BotNira Trust Center Visit BotNira.com →
UNITED KINGDOM

UK Data Residency

BotNira is designed to keep UK vendor and customer data within the United Kingdom while providing AI-powered voice and communication services.

UK DATA RESIDENCY
🇬🇧
UK Region

Customer data is stored in the UK.

Primary storage United Kingdom
Backups United Kingdom
AI processing OpenAI
Phone provider Twilio

UK data stays in the UK

When a business located in the United Kingdom signs up for BotNira, that business is treated as a UK vendor for data-residency purposes.

BotNira stores and backs up the vendor's BotNira data in the United Kingdom. This includes business information and customer information handled through the BotNira platform.

BotNira maintains separate regional infrastructure so that customer data can be stored in the region associated with the vendor.

How UK data moves through BotNira

BotNira separates regional storage from the external services used for specific communication and AI functionality.

☎
VOICE

Phone Calls

Customer → Twilio → BotNira → OpenAI
TELEPHONY PROVIDER Twilio

Twilio provides telephone connectivity and acts as the communication bridge between the customer's telephone network and BotNira.

AI PROCESSING OpenAI

Speech and AI processing may be performed through OpenAI services.

◉
MESSAGING

WhatsApp

Customer → Meta → BotNira → OpenAI
MESSAGING PROVIDER Meta / WhatsApp

WhatsApp provides the messaging infrastructure used to transmit messages between customers and BotNira.

AI PROCESSING OpenAI

Where AI processing is required, relevant message content may be processed through OpenAI services.

@
MESSAGING

Email

Customer → BotNira → OpenAI*
PLATFORM BotNira

Email communication is handled directly through BotNira infrastructure.

AI PROCESSING OpenAI*

OpenAI may be involved when an AI-powered feature requires processing of email content.

◇
WEB

Website Chat

Customer → BotNira → OpenAI*
PLATFORM BotNira

Website chat is provided and managed directly by BotNira without a separate messaging intermediary.

AI PROCESSING OpenAI*

OpenAI may process content when an AI-powered feature requires it.

* AI processing: OpenAI is used as an AI service provider for applicable BotNira AI functionality. BotNira remains responsible for the overall application, data handling and regional storage environment.

Designed around UK data protection requirements

BotNira's UK data-residency approach is designed to support businesses handling personal information under the UK data protection framework.

APPLIED

UK GDPR

BotNira's privacy and security architecture is designed to support the requirements applicable to UK personal data.

APPLIED

Data Protection Act 2018

UK data protection obligations are considered as part of BotNira's approach to UK customer data.

APPLIED

Data Security

Technical security controls are used to protect data against unauthorized access, loss, misuse and other security threats.

APPLIED

Data Retention

Vendors control retention of their customer data while using BotNira, subject to BotNira's account closure and deletion policy.

UK storage does not mean every processing operation occurs in the UK

BotNira's UK regional infrastructure is used for storage and backups of UK vendor data.

Certain BotNira AI functionality requires processing through OpenAI services. This means that relevant information may be processed outside the UK when that functionality is used.

UK data protection rules contain specific requirements for restricted international transfers. The applicable transfer mechanism depends on the destination, recipient and circumstances of the transfer.

BotNira therefore distinguishes between the location where customer data is stored and the location where a particular AI processing operation may occur.

Security controls protecting UK data

BotNira applies multiple technical and organizational safeguards to protect information throughout its lifecycle.

SSL / TLS

Secure encrypted connections are used to protect information during transmission.

Encryption at Rest

Stored data is protected using encryption controls.

Encryption in Transit

Data transmitted between systems is protected using secure communication protocols.

Two-Factor Authentication

Additional authentication controls help protect account access.

Firewall & DDoS Protection

Network security controls help protect BotNira infrastructure from malicious traffic.

Vulnerability Scanning

Regular vulnerability scanning is performed to identify potential security weaknesses.

Penetration Testing

Penetration testing has been completed as part of BotNira's security program.

Incident Response

A dedicated security team is responsible for responding to security incidents.

BotNira certifications

BotNira maintains security and compliance certifications supporting its overall trust and security program.

BotNira ISO 27001 certification

ISO 27001

BotNira ISO 27701 certification

ISO 27701

BotNira SOC 2 Type II certification

SOC 2 Type II

BotNira GDPR compliance certification

GDPR Compliance

BotNira HIPAA compliance certification

HIPAA

BotNira penetration testing certificate

Penetration Testing

Important: Certifications and security assessments reflect BotNira's security and compliance program. Individual customer requirements, contractual obligations and regulated-data requirements may require additional agreements or controls.

Your data remains under your control

While a vendor actively uses BotNira, the vendor can manage and delete its customers' calls, messages and related data through the available BotNira controls.

When a vendor closes its BotNira account, BotNira retains the account data for up to 45 days before permanently deleting it.

This retention period provides an operational window for account closure and data deletion processes.

Understand our service providers

BotNira maintains transparency about third-party providers involved in communication and AI functionality.

✓

UK customers get UK regional storage

BotNira's regional infrastructure is designed so that UK vendor data and backups remain within the United Kingdom. External providers are used only where required for specific communication or AI functionality.

UK data residency questions

Is UK customer data stored in the UK?
Yes. UK vendors are assigned to BotNira's UK regional infrastructure, where their data and backups are stored.
Is AI processing also performed in the UK?
Not necessarily. BotNira uses OpenAI for applicable AI functionality. Relevant data may therefore be processed outside the UK when AI processing is required.
Does BotNira use Twilio for UK phone calls?
Yes. Twilio provides telephone connectivity and acts as the communication bridge between the customer's telephone network and BotNira.
What happens to my data when I close my account?
BotNira retains account data for up to 45 days after account closure and then permanently deletes it.
Can vendors delete their customers' data?
Yes. While actively using BotNira, vendors can manage and delete their customers' calls, messages and related data according to the controls available within their BotNira account.
Does UK GDPR apply to international processing?
UK GDPR contains specific rules for restricted international transfers. Where those rules apply, the transfer must be covered by an applicable adequacy regulation, appropriate safeguard or applicable exception.

Security and transparency come first.

Explore BotNira's security controls, compliance documentation, subprocessors and regional data residency commitments.

Have a security or compliance question?

Our team can help with security documentation, compliance information, data residency questions, enterprise reviews and security questionnaires.