Privacy & GDPR Center

Privacy you can
actually read.

We write GDPR documents for a living, so ours should be the easiest you’ve read. Every policy, your rights, and how to use them — in one place.

  • No cookies, analytics or trackers on our website
  • We never sell personal data
  • Your data never trains AI models
  • Every rights request answered within one month
Your rights

What you can ask us for

These rights come from the GDPR and Moldovan Law No. 195/2024. Using them is free, and you don’t need to explain why.

Art. 15

Access

Find out whether we hold your data and get a copy of it, with what we use it for.

Art. 16

Rectification

Have anything inaccurate corrected, or incomplete data completed.

Art. 17

Erasure

Have your data deleted when we no longer need it or have no legal basis to keep it.

Art. 18

Restriction

Pause how we use your data while a question about it is being resolved.

Art. 20

Portability

Receive the data you gave us in a machine-readable format, or have it sent elsewhere.

Art. 21

Objection

Object to processing based on our legitimate interests — and to direct marketing at any time.

Art. 22

Human decisions

Not be subject to significant decisions made solely by automated means, including AI.

Art. 77

Complaint

Complain to a data protection authority at any time — you don’t need to ask us first.

Make a request

Three steps, one month at most

Step 1

Send us your request

Email hello@botbridge.org with the subject “Data protection request”. The template on this page covers everything we need.

Within 5 working days

We confirm and verify

We confirm receipt. If we can’t be sure the request comes from you, we ask for the minimum needed to verify it — never more.

Within 1 month

We act and reply

We complete the request and tell you what we did. For complex requests we may need up to two more months, and we’ll tell you why within the first month.

If you’re a customer of one of our clients — for example you used a chatbot we built for them — that business controls your data. Contact them first; we’ll help them answer.

Request template

Copy it, fill in the brackets, delete the rights you don’t need.

Subject: Data protection request

Hello BotBridge,

I am writing to exercise my rights under the GDPR / Law No. 195/2024.

My name: [full name]
Email or phone you may know me by: [contact details]
My relationship with BotBridge: [e.g. I sent an enquiry in March 2026 / I work for a client]

I request:
[ ] access to my personal data and a copy of it (Art. 15)
[ ] correction of: [what is wrong and what it should be] (Art. 16)
[ ] erasure of my personal data (Art. 17)
[ ] restriction of processing (Art. 18)
[ ] a copy of my data in a machine-readable format (Art. 20)
[ ] to object to the processing of my data for: [purpose] (Art. 21)

Please reply to: [email address]

Thank you,
[name]
[date]
Supervisory authorities

If you’re not satisfied

You can complain to the data protection authority where you live, work or where you think the infringement happened.

Romania — ANSPDCP

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal

B-dul G-ral Gheorghe Magheru 28–30, Sector 1, 010336 București

dataprotection.ro · anspdcp@dataprotection.ro

Republic of Moldova — NCPDP

Centrul Național pentru Protecția Datelor cu Caracter Personal

Str. Serghei Lazo 48, MD-2004 Chișinău

datepersonale.md · centru@datepersonale.md

Living elsewhere in the EU? Find your authority on the European Data Protection Board’s list.

AI transparency

How we use AI responsibly

Yes. Every chatbot we build tells users they are talking to an AI system, as Art. 50(1) of the EU AI Act (Regulation (EU) 2024/1689) has required since 2 August 2026. Where the client wants it, the chatbot also offers a route to a person.

No. We don’t train models on client or end-user data, and we only use AI providers whose business terms exclude training on customer data. Where a provider offers reduced or zero data retention, we switch it on.

Not on its own when it matters. We don’t build solutions that take decisions with legal or similarly significant effects on people without human review (Art. 22 GDPR), and we don’t build high-risk AI systems under the AI Act unless agreed separately in writing.

Guardrails: the chatbot answers only from the client’s approved knowledge base, has explicit limits on topics and commitments, and is tested by the client’s team on real cases before launch. AI can still make mistakes, which is why important answers stay under human oversight.

Legal framework

The rules we work to

Document history

Versions

We review every document at least once a year. Material changes are announced to clients 30 days before they take effect.