BotNira Trust Center Visit BotNira.com →
BOTNIRA PRIVACY

Your data. Your privacy. Our responsibility.

BotNira is designed to give businesses control over the information they process through our AI receptionist and communication platform.

We explain what information may be processed, how it moves through BotNira, where it is stored, who may process it, and how it is deleted.

PRIVACY PROGRAM
✓
Privacy Controls Active

Privacy and data protection controls apply throughout the BotNira platform.

Regional storage Enabled
Data encryption Enabled
Vendor deletion 45 days
Privacy contact Available

Privacy is part of how BotNira operates.

BotNira provides AI-powered communication services that may process information belonging to businesses and their customers.

Depending on the features a business uses, this can include voice calls, phone numbers, WhatsApp messages, emails, website conversations, CRM information and account information.

BotNira's privacy approach is based on limiting unnecessary access, protecting information during transmission and storage, using regional storage environments, and deleting applicable information after the defined retention period.

Who controls the information?

BotNira provides technology and infrastructure that businesses use to communicate with their customers.

In many customer deployments, the business using BotNira determines what customer information is collected through its calls, messages, emails, website conversations and workflows.

The business using BotNira is therefore responsible for determining whether its collection and use of customer information complies with the laws and notices applicable to its own business.

Important: BotNira's platform controls do not replace a customer's own privacy obligations. Businesses should configure their BotNira deployment and customer communications appropriately for their industry and jurisdiction.

What information may BotNira process?

The information processed depends on the services, channels and integrations enabled by the business.

Business / Vendor Information

Information associated with the business using BotNira, including account, contact, configuration and service information.

Customer Contact Information

Information provided by or about a business's customers, such as names, telephone numbers, email addresses and other information included in conversations.

Voice & Call Information

Information associated with calls handled through BotNira, including telephone numbers, call content and applicable call metadata.

WhatsApp Information

When WhatsApp is used, messages and related information are transmitted through the WhatsApp/Meta communication infrastructure before applicable processing by BotNira.

Email Information

Emails sent through supported BotNira workflows may contain sender, recipient, message and related communication information.

Website Chat Information

Conversations submitted through a BotNira website chat interface may be processed by BotNira to provide the requested service.

CRM & Integration Information

Information transferred through customer-enabled CRM or other integrations may be processed to provide the requested workflow.

Account & Billing Information

BotNira may process information necessary to administer accounts, subscriptions, billing and service relationships.

Technical Information

Technical information may be processed to operate, secure, monitor and maintain the BotNira platform.

Privacy across every communication channel.

Different communication channels can involve different infrastructure providers.

01
PHONE

Voice Calls

For phone calls, the communication path can involve the customer's telephone network, Twilio, BotNira and applicable AI processing.

Customer → Twilio → BotNira → AI → BotNira
02
WHATSAPP

WhatsApp

WhatsApp communications involve Meta's WhatsApp infrastructure. Applicable messages are then processed by BotNira according to the enabled workflow.

Customer → WhatsApp / Meta → BotNira → AI
03
EMAIL

Email

Supported email communications are processed through BotNira's email functionality without a separate communication provider being used as part of the normal BotNira email workflow.

Customer → BotNira → AI / Workflow
04
WEBSITE

Website Chat

Website chat conversations are handled by BotNira and applicable AI processing services. No separate third-party communication provider is used for the normal website chat flow.

Visitor → BotNira → AI / Workflow

Why does BotNira process information?

Information is processed to provide, secure, maintain and improve the services enabled by the business.

Service Delivery

To receive, route, process and respond to communications handled through BotNira.

AI Processing

To generate AI-powered responses, speech processing and conversational functionality where enabled.

CRM & Automation

To perform workflows and transfer information into customer-enabled integrations.

Security

To detect, investigate and respond to security threats and protect the platform.

Account Management

To maintain accounts, subscriptions, configurations and customer relationships.

Legal & Compliance

Where necessary, information may be processed to meet applicable legal, regulatory or security obligations.

How AI processing works.

BotNira uses OpenAI business/API services for applicable AI-powered processing.

Depending on the feature being used, relevant conversation information may be sent to the applicable AI service so that BotNira can generate or process a response.

AI processing is separate from BotNira's regional storage architecture. In particular, applicable AI processing may occur outside the customer's data-residency country.

Important: Regional data residency describes where BotNira stores and backs up applicable vendor data. It does not mean that every processing activity, including third-party AI processing, necessarily occurs inside that same country or region.

Learn more about BotNira AI processing →

Your data stays in its regional BotNira environment.

BotNira provides regional storage environments for vendors using the service in supported countries and regions.

🇨🇦 Canada

Canadian vendor data is stored and backed up in the Canadian regional environment.

Canada Data Residency →

🇺🇸 United States

U.S. vendor data is stored and backed up in the U.S. regional environment.

United States Data Residency →

🇪🇺 Europe

European vendor data is stored and backed up in the European regional environment.

Europe Data Residency →

🇬🇧 United Kingdom

UK vendor data is stored and backed up in the UK regional environment.

UK Data Residency →

🇦🇺 Australia

Australian vendor data is stored and backed up in the Australian regional environment.

Australia Data Residency →

🇮🇳 India

Indian vendor data is stored and backed up in the Indian regional environment.

India Data Residency →

Transparency about providers.

Some BotNira functionality depends on third-party infrastructure providers. We identify their role so customers can understand the data flow.

Twilio

Used for applicable telephone connectivity. Twilio acts as the communications bridge between the customer's telephone network and BotNira's services.

Meta / WhatsApp

Used when a business enables WhatsApp communication. WhatsApp/Meta provides the underlying WhatsApp communication infrastructure.

OpenAI

Used for applicable AI-powered processing. Information required for the AI function may be transmitted to OpenAI for processing.

How long does BotNira keep your data?

While a vendor actively uses BotNira, the vendor can manage and delete its customer calls, messages and related information using available BotNira functionality.

When the vendor stops using BotNira and closes its account, applicable data is retained for 45 days .

After the 45-day period, applicable retained data is permanently deleted.

Retention principle: BotNira does not retain vendor data indefinitely after account closure.

Businesses control their customer data.

BotNira provides businesses with control over information handled through their account.

01
CONTROL

Delete

While an account remains active, vendors can delete customer calls, messages and related information using available functionality.

02
CONTROL

Manage

Vendors determine how their BotNira workflows interact with their customer communications and integrations.

03
CONTROL

Close

When an account is closed, applicable retained data is subject to the 45-day deletion process.

Privacy rights depend on where you live.

Different privacy laws provide different rights. The rights available to an individual depend on the applicable law and circumstances.

🇪🇺 European Union / EEA

Where the GDPR applies, individuals may have rights including access, rectification, erasure, restriction, portability and objection, subject to applicable conditions and exceptions.

EU Data Residency →

🇬🇧 United Kingdom

Where the UK GDPR applies, individuals may have rights including being informed, access, rectification, erasure, restriction, portability and objection, subject to applicable conditions.

UK Data Residency →

🇨🇦 Canada

Depending on the organization and circumstances, Canadian privacy laws such as PIPEDA may apply. PIPEDA includes principles covering accountability, consent, limiting collection, safeguards, access and challenging compliance.

Canada Data Residency →

🇦🇺 Australia

Australian privacy requirements can depend on the Privacy Act and applicable Australian Privacy Principles, as well as the organization and circumstances involved.

Australia Data Residency →

🇮🇳 India

Indian privacy requirements may apply depending on the nature of the processing, organization and applicable law.

India Data Residency →

🇺🇸 United States

U.S. privacy requirements vary by federal, state and sector-specific laws. Businesses should evaluate which requirements apply to their particular activities.

U.S. Data Residency →

European privacy rights

Where the GDPR applies, individuals have important rights regarding their personal information.

  • Right to be informed
  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object

These rights are subject to the conditions, limitations and exceptions established by applicable law. :contentReference[oaicite:1]{index=1}

Canadian privacy principles

PIPEDA establishes ten fair information principles for organizations subject to the legislation, including accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, safeguards, openness, access and challenging compliance. :contentReference[oaicite:2]{index=2}

BotNira's privacy and security controls are designed to support responsible handling of information, including security safeguards, transparency, access controls and controlled retention.

Important: Canadian privacy requirements can differ depending on the organization, province, industry and type of activity. Customers remain responsible for determining the laws applicable to their own business.

Privacy and security work together.

Privacy controls are supported by BotNira's broader technical security program.

Encryption

Data is protected using encryption controls in transit and at rest.

Restricted Access

BotNira team members do not have ordinary access to customer data.

2FA

Two-factor authentication provides additional protection for supported accounts.

Vulnerability Scanning

Regular vulnerability scanning forms part of the security program.

Penetration Testing

Penetration testing has been completed.

Incident Response

A security team is responsible for responding to security incidents.

Services are designed for businesses.

BotNira is a business-to-business service and is not designed to knowingly collect personal information directly from children as its primary audience.

Businesses using BotNira are responsible for configuring their customer-facing workflows appropriately for the audiences they serve and for complying with applicable requirements concerning children's information.

Transparency about third-party processing.

Some BotNira services require third-party infrastructure providers. We maintain a dedicated subprocessor page.

Twilio

Telephone connectivity for applicable voice services.

Meta / WhatsApp

WhatsApp communication infrastructure when WhatsApp functionality is enabled.

OpenAI

AI processing for applicable BotNira AI-powered services.

@

Have a privacy question or request?

Contact the BotNira privacy contact for privacy-related questions, requests or concerns.

Privacy Contact
kamal@botnira.com

When submitting a request, please provide enough information for BotNira to understand the request and verify the relevant account or relationship where necessary.

Frequently asked privacy questions

Where is my BotNira data stored?
BotNira uses regional environments. Vendor data is stored and backed up in the applicable regional environment.
Does regional storage mean all processing happens in the same country?
No. Regional storage describes where applicable vendor data is stored and backed up. Certain processing activities, including applicable AI processing through OpenAI, may occur outside the customer's storage region.
Does BotNira use OpenAI?
Yes. BotNira uses OpenAI business/API services for applicable AI-powered processing.
Does BotNira use Twilio?
Yes. Twilio is used for applicable telephone connectivity and acts as a communications bridge for supported voice services.
Does BotNira use Meta?
Meta/WhatsApp is involved when a business uses BotNira's WhatsApp functionality.
Can I delete my customer data?
While the vendor account is active, the vendor can manage and delete applicable customer calls, messages and related data using available BotNira functionality.
What happens when I close my BotNira account?
Applicable data is retained for 45 days after account closure and then permanently deleted.
Can BotNira employees see my customer data?
BotNira team members do not have ordinary access to customer data as part of normal operations.
How do I submit a privacy request?
Does BotNira automatically make my business compliant with privacy laws?
No. BotNira provides technical, organizational and privacy controls, but each business remains responsible for determining and meeting the privacy obligations applicable to its own activities, customers and industry.
✓

Collect what is needed. Protect it. Delete it when it is no longer required.

BotNira's privacy approach is built around transparency, security, regional storage, customer control and defined retention.

Privacy information: This page provides general information about BotNira's privacy and data-processing practices. It is not legal advice and does not replace the privacy notice, contractual terms or other legal documentation applicable to a particular customer.

Privacy obligations vary by jurisdiction, industry, organization and processing activity. Customers should obtain appropriate legal advice when determining which requirements apply to their business.

Privacy you can understand.

Explore BotNira's security controls, regional data residency, AI processing and subprocessors.

Have a security or compliance question?

Our team can help with security documentation, compliance information, data residency questions, enterprise reviews and security questionnaires.