Welcome to Botxify. We operate an AI-powered chatbot platform that helps businesses engage their customers smarter. This Privacy Policy explains how Botxify ("we", "our", or "us") collects, uses, stores, and protects information about you when you visit our website or use our services.
By using Botxify, you agree to the practices described in this policy. If you disagree with anything here, please discontinue use and contact us — we're happy to answer any questions.
This policy is governed by the Digital Personal Data Protection Act, 2023 ("DPDP Act") of India. Under that Act you are a Data Principal — the individual the personal data is about — and Botxify acts in one of two roles depending on whose data is involved:
- Data Fiduciary — for the account data of merchants who register with Botxify. We decide why and how that data is processed, and we are directly answerable to you for it.
- Data Processor — for the data of shoppers who chat with a bot operated by one of our merchants. The merchant decides why and how that data is processed; we process it on their instructions under a written agreement. If you are a shopper, direct your requests to the merchant whose website you used, or to us and we will route them.
Our lawful basis for processing is your consent under Section 6 of the DPDP Act, recorded when you register or when you begin a chat, and certain legitimate uses permitted by Section 7.
Our core commitment
We never sell your personal data to third parties. Your data is used solely to operate and improve the Botxify platform.
Account & identity
- Name and email address when you register
- Billing name and payment method details (processed securely by our payment provider)
- Profile photo or avatar if you choose to upload one
- Support correspondence when you contact our team
Platform usage
- Chatbot conversations and interaction logs generated on your deployed widgets
- Knowledge base content you upload (documents, URLs, files)
- Feature usage patterns and in-app actions
- Analytics data about chatbot performance (message volume, response quality scores)
Messaging channels (WhatsApp, Instagram, Facebook Messenger)
- When a business connects its WhatsApp, Instagram, or Facebook Messenger account, we receive messages sent to that business by its customers, along with the sender's platform identifier (such as a WhatsApp phone number or a Meta page-scoped ID) and display name where provided
- This data is received from Meta Platforms, Inc. via its official Business APIs and is used solely to generate and deliver the business's chatbot replies
- Channel access tokens granted by the business are stored encrypted and used only to send and receive messages on that business's behalf
Technical & device data
- IP address and approximate geolocation
- Browser type, operating system, and device identifiers
- Pages visited, referral URLs, and session duration
- Error reports, crash logs, and performance metrics
- Cookies and similar tracking technologies (see Section 08)
Running the platform
- Create and manage your account and subscription
- Process payments and issue invoices
- Power your AI chatbots and knowledge-base retrieval
- Deliver customer support and technical assistance
Communications
- Send transactional emails (receipts, password resets, security alerts)
- Respond to your support requests and inquiries
- Share product updates and new features — you may unsubscribe at any time
Product improvement
- Analyse usage patterns to improve reliability and features
- Evaluate and improve the quality of AI responses — we do not use your data to train public AI models
- Detect and prevent fraud, abuse, and security threats
- Comply with legal obligations
We do not sell your data
We do not sell, rent, or trade your personal information to any third party for marketing or commercial purposes — ever.
We may share data only in these limited circumstances:
- Service providers: Trusted vendors (payment processors, cloud infrastructure, email delivery) who process data solely on our behalf and under strict confidentiality agreements.
- Legal requirements: When required by law, court order, or to protect the rights and safety of Botxify, our users, or the public.
- Business transfers: In the event of a merger, acquisition, or sale of assets — you will be notified before any such transfer affects your data.
- Your explicit consent: Any other sharing requires your prior, informed agreement.
Protecting your data is a top engineering priority. We implement multiple layers of security:
- All traffic encrypted in transit over HTTPS (TLS); passwords stored only as salted hashes
- Database row-level security (RLS) enforcing strict tenant data isolation
- Ongoing security reviews and hardening of our infrastructure
- Access controls — data is accessed only as needed to operate and support the service
- Application logging and monitoring to detect abuse and investigate incidents
Data retention
- Active account data is retained while your account remains open
- Conversation logs are retained for as long as needed to provide the service, and deleted on request
- Billing records are retained as long as required for tax and legal compliance
- You may request deletion of your data at any time (see Your Rights)
Regardless of where you are in the world, you have meaningful rights over your personal data. You can exercise these at any time by emailing [email protected]:
- Access (DPDP §11): Obtain a summary of the personal data we hold about you and how it is processed.
- Correction and erasure (DPDP §12): Ask us to correct inaccurate or incomplete data, complete it, or erase it.
- Withdraw consent (DPDP §6(4)): Withdraw your consent at any time, as easily as you gave it. Withdrawal does not affect processing that already lawfully happened, and we stop processing within a reasonable time.
- Grievance redressal (DPDP §13): Raise a grievance with our Grievance Officer, whose details are below.
- Nominate (DPDP §14): Nominate another individual to exercise your rights on your behalf in the event of death or incapacity.
- Portability: Receive your data in a structured, machine-readable format.
- Marketing opt-out: Unsubscribe from promotional emails at any time via the link in any email.
How to withdraw consent. Merchants can withdraw consent and delete their account from account settings, or by emailing us. Shoppers can type "delete my data" to the chatbot at any time, which erases the conversation, any saved preferences, and any contact details captured during it.
We respond to verified requests within 30 days. If you are not satisfied with our response, you have the right to complain to the Data Protection Board of India under Section 13(3) of the DPDP Act.
You can request that your data be deleted from Botxify at any time. How to do it depends on who you are:
If you have a Botxify account (business user)
- Email [email protected] with the subject "Data Deletion Request" from your registered email address
- We will delete your account data, uploaded knowledge-base content, and associated chatbot data within 30 days and confirm by email
- Billing records may be retained where required for tax and legal compliance
If you chatted with a business's bot (end user)
- Message "forget me" to the chatbot on any channel (website widget, WhatsApp, Instagram, or Facebook Messenger) — your conversation profile and remembered preferences for that business are deleted
- Or email [email protected] identifying the business you chatted with and the phone number or account you used, and we will process the deletion within 30 days
If you used Facebook, Instagram, or WhatsApp login/messaging
- Data received through Meta platforms (your messages to a connected business and your platform identifier) is deleted on request via either method above
- You may also remove the business's connection to Botxify at any time through your Facebook or Instagram settings, which stops any further data being shared with us
We use a small set of cookies to make Botxify work reliably:
Essential cookies
- Session management and authentication tokens
- CSRF protection and security headers
- User preference settings (theme, language)
Analytics cookies
- Page view and feature usage analytics to improve the product
- Performance monitoring to identify and fix slow pages
You can manage or delete cookies through your browser settings at any time. Disabling essential cookies may affect platform functionality. Third-party cookies from our integrations (e.g., analytics providers) are governed by their own privacy policies.
Botxify relies on best-in-class providers to deliver a reliable, secure service. Each is contractually bound to protect your data:
- Payment processing: Razorpay — PCI DSS certified. We never store your card numbers.
- AI & LLM inference: OpenAI / Anthropic — conversations are processed under their API data-usage policies; data is not used to train public models.
- Messaging platforms: Meta Platforms, Inc. (WhatsApp Business API, Instagram Messaging, Facebook Messenger) — messages sent to and from connected business accounts pass through Meta's infrastructure and are also subject to Meta's own privacy policies.
- Cloud infrastructure: Our hosting providers store data in secure, access-controlled data centres.
- Email delivery: Transactional emails are routed through our email service provider under data processing agreements.
- Analytics: Aggregated, anonymised usage data only. We do not share identifiable user records.
Our platform may allow you to embed widgets on external sites. Those sites' own privacy policies govern data collected independently by them.
Botxify is operated from India and is governed by Indian law. Delivering the service requires transferring some personal data outside India to the processors below. Section 16 of the DPDP Act permits such transfers except to territories the Central Government restricts by notification; we do not transfer personal data to any restricted territory.
- OpenAI (United States) — Language model inference for chat replies
- Meta Platforms (United States) — WhatsApp, Instagram and Messenger delivery
Where you chat with a bot operated by a merchant using Botxify, the content of your conversation is sent to our language model provider to generate a reply. We do not sell personal data, and we do not permit our processors to use it for their own purposes.
Under Section 9 of the DPDP Act, a child is anyone under 18 years of age. Processing a child's personal data requires verifiable consent from a parent or lawful guardian, and both behavioural tracking and targeted advertising directed at children are prohibited outright.
We do not operate a parental consent mechanism, so Botxify accounts are not offered to anyone under 18. You confirm your age when you register. We do not knowingly collect personal data from children, and we do not build behavioural profiles where we know or reasonably suspect a user is a child. If you believe a child has provided us with information, please contact us immediately and we will delete it promptly.
We may update this Privacy Policy to reflect changes in our practices or applicable law. When we make material changes, we will notify you by email and/or by displaying a prominent notice in the platform at least 14 days before the change takes effect. We encourage you to review this page periodically. The date at the top of this page always shows when it was last revised.
Section 8(7) of the DPDP Act requires us to erase personal data once the purpose it was collected for is served. We enforce the following periods automatically, by a scheduled job — not on request:
- Chat conversations and messages — 365 days from the last activity in that conversation.
- Contact details captured in chat (leads) — 730 days from capture, since merchants rely on them to follow up.
- Saved shopper preferences — 365 days from the last time you were seen.
- Account data — for as long as your account is open, then deleted on closure.
Two things outlive the periods above, for reasons the law requires: records of consent, which are the evidence that our processing was lawful, and billing and tax records, which we must retain under Indian tax law. Both are kept only for that purpose and nothing else.
Section 8(6) of the DPDP Act requires us to report a personal data breach to both the regulator and the people affected. If a breach affects your personal data, we will:
- Notify the Data Protection Board of India in the form and manner prescribed;
- Notify you directly, by email and by notice in the platform, describing what happened, what data was involved, what we are doing about it, and what you can do to protect yourself;
- Notify CERT-In within 6 hours where the incident falls within its directions, which apply in parallel to and independently of the DPDP Act;
- Notify affected merchants without undue delay where the breach concerns data we process on their behalf, so they can meet their own obligations.
Section 13 of the DPDP Act gives you the right to a readily available means of raising a grievance, and requires us to publish the contact details of the person responsible for answering it.
Vijay Shinde
Email: [email protected]
Address: Narhe, Pune
We acknowledge every grievance and respond within 30 days.
The quickest way to reach the Grievance Officer is our grievance and rights request form, which gives you a reference you can use to track progress.
You must give us the opportunity to resolve your grievance before approaching the Data Protection Board of India. If our response does not resolve it, you may then complain to the Board under Section 13(3).