Home / Legal & Compliance

Privacy Policy

Effective Date: January 1, 2026
•
Payment Gateway Compliant

At Botfyre, we treat organizational data privacy and confidential business knowledge as our foundational mandate. This Privacy Policy details what information we collect, how it is safeguarded, how payment transactions are handled, and your explicit rights under applicable data protection laws.

1. Information We Collect

A. Account & Identity Data: When you register for Botfyre, we collect your name, organizational email address, organization name, and password hash.

B. Ingested Customer Knowledge: Files uploaded by your team (PDFs, Word documents, Excel workbooks, and website URLs). This content is converted into cryptographic vector embeddings stored in isolated tenant databases.

C. Billing & Transaction Records: When you purchase a subscription, our payment aggregators (such as Razorpay and Stripe) collect billing names, billing addresses, country, and masked card identifiers. Botfyre does not collect or store full credit/debit card numbers or CVV codes.

D. Telemetry & Interaction Logs: Anonymous visitor queries submitted to your embedded widgets, latency statistics, user feedback ratings (thumbs up/down), and token usage metrics.

2. Core Commitment: Zero Public AI Training

Guaranteed Intellectual Property Protection

Your proprietary documents, indexed knowledge vectors, customer interaction logs, and chat histories are never used to train, fine-tune, or benchmark public third-party foundation AI models (such as OpenAI, Anthropic, or open-source community checkpoints).

3. Security Standards & Storage Architecture

  • Encryption Standards: All document vectors and customer records are protected with AES-256 bit encryption at rest and TLS 1.3 encryption in transit across all network boundaries.
  • Multi-Tenant Namespace Isolation: Each customer organization is quarantined in a logically distinct vector namespace. No cross-organization context leakage is mathematically possible during query retrieval.
  • Data Centers: Our servers and high-availability cloud infrastructure are hosted in Tier-4 SOC-2 certified cloud environments (AWS / Google Cloud).

4. Sharing & Third-Party Service Providers

We do not sell, rent, or trade your personal or business data. We only share scoped metadata with audited service vendors necessary for platform operation:

  • Payment Processors: Razorpay / Stripe to securely process recurring payments, generate tax invoices, and prevent fraud.
  • Cloud Infrastructure: Cloud hosting, database clusters, and CDN edge providers.
  • Transactional Email: Services (e.g. AWS SES / Postmark) solely for sending password resets, invoices, and critical security notices.

5. Cookies & Tracking Technologies

Botfyre uses essential session cookies to maintain your authenticated login state and CSRF tokens to safeguard forms. We do not employ intrusive cross-site advertising or third-party behavioral trackers.

6. Data Retention & Right to Erasure

You have the complete right to access, rectify, export, or permanently delete your knowledge bases and organizational data at any moment via your dashboard settings. Upon initiating an account deletion request, your uploaded documents and corresponding vector indexes are permanently purged from active disks within 72 hours.

7. Contact the Data Protection Desk

For inquiries regarding GDPR compliance, Indian Digital Personal Data Protection (DPDP) standards, or data access requests, please contact our Data Protection Officer:

Entity: Botfyre Legal & Compliance

Email: privacy@botfyre.com

Response Turnaround: Within 48 business hours