Data Processing Addendum

When Botmanor processes personal data on your behalf, our Data Processing Addendum governs how. This page summarises it in plain language, grounded in what the platform actually does.

Botmanor is pre-launch. The executable DPA is available on request and, for Enterprise plans, incorporated into your Order Form. Last updated: July 2026.

Roles of the Parties

For personal data contained in the bots, agents, knowledge documents, prompts, and conversation content you put into your workspace ("Customer Data"), you are the data controller and Algoshred Technologies Pvt. Ltd. ("Botmanor") acts as your data processor.

We process Customer Data only on your documented instructions — the configuration you set in the product (which LLM provider to call, which knowledge bases to build, which channels to connect) — as further described in this DPA.

Where you connect a third-party LLM provider, channel platform, or MCP server, you instruct us to route the relevant data to that party for the sole purpose of running your agent; you remain responsible for your own relationship and terms with that provider.

Scope & Purpose of Processing

We process personal data solely to provide the Botmanor agentic AI platform: app and agent configuration, knowledge base storage and retrieval, execution tracking (inputs, outputs, token counts, and cost), channel message routing, and the platform services (identity, workspace, notifications, billing) that support them.

We do not sell Customer Data and do not use it to train third-party foundation models. Any model call made on your behalf uses the LLM provider connection you configured, resolved at execution time rather than stored in the agent definition.

Categories of data subjects: your workspace members, and the end users who message your bot apps through connected channels (web widget, Slack, Teams, Discord, WhatsApp, or webhook). Categories of data: account/identity data, conversation and execution content, and technical/usage metadata.

Subprocessors

We engage a limited set of subprocessors to operate the platform — cloud infrastructure, email delivery, CDN/DNS, and billing — each bound by a data-protection agreement. The current list is published on our Subprocessors page for transparency.

The LLM providers, channel platforms, and MCP/tool servers you configure in your own workspace are also subprocessors (or, where you provide your own contract with that vendor, independent processors) with respect to the data you choose to route through them. We do not select these on your behalf — see the Subprocessors page for how this works.

We will notify customers of material changes to our core subprocessor list through this page and, where a signed Enterprise DPA is in place, per the notice mechanism in that agreement.

Security Measures

Technical and organisational measures appropriate to the risk: AES-256 encryption at rest and TLS 1.3 in transit, per-workspace tenant isolation with RBAC enforced at the API edge on every request, LLM provider and integration credentials held in managed secret stores (never in application code or logs), and an audit trail covering configuration changes and agent operations.

Full current posture — including what is in place, in progress, and planned — is published on our Security page, kept honestly up to date rather than asserting certifications we do not hold.

Data Subject Rights

We assist you in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection) through the product's own data-management tooling and, where needed, our support team, so you can meet your obligations as controller.

Where a request reaches us directly from a data subject rather than through you, we will refer it to you as the controller unless we are legally required to act on it ourselves.

International Transfers

Our primary infrastructure is hosted on Microsoft Azure in Central India. Static site assets are served through AWS-backed CDN infrastructure with a global edge.

Where personal data is transferred outside the region in which it was collected — including to a subprocessor or to an LLM provider you configure that processes data outside your region — we rely on appropriate safeguards (such as Standard Contractual Clauses) as set out in the executable DPA.

Return & Deletion

On termination, workspace owners can export Customer Data through the product for a defined window. After that window, we delete or anonymise Customer Data in line with our retention schedule, except where retention is required by law.

Deleting a knowledge base, agent, or app removes it from active service; the underlying execution and audit records are retained for the period described in our Privacy Policy for security, billing, and legal-compliance purposes.

Precedence & How to Get the Full DPA

This page is a plain-language overview. For Enterprise customers, the executable DPA (including Standard Contractual Clauses annexes where applicable) is incorporated by reference into your Order Form and takes precedence over this summary in the event of a conflict.

Self-serve customers on Free or Pro plans: the executable DPA is available on request — contact us and we will share the current version and, where needed, arrange counter-signature.

Related pages

See our Subprocessors list (including how customer-configured LLM providers are handled), our Security posture, and our Privacy Policy.

Need the executable DPA for procurement or a security review? Contact us and we will share the current version.

We use cookies for essential site functions and, with your consent, for analytics to improve Botmanor. We don't use advertising or cross-site tracking cookies. See our Cookie Policy.

Preferences