Privacy Policy

Effective Date: September 9, 2026
Last Updated: September 9, 2026
Version: 2

Bot B2B, Inc. ("BotB2B", "we", "us", "our"), a corporation organized under the laws of the State of Delaware, United States with its registered address at 131 Continental Dr, Suite 305, Newark, DE 19713, USA, operates the website https://botb2b.ai (the "Website") and the BotB2B platform at https://app.botb2b.ai and related apps, APIs and bots (together with the Website, the "Services"). This Privacy Policy explains how we collect, use, disclose and protect personal information, and the rights you have. Capitalized terms not defined here have the meanings given in our Terms of Service.

Summary (not part of the policy). We collect what we need to run a business software platform: your account and billing details, your usage, and the content you and your team put into the platform. We do not sell personal information and we do not train shared AI models on your content; advertising tags on our website and in the app only measure our own campaigns and can be switched off. Your customers' and employees' data inside your workspace belongs to you; we process it only on your instructions. Data is hosted in the EU today and processed by AI providers mainly in the United States under contracts that prohibit training and limit retention. You can access, correct, export and delete your data.

1. Who this policy covers, and our role

We act in two different roles:

(a) As a controller (or "business") for the personal information of:

  • visitors to the Website;
  • people who register for the Services, including Workspace Owners and Members ("Account holders");
  • people who contact us, subscribe to our communications, or take part in our partner and referral programs;
  • representatives of our customers, suppliers and partners.

For these people, this policy is the complete description of our processing.

(b) As a processor (or "service provider") for personal information that our customers put into their Workspaces or collect through the Services: the messages, contact details and records of their End Users, and the work reports and profiles of their Members and employees ("Customer Data"). We process Customer Data only on the instructions of the customer under our Terms of Service and Data Processing Addendum. If you are an End User of one of our customers (for example you chatted with a company's bot) or an employee of a customer, the customer is responsible for your data and for answering your requests; please contact that company first. Sections 2 to 6 of this policy describe our own processing; Section 10 explains what we do with Customer Data.

2. Personal information we collect

2.1 Information you give us

  • Account data: name, email address, phone number (if you provide it), password (stored as a hash), organization name, role, language, time zone, profile picture (optional), and the identifiers of any social or messenger sign-in you use (for example your Telegram ID).
  • Billing data: billing name and address, country, tax identification number (if you enter one), the last four digits, brand and expiry of your payment card (full card details are collected and stored by our payment processor Stripe, not by us), payment and refund history, and invoices.
  • Communications: messages you send to our support, sales or abuse teams, including attachments, and your responses to surveys.
  • Marketing preferences: your choice to receive or not receive product news, and the record of that choice.
  • Partner and referral data: if you join our partner program, your payout details and the statistics of the customers you referred.
  • Legal records: your acceptance of our Terms and other documents (version, time, IP address, browser, and how you accepted).

2.2 Information collected automatically

  • Usage data: the features you use, actions you take in the Services, Bots and AI Managers you create, Token consumption (including which AI Model handled each request), timestamps, and error reports.
  • Device and connection data: IP address, browser and operating system, device identifiers, screen size, language, referring pages, and approximate location derived from the IP address.
  • Cookies and similar technologies: as described in our Cookie Policy, including product analytics (Amplitude), web analytics (Google Analytics) and advertising measurement and remarketing tags (Google Ads, Meta Pixel and Conversions API) on the Website, and the Meta Pixel in the App to measure sign-ups and purchases that came from our ads. Advertising tags load only with your consent where the law requires consent, and you can opt out at any time (Section 8).
  • Security data: sign-in attempts, session tokens, API key usage, reCAPTCHA scores, audit-log entries of changes in a Workspace.

2.3 Information from other sources

  • Payment processor: payment status, fraud signals and the billing address you entered at checkout.
  • Messaging platforms and marketplaces you connect: your account identifiers and the data those platforms send us so that your integration works (for example your Telegram username when you connect our bot).
  • Partners and public sources: if a partner refers you, the partner tells us your organization's name and contact details; we may enrich business contact details from public business registers and websites.

2.4 What we do not collect

We do not collect precise geolocation, biometric identifiers, health, genetic, racial, religious, sexual-orientation or political data about Account holders, and we do not knowingly collect data from children under 18. We ask customers not to put such data into the Services (Terms of Service, Section 5.7).

PurposeExamplesLegal basis (where a legal basis is required, for example under the GDPR, LGPD or Quebec law)
Providing the ServicesCreating and securing your Account, running your Workspace, processing your requests to AI Models, sending Bot replies, showing reports, delivering notificationsPerformance of a contract (our Terms)
BillingCharging fees, issuing receipts and invoices, calculating taxes, processing refunds, preventing payment fraud, keeping accounting recordsPerformance of a contract; legal obligation (tax and accounting laws)
SupportAnswering your requests, troubleshooting Bots and integrations on your requestPerformance of a contract; legitimate interest in helping our customers
Security and abuse preventionDetecting unauthorized access, spam, fraud and violations of our Acceptable Use Policy; protecting End Users and platformsLegitimate interest in security; legal obligation
Improving the ServicesAnalyzing usage patterns and errors, testing new features, measuring performance, in aggregated or pseudonymized formLegitimate interest in improving our product
CommunicationsService messages about your Account, billing, legal changes and incidentsPerformance of a contract; legal obligation
MarketingProduct news, tips and offers, if you opted inConsent (which you can withdraw at any time)
Website analytics and advertisingMeasuring how the Website is used, attributing sign-ups to campaigns and partners, measuring which of our ads led to sign-ups and purchases in the App, and showing our ads to Website visitors on other services (remarketing)Consent, where required (for example Brazil, Quebec, EU); otherwise legitimate interest with the right to opt out
Partner programAttributing referrals, paying rewardsPerformance of a contract with the partner
Legal compliance and enforcementComplying with laws, tax rules, sanctions screening, lawful requests; establishing, exercising or defending legal claims; enforcing our TermsLegal obligation; legitimate interest
Business transactionsDue diligence in a merger, acquisition or financingLegitimate interest

We do not use personal information for automated decisions that have legal or similarly significant effects on you, and we do not build advertising profiles of Account holders ourselves; if advertising cookies are allowed for you, Meta may use sign-up and purchase events from the App to measure our ads and optimize their delivery under its own policy (Section 4). We do not use personal information or Customer Data to train large language models or other AI models that are made available to other customers, and our AI Model Providers are contractually prohibited from doing so. How AI is used inside the Services is described in our AI Transparency Statement.

4. How we disclose personal information

We disclose personal information only as follows:

  • Sub-processors and service providers that help us operate the Services, listed with their locations and purposes in our Sub-processor List: hosting (Hetzner), storage (Google Cloud), AI Model Providers (for example Anthropic, OpenAI, Google, xAI), payments and tax (Stripe), email delivery (Mailgun), error monitoring (Sentry), bot protection (Google reCAPTCHA) and product analytics (Amplitude). They may use the data only to provide their services to us.
  • Advertising and measurement partners: on the Website, Google (Analytics, Ads) and Meta (Pixel, Conversions API); in the App, Meta (Pixel), which receives page views and the "sign-up completed" and "purchase completed" events (order number, amount, currency). They receive identifiers, page and event data, and hashed contact data for conversion matching, and may use it under their own policies to measure and deliver advertising. See Section 4 below and the Cookie Policy for your choices.
  • Platforms you connect: when you connect a messenger, marketplace, CRM or external AI client, we exchange data with it as needed for the integration, under your instructions and its terms.
  • Within your organization: the Owner and authorized Members of your Workspace can see your name, email, role and activity in the Workspace.
  • Professional advisors: lawyers, accountants, auditors and insurers, bound by confidentiality.
  • Legal and safety: if required by law, subpoena, court order or government request, or to protect the rights, property or safety of BotB2B, our customers, End Users or the public, or to enforce our agreements. Where lawful, we notify you of requests for your data.
  • Business transfers: in connection with a merger, acquisition, financing or sale of assets, subject to this policy.
  • With your direction or consent: for any other purpose you ask for.

We do not sell personal information. On the Website and in the App we use advertising cookies and tags (Google Ads, Meta) to measure our campaigns and to show our ads to Website visitors on other services; under some U.S. state privacy laws this counts as "sharing" personal information for cross-context behavioral advertising. You can opt out at any time through the "Do Not Sell or Share My Personal Information" or "Cookie settings" link in the footer of the Website, or by sending a Global Privacy Control signal from your browser, and advertising tags do not load without your consent where the law requires consent; the same choice applies in the App. From the App, advertising partners receive only the events listed above; we do not share Customer Data, your contact details or the content of your Workspace with advertisers, and we do not disclose personal information to data brokers.

5. International data transfers

We are a U.S. company. Our servers are currently located in the European Union (Germany and Finland), our AI Model Providers and most other sub-processors are in the United States, and some providers are in Canada and the European Union. Personal information is therefore transferred to and processed in countries other than the country where you live, including the United States, whose laws may differ from yours.

We protect transfers as follows:

  • Contracts: every sub-processor is bound by data processing terms, and where required by the law of your country we use the recognized transfer instruments: the European Commission's Standard Contractual Clauses (for data from the EU/EEA), the UK International Data Transfer Addendum, the Swiss addendum, the standard contractual clauses approved by Brazil's National Data Protection Authority (ANPD), the model clauses approved by Argentina's data protection authority, and equivalent instruments elsewhere. Copies are available on request and in the Data Processing Addendum.
  • EU-U.S. Data Privacy Framework: we are not certified under the EU-U.S. Data Privacy Framework or its UK and Swiss extensions. Transfers of personal information from the EU/EEA, the United Kingdom and Switzerland to the United States rely on the Standard Contractual Clauses, the UK International Data Transfer Addendum and the Swiss addendum, not on the Framework.
  • Safeguards: encryption in transit, access controls, and contractual commitments from AI Model Providers not to train on your data and to delete it after a limited period.

You can ask us at [email protected] which instrument covers a given transfer.

6. How long we keep personal information

CategoryRetention
Account dataFor as long as your Account exists, then deleted within 10 days after you delete your Workspace or Account (30 days after other terminations), except as stated below
Customer Data in your WorkspaceUnder your control during the term; deleted with the Workspace (10 or 30 days); database and file backups are kept for up to 90 days and then deleted, so deleted data disappears from backups within that window
Billing records (orders, invoices, payments, refunds, tax records)7 years after the transaction, as required by tax and accounting laws; personal information in them is limited to what the record needs
Records of your acceptance of our documents and consents5 years after the end of the Agreement, as evidence of the contract
Support communications2 years after the ticket is closed
Security and access logs, payment logs (with personal information redacted)12 months, unless needed longer for an investigation or required by law (for Brazil, application access logs are kept at least 6 months as required by the Marco Civil da Internet)
Marketing preferences and consent recordsUntil you opt out, plus 3 years as evidence of your choice
Partner program records7 years after the last payout
AI Manager backups after deletion90 days

When retention ends we delete or anonymize the data. Anonymized data (which cannot identify you) may be kept.

7. Security

We use administrative, technical and physical safeguards designed to protect personal information, including encryption in transit, encryption at rest of files in cloud storage, password hashing, encryption of stored payment-provider secrets, role-based access, audit logging, restricted production access for a minimal number of administrators with multi-factor authentication, and vendor due diligence. Annex 2 of our Data Processing Addendum describes these measures in more detail. No system is completely secure; if we become aware of a breach affecting your personal information we will notify you and the competent authorities as required by law.

8. Your rights and choices

Depending on where you live, you may have the right to:

  • Know and access the personal information we hold about you, including the categories, sources, purposes and recipients;
  • Correct inaccurate or incomplete information;
  • Delete your personal information;
  • Port your information to you or another provider in a machine-readable format;
  • Restrict or object to certain processing, including processing based on legitimate interests and direct marketing;
  • Withdraw consent at any time where processing is based on consent, without affecting prior processing;
  • Opt out of sales and profiling for significant decisions (we do neither) and of sharing for targeted advertising (Section 4; Cookie settings or Global Privacy Control);
  • Not be discriminated against for exercising your rights;
  • Complain to a supervisory authority (see the regional sections below).

How to exercise your rights. Many settings are self-service: you can update your profile and billing details, download your Token ledger, export leads, manage notifications, and delete your Workspace in the Services. For other requests, email [email protected] with the subject "Privacy request", or write to 131 Continental Dr, Suite 305, Newark, DE 19713, USA. We will confirm receipt, verify your identity (for example by asking you to write from the email address on your Account or to confirm a code sent to it), and respond within the period required by your law (generally within 30 days, or 45 days under U.S. state laws, extendable once with notice). You may use an authorized agent where the law allows; we may ask the agent for proof of authorization and may verify your identity directly with you. If we decline a request we will explain why, and you may appeal by replying to our decision; we answer appeals within 45 days and tell you how to contact your state attorney general or data protection authority.

Requests about Customer Data. If your request concerns data in a customer's Workspace (for example your chat with a company's bot, or your work reports), we will refer you to that customer or forward your request to it, because it controls that data.

9. Regional disclosures

9.1 United States

This section applies to residents of U.S. states with comprehensive privacy laws (including, among others, California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia) and supplements the rest of this policy.

Categories of personal information we collect (California Civil Code § 1798.140). In the preceding twelve months we have collected the following categories from Account holders and Website visitors: identifiers (name, email, phone, IP address, account IDs); customer records (billing name and address, payment card last four digits); commercial information (orders, subscriptions, Token purchases); internet or network activity (usage data, log data, cookies and advertising tags); geolocation data (approximate, from IP address); professional information (organization, role); audio (voice messages you record in My AI, if you use it); inferences (product usage statistics; advertising interests inferred by our advertising partners from Website visits and App sign-up and purchase events if advertising cookies are allowed for you); and sensitive personal information limited to account credentials. We collect them from the sources in Section 2, for the purposes in Section 3, and disclose them to the categories of recipients in Section 4 for business purposes. We retain them as described in Section 6.

Sale and sharing. We do not sell personal information. We may "share" identifiers and internet activity of Website visitors, and the sign-up and purchase events of App users, with advertising partners (Google, Meta) for cross-context behavioral advertising through cookies and tags, as described in Section 4; we do not share Customer Data or the content of your Workspace. We have no actual knowledge of selling or sharing the personal information of anyone under 16. We do not use or disclose sensitive personal information for purposes other than those permitted by law.

Your rights. You have the rights described in Section 8, including the rights to know, delete, correct, and to limit the use of sensitive personal information, and the right to opt out of sharing for cross-context behavioral advertising (use the "Do Not Sell or Share My Personal Information" link in the Website footer). We do not profile you for decisions with legal or similarly significant effects. We honor Global Privacy Control signals as an opt-out of sale or sharing for the browser that sends them. We do not offer financial incentives in exchange for personal information.

Delaware. This policy is posted in accordance with the Delaware Online Privacy and Protection Act and identifies the categories of information collected, the third parties with whom it may be shared, how you can review and request changes, how you are notified of changes, and our treatment of Do Not Track signals (we do not respond to Do Not Track signals because there is no common industry standard; we do honor Global Privacy Control).

Notice at collection. We provide the disclosures required by California law at or before the point of collection through this policy and the links in our sign-up and checkout forms.

9.2 Canada

We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and equivalent provincial laws (Alberta, British Columbia, Quebec). We collect personal information with your knowledge and consent, limited to what we need for the purposes in Section 3. Your personal information may be transferred to and stored in the United States and the European Union, where it may be accessible to authorities under the laws of those countries; we protect it by contract as described in Section 5. Quebec: personal information may be communicated outside Quebec (to the United States and the European Union) after an assessment of the privacy factors required by the Act respecting the protection of personal information in the private sector; the person in charge of the protection of personal information is our privacy contact at [email protected]. You may make a complaint to the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec. We do not make decisions based exclusively on automated processing about you.

9.3 Brazil (LGPD)

We process personal information in accordance with the Lei Geral de Proteção de Dados Pessoais (Law 13.709/2018). For Account holders we act as controller (controlador) on the legal bases in Section 3 (execution of a contract, compliance with a legal obligation, legitimate interest, consent). International transfers to the United States and the European Union are made under the standard contractual clauses approved by the ANPD (Resolution CD/ANPD 19/2024) and other lawful hypotheses of Article 33 of the LGPD. You have the rights in Article 18 of the LGPD, including confirmation of processing, access, correction, anonymization, blocking, deletion, portability, information about sharing, information about the consequences of denying consent, and revocation of consent, and the right to request review of decisions made solely on the basis of automated processing (Article 20). Our data protection officer (encarregado) can be reached at [email protected] (subject "Encarregado LGPD"); you may also complain to the Autoridade Nacional de Proteção de Dados. A Portuguese translation of this policy is provided for convenience.

9.4 Mexico (Aviso de Privacidad)

This section constitutes our privacy notice under the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (2025). Responsible party: Bot B2B, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA, United States. Personal data collected: identification and contact data, billing data, usage data (Section 2). Purposes: the primary purposes in Section 3 needed to provide the Services and comply with our obligations; the secondary purpose of marketing communications, which you may refuse at any time without affecting the Services. Transfers: we transfer data to the service providers in Section 4 as necessary for the Services (which does not require your consent under Article 70 of the law) and to no other third parties without your consent. ARCO rights: you may exercise your rights of access, rectification, cancellation and opposition, limit the use or disclosure of your data, and revoke consent by emailing [email protected] with the subject "Derechos ARCO", your name and a copy of an identification document; we respond within 20 business days. You may complain to the Secretaría Anticorrupción y Buen Gobierno (the authority that replaced INAI). Changes to this notice are published at https://botb2b.ai/documents/privacy-policy.

9.5 Argentina

Bot B2B, Inc. is the responsible party for the database of Account holders. Data is transferred to the United States and the European Union under the model clauses approved by the Agencia de Acceso a la Información Pública (Disposición 60-E/2016). You have the rights of access, rectification, update and deletion under Law 25.326; access requests are answered within 10 calendar days and may be made free of charge at intervals of not less than six months unless a legitimate interest is shown. The Agencia de Acceso a la Información Pública, in its capacity as the enforcement authority of Law 25.326, has the power to handle complaints and claims filed by data subjects whose rights have been affected by non-compliance with the personal data protection rules.

9.6 Chile, Colombia, Peru and other Latin American countries

We comply with the applicable data protection laws, including Chile's Law 19.628 and Law 21.719 (from its entry into force), Colombia's Law 1581 of 2012 and Decree 1377 of 2013, Peru's Law 29733 and its regulations, Uruguay's Law 18.331, Ecuador's Organic Law on Personal Data Protection, Panama's Law 81 of 2019 and Costa Rica's Law 8968. Where these laws require it, international transfers to our sub-processors are made under contractual clauses or, for transmissions to processors, under data processing agreements, and you may exercise your rights of access, rectification, cancellation and opposition (habeas data) by contacting [email protected]. Where a law requires authorization or registration of databases or transfers, we comply with it.

9.7 European Economic Area, United Kingdom and Switzerland

We do not currently offer paid Services to customers in these territories, but this section applies if we process your personal information under the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection (for example because you visit the Website or contact us). The legal bases for our processing are set out in Section 3. You have the rights listed in Section 8 and the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner). Transfers to the United States are made under the Standard Contractual Clauses, the UK International Data Transfer Addendum and the Swiss addendum; we are not certified under the EU-U.S. Data Privacy Framework. We have not appointed a representative in the EU under Article 27 GDPR; you can contact us directly at [email protected].

10. Customer Data: what we do as a processor

When our customers use the Services, we process Customer Data on their behalf:

  • What it contains: messages between End Users and Bots, contact details captured as leads, CRM records, files and Knowledge Bases, tasks and notes, work reports of Members, AI Manager conversations and files, and the Output generated from them.
  • How we use it: only to provide the features the customer has turned on, including sending the relevant parts to AI Model Providers to generate replies, transcriptions, summaries and embeddings; to store, back up and secure it; and to support the customer on request. We do not use Customer Data for our own purposes, to train shared models, or for advertising.
  • Who receives it: the sub-processors in our Sub-processor List and the platforms the customer connects, as instructed by the customer.
  • How long we keep it: for the term of the customer's Agreement and up to 30 days after, unless the customer deletes it earlier.
  • Your rights: exercise them with the customer; we assist the customer in responding.

The Data Processing Addendum sets out our contractual obligations to customers, including security measures, sub-processor notice, breach notification and international transfer instruments.

11. Children

The Services are for businesses and are not directed to children. We do not knowingly collect personal information from anyone under 18 as an Account holder, and we do not knowingly allow customers to use the Services to process data of children under 13 (or the age of digital consent in their country) without the safeguards required by law. If you believe a child has provided us with personal information, contact [email protected] and we will delete it.

12. Third-party websites and platforms

The Services link to and interoperate with third-party websites and platforms (messengers, marketplaces, CRMs, AI clients, Stripe's checkout). Their privacy practices are governed by their own policies, which we encourage you to read.

13. Changes to this policy

We may update this policy. We post the new version at https://botb2b.ai/documents/privacy-policy with a new effective date and keep prior versions in the version history. For material changes we notify Account holders by email or in the Services at least 30 days before the change takes effect, unless a shorter period is required by law or needed for a new legal obligation.

14. Contact us

Privacy contact and data protection officer (encarregado / responsable): [email protected] (subject "Privacy request").
Security reports: [email protected] (subject "Security").
Mailing address: Bot B2B, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA.

Version 2 · Effective 9 Sep 2026 · Version history