United States
Data Residency
BotNira maintains country-specific infrastructure for supported markets. Data belonging to United States vendors is stored and backed up within the United States.
Storage & backups
US vendor data stays in the US.
Every business that signs up with BotNira is associated with a regional environment. For United States vendors, BotNira stores customer, business and operational data within the United States. Backups for the US environment are also maintained within the United States.
This country-specific architecture is applied across BotNira's supported markets so that data can remain within the vendor's designated country or region.
How data moves through BotNira.
BotNira separates communication transport, application processing, AI processing and regional storage.
Every communication channel has a defined path.
See which providers participate in each BotNira communication channel and where BotNira stores the resulting data.
Phone Calls
Twilio provides the telecommunications transport layer. BotNira manages the application and conversation layer and uses OpenAI API services where AI processing is required.
WhatsApp provides the messaging transport layer. Once the communication reaches BotNira, BotNira manages the application and conversation layer. Applicable content may be sent to OpenAI when AI processing is required.
Email communications are managed through BotNira. Where AI functionality is required, relevant content may be processed through OpenAI.
Website Chat
Website chat connects directly with BotNira's application layer. AI processing is performed through OpenAI when required by the configured BotNira functionality.
SMS
Twilio provides SMS transport. BotNira manages the application layer and applicable AI processing, with resulting BotNira data stored in the US environment.
Clear visibility into external providers.
Some BotNira communication channels require specialized third-party infrastructure. BotNira identifies those providers rather than treating the entire data path as a single system.
Twilio
Voice & SMS transportTwilio provides telecommunications infrastructure used to transport applicable voice calls and SMS communications between customers and BotNira.
Meta / WhatsApp
WhatsApp transportMeta / WhatsApp provides the communication infrastructure for WhatsApp messages before they reach the BotNira application layer.
OpenAI
AI processingOpenAI API/business services are used for applicable AI processing. The processing location depends on the applicable OpenAI service, endpoint and BotNira configuration.
BotNira's US environment is designed to keep BotNira-retained customer and vendor data in the United States. Third-party services may have their own processing infrastructure and terms. Customers should review the applicable provider documentation for the services they use.
Compliance depends on the data and the business.
The United States does not have one single comprehensive private-sector privacy law covering every organization and every type of information. Requirements can depend on the customer's state, industry, business activities and the type of data being processed.
FTC Privacy & Security
BotNira maintains security and privacy controls designed to protect information and support accurate representations about how information is handled.
HIPAA / HITECH
HIPAA requirements may apply when BotNira acts as a business associate or otherwise handles protected health information within a regulated relationship.
GLBA
Financial institutions covered by the Gramm-Leach- Bliley Act may have additional requirements for protecting customer information and managing service providers.
State Privacy Laws
Applicable state privacy requirements may include consumer rights, transparency, data minimization, contracts, security and other obligations.
US state privacy landscape.
BotNira's customers may be subject to state-specific privacy requirements depending on their location, business activities, revenue, data practices and applicable statutory thresholds.
Listing a state law does not mean that every BotNira customer is subject to that law. Applicability depends on the customer's business, location, data practices and the relevant statutory thresholds and exemptions. Customers should obtain appropriate legal advice for their specific obligations.
HIPAA
HIPAA security and compliance posture
BotNira maintains HIPAA-related compliance documentation and security controls designed to support environments where healthcare data may be subject to applicable regulatory requirements.
HIPAA applicability depends on the relationship between the parties and whether protected health information is being created, received, maintained or transmitted on behalf of a covered entity or business associate.
BotNira does not currently provide or execute a Business Associate Agreement as part of standard customer onboarding.
Customers that require a BAA should contact BotNira before transmitting or processing Protected Health Information through the platform.
GLBA & financial data
The Gramm-Leach-Bliley Act and the FTC Safeguards Rule can apply to covered financial institutions. Covered organizations have obligations concerning the protection of customer information and the oversight of service providers.
BotNira's security controls are designed to support customers that operate in security-sensitive environments. Whether a particular GLBA obligation applies depends on the customer's status and activities.
Security controls across the US environment.
BotNira applies technical, organizational and operational safeguards designed to protect data.
SSL / TLS
Secure transport encryption protects communications with BotNira services.
Encryption at Rest
Stored information is protected using encryption mechanisms appropriate to the underlying systems.
Encryption in Transit
Data transmitted between supported services and systems is protected during transfer.
Two-Factor Authentication
Two-factor authentication provides an additional security layer for supported accounts.
Firewall Protection
Network security controls help protect BotNira infrastructure from unauthorized traffic.
DDoS Protection
Infrastructure protections help mitigate distributed denial-of-service attacks.
Regular Backups
Regular backups support operational resilience and recovery.
Vulnerability Scanning
Regular vulnerability scanning is performed to identify potential security weaknesses.
Penetration Testing
Penetration testing has been performed to assess the security of the BotNira environment.
Restricted Team Access
BotNira customer data is not accessible to development or operational team members as part of routine operations.
Security Response
A dedicated security team is responsible for responding to security incidents and potential security events.
Data Deletion
Following account closure, applicable customer data is retained for 45 days and then permanently deleted.
Clear data lifecycle after account closure.
BotNira follows a defined service-level data lifecycle for customer accounts.
The vendor continues using BotNira.
The vendor stops using the BotNira service.
Applicable data remains available during the account-closure transition period.
Applicable customer data is permanently deleted.
Security and compliance evidence.
BotNira maintains security, privacy and compliance documentation that can support customer security and procurement reviews.
SOC 2 Type II
Independent assessment of applicable controls relating to security and trust services.
View document βISO/IEC 27001
Information security management certification for BotNira.
View document βISO/IEC 27701
Privacy information management certification for BotNira.
View document βGDPR Compliance
Documentation supporting BotNira's GDPR compliance posture.
View document βHIPAA Compliance
HIPAA-related compliance documentation and security controls.
View document βPenetration Testing
Security testing performed to identify potential vulnerabilities.
View document βCustomer control and data lifecycle.
During an active BotNira subscription, vendors can manage and delete applicable customer data, including calls and messages, according to the controls available within the BotNira platform.
BotNira retains applicable account data while the vendor uses the service. When the vendor closes the account, the 45-day post-closure lifecycle begins.
At the end of the applicable 45-day period, BotNira permanently deletes the applicable customer data.
Frequently asked questions.
Is US vendor data stored in the United States?
Does BotNira use third-party providers?
Does BotNira use OpenAI?
Does all processing happen in the United States?
Is BotNira HIPAA compliant?
Does GLBA apply to every BotNira customer?
How long does BotNira keep data after account closure?
Can a vendor delete customer data while using BotNira?
Need more information about BotNira security?
Security, privacy and compliance questions can be reviewed with the BotNira team before deployment.
Contact BotNira