Legal

Privacy Policy

What personal data BotPass handles as controller, and on what basis.

Version 1.0 · Effective 9 September 2026

This policy explains what personal data San Mateo Capital, S.L. handles as controller — essentially, the data of the people who hold BotPass accounts and who visit botpass.io.

Personal data that BotPass handles on behalf of a customer, which is mostly the log of requests hitting the customer's own website, is governed by the Data Processing Agreement. There the customer is the controller and we are the processor. The distinction matters and this policy does not blur it.


1. Controller#

CompanySan Mateo Capital, S.L.
Tax ID (CIF)B67381368
Registered addressC/ Roger de Lluria 137, 08037 Barcelona, Spain
Emailhello@botpass.io

We have not appointed a Data Protection Officer. Article 37 GDPR does not require one for our processing, and appointing one we did not need would be theatre. Privacy questions go to hello@botpass.io and are answered by a person.

2.1 Account data#

Name, business email, company name, plan, subscription status and dates.

2.2 Authentication data#

Password hashes, two-factor authentication secrets, and — if you sign in with Google — the Google account identifier, email and name that Google returns to us. We never receive your Google password.

2.3 Billing data#

Billing name, address, tax identifier, invoice history, and the Stripe customer and subscription identifiers.

We do not store card numbers. Payments are processed by Stripe, which acts as an independent controller for the card data you give it.

2.4 Security and audit logs#

Sign-in events, administrative actions, the IP address recorded with them, and API request logs.

2.5 Support correspondence#

Whatever you write to us and whatever we write back.

2.6 The website, botpass.io#

The public site uses only the cookies strictly necessary to serve it. We run no advertising cookies, no third-party analytics and no tracking pixels, so there is no consent banner, because there is nothing to consent to.

The site loads a font stylesheet from Google Fonts, which means your browser makes a request to Google's servers and Google sees your IP address in the process. If that matters to you, the site is designed to fall back to a system font and works without it.

Server access logs of the website are kept for thirty days for security and diagnostics, on the basis of legitimate interest.

3. What we do not do#

4. A note on shared evidence#

BotPass pools the aggregate results of experiments across customers to build a shared playbook. This is a core mechanic of the product and it is described in section 7 of the Terms of Service.

It is not a privacy matter, and we want to be precise about why: what enters the shared grid is an intervention, a page type, a measured effect and a confidence interval. No personal data, no customer identifier, no domain, no content and no traffic figures. If it ever needed to contain any of those, it would stop being aggregate evidence and start being something we would have to ask you about separately.

5. Who we share data with#

We use the following sub-processors and service providers. Each is bound by a contract that restricts what it may do with the data.

ProviderWhat it doesWhereNotes
Amazon Web Services (AWS)Hosting, database, file storage, queuesIreland (eu-west-1)All customer and account data is stored here
StripePayment processingEU / United StatesIndependent controller for card data
ResendTransactional emailEU / United StatesAccount and notification emails
Google (Sign-in)Optional authenticationEU / United StatesOnly if you choose Google sign-in
OpenAIAI provider queried during measurementUnited StatesSee 5.1
AnthropicAI provider queried during measurementUnited StatesSee 5.1
Google (Gemini)AI provider queried during measurementUnited StatesSee 5.1
PerplexityAI provider queried during measurementUnited StatesSee 5.1

We will publish changes to this list and give customers reasonable notice before a new sub-processor starts processing their data.

5.1 What actually goes to the AI providers#

We want this to be concrete, because "we use AI providers" tells you nothing about your exposure.

During a measurement window BotPass sends each configured provider a question about a topic — the kind of question a person might ask an assistant — and records whether the answer cites the customer's pages. What we send is the question and, where the provider supports it, an instruction to ground the answer in web sources. We record the provider's answer text, which URLs it cited, and whether the customer's page was among them.

We do not send account data, billing data, visitor IP addresses or log data to any AI provider.

The questions are defined by the customer or drawn from their prompt set. If a customer writes a question containing personal data, that data reaches the provider. Customers should not do that, and the Data Processing Agreement says so.

6. International transfers#

All customer and account data is stored in the European Union, in AWS's Ireland region.

The AI providers listed above, and some of the operations of Stripe, Resend and Google, involve transfers to the United States. Those transfers are covered by the European Commission's Standard Contractual Clauses and, where the provider is certified, by the EU–US Data Privacy Framework, together with the supplementary measures we consider appropriate.

You may request a copy of the transfer safeguards in place for any provider by writing to hello@botpass.io.

7. Security#

We protect data with, among other measures: encryption in transit (TLS); credentials and API keys held in a managed secret store, never in code; two-factor authentication and network restrictions on administrative access; role separation between customer accounts and operator accounts; and audit logging of administrative actions.

No system is perfectly secure, and we will not claim ours is. What we commit to is this: if a personal data breach occurs, we will notify the supervisory authority within 72 hours where Art. 33 GDPR requires it, and we will tell affected customers without undue delay — including when the news is bad for us.

8. Your rights#

Under the GDPR you may request: access to your data, rectification, erasure, restriction of processing, portability, and objection to processing based on legitimate interest. You may also withdraw any consent you have given, without affecting processing already carried out.

Write to hello@botpass.io. We will answer within one month, extendable by two further months for complex requests, and we will tell you if we need the extension.

If you are the visitor of a website that uses BotPass, we are not your controller — the website's owner is. Send your request to them; we will assist them in answering it.

You may lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (www.aepd.es), or with the authority of your country of residence. We would rather you wrote to us first, but it is your right either way.

9. Children#

BotPass is a business service and is not directed at children. We do not knowingly collect data from anyone under 18.

10. Changes to this policy#

We will post any new version here with a new effective date, and notify customers by email of material changes at least thirty days before they take effect.

11. Contact#

hello@botpass.io — San Mateo Capital, S.L., C/ Roger de Lluria 137, 08037 Barcelona, Spain.