Privacy Policy

Date: July 5th, 2026

The protection of your personal data is very important to us. Below we explain what personal data we process when you visit our website and in the course of our business, for what purposes, and on what legal basis. The processing and storage of your data takes place exclusively in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications-Telemedia Data Protection Act (TDDDG).

Scope: This Privacy Policy applies solely to our public website (www.botbrains.io) and to our business relationships with customers and partners. It does not apply to platform.botbrains.io or to any Customer Data that we process on behalf of our business customers. Our processing of Customer Data is governed by the Data Processing Agreement (B2B), available at docs.botbrains.io/data-processing-agreement.

Responsible Body

In accordance with Art. 4 para. 7 GDPR, the responsible party (controller) is:

botBrains UG (haftungsbeschränkt)
Osloer Str. 83
13359 Berlin
Germany

General contact: support@botbrains.io
Data protection requests: legal@botbrains.io

Further information can be found in our Imprint. All employees are obliged to maintain confidentiality and to handle your data in accordance with data protection law.

Data Protection Officer

We have not appointed a Data Protection Officer, as we are not legally required to do so. For any data protection matters or to exercise your rights, please contact us at legal@botbrains.io.

Encryption (TLS)

To protect your data against unauthorised access, we use technical and organisational measures and TLS encryption on our website. Your data is transmitted between your browser and our servers in encrypted form. You can recognise an encrypted connection by the lock symbol in your browser and the address beginning with https://.

Categories of personal data we process

Depending on how you interact with us, we process the following categories of personal data. The specific data, purpose, legal basis and recipients are described in the sections below.

  • Data you provide to us — e.g. when you contact us, book a demo or enter into a business relationship: name, business email address, telephone number, job title, employer, and the content of your communications.
  • Data collected automatically when you use our website: IP address, browser and device information, date and time of access, requested pages and referrer.
  • Data received from third parties: business-contact data from lead-generation and sales-intelligence providers, as described in Section B.

A. Processing on this website

1. Access data, server logs and hosting (Vercel)

Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing device. This includes the IP address, the date and time of access, the type of request, browser type and version, the operating system, and the referrer (the source of the access). The legal basis is our legitimate interest pursuant to Art. 6 para. 1 lit. f) GDPR in a reliable, secure and high-performance provision of our website (e.g. defence against attacks and ensuring a smooth connection). Log data is only stored for a longer period in the event of attacks or other legal violations, in order to preserve evidence.

Our website is hosted and delivered via the global edge network of Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. We have concluded a data processing agreement with Vercel pursuant to Art. 28 GDPR (vercel.com/legal/dpa). As Vercel Inc. is a US company, data may be transferred to the USA. The transfer is based on the EU standard contractual clauses pursuant to Art. 46 GDPR that are incorporated into Vercel's DPA; in addition, Vercel Inc. self-certifies under the EU-U.S. Data Privacy Framework. Further information: vercel.com/legal/privacy-policy.

2. Error and performance monitoring (Sentry)

To detect, diagnose and resolve technical errors and to keep our services stable and secure, we use Sentry, a service of Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. When an error occurs, Sentry may process technical data such as your IP address, browser and device information, and details of the error event. The legal basis is our legitimate interest pursuant to Art. 6 para. 1 lit. f) GDPR in the reliability and security of our services. We have concluded a data processing agreement pursuant to Art. 28 GDPR (sentry.io/legal/dpa) and use Sentry's EU data region (Frankfurt, Germany). As the contracting entity is based in the USA, data may be transferred there; Functional Software, Inc. is certified under the EU-U.S. Data Privacy Framework (adequacy decision, Art. 45 GDPR), supplemented by standard contractual clauses pursuant to Art. 46 GDPR. Sentry's EU representative is Sentry Software Netherlands B.V., Schiphol Boulevard 359, 1118 BJ Amsterdam, Netherlands. Further information: sentry.io/privacy.

3. Booking appointments (Calendly)

To let you book meetings and product demos, we use Calendly, a service of Calendly LLC, 115 E Main St, Ste A1B, Buford, GA 30518, USA. When you schedule an appointment, the data you provide (such as your name, email address, chosen time slot and any details you enter in the booking form) is processed to arrange and confirm the meeting. The legal basis is the performance of pre-contractual measures and the contract pursuant to Art. 6 para. 1 lit. b) GDPR and our legitimate interest in efficient scheduling pursuant to Art. 6 para. 1 lit. f) GDPR. We have concluded a data processing agreement pursuant to Art. 28 GDPR (calendly.com/legal/data-processing-addendum). As Calendly LLC is a US company, data may be transferred to the USA on the basis of the EU standard contractual clauses pursuant to Art. 46 GDPR. Calendly's EU representative is DPO Centre Europe, Friedrichstraße 88, 10117 Berlin, Germany. Further information: calendly.com/legal/privacy-notice.

4. Cookies

We use technically necessary cookies that are required to operate our website and to remember your settings. The legal basis for these cookies is Art. 6 para. 1 lit. f) GDPR and § 25 para. 2 TDDDG; they do not require your consent.

Beyond that, our website integrates third-party services (such as Google reCAPTCHA, Calendly and our own chat assistant) that may store cookies or similar technologies which are not strictly necessary. These are only loaded once you have given your consent. The legal basis for this is your consent pursuant to Art. 6 para. 1 lit. a) GDPR and § 25 para. 1 TDDDG. You can give, withdraw or change your consent at any time with effect for the future via the cookie settings in our cookie policy or the consent banner. Withdrawing your consent does not affect the lawfulness of processing carried out before the withdrawal.

To obtain and document this consent, we use the consent management platform Cookiebot, a service of Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark. Cookiebot stores a technically necessary cookie to record your consent choices. A current and automatically updated list of all cookies used, including their purpose and storage duration, can be found in our cookie policy. You can additionally delete cookies at any time via your browser settings and configure your browser to refuse cookies; in this case, not all functions of our website may be available.

5. botBrains platform

Our website may link to or embed our own botBrains platform (platform.botbrains.io). Any data you submit through the platform, and any Customer Data processed there, is governed by our Data Processing Agreement (B2B) rather than this Privacy Policy. See docs.botbrains.io/data-processing-agreement.

B. Data processing of customers and business partners

In the context of initiating and performing business relationships, we process personal data of contact persons at customers, prospects, partners and suppliers. Depending on the purpose, the legal basis is the performance of (pre-)contractual measures pursuant to Art. 6 para. 1 lit. b) GDPR, the fulfilment of legal obligations pursuant to Art. 6 para. 1 lit. c) GDPR (e.g. tax retention obligations), and our legitimate interest pursuant to Art. 6 para. 1 lit. f) GDPR in conducting and developing our business relationships and communicating with our contacts. Where we receive your data from third parties (e.g. lead-generation providers), the origin is described in the relevant section below. For processing based on Art. 6 para. 1 lit. f) GDPR, you have the right to object pursuant to Art. 21 GDPR.

1. Customer relationship management (HubSpot, Close)

We store and use contact details and communication histories of customers, prospects and partners in order to initiate and manage our business relationships. Processing is based on (pre-)contractual measures pursuant to Art. 6 para. 1 lit. b) GDPR and our legitimate interest pursuant to Art. 6 para. 1 lit. f) GDPR.

As our primary CRM we use HubSpot. For customers based in Germany, the contracting entity is HubSpot Germany GmbH, Am Postbahnhof 17, 10243 Berlin, Germany; the underlying platform is operated by its parent company HubSpot, Inc., 2 Canal Park, Cambridge, MA 02141, USA. We use HubSpot's EU data hosting (Frankfurt, Germany) and have concluded a data processing agreement pursuant to Art. 28 GDPR (legal.hubspot.com/dpa). Insofar as data is transferred to the USA, HubSpot, Inc. is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR), supplemented by standard contractual clauses pursuant to Art. 46 GDPR. Further information: legal.hubspot.com/privacy-policy.

In addition, we use the CRM and sales-communication tool Close, operated by Elastic, Inc. (doing business as Close), San Francisco, CA, USA, to manage leads, contacts and outreach. We have concluded a data processing agreement pursuant to Art. 28 GDPR (close.com/gdpr). As Elastic, Inc. is a US company, data may be transferred to the USA on the basis of the EU standard contractual clauses pursuant to Art. 46 GDPR. Further information: close.com/privacy.

2. Business email and video meetings (Google Workspace)

For business email (Gmail), calendars and video meetings (Google Meet), we use Google Workspace. The contracting entity for customers in the EEA is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, D04 E5W5, Ireland; the service is operated by its parent company Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. In this context we process contact and identification data, the content and metadata of emails, calendar entries, and, in the case of Google Meet, audio, video, chat and connection data of the participants. The legal basis is Art. 6 para. 1 lit. b) GDPR for direct contractual partners and Art. 6 para. 1 lit. f) GDPR for other business contacts, our legitimate interest being efficient business communication. We have concluded a data processing agreement pursuant to Art. 28 GDPR (cloud.google.com/terms/data-processing-addendum). Insofar as data is transferred to the USA, Google LLC is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR), supplemented by standard contractual clauses pursuant to Art. 46 GDPR. Further information: policies.google.com/privacy. You are not obliged to communicate with us via Google Meet; you can also reach us by email or telephone.

3. Sales intelligence and lead generation (Apollo.io)

To identify and enrich business contacts and to optimise our sales activities, we use Apollo.io, operated by Zenleads Inc. (d/b/a Apollo.io), 440 N Barranca Ave, Unit #4750, Covina, CA 91723, USA. In this context we process business-contact data such as name, business email address, telephone number, job title and employer, which may originate from Apollo's B2B database as well as from our own records. The legal basis is our legitimate interest pursuant to Art. 6 para. 1 lit. f) GDPR in efficient, targeted business development. You can object to this processing at any time pursuant to Art. 21 GDPR. We have concluded a data processing agreement pursuant to Art. 28 GDPR (apollo.io/dpa). As Zenleads Inc. is a US company, data may be transferred to the USA; Apollo is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR), supplemented by standard contractual clauses pursuant to Art. 46 GDPR. Apollo's EU representative is Lionheart Squared (Europe) Ltd. Further information: apollo.io/privacy-policy.

4. Internal documentation and collaboration (Notion)

We use the Notion platform of Notion Labs, Inc., 685 Market Street, San Francisco, CA 94105, USA, for internal organisation, documentation and collaboration. We do not use the Notion AI function. Insofar as personal data is processed in this context, this is based on our legitimate interest pursuant to Art. 6 para. 1 lit. f) GDPR in the efficient organisation of internal processes. We have concluded a data processing agreement pursuant to Art. 28 GDPR (notion.com/help/gdpr-at-notion). As Notion Labs, Inc. is a US company, data may be transferred to the USA; Notion Labs, Inc. is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR), supplemented by standard contractual clauses pursuant to Art. 46 GDPR. Further information: notion.com/trust/privacy-policy.

5. Asynchronous video messages (Loom)

To communicate with customers and partners, we use Loom to record and share asynchronous video messages (screen and/or webcam recordings with audio), including automatically generated transcripts. Loom is operated by Loom, Inc., an Atlassian company; the certifying parent entity is Atlassian, Inc., 350 Bush Street, Floor 13, San Francisco, CA 94104, USA. The legal basis is our legitimate interest pursuant to Art. 6 para. 1 lit. f) GDPR in clear and efficient communication. We have concluded a data processing agreement pursuant to Art. 28 GDPR (atlassian.com/legal/data-processing-addendum). Insofar as data is transferred to the USA, Atlassian, Inc. is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR), supplemented by standard contractual clauses pursuant to Art. 46 GDPR. Atlassian's EU representative is Atlassian B.V., Singel 236, 1016 AB Amsterdam, Netherlands. Further information: atlassian.com/legal/privacy-policy.

6. AI-assisted processing (OpenAI, Anthropic)

In our sales, marketing and partner workflows, we use large language models to draft, summarise, translate, classify and analyse text-based business content. For this purpose we use ChatGPT / the API of OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland (parent: OpenAI OpCo, LLC, San Francisco, USA), and Claude / the API of Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 E5F6, Ireland (parent: Anthropic, PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA).

In this context, the content we submit as prompts may contain business-contact personal data (such as names, email addresses and company information of contacts at customers, prospects and partners), together with the generated outputs. The legal basis is our legitimate interest pursuant to Art. 6 para. 1 lit. f) GDPR in efficient content processing; you can object at any time pursuant to Art. 21 GDPR. Both providers process the submitted content on our documented instructions as processors and, under their commercial/API terms, do not use business or API content to train their models by default.

We have concluded data processing agreements pursuant to Art. 28 GDPR with both providers (openai.com/policies/data-processing-addendum, anthropic.com/legal/data-processing-addendum). Insofar as data is transferred to the USA, the transfer is based on the EU standard contractual clauses pursuant to Art. 46 GDPR. Further information: openai.com/policies/eu-privacy-policy and anthropic.com/legal/privacy.

7. Direct marketing and communications

We send business-related communications — such as sales outreach, product and service information, event invitations and, where applicable, a newsletter — to contacts at organisations that we consider to have a professional interest in our services. For existing customers and for business-to-business contacts, the legal basis is our legitimate interest in direct marketing pursuant to Art. 6 para. 1 lit. f) GDPR (see also recital 47 GDPR); where the law requires prior consent, we rely on your consent pursuant to Art. 6 para. 1 lit. a) GDPR. For this purpose we process business-contact data such as your name, business email address, telephone number, job title and employer.

You can object to the processing of your data for direct marketing at any time, with effect for the future and free of charge — either via the unsubscribe link in our messages or by contacting legal@botbrains.io. After you object, we will no longer process your data for these purposes (Art. 21 para. 2 and 3 GDPR).

8. Recipients, storage periods and retention

Within the scope of the contractual relationship, we may commission additional processors who have access to your personal data; compliance with data protection law is ensured contractually. We store personal data only for as long as is necessary for the purposes described above. Unless a longer statutory retention period applies, we use the following retention periods:

  • Server log data: deleted promptly; retained for a longer period only in the event of a security incident or legal violation, in order to preserve evidence.
  • Appointment bookings and general enquiries: deleted no later than 12 months after the matter has been concluded, unless a business relationship arises from it.
  • Prospect and lead data (CRM, sales intelligence): processed until you object, and reviewed for continued relevance at the latest every two years.
  • Data from an ongoing business relationship: for the duration of the relationship with the customer or partner.
  • Contract, invoicing and tax-relevant data: retained for the statutory commercial and tax retention periods under German law (generally between 6 and 10 years, cf. § 257 HGB, § 147 AO), after which it is deleted.

Where we process your data on the basis of consent, or where you assert data subject rights, we also store the relevant data in order to demonstrate our compliance with the GDPR under our accountability obligation pursuant to Art. 5 para. 2 GDPR. Thereafter, your data is deleted or anonymised.

Social media presence

We maintain a company presence on LinkedIn (linkedin.com/company/botbrains-io). In addition, selected employees of botBrains UG (haftungsbeschränkt) maintain professional profiles on LinkedIn. LinkedIn is operated by the European subsidiary LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland; the parent company LinkedIn Corporation is based in the USA.

When you interact with our presence, the personal data you provide (such as comments, likes or messages) is published by the platform. We may share your content and contact you via the platform. The legal basis for this processing is our legitimate interest in public relations and communication pursuant to Art. 6 para. 1 lit. f) GDPR. The platform also provides us with anonymised statistics about the use of our page (Page Insights); for this, we and LinkedIn act as joint controllers pursuant to Art. 26 GDPR (agreement: legal.linkedin.com/pages-joint-controller-addendum).

As a separate controller, the platform operator carries out its own data processing, over which we have only limited influence, and uses web-tracking methods regardless of whether you are logged in. Personal data may be processed on servers outside the EU, in particular in the USA; LinkedIn Corporation is certified under the EU-U.S. Data Privacy Framework. Further information can be found in LinkedIn's privacy policy: linkedin.com/legal/privacy-policy. Providing your data is neither legally nor contractually required; if you do not wish to interact with us via social media, you can contact us using the details above.

Rights of data subjects

In accordance with Art. 15 GDPR, you have the right to obtain information about the personal data we store about you. Where the legal requirements are met, you also have the right to rectification (Art. 16 GDPR), erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR), as well as the right to data portability (Art. 20 GDPR).

Where processing is based on Art. 6 para. 1 lit. e) or f) GDPR, you have the right to object pursuant to Art. 21 GDPR. Where processing is based on consent pursuant to Art. 6 para. 1 lit. a) GDPR, you can revoke your consent at any time with effect for the future, without affecting the lawfulness of processing carried out before the revocation.

To exercise your rights, please contact us at legal@botbrains.io; we will respond within the period prescribed by applicable law. You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), Alt-Moabit 59-61, 10555 Berlin, mailbox@datenschutz-berlin.de.

No automated decision-making

We do not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.

Provision of your data

Unless stated otherwise in the sections above, the provision of your personal data is neither legally nor contractually required nor necessary for the conclusion of a contract. Failing to provide your data may mean, for example, that we are unable to respond to your enquiry.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our processing activities or in the applicable legal requirements. The current version always applies and is published on this page; it is identified by the date shown at the top. In the event of material changes, we will take appropriate steps to inform you. We recommend that you review this Privacy Policy regularly.

This Privacy Policy was last updated on July 5th, 2026. If you have any questions about our privacy practices, please contact us at legal@botbrains.io.