Privacy Policy

Last Updated: August 16, 2026. Effective Date: August 16, 2026.

1. Who We Are

The Botalio service at botalio.com is operated under the trading name "Botalio" as a sole proprietary concern carrying on business in India ("Botalio", "we", "us", "our").

Botalio is a trading name. It is not a company or a limited liability partnership.

This policy explains how we handle personal data under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

The Service is provided free of charge. We take no payments, we process no payment instruments, and we hold no billing, card, bank or UPI data of any kind.

Contact for all purposes under this policy: hello@botalio.com.

2. The Two Roles We Play

When you are our account holder, we are the Data Fiduciary for your personal data, such as your name and email address.

When your chatbot collects data from your website visitors, you are the Data Fiduciary and we act only as a Data Processor on your instructions. You decide what your chatbot asks, what it stores and how long it is kept. You are responsible for telling your visitors that a chatbot is collecting their data, for obtaining their consent, for answering their requests, and for notifying the Data Protection Board of India if a breach occurs on your side. Our processing terms with you are in Annexure A to the Terms of Service.

If you are a website visitor who has chatted with a Botalio chatbot and you want your data corrected or deleted, contact the business whose website you used. That business, not Botalio, is responsible for it. You may also write to hello@botalio.com and we will pass your request to that business.

3. Personal Data We Collect

About account holders:

  • Name, email address, hashed password
  • Business name, business type or industry, city and state
  • Chatbot configuration you create: chatbot name, welcome message, prompts, branding
  • Knowledge base content you upload, which may include documents and website URLs
  • Emails and messages you send us
  • Usage data: features used, conversation counts, timestamps, error logs
  • Technical data: IP address, browser and device type, operating system, referring URL, language preference

About your end users, processed on your behalf:

  • Name, phone number and email address, where your chatbot asks for them and the visitor supplies them
  • Conversation transcripts
  • Page URL, referrer and UTM parameters where present
  • IP address and timestamps

4. What We Do Not Collect

We do not collect or knowingly process:

  • Payment card, bank account or UPI details. We take no payments.
  • Aadhaar, PAN, passport or other government identifiers.
  • Health records, medical history, diagnoses, prescriptions or biometric data.
  • Personal data of any person we know to be under eighteen (18) years of age.

The Terms of Service prohibit account holders from configuring chatbots to collect any of the above. If any such data reaches us, write to hello@botalio.com and we will delete it.

5. Why We Process Personal Data

We process personal data to: create and secure your account; operate the chatbot and generate responses; store and show you your conversations and enquiries; send notifications you have enabled; send service and security emails; enforce usage limits and control our operating costs; detect and prevent abuse, fraud and security incidents; fix problems and improve the Service; and comply with law and lawful orders.

Our lawful basis under the DPDP Act is your consent, given when you request access and accept these policies, and, where applicable, the legitimate uses permitted under Section 7 of the Act.

We do not use your data, or your end users' data, for advertising. We do not sell personal data. We do not share it with data brokers.

6. Who Processes Data on Our Behalf

ProviderWhat it doesWhere it processes
SupabaseDatabase, authentication, file storageMumbai, India
VercelWebsite and application hosting, edge networkMumbai region primary, global edge network
Google LLC (Gemini API)Generates chatbot responses and embeddingsOutside India
ResendTransactional and notification emailOutside India

6.1 Each provider is bound by its own contractual terms and processes data only to deliver its service to us.

6.2 We will update this table before engaging a new provider. The current version of this page is always the operative list.

6.3 AI processing happens outside India. To generate a chatbot response we send the relevant part of your knowledge base and the visitor's message to our AI provider. We do not send account passwords. This is a cross-border transfer of personal data and by using the Service you consent to it. We will comply with any restriction the Central Government notifies under Section 16 of the DPDP Act, and if a provider becomes restricted we will change providers or suspend the Service.

6.4 Model training. Our AI provider is Google LLC. We currently use the free tier of the Gemini API. Under Google's terms for that tier, Google may use the content sent to the API, including chatbot messages and knowledge base content, to improve its products and models. We are stating this plainly rather than omitting it. We do not train any model of our own on your data. If you do not want your content used this way, do not upload it.

6.5 We may disclose personal data where required by law, by a court, or by a government or regulatory authority, to enforce our Terms, to investigate suspected abuse or a security incident, or to protect the rights or safety of any person.

7. Where Data Is Stored

Account data, chatbot configuration, knowledge base content, conversation transcripts and enquiry records are stored in Supabase infrastructure in the Mumbai, India region.

Data leaves India when it is sent to the providers in Section 6 that process outside India, principally for AI response generation and email delivery. We do not claim that all data stays within India, because that would not be accurate.

8. How Long We Keep Data

DataRetention
Account recordFor as long as your account exists. Deleted within 30 days of account deletion.
Chatbot configuration and knowledge baseFor as long as your account exists. Deleted within 30 days of account deletion.
Conversation transcriptsRetained for as long as your account exists. Deleted within 30 days of account deletion.
Enquiry and contact records captured by your chatbotRetained for as long as your account exists. Deleted within 30 days of account deletion.
Support emailsUp to 12 months.
Server and application logsUp to 90 days.

We do not currently apply an automatic time limit to conversation transcripts or enquiry records. They are kept while your account is active. We are building scheduled deletion so that older records are removed automatically, and we will update this policy with the specific periods once it is in place. Today, the way to remove this data is to delete your account, which you can do at any time from your dashboard and which removes everything.

We deliberately keep less data than most services, because holding data we do not need creates risk for you and for us. Where the law requires longer retention, or where data is needed for an ongoing legal claim, we will keep only what is required and only for as long as required.

Deleted records may persist in encrypted backups for up to 30 days before being overwritten.

9. Your Rights

Under the DPDP Act you may: ask what personal data of yours we hold and who we have shared it with; ask us to correct or complete inaccurate data; ask us to erase your data, subject to any legal requirement to keep it; nominate a person to exercise your rights if you die or become incapacitated; withdraw consent at any time; and complain to us and then to the Data Protection Board of India.

Withdrawing consent or deleting your account stops the Service working for you. That is the practical consequence, and we will not treat it as a reason to refuse the request.

To exercise a right, email hello@botalio.com from the address on your account. We may need to verify your identity before acting. We will respond within 30 days.

10. Grievances

Send any grievance to hello@botalio.com, marked "Grievance". This is the mechanism by which any user or affected person may make a complaint about the Service, about content available through it, or about our handling of personal data.

We will acknowledge your complaint within twenty four (24) hours and resolve it within fifteen (15) days, in line with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Data protection grievances are resolved within thirty (30) days at the latest.

If you are not satisfied, you may approach the Data Protection Board of India.

11. Security

We use: encryption in transit over TLS; encryption at rest as provided by Supabase; row level security so that one account cannot read another account's data; hashed passwords; access controls limiting administrative access; and environment variables for secrets, which are never committed to source control.

We are a small operation providing a free service and we hold no ISO 27001, SOC 2 or equivalent certification. We do not claim to. No system is completely secure and we cannot guarantee that data will never be accessed without authorisation. To the maximum extent permitted by law we disclaim liability for unauthorised access occurring despite reasonable safeguards, and our overall liability is limited as set out in the Terms of Service.

If a breach affects your account data we will notify you and, where required, the Data Protection Board of India. Where a breach affects end user data for which you are the Data Fiduciary, we will notify you and you are responsible for notifying the Board and the affected data principals.

12. Children

The Service is for businesses and is not directed at children. We do not knowingly collect personal data of anyone under eighteen (18).

Account holders are contractually prohibited from deploying chatbots on properties directed at children and from configuring chatbots to request personal data from anyone under eighteen. Where an account holder's business serves minors, such as a coaching institute or school, the account holder must configure the chatbot to request contact details only from a parent or lawful guardian and is solely responsible for obtaining verifiable parental consent under Section 9 of the DPDP Act.

If you believe a child's data has reached us, write to hello@botalio.com and we will delete it.

13. Cookies

See the Cookie Policy.

14. Changes

We may update this policy. The "Last Updated" date shows the current version. Where a change is material we will make reasonable efforts to notify you by email or in the dashboard at least fifteen (15) days before it takes effect.

15. Contact

Botalio
hello@botalio.com