- Our website sets no cookies and runs no analytics, ad pixels or tracking scripts.
- We only use what you send us — to reply, prepare a quote and deliver the work you hire us for.
- If you use the chat assistant on our website, your messages are stored on our n8n server and answered by AI. The chat never asks who you are (section 05).
- We never sell personal data, and we never let AI providers train their models on it.
- You can ask for a copy, a correction or deletion at any time: hello@botbridge.org. We answer within one month.
01Who is responsible for your dataArt. 13(1)(a) GDPR
This policy explains how BotBridge (“we”, “us”) processes personal data as a data controller.
| Contact | Details |
|---|---|
| Privacy enquiries | hello@botbridge.org — subject line “Data protection request” |
| Phone | +40 754 050 706 |
Data Protection Officer. Under Art. 37 GDPR we are not required to appoint a DPO: we are not a public authority, and our core activities do not involve large-scale systematic monitoring of people or large-scale processing of sensitive data. The privacy contact above handles every data protection matter and reports directly to management.
When we act for our clients. When we build and run chatbots, workflows or websites for a client, the client decides why and how their customers’ data is used — the client is the controller and we are their processor. In that case the client’s own privacy notice applies, and our obligations are set out in our Data Processing Agreement.
02Which laws apply
We process personal data in line with:
- Regulation (EU) 2016/679 — the General Data Protection Regulation (“GDPR”), including where it applies to us under Art. 3(2) because we offer services to people and businesses in the European Union;
- Romanian Law No. 190/2018 on measures implementing the GDPR, and Law No. 506/2004 on electronic communications privacy;
- Law No. 195/2024 of the Republic of Moldova on personal data protection, in force since 23 August 2026;
- Directive 2002/58/EC (ePrivacy) for anything stored on or read from your device — see our Cookie Policy.
03What we collect and where it comes from
Information you give us
- Enquiries — your name, email address, company, the service you’re interested in, and anything you write in your message. Our contact form doesn’t send data to a server: it opens your own email app with the message pre-filled, and we receive it as an ordinary email.
- Calls and meetings — your phone number, what we discuss and any notes we take. We never record calls without asking you first.
- Instagram messages — your username, profile name and message content when you contact @botbridgeagcy.
- Clients — the name, role, email and phone number of your contact people; billing details (company name, tax ID, address, bank details for payments); our project correspondence, approvals and signed documents.
- Chat assistant — the messages you type into the chat on our website. The chat doesn’t ask for your name, email or phone number. Please don’t share sensitive information in it.
- Job and collaboration applications — your CV, portfolio and anything else you choose to send.
Information collected automatically
- Server logs — when you load a page, your browser sends our hosting provider technical data: IP address, date and time, the page requested, browser and operating system, and the referring page. This happens on every website and is needed to deliver pages and keep the service secure.
- Chat session — only if you click the chat button: a random session ID saved in your browser’s local storage so your messages form one conversation, a copy of the conversation kept in that browser tab’s session storage so it stays in place when you move between pages, plus the IP address and browser details your browser sends when the chat loads its code from jsDelivr and connects to our n8n server. See our Cookie Policy.
We do not use cookies, analytics, advertising pixels, session recording, fingerprinting or social media plugins on this website.
Information from others
If a colleague introduces you, or your company names you as its contact person, we receive your business contact details from them. We may also look up publicly available company information (for example trade registers) to check who we are contracting with.
Sensitive data
We don’t ask for special categories of data (health, religion, political views, biometrics and the like, Art. 9 GDPR) or data about criminal convictions (Art. 10). Please don’t include them in your messages. If you do, we delete them unless they are genuinely needed to answer you.
04Why we use it, and our legal basisArt. 6 GDPR
We only process personal data when a legal basis under Art. 6(1) GDPR applies:
| Purpose | Data used | Legal basis |
|---|---|---|
| Delivering the website and keeping it secure | Server logs | Legitimate interests — running a secure, reliable website (Art. 6(1)(f)) |
| Answering your enquiry and preparing a quote | Enquiry data, call notes, Instagram messages | Steps you asked for before a contract (Art. 6(1)(b)); if you write on behalf of a company, our legitimate interest in replying to business enquiries (Art. 6(1)(f)) |
| Answering questions through the chat assistant, and keeping the conversation history | Chat messages, chat session ID, IP address and browser details | Legitimate interests — answering visitors’ questions about our services and checking the quality of the answers (Art. 6(1)(f)); where you ask about hiring us, steps you asked for before a contract (Art. 6(1)(b)) |
| Delivering the services you hire us for | Client contact data, project correspondence | Performance of a contract (Art. 6(1)(b)); for company contact people, legitimate interests (Art. 6(1)(f)) |
| Invoicing, accounting and tax | Billing details, invoices, payment records | Legal obligations under accounting and tax law (Art. 6(1)(c)) |
| Keeping clients informed about related services | Business email address | Legitimate interests, only for existing clients and similar services, with an opt-out in every message (Art. 6(1)(f); Art. 12(2) of Law 506/2004) |
| Reviewing applications to work with us | CV and application details | Steps before a contract (Art. 6(1)(b)); keeping your CV for future roles only with your consent (Art. 6(1)(a)) |
| Establishing, exercising or defending legal claims; answering authorities | Whatever data is relevant to the matter | Legal obligations (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have weighed our interests against your rights and expectations and concluded they are not overridden. You can ask for a summary of that assessment, and you can object at any time (section 10).
We don’t send newsletters or marketing to people who aren’t clients. If we ever start, we will ask for your consent first. Giving us your details is voluntary, but without an email address or phone number we cannot reply to you, and without billing details we cannot enter into a contract.
05AI and automated decisionsArt. 22 GDPR
We don’t make decisions about you based solely on automated processing, including profiling, that produce legal effects or similarly significant effects on you.
We sometimes use AI tools internally — for example to summarise a long brief or draft a reply that a person then reviews. When we do, we use business services whose terms don’t allow your data to be used to train their models, and we share only what the task needs.
The chat assistant on our website. The chat (“Bob”) is an AI system, not a person, and it says so when the conversation starts. It runs on an n8n workflow that sends your messages to OpenAI’s ChatGPT models to write a reply, and the conversation is stored on our n8n server. It gives general information only, doesn’t make decisions about you, and its answers are not a quote or a binding offer. For anything that matters, contact us directly.
The chatbots we build for clients always tell people they are talking to an AI system, as required by Art. 50(1) of Regulation (EU) 2024/1689 (the AI Act).
06Who we share it withArt. 13(1)(e) GDPR
We never sell or rent personal data. We share it only with:
- Service providers acting for us (processors) — our website host Vercel (Vercel Inc.), our email provider Gmail (Google), and our accountant. Each is bound by a data processing agreement under Art. 28 GDPR.
- n8n — n8n GmbH (Berlin, Germany) runs the workflow behind our chat assistant on n8n Cloud and stores chat conversations for us as our processor under a data processing agreement (Art. 28 GDPR). See n8n’s privacy policy.
- OpenAI — OpenAI Ireland Ltd / OpenAI, L.L.C. receives the text of your chat messages and the recent conversation so its ChatGPT models can write a reply. It acts as our processor under its data processing addendum, doesn’t use data sent through its API to train its models, and may keep it for up to 30 days to detect abuse before deleting it. It may process data in the United States (see section 07). See OpenAI’s privacy policy.
- jsDelivr — the public network that serves the chat’s code receives your IP address and browser details when you open the chat. See jsDelivr’s privacy policy.
- Meta — if you contact us on Instagram, Meta Platforms Ireland Ltd processes that conversation as an independent controller under Instagram’s privacy policy. Where Meta gives us aggregated statistics about our account, Meta and BotBridge may be joint controllers for those statistics (Art. 26 GDPR), and Meta has taken primary responsibility for them.
- Banks and payment providers — to receive and reconcile payments.
- Professional advisers — lawyers, auditors and insurers, under a duty of confidentiality.
- Authorities and courts — only when the law requires it or to defend legal claims.
- A buyer or successor — if our business is reorganised, merged or sold, subject to the same protections.
A current list of the providers we use to deliver client projects is in Annex III of our Data Processing Agreement.
07International transfersArts. 44–49 GDPR
We operate from Romania and the Republic of Moldova. Some of our providers process data in other countries, including the United States. When personal data leaves the European Economic Area, we make sure it stays protected by:
- an adequacy decision of the European Commission — for US companies certified under the EU–US Data Privacy Framework, Commission Implementing Decision (EU) 2023/1795; or
- the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914), together with a transfer risk assessment and additional safeguards where needed.
The Republic of Moldova has no EU adequacy decision. Where data subject to the GDPR is accessed from Moldova, we apply the Standard Contractual Clauses or, where the GDPR applies to us directly, its full set of obligations — alongside Moldovan Law No. 195/2024, which mirrors the GDPR. You can ask us for a copy of the safeguards that apply.
08How long we keep itArt. 5(1)(e) GDPR
| Data | Retention period |
|---|---|
| Enquiries that don’t become a project | 12 months after our last contact, then deleted |
| Chat assistant conversations | The assistant’s memory holds only the last 5 exchanges of each conversation, and older messages drop out as new ones arrive. A record of each message is also kept in n8n’s execution history until it is deleted automatically at the end of the retention period of our n8n Cloud plan. OpenAI may keep messages for up to 30 days to detect abuse. The session ID stays in your browser until you clear this site’s data; the copy of the conversation in your browser tab is removed when you close the tab. |
| Client correspondence and project records | For the contract, plus 3 years (the general limitation period for claims) |
| Invoices and accounting records | As long as accounting and tax law requires — generally 5 to 10 years from the end of the financial year |
| Server logs | A short period set by our hosting provider; we only look at them to investigate a security incident |
| Job applications | 6 months after the role is filled, or 2 years if you consent to being considered for future roles |
| Objections and marketing opt-outs | Kept for as long as needed to respect your choice |
When a period ends we delete the data or anonymise it so it can no longer identify you. Backups are overwritten in their normal cycle. If data is needed for a legal claim or an investigation, we keep it until that is resolved.
09How we protect itArt. 32 GDPR
We use technical and organisational measures appropriate to the risk, including:
- encryption in transit (HTTPS/TLS) and encryption at rest provided by our infrastructure;
- multi-factor authentication, unique accounts and a password manager for every system we use;
- access limited to the people who need it, with written confidentiality obligations;
- API keys and credentials kept in secret stores, never in source code;
- encrypted, up-to-date devices with screen locks;
- checking the security and data protection terms of every provider before we use it;
- a documented procedure for handling personal data breaches.
If a personal data breach occurs, we notify the competent supervisory authority within 72 hours where required (Art. 33 GDPR), and we inform you without undue delay if the breach is likely to put your rights and freedoms at high risk (Art. 34 GDPR).
10Your rightsArts. 15–22 GDPR
You have the right to:
- Access — get confirmation of whether we process your data, and a copy of it (Art. 15);
- Rectification — have inaccurate data corrected or incomplete data completed (Art. 16);
- Erasure — have your data deleted, for example when it is no longer needed or you withdraw consent (Art. 17);
- Restriction — have us limit processing while a dispute about accuracy or lawfulness is resolved (Art. 18);
- Portability — receive data you gave us, on the basis of consent or a contract, in a structured, machine-readable format, or have it sent to someone else (Art. 20);
- Object — to processing based on legitimate interests, on grounds relating to your situation, and at any time and without giving reasons to direct marketing (Art. 21);
- Withdraw consent at any time, without affecting processing that already took place (Art. 7(3));
- Not be subject to decisions based solely on automated processing (Art. 22).
How to exercise them
Email hello@botbridge.org with the subject “Data protection request”. Our Privacy & GDPR Center has a ready-to-use request template. Requests are free. We reply within one month; for complex or numerous requests we may extend this by two further months and will tell you why within the first month (Art. 12(3)). If we can’t confirm who you are, we may ask for the minimum information needed to verify your identity (Art. 12(6)). If a request is manifestly unfounded or excessive, we may charge a reasonable fee or decline it, and we will explain why (Art. 12(5)).
Your right to complain
You can complain to a supervisory authority, in particular in the country where you live, work or where the alleged infringement took place (Art. 77 GDPR):
Elsewhere in the EU, you can find your authority on the European Data Protection Board’s list of members. We’d appreciate the chance to sort out your concern first, but you don’t have to contact us before going to an authority or a court (Art. 79 GDPR).
11Children
Our services are for businesses and professionals. They are not directed at children, and we don’t knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, contact us and we will delete it.
12Other websites
Our site links to other websites, such as Instagram and the sites of clients we’ve worked with. We aren’t responsible for how they handle personal data, so please read their own privacy policies.
13Changes to this policy
We review this policy at least once a year and whenever our processing changes. The date and version at the top show when it last changed. If a change significantly affects how we use your data, we will tell our clients and active contacts directly before it takes effect.