Data Processing Agreement & framework.
BotNira is developing its formal jurisdiction-specific data processing framework for business customers.
This page explains the current framework, responsibilities and the work underway to formalize additional contractual protections.
Formal contractual framework currently being developed.
We are actively working on a formal DPA framework and jurisdiction-specific contractual documentation. Our current objective is to complete this compliance enhancement program within the next two months.
How BotNira approaches customer data processing.
BotNira is designed around clear responsibilities between the business using the platform and BotNira as the service provider.
Customer as Business Controller
Depending on the relationship and applicable law, the business using BotNira generally determines why and how its customer data is processed.
BotNira as Service Provider
BotNira processes information as necessary to provide the configured communication, automation, AI and integration services.
Purpose Limitation
Customer information is processed to provide the services and functions configured by the customer, subject to applicable law and contractual requirements.
Security
BotNira applies technical and organizational safeguards designed to protect customer data.
Regional Storage
BotNira maintains regional storage and backup environments for supported service regions.
Subprocessors
Third-party providers involved in applicable processing are disclosed through the BotNira Subprocessors page.
Types of processing performed by BotNira.
Voice
BotNira may process calls, transcripts and related information required to provide AI-powered voice services.
WhatsApp communications may involve Meta as the communication provider before information is processed by BotNira.
Email communications may be processed by BotNira according to the configured workflow.
Website Chat
Website chat information can be processed directly through BotNira's platform and applicable AI services.
AI Processing
Applicable AI functionality may involve OpenAI API/business services.
CRM & Integrations
Information may be transferred to customer configured integrations when required to perform an authorized workflow.
Data protection controls.
Encryption in Transit
Data transmitted through applicable BotNira services is protected using encryption in transit.
Encryption at Rest
Applicable stored information is protected using encryption at rest.
2FA
Two-factor authentication is included among BotNira security controls.
Firewall & DDoS Protection
Infrastructure security includes firewall and DDoS protection controls.
Vulnerability Scanning
Regular vulnerability scanning is performed.
Penetration Testing
BotNira has completed penetration testing.
Customer data retention.
While a vendor continues using BotNira, applicable customer data may be retained according to the vendor's configured use of the platform.
Vendors can manage or delete applicable customer calls and messages through their BotNira environment where those controls are available.
When a vendor stops using BotNira and closes its account, BotNira retains applicable data for 45 days and then permanently deletes it, subject to applicable legal or contractual requirements.
Building a broader global data-processing framework.
BotNira is actively working to formalize additional data-processing agreements, jurisdiction-specific contractual terms and supporting documentation.
Our current objective is to complete the current legal and compliance enhancement program within the next two months.
This work includes reviewing applicable requirements across the jurisdictions where BotNira provides services and updating our documentation and contractual processes accordingly.
Need a DPA or data-processing information?
Contact our data protection team.
kamal@botnira.com
Where a formal DPA or other data-processing agreement is required, customers should contact BotNira to discuss the applicable contractual process.
Data protection is an ongoing commitment.
We continue to strengthen BotNira's legal, privacy and compliance framework.