Scope
This policy applies to all information that botBrains creates, receives, stores, or transmits in any form (electronic or physical), and to every system that processes it. A system inherits the classification of the highest-sensitivity data it holds.Classification levels
botBrains uses four levels. When the level isn’t obvious, choose the higher one.Labeling
Repository and platform context establishes the level for most data: GitHub private repositories hold Confidential source code, the production multi-tenant database and object storage hold Customer Data, and the shared password manager holds Confidential secrets. Personnel apply an explicit “Confidential” label only when a document leaves its default context, for example a security report shared outside the platform.Handling rules
Handling requirements increase with sensitivity. The Cryptography Policy defines encryption standards once; retention periods and secure deletion live in the Data Retention Policy.
botBrains processes Customer Data only within the EU, using the subprocessors listed at Subprocessors, with no transfer to a third country.