India Data Residency
BotNira provides Indian vendors with regional data storage and backups in India while delivering AI-powered voice, messaging, email and website communication services.
Customer data is stored in India.
Indian vendor data stays in India
When a business located in India signs up for BotNira, that business is treated as an Indian vendor for data-residency purposes.
BotNira stores the vendor's BotNira data within its Indian regional infrastructure. Backups for Indian vendor data are also maintained in India.
This means that the primary BotNira application data belonging to an Indian vendor is maintained within the Indian region.
Regional storage does not mean that every technical processing operation necessarily occurs inside India. Certain BotNira functionality uses external service providers, including OpenAI for applicable AI processing.
What Indian vendors' data can include
Depending on how a vendor uses BotNira, the platform may handle different categories of business and customer information.
Vendor Information
Business information, account information, configuration data and information required to operate the BotNira account.
Customer Information
Information submitted by or exchanged with customers communicating with the vendor through BotNira.
Call Data
Depending on the configured service, voice conversations and related call information may be processed through BotNira.
Messaging Data
Messages exchanged through supported communication channels may be handled by BotNira.
Email Data
Email communication handled through BotNira may be stored within the vendor's regional environment.
Website Chat Data
Conversations conducted through BotNira website chat functionality may be stored and managed through BotNira.
How Indian data moves through BotNira
BotNira keeps regional storage separate from external communication and AI services used to deliver specific functionality.
Phone Calls
Twilio provides telephone connectivity and acts as the communication bridge between the customer's telephone network and BotNira.
Applicable voice and AI processing may be performed through OpenAI services.
Meta provides the WhatsApp communication infrastructure used to transmit messages between customers and BotNira.
Where an AI-powered response is required, applicable message content may be processed through OpenAI services.
Email communication is handled through BotNira infrastructure without a separate messaging intermediary.
OpenAI may be involved when an AI-powered feature requires processing of email content.
Website Chat
Website chat is provided and managed directly through BotNira infrastructure.
OpenAI may process content when an AI-powered website chat feature requires it.
Digital Personal Data Protection framework
India's Digital Personal Data Protection Act, 2023 establishes a framework for processing digital personal data while recognizing individuals' rights and lawful purposes for processing.
DPDP Act, 2023
The Digital Personal Data Protection Act, 2023 provides India's principal framework for the processing of digital personal data.
DPDP Rules, 2025
The Government of India notified the Digital Personal Data Protection Rules, 2025 on November 14, 2025.
Data Fiduciary
The DPDP framework establishes obligations for organizations determining the purpose and means of processing digital personal data.
Data Principal Rights
The framework provides individuals with rights concerning their personal data, subject to the applicable provisions and implementation timeline.
Key privacy principles relevant to BotNira
BotNira's Indian data handling approach is designed to support responsible processing of digital personal data.
Lawful Processing
Personal data should be processed for lawful purposes and in accordance with the applicable requirements of the DPDP framework.
Notice & Transparency
Individuals should receive appropriate information about the processing of their personal data as required by applicable law.
Purpose-Based Processing
Personal data should be processed for legitimate and disclosed purposes rather than used without an appropriate basis.
Data Security
Appropriate safeguards are used to protect personal data against unauthorized access, misuse, loss and security threats.
Data Deletion
Data should not be retained longer than necessary for the applicable purpose or legal requirements, subject to BotNira's documented retention policy.
Individual Rights
The DPDP framework provides rights to Data Principals, including rights relating to access, correction and grievance redressal, subject to applicable provisions.
Data protection contact
BotNira maintains a dedicated data protection contact responsible for privacy and data protection matters across its regions.
Indian storage and international AI processing
Indian vendor data is stored and backed up within BotNira's Indian regional infrastructure.
However, some BotNira functionality requires processing through OpenAI services. Relevant information may therefore be processed outside India when an AI-powered feature is used.
This distinction is important: data residency refers to where BotNira stores the vendor's data, while AI processing refers to where a particular operation required to provide an AI feature may occur.
BotNira does not represent that every processing operation involving an Indian vendor occurs exclusively inside India.
Indian cybersecurity requirements
BotNira considers applicable Indian cybersecurity requirements as part of its regional security architecture.
CERT-In Directions
The Indian Computer Emergency Response Team (CERT-In) has issued directions under the Information Technology Act addressing cybersecurity incident reporting, logging and related controls for covered entities.
ICT System Logs
Applicable CERT-In requirements include maintaining ICT system logs securely for a rolling period of 180 days within Indian jurisdiction.
Security Incident Response
BotNira maintains a security team responsible for responding to security incidents and coordinating appropriate response activities.
Security Monitoring
BotNira performs regular vulnerability scanning and maintains security controls intended to identify and address potential threats.
Security controls protecting Indian data
BotNira applies multiple technical and organizational safeguards to protect information throughout its lifecycle.
SSL / TLS
Secure encrypted connections protect information during transmission.
Encryption at Rest
Stored information is protected using encryption controls.
Encryption in Transit
Information transmitted between systems is protected using secure communication protocols.
Two-Factor Authentication
Additional authentication controls help protect account access.
Firewall
Network security controls help protect BotNira infrastructure from unauthorized traffic.
DDoS Protection
Distributed denial-of-service protection helps defend infrastructure against malicious traffic.
Database Backups
Regular backups support data resilience and operational recovery.
Vulnerability Scanning
Regular vulnerability scanning is performed to identify potential weaknesses.
Penetration Testing
Penetration testing has been completed as part of BotNira's security program.
Employee Access Controls
BotNira restricts internal team access to customer data. Customer data is not accessible to members of the team as part of ordinary operations.
Incident Response
A dedicated security team is responsible for responding to security incidents.
Data Deletion
Data is permanently deleted following the applicable account closure retention period.
BotNira certifications
BotNira maintains security and compliance certifications supporting its overall trust and security program.
ISO 27001
ISO 27701
SOC 2 Type II
GDPR Compliance
HIPAA
Penetration Testing
Data retention and deletion
While an Indian vendor actively uses BotNira, the vendor can manage and delete its customers' calls, messages and related data using the available BotNira controls.
When a vendor closes its BotNira account, BotNira retains account data for up to 45 days before permanently deleting it.
The retention period provides an operational window for account closure and deletion processes.
Vendors control their customer data
BotNira provides vendors with control over customer communication data handled through their account.
Calls
Vendors can manage and delete applicable call data while actively using BotNira.
Messages
Vendors can manage and delete applicable messaging data through their BotNira account.
Customer Information
Vendors determine how their customer information is managed within their BotNira environment, subject to applicable law.
Account Closure
Following account closure, BotNira retains applicable account data for up to 45 days before permanent deletion.
Know which providers are involved
BotNira identifies the third-party providers involved in communication and AI functionality.
Indian vendors get Indian regional storage
BotNira's regional infrastructure is designed so that Indian vendor data and backups remain within India. External providers are used where required for specific communication or AI functionality.
India data residency questions
Is Indian vendor data stored in India?
Is all processing performed inside India?
Does BotNira use Twilio for Indian phone calls?
Does WhatsApp involve another provider?
Does BotNira use OpenAI?
What happens to my data when I close my account?
Can Indian vendors delete their customer data?
Does India require every type of data processing to occur inside India?
Does BotNira follow the Digital Personal Data Protection framework?
Does BotNira maintain security controls for Indian data?
Who can I contact about data protection?
Customers operating in regulated sectors may have additional requirements imposed by sector-specific regulators, contractual obligations or applicable Indian law.
Security and transparency come first.
Explore BotNira's security controls, compliance documentation, subprocessors and regional data residency commitments.