BotNira Trust Center Visit BotNira.com β†’
πŸ‡ΊπŸ‡Έ UNITED STATES

United States
Data Residency

BotNira maintains country-specific infrastructure for supported markets. Data belonging to United States vendors is stored and backed up within the United States.

UNITED STATES ENVIRONMENT
πŸ‡ΊπŸ‡Έ
US Data Residency

Storage & backups

Primary storage United States
Backup storage United States
AI processing OpenAI*
Voice transport Twilio
βœ“

US vendor data stays in the US.

Every business that signs up with BotNira is associated with a regional environment. For United States vendors, BotNira stores customer, business and operational data within the United States. Backups for the US environment are also maintained within the United States.

This country-specific architecture is applied across BotNira's supported markets so that data can remain within the vendor's designated country or region.

How data moves through BotNira.

BotNira separates communication transport, application processing, AI processing and regional storage.

01 Customer Voice / Message
β†’
02 Communication Provider Twilio / Meta*
β†’
03 BotNira Application Layer
β†’
04 OpenAI* AI Processing
β†’
05 BotNira Application Layer
β†’
06 US Storage US Backup
Important: The exact providers and processing stages depend on the communication channel and BotNira feature being used. AI processing occurs only where required by the applicable BotNira functionality.

Every communication channel has a defined path.

See which providers participate in each BotNira communication channel and where BotNira stores the resulting data.

☎
VOICE

Phone Calls

Customer β†’ Twilio β†’ BotNira β†’ OpenAI* β†’ BotNira β†’ US Storage
TRANSPORT Twilio
AI OpenAI*
STORAGE USA

Twilio provides the telecommunications transport layer. BotNira manages the application and conversation layer and uses OpenAI API services where AI processing is required.

β—‡
MESSAGING

WhatsApp

Customer β†’ Meta / WhatsApp β†’ BotNira β†’ OpenAI* β†’ BotNira β†’ US Storage
TRANSPORT Meta / WhatsApp
AI OpenAI*
STORAGE USA

WhatsApp provides the messaging transport layer. Once the communication reaches BotNira, BotNira manages the application and conversation layer. Applicable content may be sent to OpenAI when AI processing is required.

@
MESSAGING

Email

Customer β†’ BotNira β†’ OpenAI* β†’ BotNira β†’ US Storage
APPLICATION BotNira
AI OpenAI*
STORAGE USA

Email communications are managed through BotNira. Where AI functionality is required, relevant content may be processed through OpenAI.

β—Œ
WEB

Website Chat

Visitor β†’ BotNira β†’ OpenAI* β†’ BotNira β†’ US Storage
APPLICATION BotNira
AI OpenAI*
STORAGE USA

Website chat connects directly with BotNira's application layer. AI processing is performed through OpenAI when required by the configured BotNira functionality.

#
MESSAGING

SMS

Customer β†’ Twilio β†’ BotNira β†’ OpenAI* β†’ BotNira β†’ US Storage
TRANSPORT Twilio
AI OpenAI*
STORAGE USA

Twilio provides SMS transport. BotNira manages the application layer and applicable AI processing, with resulting BotNira data stored in the US environment.

* AI processing BotNira uses OpenAI API/business services for applicable AI functionality. The exact information submitted for processing depends on the feature being used and the customer's configuration.

Clear visibility into external providers.

Some BotNira communication channels require specialized third-party infrastructure. BotNira identifies those providers rather than treating the entire data path as a single system.

01

Twilio

Voice & SMS transport

Twilio provides telecommunications infrastructure used to transport applicable voice calls and SMS communications between customers and BotNira.

02

Meta / WhatsApp

WhatsApp transport

Meta / WhatsApp provides the communication infrastructure for WhatsApp messages before they reach the BotNira application layer.

03

OpenAI

AI processing

OpenAI API/business services are used for applicable AI processing. The processing location depends on the applicable OpenAI service, endpoint and BotNira configuration.

Regional processing

BotNira's US environment is designed to keep BotNira-retained customer and vendor data in the United States. Third-party services may have their own processing infrastructure and terms. Customers should review the applicable provider documentation for the services they use.

Compliance depends on the data and the business.

The United States does not have one single comprehensive private-sector privacy law covering every organization and every type of information. Requirements can depend on the customer's state, industry, business activities and the type of data being processed.

FEDERAL

FTC Privacy & Security

BotNira maintains security and privacy controls designed to protect information and support accurate representations about how information is handled.

HEALTHCARE

HIPAA / HITECH

HIPAA requirements may apply when BotNira acts as a business associate or otherwise handles protected health information within a regulated relationship.

FINANCIAL

GLBA

Financial institutions covered by the Gramm-Leach- Bliley Act may have additional requirements for protecting customer information and managing service providers.

STATE

State Privacy Laws

Applicable state privacy requirements may include consumer rights, transparency, data minimization, contracts, security and other obligations.

US state privacy landscape.

BotNira's customers may be subject to state-specific privacy requirements depending on their location, business activities, revenue, data practices and applicable statutory thresholds.

California CCPA / CPRA
Colorado Colorado Privacy Act
Connecticut CTDPA
Virginia VCDPA
Utah UCPA
Texas TDPSA
Oregon OCPA
Montana MCDPA
Delaware Delaware PDPA
New Jersey NJDPA
New Hampshire NH Privacy Law
Kentucky KCDPA
Maryland MODPA
Minnesota MNCDPA
Indiana ICDPA
Tennessee TIPA
Nebraska Nebraska Privacy Act
Rhode Island RI Privacy Framework
+

HIPAA

HIPAA security and compliance posture

BotNira maintains HIPAA-related compliance documentation and security controls designed to support environments where healthcare data may be subject to applicable regulatory requirements.

HIPAA applicability depends on the relationship between the parties and whether protected health information is being created, received, maintained or transmitted on behalf of a covered entity or business associate.

Important HIPAA notice

BotNira does not currently provide or execute a Business Associate Agreement as part of standard customer onboarding.

Customers that require a BAA should contact BotNira before transmitting or processing Protected Health Information through the platform.

GLBA & financial data

The Gramm-Leach-Bliley Act and the FTC Safeguards Rule can apply to covered financial institutions. Covered organizations have obligations concerning the protection of customer information and the oversight of service providers.

BotNira's security controls are designed to support customers that operate in security-sensitive environments. Whether a particular GLBA obligation applies depends on the customer's status and activities.

BotNira does not represent that every customer is a covered financial institution under GLBA.

Security controls across the US environment.

BotNira applies technical, organizational and operational safeguards designed to protect data.

01

SSL / TLS

Secure transport encryption protects communications with BotNira services.

02

Encryption at Rest

Stored information is protected using encryption mechanisms appropriate to the underlying systems.

03

Encryption in Transit

Data transmitted between supported services and systems is protected during transfer.

04

Two-Factor Authentication

Two-factor authentication provides an additional security layer for supported accounts.

05

Firewall Protection

Network security controls help protect BotNira infrastructure from unauthorized traffic.

06

DDoS Protection

Infrastructure protections help mitigate distributed denial-of-service attacks.

07

Regular Backups

Regular backups support operational resilience and recovery.

08

Vulnerability Scanning

Regular vulnerability scanning is performed to identify potential security weaknesses.

09

Penetration Testing

Penetration testing has been performed to assess the security of the BotNira environment.

10

Restricted Team Access

BotNira customer data is not accessible to development or operational team members as part of routine operations.

11

Security Response

A dedicated security team is responsible for responding to security incidents and potential security events.

12

Data Deletion

Following account closure, applicable customer data is retained for 45 days and then permanently deleted.

Clear data lifecycle after account closure.

BotNira follows a defined service-level data lifecycle for customer accounts.

01 Active Account

The vendor continues using BotNira.

02 Account Closure

The vendor stops using the BotNira service.

03 45-Day Period

Applicable data remains available during the account-closure transition period.

04 Permanent Deletion

Applicable customer data is permanently deleted.

Retention principle The 45-day post-closure period is BotNira's service lifecycle policy. Applicable legal, regulatory or contractual requirements may affect the handling of particular information.

Customer control and data lifecycle.

During an active BotNira subscription, vendors can manage and delete applicable customer data, including calls and messages, according to the controls available within the BotNira platform.

BotNira retains applicable account data while the vendor uses the service. When the vendor closes the account, the 45-day post-closure lifecycle begins.

At the end of the applicable 45-day period, BotNira permanently deletes the applicable customer data.

Frequently asked questions.

Is US vendor data stored in the United States?
Yes. BotNira's US vendor environment stores BotNira-retained customer, business and operational data within the United States. Backups for US vendor environments are also maintained within the United States.
Does BotNira use third-party providers?
Yes. Depending on the communication channel, BotNira uses Twilio for voice and SMS transport, Meta / WhatsApp for WhatsApp transport, and OpenAI API/business services for applicable AI processing.
Does BotNira use OpenAI?
Yes. BotNira uses OpenAI API/business services for applicable AI functionality. The exact information processed depends on the BotNira feature and configuration.
Does all processing happen in the United States?
BotNira stores and backs up its US vendor data in the United States. Third-party providers may have separate infrastructure and processing locations. AI processing through OpenAI depends on the applicable OpenAI service, endpoint and configuration.
Is BotNira HIPAA compliant?
BotNira maintains HIPAA-related compliance documentation and security controls. However, BotNira does not currently execute Business Associate Agreements as part of standard customer onboarding. Customers requiring a BAA should contact BotNira before processing Protected Health Information through the service.
Does GLBA apply to every BotNira customer?
No. GLBA requirements apply to covered financial institutions and related circumstances. Whether GLBA applies depends on the customer's business, activities and regulatory status.
How long does BotNira keep data after account closure?
BotNira retains applicable data for 45 days after account closure and then permanently deletes the applicable customer data.
Can a vendor delete customer data while using BotNira?
Vendors can manage and delete applicable customer data, including calls and messages, using the controls available within the BotNira platform.

Need more information about BotNira security?

Security, privacy and compliance questions can be reviewed with the BotNira team before deployment.

Contact BotNira

Have a security or compliance question?

Our team can help with security documentation, compliance information, data residency questions, enterprise reviews and security questionnaires.