Privacy Policy
What personal data BotPass handles as controller, and on what basis.
This policy explains what personal data San Mateo Capital, S.L. handles as controller — essentially, the data of the people who hold BotPass accounts and who visit botpass.io.
Personal data that BotPass handles on behalf of a customer, which is mostly the log of requests hitting the customer's own website, is governed by the Data Processing Agreement. There the customer is the controller and we are the processor. The distinction matters and this policy does not blur it.
1. Controller#
| Company | San Mateo Capital, S.L. |
| Tax ID (CIF) | B67381368 |
| Registered address | C/ Roger de Lluria 137, 08037 Barcelona, Spain |
| hello@botpass.io |
We have not appointed a Data Protection Officer. Article 37 GDPR does not require one for our processing, and appointing one we did not need would be theatre. Privacy questions go to hello@botpass.io and are answered by a person.
2. What we collect, why, and on what legal basis#
2.1 Account data#
Name, business email, company name, plan, subscription status and dates.
- Purpose: creating and running your account, support, invoicing.
- Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Retention: for the life of the account, then six years to meet Spanish commercial and tax record-keeping obligations (Art. 30 Código de Comercio; Art. 66 Ley General Tributaria).
2.2 Authentication data#
Password hashes, two-factor authentication secrets, and — if you sign in with Google — the Google account identifier, email and name that Google returns to us. We never receive your Google password.
- Purpose: letting you in and keeping everyone else out.
- Legal basis: contract, and our legitimate interest in securing the service (Art. 6(1)(b) and (f)).
- Retention: for the life of the account.
2.3 Billing data#
Billing name, address, tax identifier, invoice history, and the Stripe customer and subscription identifiers.
We do not store card numbers. Payments are processed by Stripe, which acts as an independent controller for the card data you give it.
- Legal basis: contract, and legal obligation for invoices (Art. 6(1)(b) and (c)).
- Retention: six years, as above.
2.4 Security and audit logs#
Sign-in events, administrative actions, the IP address recorded with them, and API request logs.
- Purpose: detecting unauthorised access, investigating incidents, and being able to say who did what. Administrative screens in BotPass can change hundreds of live websites at once; an unlogged console would be indefensible.
- Legal basis: legitimate interest in the security and integrity of the service (Art. 6(1)(f)).
- Retention: API request logs are deleted after 90 days. Administrative audit entries — who signed in to the operator console and what they changed — are kept for twelve months and then deleted.
- A caveat we would rather state than hide: the IP recorded in the administrative audit log is the one reported by the request chain and can be spoofed by someone determined to do so. It is useful for diagnosis. It is not forensic proof, and we do not present it as such.
2.5 Support correspondence#
Whatever you write to us and whatever we write back.
- Legal basis: contract and legitimate interest (Art. 6(1)(b) and (f)).
- Retention: three years from the last message.
2.6 The website, botpass.io#
The public site uses only the cookies strictly necessary to serve it. We run no advertising cookies, no third-party analytics and no tracking pixels, so there is no consent banner, because there is nothing to consent to.
The site loads a font stylesheet from Google Fonts, which means your browser makes a request to Google's servers and Google sees your IP address in the process. If that matters to you, the site is designed to fall back to a system font and works without it.
Server access logs of the website are kept for thirty days for security and diagnostics, on the basis of legitimate interest.
3. What we do not do#
- We do not sell personal data. Not to anyone, not ever.
- We do not use your data for advertising or profiling.
- We do not take automated decisions producing legal or similarly significant effects on you (Art. 22 GDPR). BotPass automates decisions about web pages, not about people.
- We do not read our customers' website visitors' data for our own purposes. What we do with it, we do on the customer's instructions, under the Data Processing Agreement.
4. A note on shared evidence#
BotPass pools the aggregate results of experiments across customers to build a shared playbook. This is a core mechanic of the product and it is described in section 7 of the Terms of Service.
It is not a privacy matter, and we want to be precise about why: what enters the shared grid is an intervention, a page type, a measured effect and a confidence interval. No personal data, no customer identifier, no domain, no content and no traffic figures. If it ever needed to contain any of those, it would stop being aggregate evidence and start being something we would have to ask you about separately.
5. Who we share data with#
We use the following sub-processors and service providers. Each is bound by a contract that restricts what it may do with the data.
| Provider | What it does | Where | Notes |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting, database, file storage, queues | Ireland (eu-west-1) | All customer and account data is stored here |
| Stripe | Payment processing | EU / United States | Independent controller for card data |
| Resend | Transactional email | EU / United States | Account and notification emails |
| Google (Sign-in) | Optional authentication | EU / United States | Only if you choose Google sign-in |
| OpenAI | AI provider queried during measurement | United States | See 5.1 |
| Anthropic | AI provider queried during measurement | United States | See 5.1 |
| Google (Gemini) | AI provider queried during measurement | United States | See 5.1 |
| Perplexity | AI provider queried during measurement | United States | See 5.1 |
We will publish changes to this list and give customers reasonable notice before a new sub-processor starts processing their data.
5.1 What actually goes to the AI providers#
We want this to be concrete, because "we use AI providers" tells you nothing about your exposure.
During a measurement window BotPass sends each configured provider a question about a topic — the kind of question a person might ask an assistant — and records whether the answer cites the customer's pages. What we send is the question and, where the provider supports it, an instruction to ground the answer in web sources. We record the provider's answer text, which URLs it cited, and whether the customer's page was among them.
We do not send account data, billing data, visitor IP addresses or log data to any AI provider.
The questions are defined by the customer or drawn from their prompt set. If a customer writes a question containing personal data, that data reaches the provider. Customers should not do that, and the Data Processing Agreement says so.
6. International transfers#
All customer and account data is stored in the European Union, in AWS's Ireland region.
The AI providers listed above, and some of the operations of Stripe, Resend and Google, involve transfers to the United States. Those transfers are covered by the European Commission's Standard Contractual Clauses and, where the provider is certified, by the EU–US Data Privacy Framework, together with the supplementary measures we consider appropriate.
You may request a copy of the transfer safeguards in place for any provider by writing to hello@botpass.io.
7. Security#
We protect data with, among other measures: encryption in transit (TLS); credentials and API keys held in a managed secret store, never in code; two-factor authentication and network restrictions on administrative access; role separation between customer accounts and operator accounts; and audit logging of administrative actions.
No system is perfectly secure, and we will not claim ours is. What we commit to is this: if a personal data breach occurs, we will notify the supervisory authority within 72 hours where Art. 33 GDPR requires it, and we will tell affected customers without undue delay — including when the news is bad for us.
8. Your rights#
Under the GDPR you may request: access to your data, rectification, erasure, restriction of processing, portability, and objection to processing based on legitimate interest. You may also withdraw any consent you have given, without affecting processing already carried out.
Write to hello@botpass.io. We will answer within one month, extendable by two further months for complex requests, and we will tell you if we need the extension.
If you are the visitor of a website that uses BotPass, we are not your controller — the website's owner is. Send your request to them; we will assist them in answering it.
You may lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (www.aepd.es), or with the authority of your country of residence. We would rather you wrote to us first, but it is your right either way.
9. Children#
BotPass is a business service and is not directed at children. We do not knowingly collect data from anyone under 18.
10. Changes to this policy#
We will post any new version here with a new effective date, and notify customers by email of material changes at least thirty days before they take effect.
11. Contact#
hello@botpass.io — San Mateo Capital, S.L., C/ Roger de Lluria 137, 08037 Barcelona, Spain.