Data Processing Agreement (DPA)
Effective date: 24 August 2026
|GDPR Art. 28 Aligned
For Business Customers Processing EU / UK / Swiss Personal Data
Who Needs This
If you use Botvee to process the personal data of individuals in the EU, UK, or Switzerland (your End-Users), Article 28 of the GDPR (and the UK GDPR) requires a DPA between you (the Controller) and Botvee (the Processor). This DPA is incorporated by reference into, and forms part of, the Terms of Service and takes effect when you first use the Service to process such personal data. For a countersigned copy, email legal@botvee.ai (subject: "DPA Execution Request — [Company Name]").
Parties
- Controller: the customer entity that subscribes to and uses the Service.
- Processor: BOTVEE (PRIVATE) LIMITED, Ward No. 3, Near Government Boys High School, Golarchi, District Badin, Sindh 72220, Pakistan ("Botvee").
Definitions
"GDPR" means Regulation (EU) 2016/679 and, where applicable, the UK GDPR. "Personal Data", "Data Subject", "Processing", "Controller", "Processor", and "Sub-Processor" have the meanings in the GDPR. "Services" means the Botvee SaaS platform under the Terms of Service. "SCCs" means the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914. "Applicable Data Protection Law" means the GDPR, UK GDPR, Swiss FADP, and any other applicable data-protection law.
Subject Matter and Nature of Processing
- Subject matter: Processing of the Controller's End-Users' Personal Data through the Service.
- Nature and purpose: automated collection via AI agent, storage, retrieval, use, transmission across the channels and integrations enabled by the Controller, and deletion, to provide the Service.
- Duration: for the term of the subscription and the period required to complete deletion or return under Section 10.
Categories of Data and Data Subjects
4.1 Categories of Personal Data
As configured by the Controller and depending on the features/channels enabled:
- End-User identifiers and contact details: names, email addresses, phone numbers.
- Channel identifiers where the channel is enabled: WhatsApp phone numbers, Telegram IDs, Instagram/Messenger IDs, email addresses.
- End-User messages and conversation content submitted to deployed AI agents.
- Lead and lead-scoring data, customer notes and tags.
- Booking and appointment data (including via calendar integrations).
- For e-commerce Controllers: order and product data, cash-on-delivery order details, courier/delivery tracking details, abandoned-cart, browse-session, back-in-stock, and post-delivery data. This data is held in the Controller's workspace; it is not shared with courier/delivery providers (see Section 6).
- Technical identifiers: IP address, session identifiers, device information.
- Integration tokens and related data where the Controller connects a third-party integration.
- Any additional categories the Controller configures its agent to collect.
The Controller must not configure the Service to process special categories of Personal Data (GDPR Art. 9) or criminal-offence data (Art. 10) without an appropriate lawful basis and safeguards.
4.2 Data Subjects
The Controller's End-Users — individuals who interact with the Controller's Botvee-powered AI agents.
Processor Obligations (Botvee)
Botvee shall, in respect of Personal Data Processed on behalf of the Controller:
- Process Personal Data only on the Controller's documented instructions (including regarding transfers), unless required otherwise by applicable law.
- Ensure persons authorised to Process the Personal Data are bound by confidentiality.
- Implement appropriate technical and organisational measures under GDPR Art. 32 (see Security Policy).
- Respect the conditions in Section 6 for engaging Sub-Processors.
- Assist the Controller, by appropriate measures and taking into account the nature of Processing, to respond to Data Subject requests — including by providing workspace tools that allow the Controller's owner/admin users to export and erase an End-User's data.
- Assist the Controller in complying with GDPR Arts. 32–36 (security, breach notification, DPIAs, prior consultation), taking into account the information available to Botvee.
- At the Controller's election, delete or return Personal Data as set out in Section 10.
- Make available information reasonably necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits as set out in Section 11.
Sub-Processors
The Controller provides general written authorisation for Botvee to engage Sub-Processors to provide the Service. Botvee's current Sub-Processors — core providers (always used) and additional providers used only where the Controller enables the corresponding channel or integration — are listed at botvee.ai/subprocessors. Botvee shall: give at least 14 days' prior notice of any addition or replacement; allow the Controller to object on reasonable data-protection grounds within that period (sole remedy: terminate the affected part of the Service if no commercially reasonable alternative exists); impose data-protection obligations on Sub-Processors that are, in substance, no less protective than this DPA (including the SCCs where applicable); and remain responsible for its Sub-Processors' performance, subject to the limitations of liability in Section 12.
Courier/delivery providers. Courier tracking is not yet live, and no Personal Data is sent to any courier today. When it launches, the Controller will instruct and authorise Botvee to query the courier the Controller configures, using the Controller's own courier credentials, in order to read a shipment's delivery status. The only value sent will be the tracking number; End-User names, addresses, and phone numbers will not be transmitted to the courier, and Botvee will not book shipments.
International Transfers
Where Botvee transfers Personal Data from the EU/UK/Switzerland to a country not recognised as adequate, Botvee will apply an appropriate transfer mechanism, which may include: the EU SCCs (2021/914) — Module 2 (Controller-to-Processor) between the Controller and Botvee, and Module 3 (Processor-to-Sub-Processor) between Botvee and its Sub-Processors; the UK IDTA or Addendum for UK data; safeguards recognised under the Swiss FADP for Swiss data; and supplementary measures such as encryption and access controls. The applicable SCCs are incorporated by reference into this DPA.
Personal-Data Breach Notification
Botvee will notify the Controller without undue delay after becoming aware of a Personal Data breach affecting Personal Data Processed on behalf of the Controller, with the information then available, to help the Controller meet its own GDPR Art. 33 obligations. Botvee will reasonably cooperate in investigating and mitigating the breach. The Controller is responsible for notifying its End-Users and any supervisory authority where required.
Data Subject Rights Assistance
Taking into account the nature of the Processing, Botvee will provide reasonable assistance to help the Controller fulfil Data Subject requests (access, rectification, erasure, restriction, portability, objection), including workspace tools enabling the Controller's owner/admin to erase an End-User's data. The Controller remains responsible for receiving and responding to requests from its own End-Users. Where Botvee receives a request directly from a Data Subject, it will, where permitted, refer it to the Controller.
Deletion or Return on Termination
On termination, Botvee will, at the Controller's written election, (a) securely delete Personal Data Processed on behalf of the Controller within 30 days, or (b) return it in a structured, machine-readable format before deletion. Written confirmation is available on request. Botvee may retain Personal Data to the extent required by law; any such data remains subject to this DPA's confidentiality and security obligations. Billing records that are Botvee's own financial records (retained for tax/regulatory reasons) are not Controller Personal Data under this DPA.
Audits
Botvee will make available information reasonably necessary to demonstrate Art. 28 compliance and allow for and contribute to audits. To protect the security and confidentiality of Botvee's systems and other customers' data, audits will be on reasonable prior written notice, no more than once per year (except where required by a supervisory authority or following a breach), during business hours, subject to confidentiality, and at the Controller's cost. Botvee may satisfy audit requests by providing relevant certifications or reports of its infrastructure providers where these reasonably address the request.
Liability
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms of Service, which apply to the parties' total combined liability under the Terms and this DPA. Nothing here limits liability to a Data Subject or supervisory authority to the extent such limitation is not permitted by Applicable Data Protection Law.
Governing Law
This DPA is governed by the laws of Pakistan and, to the extent required for compliance, by Applicable Data Protection Law. Disputes are subject to the dispute-resolution and jurisdiction provisions of the Terms of Service.
How to Execute This DPA
- Email legal@botvee.ai — subject "DPA Execution Request — [Your Company Name]".
- Provide your company's legal name, registered address, registration number, and a contact person.
- Botvee will provide a completed, execution-ready DPA.
- Both parties sign electronically; each retains a copy.
- The DPA takes effect from the Controller's signature date (or, absent signature, when the Controller first uses the Service to process EU/UK/Swiss Personal Data).
Contact
Legal / DPA
Company
BOTVEE (PRIVATE) LIMITED (SECP: 0326112)
Postal
Ward No. 3, Near Government Boys High School, Golarchi, District Badin, Sindh 72220, Pakistan
BOTVEE (PRIVATE) LIMITED