Core Policy

Privacy Policy

Effective date: 24 August 2026

BOTVEE (PRIVATE) LIMITED  ·  SECP: 0326112  ·  FBR: I510669  ·  PSEB: Z-25-19163/26

APPLICABLE LAWS

This Privacy Policy is issued under the laws of the Islamic Republic of Pakistan — the Prevention of Electronic Crimes Act 2016 (PECA), the Electronic Transactions Ordinance 2002 (ETO), and the principles of the Personal Data Protection Bill (as and when enacted), which Botvee voluntarily seeks to follow. Where Botvee processes personal data of individuals in other jurisdictions, we also seek to align with the EU GDPR 2016/679, UK GDPR and Data Protection Act 2018, the EU ePrivacy Directive 2002/58/EC, the California CCPA/CPRA, and Canada's PIPEDA — each only to the extent that law actually applies to a given processing activity.

BOTVEE (PRIVATE) LIMITED ("Botvee", "we", "us") provides a Software-as-a-Service platform that lets businesses build and deploy AI agents for customer support, lead capture, booking, and related automation across multiple channels ("the Service"). This Policy explains how we handle personal information in connection with our website (botvee.ai) and the Service. By accessing or using Botvee, you acknowledge the practices described here.

1

Who We Are and Our Two Roles

BOTVEE (PRIVATE) LIMITED ("Botvee", "we", "us") is incorporated under Pakistan's Companies Act 2017 (SECP: 0326112, PSEB: Z-25-19163/26, FBR: I510669), registered at Ward Number 3, Near Government Boys High School, Golarchi, District Badin, Sindh 72220, Pakistan.

Botvee acts in two capacities, and the distinction matters:

  • As a data controller — for the personal data of the people who register for and administer a Botvee account (our customers and their team members) and for visitors to botvee.ai.
  • As a data processor — for the personal data a customer's AI agent collects from that customer's own end-users. Here the customer is the data controller and Botvee processes such data only on the customer's documented instructions, under our Data Processing Agreement. Responsibility for the lawfulness of that data — including notices to and consents from end-users — rests with the customer.

This Policy primarily describes Botvee's activities as a controller. Our activities as a processor are governed by the DPA.

Privacy Officer

privacy@botvee.ai

Legal / DPA

legal@botvee.ai

Phone / WhatsApp

+92 319 3981020

Address

Golarchi, District Badin, Sindh 72220, Pakistan

2

Scope

This Policy applies to all users of botvee.ai worldwide. The specific legal rights available to an individual depend on their location and on which laws apply to them; a summary by jurisdiction appears in our International Data Rights page.

3

Information We Collect

3.1 Account and identity data (as controller)

Name, business name, email address, business information you provide, and a password. A phone or WhatsApp number is optional — you may add one during sign-up or later in your profile, and the account works without it; where you do provide one, we store it and may use it for account and service notifications. Passwords are stored only in hashed form and are never accessible in readable form to anyone, including Botvee staff. Date of birth may be collected solely to confirm you meet our minimum age requirement (Section 9).

3.2 Billing data (as controller)

We do not store full payment-card numbers, CVV codes, or bank-account details. Payments are processed by Stripe (PCI-DSS Level 1). We receive limited billing information such as transaction confirmation, amount, billing name, email, and invoice records.

3.3 Technical and usage data (as controller)

IP address, device and browser type, operating system, session identifiers, pages viewed, and referral source, collected when you use botvee.ai and the dashboard.

Approximate location. We derive an approximate country from the IP address. This is country-level only — we do not collect GPS, street address, or any precise location.

Login device recognition. To spot sign-ins from a device you have not used before, we store a device identifier for each login, together with a short description ("Chrome on Windows") and the first and last time it was seen. The identifier is a one-way hash of your browser family and your IP address — the IP itself is not stored in readable form, and the identifier cannot be reversed back into it. You can review and remove your recognised devices in your account security settings.

3.4 Content you upload to train your agent (as processor for the customer)

Documents, FAQs, and website URLs you provide so your agent can answer from your material. To build your agent, Botvee's own crawler fetches and processes the pages you point us to — this runs on Botvee's own infrastructure, and the page content is not handed to a third-party crawling service. This content is used to provide the Service for you and is not shared with unrelated third parties except as needed to provide the Service or to comply with law.

3.5 End-user conversation and interaction data (as processor for the customer)

Messages exchanged between your end-users and your deployed AI agents, interaction timestamps, and session identifiers. Depending on the channels you enable, this may include channel identifiers such as Telegram user IDs, WhatsApp phone numbers, Instagram/Messenger IDs (as those channels become available), and email addresses. Where a visitor sends a voice message, the audio may be transcribed to text using our AI provider. Chat content is processed through our AI provider to generate responses (see Section 4).

3.6 Lead, contact, booking, and order data (as processor for the customer)

Where you enable the relevant features, your agent may collect end-user names, emails, and phone numbers; capture and score leads; store customer notes and tags; book appointments; and — for e-commerce customers — process orders, confirm cash-on-delivery orders, run abandoned-cart, browse-abandonment, back-in-stock, and post-delivery automations, and record courier/delivery tracking details. You control and are responsible for this data as the data controller.

3.7 Behavioural / visitor data (as processor for the customer)

Where you enable visitor tracking and recovery features, the Service may record which pages an end-user viewed, browse sessions, and prior conversation history, so your agent can respond in context and run recovery automations. For each visitor we also record a device category (mobile / tablet / desktop), browser, and operating system, read from the browser's user-agent string, and the approximate country described in Section 3.3.

3.8 Information we derive from conversations (as processor for the customer)

Beyond storing messages, the Service analyses them and keeps what it works out. Where the relevant features are enabled, this includes:

  • Remembered facts. Details an end-user states in conversation — such as their name, email address, phone number, or a stated budget — are extracted and stored as persistent facts, so your agent can recall them in a later conversation instead of asking again.
  • Conversation triage. Conversations are automatically classified by topic, sentiment (how positive or negative the exchange reads), and priority, so your inbox can be sorted and filtered.
  • Lead scoring. An interest or intent score is calculated from the conversation against rules you configure.
  • A combined customer profile. Where an end-user can be recognised across visits (usually by email address), their conversations, remembered facts, leads, tickets, orders, bookings, notes, and tags are brought together into a single profile that persists across separate sessions and is shown to your agents in the inbox.

This is profiling. You, as the data controller, decide whether to enable these features and are responsible for telling your end-users about them and for having a lawful basis; the profile is confined to your own workspace and is never combined with another customer's data.

3.9 Integration data (as processor / controller as applicable)

Where you connect a third-party integration (for example, Google, Shopify, WordPress, or a messaging channel), we process the access tokens and the data necessary to operate that integration, which are stored in encrypted form.

Connected mailboxes. If you connect an email account (Gmail or an IMAP/SMTP mailbox) to an agent, Botvee reads the messages arriving in it so they can appear in your inbox and be answered — including sender address, subject, body, and attachments. Only the mailbox you connect is read, you choose which agent it belongs to, and disconnecting it stops the reading.

3.10 Partner Programme data (as controller)

If you apply to the Partner (affiliate) Programme, we collect and store the information you submit — your country, how you intend to promote Botvee, your promotional link or channel, a description of your audience, and your reason for applying — together with your referral code, recorded clicks and sign-ups attributed to it, and your commission balance and payout records.

3.11 Information we do not collect

We do not seek to collect special categories of personal data (such as health, religious, biometric, or racial/ethnic data). Customers must not configure agents to collect such data without a lawful basis and safeguards (see our Acceptable Use Policy). We do not knowingly collect personal data from children (Section 9).

4

AI Transparency and Important Disclaimers

IMPORTANT AI DISCLOSURE

Botvee's AI agents generate responses using a third-party AI provider (currently OpenAI). AI-generated content may be inaccurate, incomplete, or out of date. It is provided for general information and is not professional, legal, medical, or financial advice. Verify important information independently.

  • Under current provider terms, data sent to our AI provider via its API is not used to train its models by default. This reflects that provider's policy as it stands from time to time and is not an absolute or perpetual guarantee by Botvee about a third party.
  • An AI agent may take limited actions on request (for example, providing order status, capturing a lead, or helping arrange a booking). Where an agent performs actions, the deploying customer remains responsible for their accuracy, legality, and appropriateness and for the agent's configured knowledge base.
  • Please avoid submitting highly sensitive personal information through AI agent conversations, and do not upload passwords, financial account numbers, government-issued ID numbers, or medical records to training datasets.
5

Legal Bases for Processing

Where our processing as a controller is subject to the GDPR or UK GDPR, we rely on:

  • Contract (Art. 6(1)(b)) to provide the Service and manage your account
  • Legitimate interests (Art. 6(1)(f)) for platform security, fraud prevention, service improvement, and aggregated or anonymised analytics
  • Consent (Art. 6(1)(a)) for non-essential cookies and marketing, where required
  • Legal obligation (Art. 6(1)(c)) for tax, regulatory, and legal compliance

Under Pakistani law, processing is supported by the parties' contract, the ETO 2002, PECA 2016, and record-retention obligations (including Income Tax Ordinance 2001, s. 174).

6

Sharing and Subprocessors

We do not sell personal data. We share personal data only with service providers ("subprocessors") who help us deliver the Service, under contracts requiring appropriate protection. Our core providers (always used) include our AI provider, payment provider, database and hosting providers, file-storage, cache, and email-delivery providers. Website crawling is not among them — it runs on Botvee's own infrastructure (Section 3.4). Additional providers are used only where you enable the corresponding channel or integration (for example, messaging channels, Google, Shopify, WordPress, and courier/delivery providers).

The current list, with purpose and location, is maintained at botvee.ai/subprocessors.

Legal Disclosure

We may disclose personal data to courts, regulators, or law enforcement where required by law, and only to the extent required. Where legally permitted and practicable, affected individuals or the relevant controller may be notified.

7

International Data Transfers

Botvee operates from Pakistan and uses providers located in various countries. Where personal data is transferred to a country not recognised as providing adequate protection, we rely on an appropriate transfer mechanism, which may include the EU Standard Contractual Clauses (Commission Decision 2021/914) in the applicable module, the UK IDTA/Addendum, and safeguards recognised under the Swiss FADP, supported by supplementary measures such as encryption and access controls. Further detail is in our International Data Rights page and DPA.

8

Data Retention and Deletion

We retain personal data for as long as your account is active and as needed for the purposes in this Policy, or as required by law. Your conversations and other content are not aged out on a fixed schedule — we do not delete them just because they have reached a certain age. Deletion happens in one of two ways: you close your account and request deletion, or you exercise a deletion/erasure request. On a verified erasure request, we delete the relevant personal data across our systems, scoped to the requesting workspace, and record an audit entry.

One exception: a long-unpaid account. If a subscription goes unpaid, the workspace first becomes read-only, then export-only, and after 90 days of continued non-payment it becomes eligible for deletion under this Policy. You are notified along the way and can export your data at any point before that.

Data CategoryRetentionBasis
Billing, invoice, and transaction recordsUp to 7 yearsIncome Tax Ordinance 2001, s. 174 and tax/regulatory obligations
Account and profile dataWhile the account is active; deleted after verified closure/deletion requestContract
End-user conversation, lead, order, and related data (as processor)While the account is active or per the customer's instructions and the DPA; deleted on erasure requestController (customer) instructions
Uploaded training contentWhile the account is active; deleted on closure or requestContract
Technical / analytics dataRetained as needed for security and service operationLegitimate interests
Consent, opt-out, suppression, and audit recordsRetained as compliance evidenceLegal/compliance

Note: Certain financial records may be retained after account closure where required by law.

9

Age Policy

Minimum Age — 18

Botvee is a business tool for organisations and professionals. You must be at least 18 years old to open or administer a Botvee account on your own. Nobody under 14 may hold an account under any circumstances.

9.1 Ages 14–17 — only with verified parental consent

A person aged 14 to 17 may hold an account only if a parent or legal guardian has given us verifiable consent first. Without that consent the account is not permitted, and we will close it when we find out.

To give consent, the parent or guardian emails privacy@botvee.ai with the subject "Parental Consent — [account email]" and provides:

  • their own full name and contact details;
  • reasonable proof of identity; and
  • reasonable proof that they are the minor's parent or legal guardian.

We aim to review such requests within 14 calendar days. Until consent is verified, the account is treated as not permitted.

A consenting parent or guardian keeps control. At any time they may ask us for a copy of the minor's data, have it corrected, have it deleted, have the account transferred into their own name, or withdraw consent — and withdrawing consent closes the account.

9.2 Tell us about a child's account — we will close it

If you believe an account belongs to a child, tell us and we will act. Email privacy@botvee.ai with whatever you know — the account email is enough, and you do not have to prove anything or explain who you are.

On a credible report we suspend the account immediately, while we look into it. If it turns out to belong to someone under 14, or to someone aged 14–17 with no verified parental consent, the account is closed and the personal data in it is deleted. We do not require the person who reported it to justify the report, and we do not tell the account holder who reported them.

9.3 No marketing or non-essential tracking of minors

We do not knowingly send marketing to anyone we know to be under 18, and we do not knowingly set non-essential technologies for a user we know to be a minor.

9.4 Your own end-users

Where a customer's own end-users are minors, responsibility for handling their data lawfully — including any consent their local law requires — rests with that customer as the data controller, not with Botvee.

10

Cookies

botvee.ai keeps very little in your browser: a sign-in session, your display preferences, and — if you arrived through a partner's referral link — that partner's code. We use no analytics cookies, no advertising or retargeting cookies, and no cross-site tracking. Our Cookie Policy lists every item in full, says how long each one stays, and explains how to remove them.

11

Security

We apply appropriate technical and organisational measures, including encryption of data in transit (TLS 1.2+) and at rest (AES-256), hashed passwords, encrypted storage of integration tokens, workspace role-based access controls, two-factor authentication (TOTP), which you can switch on for your own account, login-device recognition (Section 3.3), audit logging, and hosting on established cloud infrastructure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Full detail is in our Security Policy.

12

Your Privacy Rights

Subject to the law that applies to you, you may have rights to access, correct, delete/erase, restrict, or object to certain processing, to portability, to withdraw consent, and to lodge a complaint with your supervisory authority. A full description by jurisdiction — including EU/UK GDPR, California CCPA/CPRA, and Canada PIPEDA — and how to exercise them is in our International Data Rights page.

How to Make a Request

Email privacy@botvee.ai with subject "Privacy Rights Request — [Jurisdiction] — [Account Email]". We acknowledge within a reasonable time and respond within the period required by applicable law (generally 30 days; 45 days for CCPA; extendable where the law permits for complex or numerous requests, in which case we will inform you). We may verify your identity. No charge applies unless a request is manifestly unfounded, excessive, or repetitive.

Where Botvee acts as a processor, an end-user's request should be directed to the relevant customer (the controller). Customer administrators (owner/admin) can action erasure of an end-user's data within their own workspace, and Botvee provides reasonable assistance as set out in the DPA.

13

Automated Processing

An AI agent may qualify or route conversations, score leads, classify them by topic, sentiment, and priority, build the combined customer profile described in Section 3.8, and take limited actions at an end-user's request. These functions are designed to assist a human, not to replace one — a human handoff is always available, and none of them decides anything about a person on its own. Where automated processing would produce a legal or similarly significant effect and the law requires it, meaningful human involvement can be provided; the deploying customer is responsible for enabling appropriate human oversight for its use case.

14

Force Majeure

Botvee is not responsible for delays or failures in meeting its obligations under this Policy caused by events beyond its reasonable control, including natural disasters, epidemics or pandemics, acts of government, failures of third-party infrastructure providers, or major internet or power disruptions.

15

Changes to This Policy

We may update this Policy from time to time. Material changes may be communicated by email or through the website before taking effect, where appropriate. The "Effective date" reflects the latest revision. Continued use after an update indicates acknowledgement, to the extent permitted by law.

16

Related Policies

17

Contact

Privacy / Data Protection

privacy@botvee.ai

Legal / DPA

legal@botvee.ai

Phone / WhatsApp

+92 319 3981020

Postal

BOTVEE (PRIVATE) LIMITED, Ward No. 3, Near Government Boys High School, Golarchi, District Badin, Sindh 72220, Pakistan

BOTVEE (PRIVATE) LIMITED

SECP: 0326112  ·  FBR: I510669  ·  PSEB: Z-25-19163/26