Data processing addendum
Last updated 23 September 2026. Privacy Terms Subprocessors
- The short version
- 1. Definitions
- 2. When this applies
- 3. Roles
- 4. What we will and will not do with your data
- 5. Compliance with law
- 6. Security
- 7. Telling you about a security incident
- 8. Helping you comply
- 9. Subprocessors
- 10. Confidentiality
- 11. Audits and information requests
- 12. Data subject requests
- 13. Return or deletion of customer data
- 14. International transfers
- 15. California
- 16. Liability
- 17. Conflict and duration
- Annex I: details of the processing
- Annex II: subprocessors
This addendum forms part of the BotSay Terms of Service between you and Caspio, Inc. ("we", "us"). It applies wherever we process personal data on your behalf. It is incorporated into the Terms of Service and takes effect when you accept them. No separate signature is required.
If it conflicts with the Terms of Service on data protection, this addendum prevails.
The short version
- You decide what personal data goes into BotSay. We process it to run the service for you.
- The main thing that leaves our systems is the text of the questions you wrote, which goes to the AI engines in Annex II. That is what the product is.
- We do not send your users' details, your account details or anything identifying you to those engines.
- We tell you before we add a subprocessor, and you can object.
- We tell you without undue delay if there is a breach affecting your data.
- When your subscription ends, we return or delete your data within 60 days.
The numbered sections are the binding version.
1. Definitions
"Personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in applicable data protection law. "Customer data" means data you put into BotSay or that we generate for you in your account. "Applicable data protection law" means whichever of the GDPR, the UK GDPR, the Swiss FADP, the CCPA as amended and any other data protection law applies to the processing. Terms not defined here have the meaning given in the Terms of Service.
2. When this applies
This addendum applies whenever we process personal data on your behalf in connection with BotSay.
It does not apply to personal data we process on our own account, such as your billing contact's details and the details of the individuals who administer and use your account. Our Privacy Policy covers that processing and we are the controller of it.
3. Roles
You act as controller, or as a processor for a controller of your own. We act as your processor or, where you are a processor, as your subprocessor. The companies in Annex II act as our subprocessors.
Annex I sets out the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject. It is written to serve as the record required by GDPR Art. 30 in respect of this processing.
4. What we will and will not do with your data
We will process customer data only:
- to provide BotSay to you under the Terms of Service,
- on your documented instructions, which the Terms of Service and your use of the product's features constitute, and
- where the law requires it, in which case we will tell you first unless we are forbidden to.
We will not sell customer data, will not share it for cross-context behavioural advertising, and will not use it for our own purposes.
We will not use customer data to train machine learning models. Where a subprocessor's terms allow us to require the same of them, we do.
We may create and use aggregated, de-identified data derived from the processing. It identifies no data subject, customer, brand or market and cannot reasonably be used to re-identify any of them.
If we believe an instruction breaches applicable data protection law, we will tell you.
Everyone who handles customer data for us is under a duty of confidentiality.
5. Compliance with law
Each of us will comply with applicable data protection law in respect of this processing. You are responsible for the lawfulness of what you put into BotSay, including for having a lawful basis to send the content of a question to the AI engines in Annex II. See section 5 of the Terms of Service.
6. Security
We maintain appropriate technical and organisational measures to protect customer data, taking account of the state of the art, the cost of implementation and the nature, scope, context and purposes of the processing, including:
- single sign-on against your identity provider, with authorisation checked on every request;
- encryption of customer data in transit;
- access to production systems restricted to personnel who require it;
- review of changes before they reach production, and automated testing;
- payment handled entirely by our payment provider, so no card data enters our systems;
- data minimisation as the principal measure: we send an AI engine the text of one question and usually a country code, and nothing identifying you, your account or your users; we do not retain raw provider responses once an answer has been processed;
- assessment of a subprocessor's security posture before it processes customer data.
We may change these measures as the product changes, but not in a way that materially weakens overall security.
We hold no security certification covering BotSay and make no certification claim.
7. Telling you about a security incident
If we become aware of a personal data breach affecting customer data we will:
- notify you without undue delay after confirming it,
- tell you what we know about what happened, what data and approximately how many people are affected, the likely consequences and what we are doing about it,
- keep you updated as we learn more, and
- assist you in meeting your own notification obligations.
Telling you about an incident is not an admission of fault.
8. Helping you comply
Taking into account the nature of the processing and the information available to us, we will give you reasonable assistance with data protection impact assessments and prior consultations, and with your obligations to keep personal data secure and to report breaches. Most of what an assessment requires is in Annex I, section 6 and our published methodology page. We may charge a reasonable fee for assistance that goes substantially beyond that.
9. Subprocessors
You give us general authorisation to use subprocessors. The current list is in Annex II and is maintained at botsay.ai/subprocessors.
Before a new subprocessor begins processing customer data we will give you at least 30 days' notice.
If you reasonably object on data protection grounds within that period, we will use commercially reasonable efforts to give you a way to avoid the objected-to subprocessor. For an AI engine, you can disable that engine for your account yourself from the admin screen, in which case your reports will not cover it. If we cannot offer a workaround you can accept, you may terminate the affected part of the subscription and we will refund fees paid for the period after termination.
We impose data protection obligations on each subprocessor that are no less protective than those in this addendum, and we remain responsible to you for what they do.
The AI engines are subprocessors and their own terms apply to what we send them. Annex II describes what each one receives.
10. Confidentiality
We treat customer data as your confidential information under the Terms of Service.
11. Audits and information requests
On written request, and no more than once in any twelve month period, we will provide the information reasonably necessary to demonstrate compliance with this addendum.
We will do so first by providing our documentation: this addendum with its annexes, our security documentation, and any current third-party audit report or certification we hold.
If that documentation genuinely does not answer your question, we will cooperate with an audit on reasonable notice, during business hours, in a manner that does not disrupt the service or risk another customer's confidentiality, at your cost. An auditor must sign a confidentiality agreement and must not be a competitor of ours.
Where applicable law gives a supervisory authority a right of audit, nothing here limits it.
12. Data subject requests
If a data subject contacts us directly about data we process for you, we will not respond substantively. We will direct them to you and tell you promptly.
Where you cannot resolve a request yourself, we will give you reasonable assistance. We may charge a reasonable fee for assistance that goes substantially beyond passing on the request.
13. Return or deletion of customer data
Within 30 days of the end of your subscription you may ask us in writing for an export of customer data. We will provide one export, in our standard machine-readable format, within 30 days of that request.
We will delete customer data within 60 days of the end of your subscription, however it ends. If you have requested an export, deletion follows delivery of that export.
The exceptions, and there are only three:
- Our own business records. Our record of what the service cost us to run, and our record that you were a customer and paid, kept for the statutory accounting period. Neither contains anything you wrote, anything an AI engine returned, or the name or address of any of your users.
- Backups taken in the ordinary course, which are overwritten on their normal cycle and remain protected by this addendum until they are.
- Anything the law requires us to keep, in which case we keep only what we must, for only as long as we must, and continue to protect it.
14. International transfers
Customer data is transferred to and processed in the United States, and in the other countries stated in Annex II.
Where personal data protected by European, UK or Swiss law is transferred to a country without an adequacy decision, the transfer is made under the EU-US Data Privacy Framework together with its UK Extension and the Swiss-US Data Privacy Framework.
Where that framework does not apply to a transfer, or ceases to be a valid transfer mechanism, the European Commission's Standard Contractual Clauses of 4 June 2021 apply and are incorporated into this addendum by reference, with Module Two (controller to processor) where you are a controller and Module Three (processor to processor) where you are a processor. For transfers subject to UK law, the UK International Data Transfer Addendum applies to those clauses. For the purposes of those clauses:
- you are the data exporter and we are the data importer;
- the optional docking clause applies;
- for Clause 9, general written authorisation applies with the 30 day notice period in section 9;
- for Clause 11, the independent dispute resolution option does not apply;
- for Clause 17 and Clause 18, the governing law and forum are those of Ireland;
- Annex I and Annex II of this addendum populate the corresponding annexes of those clauses, and section 6 populates the technical and organisational measures.
If a transfer mechanism ceases to be valid we will implement an alternative without undue delay.
15. California
Where the CCPA as amended applies, we act as a service provider. We:
- do not sell or share personal information as those terms are defined,
- do not retain, use or disclose personal information for any purpose other than performing the service, or as the CCPA otherwise permits,
- do not combine personal information received from you with personal information from another source, except as the CCPA permits,
- comply with the obligations the CCPA places on a service provider and provide the same level of protection it requires, and
- will tell you if we determine we can no longer meet those obligations.
You may take reasonable steps to confirm we use personal information consistently with your obligations, using section 11.
16. Liability
The limits in the Terms of Service apply to this addendum. Our total liability under the Terms of Service and this addendum together is subject to a single aggregate cap, not a separate cap under each.
17. Conflict and duration
If this addendum conflicts with the Terms of Service on data protection, this addendum prevails. Where a transfer mechanism in section 14 conflicts with either, that mechanism prevails.
This addendum lasts as long as we process customer data for you, and its obligations survive the end of the Terms of Service for as long as we hold any of it.
Annex I: details of the processing
Processor: Caspio, Inc., 1286 Kifer Road, Suite 107, Sunnyvale, CA 94086, USA.
Data protection contact: support.botsay.ai
Controller: you, the customer identified in the Terms of Service.
Subject matter. Providing BotSay, an AI-search visibility measurement service.
Duration. For the term of the subscription, plus the return and deletion periods in section 13.
Nature and purpose. Putting questions written by you to third-party AI engines; receiving and processing their answers; extracting brand mentions and citations from those answers using an AI model; computing summary measurements; storing the results; making them available to your authorised users; and sending a periodic summary email.
Types of personal data.
| Category | Source |
|---|---|
| Any personal data you choose to put into a question | You. We cannot see it in advance and it is sent to the AI engines in Annex II. The Terms of Service prohibit putting special categories of personal data, health information, payment card data and government identification numbers into a question, and ask you not to put other personal data into one |
| Any personal data appearing in an AI engine's answer or on a web page it cited | The engines. We do not select it. What is retained is a short verbatim extract per brand mention, plus URLs and page titles |
| An identifier for whoever made a settings change, in our account records | Your users' actions |
Special categories of personal data. None permitted.
Categories of data subject.
- Any individual you name in a question.
- Any individual named in an answer an AI engine returned, or on a web page it cited. We do not select these individuals and cannot anticipate them.
- Your authorised users, in respect of the account records above.
Frequency. Continuous for the web application. Scheduled for the measurement cycle.
Retention. As set out in the Privacy Policy and section 13 of this addendum. In summary: raw provider responses are not retained once processed; measurement records are kept for as long as the account is open; all customer data is deleted within 60 days of the account ending.
Location of processing. The United States, and the locations stated in Annex II.
Annex II: subprocessors
Maintained at botsay.ai/subprocessors. We give at least 30 days' notice before a new subprocessor begins processing customer data.
AI engines, which receive the text of the questions you wrote
Each receives one question at a time, in most cases with a two-letter country code indicating which market to search from. None receives your identity, your users' details or your account information.
| Subprocessor | What we send | Purpose | Location |
|---|---|---|---|
| OpenAI | Question text, market | Measuring how ChatGPT answers | United States |
| Anthropic | Question text, market. Separately, the stored answer text from every engine | Measuring how Claude answers, and extracting brand mentions from every answer | United States |
| Question text | Measuring how Gemini answers | United States | |
| Perplexity | Question text, market | Measuring how Perplexity answers | United States |
| DataForSEO | Question text as a search query, with location and language | Retrieving Google's AI search surfaces through licensed search infrastructure | Estonia |
Anthropic appears twice on purpose. As well as being one of the measured engines, a Claude model extracts brand mentions from each stored answer, so Anthropic receives answer text from every engine, not only its own.
Which of these apply to you depends on your plan and on which engines you have enabled. You can disable an included engine for your account at any time.
Infrastructure and operations
| Subprocessor | What they receive | Purpose | Location |
|---|---|---|---|
| Caspio | All customer data | The database holding every BotSay record | United States |
| Railway | Data in transit through the running application | Hosting the application and the scheduled worker | United States (US West) |
| Railway (buckets) | Compressed copies of measurement records | Storage of measurement history | United States (US West) |
| Stripe | Billing contact details and card details, provided by you directly to Stripe | Taking payment. Card details do not pass through our systems | United States |
| Resend | Recipient email addresses and message content | Sending summary and service email | United States |
| Cloudflare | Bot-check signals from the free report form | Preventing automated abuse | Global |
Planned, not yet active
HubSpot. We plan to send customer account data to HubSpot, our customer relationship management system: the workspace as a company, its admins and members as contacts, the plan, the account state and its dates. Never the questions, answers, mentions, citations or figures in a customer's account.
This subprocessor is not yet in use. Section 9's general authorisation and 30 day notice apply to it like any other addition, and this table must be updated, and the notice period must run, before this sync is switched on.