important: CERT-In requirements can depend on the nature of an organization's activities and applicable legal classification. This Trust Center describes BotNira's general security architecture and does not constitute legal advice or a sector-specific compliance determination.

Security controls protecting Indian data

BotNira applies multiple technical and organizational safeguards to protect information throughout its lifecycle.

SSL / TLS

Secure encrypted connections protect information during transmission.

Encryption at Rest

Stored information is protected using encryption controls.

Encryption in Transit

Information transmitted between systems is protected using secure communication protocols.

Two-Factor Authentication

Additional authentication controls help protect account access.

Firewall

Network security controls help protect BotNira infrastructure from unauthorized traffic.

DDoS Protection

Distributed denial-of-service protection helps defend infrastructure against malicious traffic.

Database Backups

Regular backups support data resilience and operational recovery.

Vulnerability Scanning

Regular vulnerability scanning is performed to identify potential weaknesses.

Penetration Testing

Penetration testing has been completed as part of BotNira's security program.

Employee Access Controls

BotNira restricts internal team access to customer data. Customer data is not accessible to members of the team as part of ordinary operations.

Incident Response

A dedicated security team is responsible for responding to security incidents.

Data Deletion

Data is permanently deleted following the applicable account closure retention period.

BotNira certifications

BotNira maintains security and compliance certifications supporting its overall trust and security program.

BotNira ISO 27001 certification

ISO 27001

BotNira ISO 27701 certification

ISO 27701

BotNira SOC 2 Type II certification

SOC 2 Type II

BotNira GDPR compliance certification

GDPR Compliance

BotNira HIPAA certification

HIPAA

BotNira penetration testing certificate

Penetration Testing

Important: Certifications and security assessments reflect BotNira's security and compliance program. Individual customer requirements, contractual obligations and regulated-data requirements may require additional agreements or controls.

Data retention and deletion

While an Indian vendor actively uses BotNira, the vendor can manage and delete its customers' calls, messages and related data using the available BotNira controls.

When a vendor closes its BotNira account, BotNira retains account data for up to 45 days before permanently deleting it.

The retention period provides an operational window for account closure and deletion processes.

Vendors control their customer data

BotNira provides vendors with control over customer communication data handled through their account.

Calls

Vendors can manage and delete applicable call data while actively using BotNira.

Messages

Vendors can manage and delete applicable messaging data through their BotNira account.

Customer Information

Vendors determine how their customer information is managed within their BotNira environment, subject to applicable law.

Account Closure

Following account closure, BotNira retains applicable account data for up to 45 days before permanent deletion.

Know which providers are involved

BotNira identifies the third-party providers involved in communication and AI functionality.

✓

Indian vendors get Indian regional storage

BotNira's regional infrastructure is designed so that Indian vendor data and backups remain within India. External providers are used where required for specific communication or AI functionality.

India data residency questions

Is Indian vendor data stored in India?
Yes. Indian vendors are assigned to BotNira's Indian regional infrastructure, where their primary data and backups are stored.
Is all processing performed inside India?
No. BotNira distinguishes between regional storage and external processing. Certain AI-powered functionality uses OpenAI services, which may involve processing outside India.
Does BotNira use Twilio for Indian phone calls?
Yes. Twilio provides telephone connectivity and acts as the communication bridge between the customer's telephone network and BotNira.
Does WhatsApp involve another provider?
Yes. WhatsApp is provided through Meta. Meta provides the WhatsApp messaging infrastructure used to transmit messages before applicable processing occurs through BotNira.
Does BotNira use OpenAI?
Yes. BotNira uses OpenAI API/business services for applicable AI-powered functionality, including speech and AI processing.
What happens to my data when I close my account?
BotNira retains applicable account data for up to 45 days following account closure and then permanently deletes it.
Can Indian vendors delete their customer data?
Yes. While actively using BotNira, vendors can manage and delete applicable calls, messages and related customer data through the available BotNira controls.
Does India require every type of data processing to occur inside India?
Indian privacy requirements should not be represented as a blanket statement that every processing operation must occur in India. Applicable requirements depend on the nature of the data, organization, processing activity and applicable law or sector-specific regulation.
Does BotNira follow the Digital Personal Data Protection framework?
BotNira's Indian privacy and security architecture is designed with India's Digital Personal Data Protection framework in mind, including the Digital Personal Data Protection Act, 2023 and the notified Digital Personal Data Protection Rules, 2025.
Does BotNira maintain security controls for Indian data?
Yes. BotNira uses encryption, SSL/TLS, two-factor authentication, firewall protection, DDoS protection, backups, vulnerability scanning, penetration testing and incident response controls.
Who can I contact about data protection?
You can contact BotNira's data protection contact at:

Kamal
kamal@botnira.com
Compliance information: The information on this page describes BotNira's current data-residency architecture, security controls and compliance approach. It is provided for transparency and informational purposes and does not constitute legal advice or a guarantee that a particular customer's use of BotNira satisfies every obligation applicable to that customer's industry, data or regulatory status.

Customers operating in regulated sectors may have additional requirements imposed by sector-specific regulators, contractual obligations or applicable Indian law.

Security and transparency come first.

Explore BotNira's security controls, compliance documentation, subprocessors and regional data residency commitments.

Have a security or compliance question?

Our team can help with security documentation, compliance information, data residency questions, enterprise reviews and security questionnaires.