1-) Purpose Of Policy
This Policy has been updated to comply with the requirements of a new data privacy law known as the EU General Data Protection Regulation (“GDPR”). Specifically, if you use the Service in connection with End-Users in the European Economic Area or Switzerland, the terms of the Data Processing Addendum (available here: https://botanalytics.co/dpa) apply to your use of the Service.
Do not hesitate to contact us at firstname.lastname@example.org if you have any questions or want to discuss this Policy.
2-) INFORMATION WE COLLECT AND HOW WE USE IT
Required Information You Voluntarily Provide Us.
When you sign up for an account as a user of the Service, you will be required to provide us with various information that, on its own or in combination with other information, used to identify you as an individual (“Personal Data”).
To access the Service, you will be required to provide us with various information, including your name, email address, bot name(s), and password.
Optional Information You Voluntarily Provide Us.
In addition to the required information that you provide to Botanalytics to create an account, there are various pieces of information you can, or may in the future be able to, choose to provide through the Service.
Such information may include communications that occur through the Service or outside of the Service between you and Botanalytics.
Further, now or in the future, we may allow you to provide us with access to additional information and data through integrations with third party goods and services.
Through the Service, we will provide you with a token, which will integrate your chatbots into the Service and collect Personal Data and other information from you and your End-Users, including all transcripts of conversations between your End-Users and your bots, your End-User’s pictures, timestamps, channels, groups, teams, usernames, message types, chat id’s, avatars, SMS information, and other similar information regarding communications between your End-Users and your bots, which in many cases may include sensitive Personal Data (“End-User Data”).
Information About You Collected Automatically As You Use The Service.
In addition to the information that you provide to us voluntarily, Botanalytics may automatically collect information through the Service about how you use and interact with the Service and other similar activities.
Other Data We Collect.
Do Not Track Signals.
To the extent that we receive any Do-Not-Track signals, we reserve the right to not comply with them.
3-) PURPOSES OF COLLECTION AND LEGAL BASES FOR USE
We use the Personal Data, and specifically End-User Data, described above primarily for providing you with the core aspects of the Service, namely to provide you with analytics and metrics about the behavior and performance of your chatbots and related information.
However, we also use your Personal Data, or aggregated and/or anonymized End-User Data (but not End-User Data that can be used to identify your End-Users), for our own purposes of understanding our users and how they use the Service, improving the Service over time, and to send you information about Botanalytics and the Service. By using the Service, you consent to these additional uses, including us sending you communications for marketing purposes about our business, such as to contact you about promotions, updates, and features of the Service.
The legal grounds for our processing your Personal Data for the purposes above are:
- first and foremost, you provided your consent by agreeing to this Policy, which you may withdraw at any time by emailing us at email@example.com;
- it is necessary for our contractual relationship;
- the processing is necessary for us to comply with our legal or regulatory obligations; and/or
- the processing is in our legitimate interest as a provider of the Services (for example, to protect the security and integrity of our systems and to provide you with customer service and the core functionality of the Service).
4-) HOW WE SHARE YOUR INFORMATION
First of all, we do not sell or share your Personal Data or End-User Data with advertisers. We also do not share Personal Data or End-User Data with other third parties except to the extent that it is in furtherance of the Service, or as described in this Policy.
Information Shared By You Through The Service
You may, now or in the future, be able to choose to voluntarily share information collected through the Service through email, or other means of communication. In addition, as described in this Policy, some aspects of the functionality of the Service will require us to share your personally identifiable information, including information about or from your End-Users, with third parties. For example, we may share your information with third parties that help us to analyze End-User Data in order to provide you with analytics and metrics to improve the performance of your bots.
To be able to effectively provide you with the Service, and to improve the functionality of the Service, we may disclose Personal Data and End-User Data to our employees, contractors, and agents to the extent that such persons or entities have a need-to-know such information in furtherance of the Service.
We work with third party service providers to provide website, application development, hosting, maintenance, data processing, customer service, and other services for us in furtherance of the Service. These third parties may have access to or process your Personal Data and End-User Data as part of providing those services for us. However, we limit the information provided to these service providers to that which is reasonably necessary for them to perform their functions.
Sale of Company or Assets.
In the event that we sell all or substantially all of our company or its assets, including the Personal Data and End-User Data collected through our Service, we may transfer your information, upon reasonable notice to you, to the acquiring company.
Other Third Parties.
In addition to our practices described above, we may share your Personal Data or End-User Data if we have a good-faith belief that such action is necessary to (1) comply with the law (see the section below on “Government Requests”), (2) protect and defend the rights or property of Botanalytics, or (3) prevent an emergency involving danger of death or serious physical injury to any person. We will only share your Personal Data for the foregoing reasons to the extent permitted by GDPR.
5-) STORING YOUR INFORMATION
Duration of Storage of Personal Data.
We will store your Personal Data for as long as it is needed to provide the Service, however, we may not know if you have stopped using the Service so we encourage you to contact us if you are no longer using the Service. However, if required by applicable law, we may retain your Personal Data for such period as may be required by such law. To continue to provide an effective service, we may store non-Personal Data perpetually and may anonymize your Personal Data and store that anonymized information perpetually.
Additionally, as described in this Policy, we use third parties to provide the Service and do not have full control over their practices related to storage and retention of your Personal Data. However, we will work with such third parties to delete or modify your Personal Data to the extent required by GDPR and the EU-U.S. and Swiss-U.S. Privacy Shield Principles (“Privacy Shield”).
We use reasonable efforts to secure your Personal Data and End-User Data and to attempt to prevent the loss, misuse, and alteration of he information that we obtain from you. For example, we require our personnel to sign confidentiality agreements that extend to your Personal Data and End-User Data; and we restrict access to your Personal Data and End-User Data to individuals within and outside of Botanalytics who need access to such information to provide the Service. In addition, we rely on the technical safeguards provided by the third party vendors we use to host, store, and process your Personal Data and End-User Data. However, you acknowledge and agree that loss, misuse, and alteration may occur despite our efforts to protect your Personal Data and End-User Data. We are not responsible to our users or to any third party, including your End-Users, due to any such loss, misuse, or alteration, except to the extent required by GDPR, Privacy Shield, or other applicable law.
6-) YOUR CHOICES
You can change some of your Personal Data through the account settings provided on the Service. In addition, if you wish to access, receive a copy of, change or delete the Personal Data we hold about you, you may contact us as described at the end of this Policy.
You may withdraw the consent granted in this Policy for us or our Partners to use the Personal Data described in this Policy by contacting us as described at the end of this Policy. Please note that if you do so, it will not affect the lawfulness of the use of your Personal Data based on your prior consent.
In addition, you may contact us as described at the end of this Policy to request that we do not disclose your Personal Data to third parties (other than those that are acting as our agent to perform tasks on our behalf, such as data processors) or to request that your Personal Data not be used for a purpose that is materially different from the purposes for which it was originally collected or for purposes subsequently authorized by you.
If you receive commercial email from us, you may unsubscribe at any time by following the instructions contained within the email. You may also opt-out from receiving commercial email from us, and any other promotional communications that we may send to you from time to time, by contacting us as described at the end of this Policy. Please be aware that if you opt-out of receiving commercial email from us or otherwise modify the nature or frequency of promotional communications you receive from us, even after you opt-out from receiving commercial messages from us, you may continue to receive administrative messages from us regarding the Service.
Upon receipt of any of the above request(s), we will use reasonable efforts to reflect any changes you request in our databases to the full extent required by GDPR, Privacy Shield, or other applicable law.
If you are not happy with how we have attempted to resolve your complaint, you may contact the relevant data protection authority.
7-) INTERNATIONAL VISITORS AND DATA TRANSFERS
The Service is hosted in the United States and is intended for visitors located within the United States as well as users located outside of the United States. If you choose to use the Service from the European Economic Area, Switzerland, or other regions of the world with laws governing data collection and use that may differ from U.S. law, then please note that you are transferring your Personal Data and End-User Data outside of those regions to the United States for storage and processing. By providing any information, including Personal Data about you or your End-Users, on or to the Service, you consent to such transfer, storage, and processing.
Botanalytics participates in, and complies with Privacy Shield regarding the collection, use, sharing, and retention of personal information from the European Economic Area and Switzerland. If there is any conflict between the terms in this Policy and Privacy Shield Principles, then Privacy Shield shall govern. Our participation in Privacy Shield applies to all Personal Data that is subject to this Policy and is received from the European Economic Area or Switzerland. We will comply with Privacy Shield in respect of such Personal Data.
To learn more about Privacy Shield, please visit: https://www.privacyshield.gov/. To view a list of companies that have certified that they adhere to Privacy Shield, please visit: https://www.privacyshield.gov/list.
As part of our participation in Privacy Shield, if you have a dispute with us about our adherence to Privacy Shield, we will seek to resolve it through JAMS, an independent alternative dispute resolution body based in the United States. You can learn more about JAMS at the following URL: https://www.jamsadr.com/.
In certain circumstances, you may have the right to invoke binding arbitration under Privacy Shield, as described in Annex I to the Privacy Shield Principles, which can be found at the following URL: https://www.privacyshield.gov/article?id=ANNEX-I-introduction.
Privacy Shield participants, such as Botanalytics, are subject to the investigatory and enforcement powers of the US Federal Trade Commission and other authorized statutory bodies. Under certain circumstances, we may be liable for the transfer of personal data that we receive and subsequently transfers to a third party, as described in Privacy Shield.
As described in this Policy, we may share Personal Data with third parties and may be required to disclose information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
8-) GOVERNMENT REQUESTS
From time to time, we may receive requests from government agencies to obtain information about our users. In handling such government requests, we greatly value the privacy of Personal Data. While we may be required to turn over user information at times, we will strive to require a search warrant or subpoena, to the extent that we can reasonably demand such warrant or subpoena, before we turn over Personal Data about you or your End-Users and we will also strive to notify users when we receive government requests about their data.
9-) THIRD PARTY SERVICES AND PRACTICES ARE BEYOND OUR CONTROL
Our Service may utilize numerous third party services as part of the functionality of the Service, such as hosting services, analytics providers, communications services, and other vendors; and we may share your Personal Data and End-User Data with third parties to the extent explained in this Policy. We have no control over such third parties, except to the extent required by GDPR and Privacy Shield. Thus, we make no guarantees about, and assume no responsibility for the information, services, or data/privacy practices of third parties, except to the extent required by GDPR and Privacy Shield. We encourage you to review the privacy practices of such third parties.
10-) CHANGES TO THIS POLICY
11-) PLEASE REACH OUT TO US WITH ANY QUESTIONS OR FEEDBACK
If you have any questions about this Policy or our Service, please feel free to contact us by email at firstname.lastname@example.org, or by mailing us at the following address:
340 Fremont Street, San Francisco, California 94105, United States
12-) DATA PROTECTION OFFICER
In addition, we have appointed a Data Protection Officer (“DPO”). Our DPO can be contacted directly by email at DPO@botanalytics.co or by mail at:
ATTN: Data Protection Officer
340 Fremont Street,
San Francisco, CA 94105