Skip to content

Privacy Policy

Last updated:

This policy explains how Botify handles personal information when you visit our website, use our agent platform, or interact with an agent through an enabled channel. For an organization-managed workspace, the organization controls its agents and content; its own notices and agreements may also apply.

1. Information we process

Account information includes your name, email, workspace membership, authentication details and connection authorizations. Passwords are stored as hashes; connector credentials and OAuth tokens are stored in an encrypted credential vault.

Service information can include messages, uploaded knowledge documents, retrieved excerpts, agent configuration, tool inputs and outputs, approvals, generated reports, and agent memory when enabled. Operational records can include IP addresses, session information, timestamps, errors, usage and audit events.

Voice, telephone and embedded-widget channels process visitor or caller information and conversation content when enabled. Voice recordings and post-call analysis depend on the workspace configuration. The workspace operator is responsible for providing appropriate notices and obtaining required consent.

2. Why we use information

We process information to authenticate users, operate workspaces, answer requests using configured knowledge and integrations, execute authorized actions, record approvals, generate requested reports, manage usage and credits, and provide support.

We also process necessary operational information to secure the service, investigate abuse and failures, maintain reliability and meet applicable legal obligations. Do not submit information you are not authorized to share.

3. Google account and Workspace data

Google sign-in provides the identity information you authorize, such as your name and email. Connecting a Google service is a separate authorization. Depending on the service and permissions you grant, Botify can access Gmail messages, threads and labels; calendar events; Drive files and metadata; Docs and Sheets content; contacts; and tasks.

This access supports the features you choose, including searching and summarizing mail, preparing drafts or sending requested messages, scheduling events, finding and editing documents, working with spreadsheets, and managing contacts and tasks. Available actions depend on granted permissions, enabled tools and workspace policies.

Relevant Google content may be included in model requests to provide the AI features you use, and retained in conversation, tool-result, report or memory records where those features are enabled. Connecting a service does not make its data public; workspace access and channel permissions still apply.

Botify’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold or used for advertising, creditworthiness or lending purposes, and is not used to train generalized AI or machine-learning models.

Human access to Google user data is limited to your affirmative agreement to inspect specific data, necessary security investigations, legal requirements, or permitted aggregated internal operations. Transfers are limited to permitted user-facing features with consent, security purposes, applicable legal requirements, or a business transfer with the required prior consent.

You can disconnect a service in the agent’s Connections page or revoke access through your Google Account permissions. Revocation stops future authorized access but does not by itself delete previously stored conversation or report records. Contact us to request deletion of retained data.

Google API Services User Data Policy

4. Sharing and service providers

Relevant information is sent to connected systems when an authorized tool runs. AI model, embedding, hosting, storage, email and, when enabled, voice or telephony providers process the information required for their respective functions. The providers used depend on the deployment and configuration; contact us for information about those used for your workspace.

Messages, retrieved excerpts and tool results may be sent to the configured model provider to generate an answer. Uploading a knowledge source may involve sending its text to an embedding provider. Do not assume processing stays within your organization or country unless your agreement specifically provides for that.

Authorized workspace members may access information according to their roles. We may disclose information where legally required or necessary to protect rights and security. We do not sell personal information. Google API data remains subject to the restrictions in section 3.

5. Retention and deletion

Retention depends on the type of record, workspace settings, operational needs and applicable legal or contractual obligations. Conversations, knowledge sources, memory, reports and audit records can remain stored beyond a single session. We do not promise one fixed retention period for all data.

Ask your workspace administrator or contact us to request access, correction or deletion. We may need to verify your identity and authority. Backup copies and records required for security, dispute resolution or legal compliance may remain for the relevant retention period; removing a connection is not a substitute for a deletion request.

6. Cookies and browser storage

The website uses session cookies for authentication and browser storage for preferences such as theme and widget state. Embedded widgets use identifiers to maintain conversations. You can manage browser cookies and storage, but blocking necessary cookies may prevent sign-in or other features from working.

7. Security and international processing

Botify uses controls including encrypted connector credentials, tenant-scoped access, role permissions and audit records. No online service can guarantee absolute security. Keep account credentials private and review permissions before connecting systems.

Our infrastructure and providers may process information in countries different from yours. Applicable data-transfer requirements and any additional safeguards are addressed through the arrangements that apply to your workspace; contact us before submitting data subject to special residency requirements.

8. Your choices and rights

Depending on applicable law, you may have rights to access, correct, delete or receive a copy of personal information, object to certain processing, or withdraw consent. Send requests to the contact address below. Where a customer organization controls the data, we may refer the request to its administrator.

Botify is intended for business use and is not directed at children. Do not create an account or provide children’s information without a lawful basis and appropriate authorization.

9. Policy changes and contact

We may update this policy as the service or requirements change and will update the date above. Material changes will be communicated where required. New uses of Google data requiring consent will not be applied without the necessary notice and consent.

For privacy questions, data requests, or information about the service provider and processing arrangements for your workspace, contact Botify using the email below.

Questions about this policy? Contact us at hello@botifyarabia.ai.