Privacy policy
Last updated 2026-09-19
Who we are
Botseon is the name this service is sold under. The company behind it is Nordio ApS, a Danish company, CVR 46714040, Skansevej 88, 3400 Hillerød, Denmark. Write to us at the address in Contact at the end of this page.
There are two different relationships in this policy, and it matters which one you are reading about:
- We are the controller for your account, your billing records and the security records we keep about sign-ins and administration. We decide what we collect and why, and this policy is our notice to you about it.
- We are the processor for everything your bots read, remember or send on your organisation's behalf. Your organisation decides what that is; we only run it. The Data processing addendum is the contract for that half.
What this website collects
This website, the pages you are reading now, sets no cookies, runs no analytics and loads no trackers. It stores nothing about you in your browser: it follows your device's light or dark setting and has no theme control of its own. Its one script deletes a single storage key that an earlier version of the site used, and writes nothing back. The Cookie statement says the same thing in more detail.
Hosting a website means our host sees the request: your IP address, the page you asked for, your browser's user-agent string and the time. We use that only to serve the page and to keep the site up, and we do not build a profile from it.
What the service collects
The Botseon app, the product you sign into, holds two different things.
Data we are the controller for. Your name and e-mail address, your organisation and your role in it, your plan and your payment records, your usage against your allowance, and a security record of sign-ins and administrative actions.
Data we are the processor for. Everything your bots work on: conversations and their attachments, what a bot remembers, the files on a bot's computer, the messages a bot sends, and the records of each run. This can include personal data about people who never signed up to Botseon, someone your bot e-mails, for instance. Your organisation is the controller for all of it and decides what its bots may read and remember.
Why we are allowed to hold it (legal bases)
For the data we control:
- To provide the service you asked for: your account, your organisation, your bots. This is the performance of our contract with you (Article 6(1)(b) GDPR).
- To take payment and keep our books: our contract with you, and our legal obligation under Danish bookkeeping law (Article 6(1)(b) and (c)).
- To keep the service safe: the sign-in and administration records, abuse prevention, and protecting our systems. This is our legitimate interest in a service that is not abused (Article 6(1)(f)).
For data your bots handle, your organisation chooses the legal basis, not us. If you are not sure which basis covers the people your bots read about and remember, ask us. We hand tenants an assessment template for exactly that case.
Where your data is processed
Your account, your content and everything we store are held in the EU. Model calls are the one part of the service where that is not yet true of every route, and Models below says exactly which route goes where. What the rest looks like, provider by provider:
| What | Provider | Where | Who we contract with |
|---|---|---|---|
| Database, authentication and file storage | Supabase | eu-central-1 (Frankfurt) | Supabase Pte. Ltd., Singapore |
| The website and the web app | Vercel | fra1 (Frankfurt) | Vercel Inc., United States |
| The computer each bot works on | Fly.io | fra (Frankfurt) | Fly.io, Inc., United States |
| Transactional e-mail | Resend | eu-west-1 (Ireland) | Resend, Inc., United States |
| Billing and payment | Stripe | EU | Stripe Payments Europe, Ltd., Ireland |
| Language and vision models | see Models, below | EU, except the Claude route | see Sub-processors |
Four of those companies are established outside the EU even though the region you get is in the EU. That is a real thing and we are not going to write around it: when a company established outside the EEA can reach data held in the EU, that is a transfer under Chapter V of the GDPR, and it needs a legal instrument. Ours are the European Commission's Standard Contractual Clauses, and for some providers an active EU–US Data Privacy Framework certification alongside them. The Sub-processors page names the instrument for each one.
Our own support staff work from the EU, and support access to a customer's data is from the EU.
Models
A bot's answer is produced by a language model, and the message it is answering is sent to the model provider to produce it. These are the routes as they stand today, and we would rather state them plainly than describe a position we have not reached yet.
Live EU routes:
- Mistral AI, France. Mistral's own models, and embeddings.
- Microsoft Azure AI Foundry, Sweden Central, EU data zone, serving Mistral Large 3.
The Claude route is not EU-resident yet:
- Anthropic PBC, United States, is the primary route for Anthropic's Claude models. It is the route a Claude call takes today, not a fallback, and it is the one case in which a model call leaves the EU.
- Google Cloud Vertex AI, EU multi-region, and Amazon Bedrock,
eu-central-1(Frankfurt), are being enabled and are not used for customer data until they are. When an EU-resident Claude route is switched on, the United States route goes.
EU processing for every plan from a date to be announced. We are not going to name a date we cannot hold, and we will tell the administrators of every organisation when the switch happens.
Your data is sent to a model provider to produce the answer and for nothing else. It is not used to train their models. Google's Service Specific Terms state that Google will not use customer data to train or fine-tune AI/ML models without the customer's prior permission or instruction (https://cloud.google.com/terms/service-terms, as published on 2026-09-06). The equivalent commitments from Microsoft, Mistral AI and Anthropic are recorded on the Sub-processors page.
Model providers may hold a copy of a request for a short period for abuse monitoring. Where a provider does that, its row on the Sub-processors page says so and for how long.
How long we keep it
Each kind of record has a shortest period we keep it for, a default, and a longest we will ever keep it.
| What | Shortest | Default | Longest |
|---|---|---|---|
| Conversations, their attachments and voice transcripts | 30 days | 730 days | 2,555 days |
| What a bot remembers | 30 days | 180 days | 730 days |
| The event record of a run | 30 days | 90 days | 365 days |
| Files and snapshots on a bot's computer | 7 days | 30 days | 90 days |
| The security and administration record (audit log) | 180 days | 365 days | 730 days |
| The record that an AI disclosure was shown | 180 days | 365 days | 1,825 days |
| Usage records behind your bill | 30 days | 90 days | 365 days |
| The log that an account e-mail was sent (never its body) | none set | 90 days | 365 days |
The intention is that an organisation sets its own default between the shortest and the longest. That control is not built yet, so today the defaults above are what applies.
Invoices and accounting records are kept for as long as Danish bookkeeping law requires.
Deleting your account is always available, whatever the schedule above says about any one kind of record. When an organisation is deleted, its content is hidden immediately and permanently removed after a 7-day grace period; the key that protects the encrypted part is destroyed at the same point. A request from an individual to be erased is answered straight away, with no grace period. The Data processing addendum explains what erasure does and does not reach.
Who else sees it
The companies we use, what each one does, where, and under what legal instrument, are listed on the Sub-processors page. That page separates two things that are easy to confuse: the providers we have appointed to run the service, and the places a member of your organisation chooses to connect a bot to, such as their own mailbox. The second is your organisation's choice, not ours.
We do not sell your data and we do not share it for advertising.
Push notifications
If you turn on push notifications, the notification itself, the bot's name, its avatar and a short excerpt of the message, travels through Apple's and Google's push services to reach your device. That is how push works on a phone; there is no way to deliver a preview without it. Turn previews off in your device settings if you would rather they did not.
Your rights
You can ask us to give you a copy of your data, to correct it, to move it elsewhere, to delete it, to restrict what we do with it, or to object to processing we base on our legitimate interest.
On the hosted service, delete your own account from Settings → General; for anything else, write to
the address below and we will answer within one month. On a self-hosted installation, your
administrator runs botseon privacy export and botseon privacy erase.
One right is honest to flag: restriction is not yet something we can switch on for you from the product. Write to us and we will handle it by hand until it is.
If your bots hold data about you and you are not a member of the organisation that runs them, that organisation is the controller and your request goes to them. Tell us and we will pass it on.
You can complain to the Danish Data Protection Agency, Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark, or to the supervisory authority where you live.
Changes to this policy
If we change this policy in a way that matters, we will tell the administrators of every organisation before it takes effect. The date at the top is the version you are reading.
Contact
Nordio ApS, CVR 46714040 Skansevej 88, 3400 Hillerød, Denmark
Privacy questions: privacy@botseon.com
We have not appointed a Data Protection Officer.