Subprocessors
To provide Botmanor, we engage a small set of trusted third parties that process personal data on our behalf. This page lists them for transparency, split into what Botmanor itself engages and what your own workspace configuration determines.
Last updated: July 2026
Core platform subprocessors
These providers process data for every Botmanor workspace, regardless of what you configure.
| Subprocessor | Role | Location | Data categories |
|---|---|---|---|
Microsoft Azure Microsoft Corporation | Primary cloud infrastructure — compute, databases, caching, secrets management, and application hosting for the Botmanor platform | Central India | All categories of Customer Data hosted on the service |
Amazon Web Services Amazon Web Services, Inc. | Static site hosting and delivery for the botmanor.com marketing site (S3 + CloudFront), plus transactional email delivery | ap-south-1 (Mumbai, India) and CloudFront global edge | Static assets; email address and content of transactional emails |
Cloudflare Cloudflare, Inc. | DNS, WAF, and Zero Trust access control | Global edge | Connection metadata, IP addresses, request headers |
Stripe Stripe, Inc. | Billing and subscription payment processing (PCI-DSS certified processor) | US / EU | Billing identifiers; tokenised card data (Stripe never passes raw card data to us) |
Shared Burdenoff platform services Burdenoff Consultancy Services Pvt. Ltd. | Identity, workspace, RBAC, notifications, tags, and file storage services shared across the Burdenoff Workspaces platform that Botmanor is built on | India (Azure Central India) | Account/identity data, workspace membership, uploaded files, notification content |
Algoshred Technologies Corp Algoshred Technologies Corp (Delaware, USA) | International invoicing entity for customers billed outside India (via Stripe) | USA | Billing identifiers for international invoicing |
Customer-configured LLM providers
Botmanor does not run its own foundation model and does not pick an LLM provider for you. Each workspace admin registers the provider connections they want (with their own API key) in the provider registry — that choice is what routes an agent's prompts and knowledge-base context to a given provider. A provider below only processes data for your workspace if you configure a connection of that type.
| Provider type | Engaged when | Data categories |
|---|---|---|
| OpenAI | A workspace admin registers a OpenAI connection with their own API key. | Agent prompts, conversation content, and retrieved knowledge-base context sent to that provider at execution time |
| Anthropic | A workspace admin registers a Anthropic connection with their own API key. | Agent prompts, conversation content, and retrieved knowledge-base context sent to that provider at execution time |
| A workspace admin registers a Google connection with their own API key. | Agent prompts, conversation content, and retrieved knowledge-base context sent to that provider at execution time | |
| Cohere | A workspace admin registers a Cohere connection with their own API key. | Agent prompts, conversation content, and retrieved knowledge-base context sent to that provider at execution time |
| Mistral | A workspace admin registers a Mistral connection with their own API key. | Agent prompts, conversation content, and retrieved knowledge-base context sent to that provider at execution time |
| Groq | A workspace admin registers a Groq connection with their own API key. | Agent prompts, conversation content, and retrieved knowledge-base context sent to that provider at execution time |
| Together | A workspace admin registers a Together connection with their own API key. | Agent prompts, conversation content, and retrieved knowledge-base context sent to that provider at execution time |
| HuggingFace | A workspace admin registers a HuggingFace connection with their own API key. | Agent prompts, conversation content, and retrieved knowledge-base context sent to that provider at execution time |
| Azure OpenAI | A workspace admin registers a Azure OpenAI connection with their own API key. | Agent prompts, conversation content, and retrieved knowledge-base context sent to that provider at execution time |
| AWS Bedrock | A workspace admin registers a AWS Bedrock connection with their own API key. | Agent prompts, conversation content, and retrieved knowledge-base context sent to that provider at execution time |
| Custom | A workspace admin points the custom endpoint type at a custom OpenAI-compatible endpoint pointed at a model server you host yourself, or another OpenAI-compatible API. | Agent prompts, conversation content, and retrieved knowledge-base context sent to that provider at execution time |
Your relationship with a connected LLM provider (its own data-handling terms, retention, and any zero-retention options) is governed by your own agreement with that provider — Botmanor vaults the credential and calls the API on your instruction, it does not modify that provider's terms.
Customer-configured channel platforms
Similarly, connecting a bot app to an external channel routes end-user messages through that platform. This only happens for the channels you connect: Slack, Microsoft Teams, Discord, and WhatsApp are supported today, alongside inbound webhooks and a web-widget channel type. When connected, the relevant channel platform (Slack Technologies, Microsoft, Discord Inc., or Meta Platforms, as applicable) processes the message content and platform identifiers needed to deliver and receive that message.
Good to know
- For Enterprise plans, your Order Form or DPA may narrow the applicable subprocessor list (for example, restricting to specific LLM provider types or regions).
- We will update the core subprocessor table above when we add or remove a platform subprocessor, and notify Enterprise customers per the notice mechanism in their signed DPA.
- Questions about data processing? See our DPA, our Privacy Policy, and our Security page, or contact us.