Publication Condition: Replace every highlighted placeholder field with an evidence-backed production fact before publication.

Legal & Trust

Privacy Policy

Learn what information is collected, why it is used, who receives it, how long it is kept, and how to request help.

Effective date: Approved date Last updated: Date of substantive review

This Privacy Policy explains how BotSpace collects, receives, uses, shares, retains and protects personal information.

This Policy applies to:

  • • The BotSpace website at botspace.shop
  • • BotSpace customer accounts and workspaces
  • • The Omnichannel Enquiry Desk
  • • Supported optional modules and integrations
  • • Sales, activation, support, billing, privacy & security contacts
If you communicated with a business through its BotSpace-powered chatbot or messaging account, that business may be primarily responsible for deciding how your information is collected and used.

Who operates BotSpace?

Operator informationVerified detail required
Legal entity Full registered legal name
Trading nameBotSpace
Registration number Registration number
Registering authority Authority
Registered address Full address and country
General contact Monitored contact route
Privacy contact Restricted privacy form or email
Data protection officer Include only if formally appointed
Representative Include only if legally required

References to "BotSpace," "we," "us" or "our" mean the verified operator identified above.

Who does this Policy cover?

  • Visitors to the BotSpace website
  • People who request information or a demo
  • BotSpace customers and billing contacts
  • Workspace administrators and staff users
  • People who contact a business through BotSpace
  • People whose info is entered into a workspace
  • Supplier and partner contacts
  • People who contact BotSpace for support
  • People whose info appears in a knowledge source

What is BotSpace's privacy role?

BotSpace's role depends on the processing activity and applicable law.

Processing contextTypical BotSpace rolePrimary decision-maker
Website, sales and direct marketingBotSpace determines its purposesBotSpace
Account, billing and administrationBotSpace determines necessary purposesBotSpace
Security, abuse prevention and legal recordsBotSpace may determine independent purposesBotSpace
Customer-configured conversations and leadsBotSpace normally processes for the customerBotSpace customer
Customer knowledge and operational recordsBotSpace normally processes for the customerBotSpace customer
Connected channels and integrationsRoles depend on provider and configurationCustomer, provider and/or BotSpace

These descriptions are general. Actual legal roles depend on the relevant activity, contract and jurisdiction. The customer agreement and any DPA provide additional details.

What information does BotSpace process?

Account & business

  • Name and business contact info
  • Organization and job role
  • Workspace membership & permissions
  • Authentication & access information
  • Business profile & settings
  • Subscription, invoice & payment records
  • Communication preferences & consent

Conversation & enquiry

  • Messages sent through connected channels
  • AI-generated responses
  • Human-handoff messages & notes
  • Conversation summaries
  • Enquiry category, status & ownership
  • Customer name & contact information
  • Services, dates, locations & requirements
  • Channel, campaign or referral info

Knowledge information

  • Uploaded documents
  • Approved webpages and FAQs
  • Extracted text and source metadata
  • Knowledge ownership & review info
  • Derived chunks, embeddings or retrieval reps
  • AI drafts, summaries & knowledge-gap findings

Embeddings and derived representations must be handled according to the same workspace and deletion controls.

Travel operational info

When optional travel modules are enabled:

  • Destination, dates & group size
  • Quotations & pricing components
  • Booking references & supplier records
  • Payment status & transactions
  • Departure-readiness info
  • Amendments, cancellations & refunds
  • Trip-support messages

Technical & usage

  • IP address and network info
  • Browser, device & OS info
  • Cookie & local-storage identifiers
  • Login and authorization events
  • Channel and integration events
  • Error, security & diagnostic records
  • Workflow & message-delivery events
  • Monthly Active Enquiry & plan capacity

Support & contact

  • Contact-form submissions
  • Support and onboarding messages
  • Sanitized screenshots & attachments
  • Demonstration requirements
  • Privacy and security reports
  • Feedback and survey responses

Restricted Information Warning

BotSpace is not designed to collect full payment-card details through ordinary chat. Passport copies, visa information, government identifiers, health information and accessibility requirements must not be collected through a general enquiry workflow unless the use is specifically supported, legally reviewed and covered by appropriate safeguards.

Where does the information come from?

  • Directly from you
  • From a BotSpace customer
  • From a workspace administrator
  • Through website chat
  • Through WhatsApp, Messenger or Instagram
  • From another supported communication provider
  • From customer-selected CRM, booking or automation services
  • Automatically through browser, application and server events
  • From public or licensed sources approved for a workflow
  • Through generated outputs (summaries, classifications, embeddings)

If a customer or another person provides information about you, they are responsible for having the authority and lawful basis required to provide it.

Why does BotSpace use personal information?

PurposeExamples
Provide the serviceOperate channels, inboxes, knowledge answers and handoff
Manage enquiriesCapture, classify, assign and progress customer requests
Run workflowsTrigger approved messages, tasks, reminders and escalations
Provide optional modulesSupport CRM, quotation, booking and supplier processes
Manage accountsAuthenticate users and administer permissions
Measure usageCalculate Monthly Active Enquiries and plan capacity
Provide supportOnboard customers and investigate problems
Administer billingManage plans, invoices, payments and additional usage
Secure the serviceDetect abuse, investigate incidents and protect credentials
Improve reliabilityDiagnose errors, evaluate workflows and test releases
CommunicateSend service notices and respond to requests
MarketingSend permitted marketing to appropriate contacts
Legal complianceMaintain required records and respond to lawful requests

Legal bases

Where applicable law requires a legal basis, BotSpace must map each activity to the applicable basis. Depending on the activity and jurisdiction, a basis may include:

  • Performing or preparing to enter a contract.
  • Compliance with a legal obligation.
  • BotSpace's or another party's legitimate interests.
  • Consent.
  • Protection of a person's vital interests.
Note: Consent must not be described as the basis for every processing activity. Contractual administration, security, billing and legal records may rely on different grounds. The final basis mapping must be approved in BotSpace's internal processing register.

How is customer-controlled information handled?

BotSpace customers determine many aspects of the information processed within their workspace, including:

Connected channelsApproved knowledge sourcesEnquiry fieldsStaff accessAssignment rulesHuman-handoff conditionsWorkflow messagesOptional modulesConnected integrationsRetention settings

Customers are responsible for:

  • • Providing appropriate privacy notices
  • • Having a lawful reason to collect data
  • • Requesting only necessary information
  • • Maintaining accurate knowledge/content
  • • Managing staff and provider access
  • • Responding to individual requests
  • • Ensuring integrations are authorized
  • • Providing BotSpace lawful instructions

BotSpace uses customer-controlled information to provide, secure and support the agreed service and for other purposes described in the applicable agreement.

Sale and unrelated use statement

Requires formal business approval
"BotSpace does not sell customer-controlled conversations, leads, knowledge or operational records as a data-broker product and does not use them for unrelated advertising."

Transcripts and leads

Messages exchanged through a BotSpace-powered channel may be stored as a conversation transcript. A transcript may contain customer/staff messages, AI responses, timestamps, attachments, handoff notes, and summaries.

Customers may configure BotSpace to request lead information such as:

  • • Name & Email
  • • Telephone number
  • • Preferred service
  • • Date or location
  • • Budget range
  • • Other requirements

Authorized customer staff may access transcripts and leads through the inbox, reports, exports and approved integrations. The original messaging provider may retain its own copy. Deleting information from BotSpace does not automatically delete corresponding information held by the customer, WhatsApp, Meta or another provider.

Knowledge sources

Customers may provide documents, FAQs, webpages and other approved sources to support AI-assisted answers. Processing may include:

  1. Uploading or importing a source
  2. Extracting and structuring text
  3. Dividing content into retrieval units
  4. Creating embeddings
  5. Recording source metadata
  6. Retrieving relevant information for a response
  7. Creating summaries or draft FAQs
  8. Identifying possible knowledge gaps
Customer Obligations:Customers must not upload information unless they have the right to use it and it is appropriate for the intended audience. Internal-only content should be separated from sources approved for customer-facing answers. When a source is deleted, its active content and related retrieval data should be removed according to the documented deletion process.

AI processing

Depending on the enabled feature, BotSpace may send selected information to an approved AI provider to generate answers, extract structured info, classify intent, summarize, draft, or recommend actions.

The final Policy must identify:

  • • Each AI provider used
  • • Information sent & processing purpose
  • • Provider location & retention settings
  • • Whether provider logging is enabled
  • • Whether data is used for model training
  • • Available customer controls
  • • Relevant contractual safeguards

Model training statement

Requires verification of production settings and contract. Choose one verified statement:

Customer content is not used to train general-purpose models; OR
Particular information may be used for training under stated conditions; OR
Customers can select or control the relevant setting.

Automated decisions

BotSpace is not intended to make solely automated decisions that create legal or similarly significant effects unless the workflow has been specifically reviewed and safeguarded.

AI assistance does not replace human verification of prices, availability, bookings, payments, refunds, or bank details.

Connected channels & subprocessors

Connected Channels

BotSpace may connect with website chat, WhatsApp, Facebook Messenger, Instagram, and customer-selected CRM/booking tools.

When someone uses a connected channel, the provider operating that channel may process account identifiers, messages, device info and delivery events under its own privacy terms. Disconnecting a provider from BotSpace does not automatically delete information held independently by that provider.

Subprocessors

BotSpace may appoint providers to support hosting, databases, storage, AI models, authentication, messaging, monitoring, email, billing, support, and integrations.

The final disclosure must identify each relevant provider, purpose, processing location and role.

ChatbotX clarification

Using self-hosted ChatbotX software does not automatically mean ChatbotX or its maintainers receive BotSpace customer info. However, if BotSpace uses ChatbotX Cloud, hosted APIs, or support services, that provider relationship must be included in the subprocessor inventory.

International transfers

BotSpace, its customers and its service providers may operate in different countries. Personal information may therefore be processed outside the country in which it was collected.

The final Policy must identify:

  • BotSpace's primary hosting region
  • Backup regions
  • AI-provider processing locations
  • Messaging-provider locations
  • Customer selectable regions
  • Transfer safeguards

Do not claim that a particular contractual clause, adequacy decision or transfer mechanism applies unless it has been executed and assessed for the relevant transfer. Dedicated data residency applies only when technically supported and expressly agreed.

Retention and deletion

Information categoryApproved rule required
Website and sales enquiries Period after last meaningful contact
Account and workspace data Subscription plus closure period
Conversation transcripts Default and configurable periods
Enquiry and lead records Default and deletion options
Knowledge sources Active period and deletion lifecycle
Embeddings and retrieval data Relationship to source deletion
Travel operational records Applicable operational and legal period
Monthly Active Enquiry records Billing evidence period
Billing and invoice records Tax and accounting period
Support and onboarding records Approved period
Privacy and security cases Restricted retention period
Security and audit logs Period by log category
Exports and temporary files Short expiry period
Backups Maximum lifecycle
Cookies and analytics Verified duration
When an authorized deletion request is accepted, BotSpace will remove or de-identify applicable information from active systems according to the approved workflow. Information may remain temporarily in restricted backups, security evidence or provider systems where immediate deletion is not technically possible or legally required. Plan downgrade must not silently delete customer knowledge.

Privacy rights

Depending on your location, BotSpace's role and applicable law, you may have rights to:

Receive infoAccess dataCorrect infoRequest deletionRestrict processingObject to processingWithdraw consentData portabilityHuman review of AIComplain to authority

These rights are not absolute. Information may need to be retained for legal obligations, security, fraud prevention, dispute resolution or another person's rights.

How to make a request

Use the Privacy option on the BotSpace Contact page and provide:

  • Your name and safe contact method
  • The BotSpace customer or workspace involved
  • The channel or context
  • The action you are requesting
  • Information needed to locate the record
Do not send an identity document through the initial form. If the information belongs to a customer-controlled workspace, BotSpace may refer the request to that customer or assist the customer in responding.

Children's information

BotSpace is a business service and is not intended for children to create or administer workspaces.

A BotSpace customer's audience may include children or families. The customer is responsible for determining whether its use is appropriate, providing required notices and obtaining any necessary authorization.

Customers must not configure BotSpace to intentionally collect children's information unless the use has been legally reviewed and suitable contractual and technical safeguards are in place.

Cookies and analytics

The BotSpace website and application may use cookies, local storage, pixels, SDKs or similar technologies for authentication, security, preferences, chat continuity, analytics, error reporting, performance monitoring, and marketing measurement.

The final notice or cookie panel must identify:

Technology nameProviderPurposeDurationInformation collectedWhether it is essentialAvailable user choice
Where required, non-essential analytics and marketing technologies must remain disabled until the user makes a valid choice. Do not claim "no cookies," "no tracking" or "essential cookies only" until the rendered website, application, embedded chatbot and tag-management configuration have been audited.

Security

BotSpace uses technical and organizational measures appropriate to the implemented service and assessed risk. Details are available on the Security page.

No online system can guarantee absolute security. Customers remain responsible for their users, devices, accounts, uploads and integrations.

Policy changes

BotSpace may update this Policy when services, providers, legal requirements or practices change. The page will display the effective date and a description of material changes.

A revised privacy notice does not by itself create a lawful basis for materially different processing.

Privacy contact

Use the Privacy option on the Contact BotSpace page to ask about this Policy, request access/correction/deletion, raise concerns about data sources, ask about transfers, withdraw consent, or report unauthorized processing.

Privacy contact: Restricted monitored route
Postal address: Verified operator address
DPO / Representative: Only if appointed
Do not include passwords, one-time codes, private keys, full payment-card information or unnecessary identity documents in initial communications.

Internal Implementation Requirements

This section is for internal tracking and must be removed prior to public launch.

Before legal review, build four operational artefacts:

  1. Processing inventory: every data field, source, purpose, owner and destination.
  2. Role map: when BotSpace acts for itself and when it processes for customers.
  3. Provider register: every service that receives production information.
  4. Retention schedule: exact deletion rule for each information category.

The Privacy Policy must be generated from these records—not the other way around.

Critical publication gates:

Legal operator, jurisdiction and address
Privacy contact and responsible owner
Complete processing/data inventory
Controller/processor role map
Customer data-processing agreement
Purpose-to-legal-basis mapping
Exact AI providers and model settings
Definitive AI-training position
ChatbotX hosted/self-hosted relationship
Hosting, database and backup regions
Messaging/AI/Infrastructure provider inventory
International-transfer mechanisms
Exact retention schedule
Working access/correction/deletion process
Deletion of knowledge-derived embeddings
Treatment of travel docs & sensitive reqs
MAE audit-data retention
Rendered cookie, analytics and SDK audit
Children's-data position
Security, Terms, forms and contract alignment