Skip to main content
This page answers the questions procurement, legal, and security teams ask most often when evaluating botBrains. For anything not covered here, email legal@botbrains.io.

Which agreements govern botBrains?

DocumentPurpose
Commercial offerGoverns commercial terms (pricing, scope, SLAs), collateral agreements
Terms of ServiceThe contract governing your use of the platform
Data Processing AgreementGoverns how botBrains processes personal data on your behalf

Is botBrains a controller or processor?

You are the controller of the personal data in your conversations, and botBrains acts as your processor. botBrains in turn engages subprocessors to deliver the service. The Data Processing Agreement sets out the details of this relationship.

Does botBrains provide a privacy policy?

botBrains is processor, not controller of customer data on the botBrains platform. The controller needs to publish a privacy policy for their users. We cannot publish a privacy policy for you. You, the controller, needs to inform your end-user about the use of their personal data. Please refer to How to Privacy Policy for guidance on what to include in your privacy policy. Data outside of the botBrains Platform (platform.botbrains.io), namely the websites, botBrains is controller of the data and publishes a Privacy Policy.

Where does botBrains store and process data?

botBrains stores all application data in Germany. We process your data within the EU, with our server infrastructure located in Germany. AI inference runs in the EU. No third-country transfer takes place. See Subprocessors for the full list of services and data locations. The primary hosting providers are Hetzner and AWS. We use Vercel for the static website serving, Hetzner for the API, background workers, and caching servers, and AWS for database and object storage.

Where is AI inference performed?

botBrains uses subprocessors to run AI inference. We enforce 3 requirements on all model hosting subprocessors:
  1. Data residency in the EU
    Data must be stored in the EU, and no third-country transfer may take place. We opt for Zero Data Retention Agreements where offered to minimize data retention. Context-caching and short-term caching for inference is allowed, but no long-term storage of data is permitted.
  2. Inference residency in the EU
    It’s not sufficient to proxy from an EU-intake server to a non-EU inference server. Processing must happen in the EU.
  3. Model training is prohibited
    Model training on botBrains-sent data is prohibited.
We currently run inference on OpenAI Enterprise EU data and inference residency and have a Zero Data Retention Agreement in place. We also use Azure OpenAI Service with regional endpoints for EU-bound storage and inference. We also run inference via AWS Bedrock in Frankfurt.

Is botBrains GDPR compliant?

Yes. botBrains supports GDPR and DSGVO compliance through EU data residency, a Data Processing Agreement, and documented security measures. See GDPR for the full Q&A.

Is botBrains EU AI Act compliant?

The EU AI Act sets obligations for providers and deployers of AI systems. botBrains designs its AI agents to support these obligations, including the transparency requirement to make clear when users are interacting with an AI agent rather than a human. See EU AI Act for details.

Which subprocessors does botBrains use?

The current list, including each subprocessor’s purpose and data location, is on the Subprocessors page.

Is botBrains ISO 27001 or SOC 2 Type II certified?

We’re preparing for ISO 27001. See ISO 27001 for our ISMS and policies, and Certification Roadmap for other standards.

How does botBrains keep my data safe?

botBrains operates an information security management system (ISMS) aligned to ISO 27001. A selection of the measures in place:
  • Secured infrastructure. Hosting on ISO 27001-certified providers and data centers.
  • EU data residency. botBrains stores and processes customer data in the EU. All subprocessors sign DPAs that preserve your exclusive controller rights.
  • Encryption everywhere. AES-256 at rest and TLS 1.3 in transit, including backups.
  • Least-privilege access. Multi-factor authentication and role-based access restrict production access to what each person needs.
  • Separated environments. Fully separate staging and production environments, and testing never uses production data.
  • Threat detection. Intrusion detection and active vulnerability monitoring across our production systems.
  • Resilient backups. Continuous Point-in-Time Recovery and cross-region backups within the EU.
  • Monitored availability. Uptime published on status.botbrains.io, backed by tested backups and disaster recovery / business continuity plan.
For the complete set of controls, see our technical and organizational measures and policies.

Where is security documentation available?

Please see our technical and organizational measures and our policies for details on our security practices. To request a signed agreement or a completed security questionnaire email support@botbrains.io.

How do I report a security vulnerability?

See security.txt and our Responsible Disclosure Policy for how to report a vulnerability.