BotSay.ai
Legal

Data processing addendum

Last updated 23 September 2026. Privacy   Terms   Subprocessors

  1. The short version
  2. 1. Definitions
  3. 2. When this applies
  4. 3. Roles
  5. 4. What we will and will not do with your data
  6. 5. Compliance with law
  7. 6. Security
  8. 7. Telling you about a security incident
  9. 8. Helping you comply
  10. 9. Subprocessors
  11. 10. Confidentiality
  12. 11. Audits and information requests
  13. 12. Data subject requests
  14. 13. Return or deletion of customer data
  15. 14. International transfers
  16. 15. California
  17. 16. Liability
  18. 17. Conflict and duration
  19. Annex I: details of the processing
  20. Annex II: subprocessors

This addendum forms part of the BotSay Terms of Service between you and Caspio, Inc. ("we", "us"). It applies wherever we process personal data on your behalf. It is incorporated into the Terms of Service and takes effect when you accept them. No separate signature is required.

If it conflicts with the Terms of Service on data protection, this addendum prevails.

The short version

The numbered sections are the binding version.

1. Definitions

"Personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in applicable data protection law. "Customer data" means data you put into BotSay or that we generate for you in your account. "Applicable data protection law" means whichever of the GDPR, the UK GDPR, the Swiss FADP, the CCPA as amended and any other data protection law applies to the processing. Terms not defined here have the meaning given in the Terms of Service.

2. When this applies

This addendum applies whenever we process personal data on your behalf in connection with BotSay.

It does not apply to personal data we process on our own account, such as your billing contact's details and the details of the individuals who administer and use your account. Our Privacy Policy covers that processing and we are the controller of it.

3. Roles

You act as controller, or as a processor for a controller of your own. We act as your processor or, where you are a processor, as your subprocessor. The companies in Annex II act as our subprocessors.

Annex I sets out the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject. It is written to serve as the record required by GDPR Art. 30 in respect of this processing.

4. What we will and will not do with your data

We will process customer data only:

We will not sell customer data, will not share it for cross-context behavioural advertising, and will not use it for our own purposes.

We will not use customer data to train machine learning models. Where a subprocessor's terms allow us to require the same of them, we do.

We may create and use aggregated, de-identified data derived from the processing. It identifies no data subject, customer, brand or market and cannot reasonably be used to re-identify any of them.

If we believe an instruction breaches applicable data protection law, we will tell you.

Everyone who handles customer data for us is under a duty of confidentiality.

5. Compliance with law

Each of us will comply with applicable data protection law in respect of this processing. You are responsible for the lawfulness of what you put into BotSay, including for having a lawful basis to send the content of a question to the AI engines in Annex II. See section 5 of the Terms of Service.

6. Security

We maintain appropriate technical and organisational measures to protect customer data, taking account of the state of the art, the cost of implementation and the nature, scope, context and purposes of the processing, including:

We may change these measures as the product changes, but not in a way that materially weakens overall security.

We hold no security certification covering BotSay and make no certification claim.

7. Telling you about a security incident

If we become aware of a personal data breach affecting customer data we will:

Telling you about an incident is not an admission of fault.

8. Helping you comply

Taking into account the nature of the processing and the information available to us, we will give you reasonable assistance with data protection impact assessments and prior consultations, and with your obligations to keep personal data secure and to report breaches. Most of what an assessment requires is in Annex I, section 6 and our published methodology page. We may charge a reasonable fee for assistance that goes substantially beyond that.

9. Subprocessors

You give us general authorisation to use subprocessors. The current list is in Annex II and is maintained at botsay.ai/subprocessors.

Before a new subprocessor begins processing customer data we will give you at least 30 days' notice.

If you reasonably object on data protection grounds within that period, we will use commercially reasonable efforts to give you a way to avoid the objected-to subprocessor. For an AI engine, you can disable that engine for your account yourself from the admin screen, in which case your reports will not cover it. If we cannot offer a workaround you can accept, you may terminate the affected part of the subscription and we will refund fees paid for the period after termination.

We impose data protection obligations on each subprocessor that are no less protective than those in this addendum, and we remain responsible to you for what they do.

The AI engines are subprocessors and their own terms apply to what we send them. Annex II describes what each one receives.

10. Confidentiality

We treat customer data as your confidential information under the Terms of Service.

11. Audits and information requests

On written request, and no more than once in any twelve month period, we will provide the information reasonably necessary to demonstrate compliance with this addendum.

We will do so first by providing our documentation: this addendum with its annexes, our security documentation, and any current third-party audit report or certification we hold.

If that documentation genuinely does not answer your question, we will cooperate with an audit on reasonable notice, during business hours, in a manner that does not disrupt the service or risk another customer's confidentiality, at your cost. An auditor must sign a confidentiality agreement and must not be a competitor of ours.

Where applicable law gives a supervisory authority a right of audit, nothing here limits it.

12. Data subject requests

If a data subject contacts us directly about data we process for you, we will not respond substantively. We will direct them to you and tell you promptly.

Where you cannot resolve a request yourself, we will give you reasonable assistance. We may charge a reasonable fee for assistance that goes substantially beyond passing on the request.

13. Return or deletion of customer data

Within 30 days of the end of your subscription you may ask us in writing for an export of customer data. We will provide one export, in our standard machine-readable format, within 30 days of that request.

We will delete customer data within 60 days of the end of your subscription, however it ends. If you have requested an export, deletion follows delivery of that export.

The exceptions, and there are only three:

  1. Our own business records. Our record of what the service cost us to run, and our record that you were a customer and paid, kept for the statutory accounting period. Neither contains anything you wrote, anything an AI engine returned, or the name or address of any of your users.
  2. Backups taken in the ordinary course, which are overwritten on their normal cycle and remain protected by this addendum until they are.
  3. Anything the law requires us to keep, in which case we keep only what we must, for only as long as we must, and continue to protect it.

14. International transfers

Customer data is transferred to and processed in the United States, and in the other countries stated in Annex II.

Where personal data protected by European, UK or Swiss law is transferred to a country without an adequacy decision, the transfer is made under the EU-US Data Privacy Framework together with its UK Extension and the Swiss-US Data Privacy Framework.

Where that framework does not apply to a transfer, or ceases to be a valid transfer mechanism, the European Commission's Standard Contractual Clauses of 4 June 2021 apply and are incorporated into this addendum by reference, with Module Two (controller to processor) where you are a controller and Module Three (processor to processor) where you are a processor. For transfers subject to UK law, the UK International Data Transfer Addendum applies to those clauses. For the purposes of those clauses:

If a transfer mechanism ceases to be valid we will implement an alternative without undue delay.

15. California

Where the CCPA as amended applies, we act as a service provider. We:

You may take reasonable steps to confirm we use personal information consistently with your obligations, using section 11.

16. Liability

The limits in the Terms of Service apply to this addendum. Our total liability under the Terms of Service and this addendum together is subject to a single aggregate cap, not a separate cap under each.

17. Conflict and duration

If this addendum conflicts with the Terms of Service on data protection, this addendum prevails. Where a transfer mechanism in section 14 conflicts with either, that mechanism prevails.

This addendum lasts as long as we process customer data for you, and its obligations survive the end of the Terms of Service for as long as we hold any of it.


Annex I: details of the processing

Processor: Caspio, Inc., 1286 Kifer Road, Suite 107, Sunnyvale, CA 94086, USA.
Data protection contact: support.botsay.ai

Controller: you, the customer identified in the Terms of Service.

Subject matter. Providing BotSay, an AI-search visibility measurement service.

Duration. For the term of the subscription, plus the return and deletion periods in section 13.

Nature and purpose. Putting questions written by you to third-party AI engines; receiving and processing their answers; extracting brand mentions and citations from those answers using an AI model; computing summary measurements; storing the results; making them available to your authorised users; and sending a periodic summary email.

Types of personal data.

Category Source
Any personal data you choose to put into a question You. We cannot see it in advance and it is sent to the AI engines in Annex II. The Terms of Service prohibit putting special categories of personal data, health information, payment card data and government identification numbers into a question, and ask you not to put other personal data into one
Any personal data appearing in an AI engine's answer or on a web page it cited The engines. We do not select it. What is retained is a short verbatim extract per brand mention, plus URLs and page titles
An identifier for whoever made a settings change, in our account records Your users' actions

Special categories of personal data. None permitted.

Categories of data subject.

Frequency. Continuous for the web application. Scheduled for the measurement cycle.

Retention. As set out in the Privacy Policy and section 13 of this addendum. In summary: raw provider responses are not retained once processed; measurement records are kept for as long as the account is open; all customer data is deleted within 60 days of the account ending.

Location of processing. The United States, and the locations stated in Annex II.


Annex II: subprocessors

Maintained at botsay.ai/subprocessors. We give at least 30 days' notice before a new subprocessor begins processing customer data.

AI engines, which receive the text of the questions you wrote

Each receives one question at a time, in most cases with a two-letter country code indicating which market to search from. None receives your identity, your users' details or your account information.

Subprocessor What we send Purpose Location
OpenAI Question text, market Measuring how ChatGPT answers United States
Anthropic Question text, market. Separately, the stored answer text from every engine Measuring how Claude answers, and extracting brand mentions from every answer United States
Google Question text Measuring how Gemini answers United States
Perplexity Question text, market Measuring how Perplexity answers United States
DataForSEO Question text as a search query, with location and language Retrieving Google's AI search surfaces through licensed search infrastructure Estonia

Anthropic appears twice on purpose. As well as being one of the measured engines, a Claude model extracts brand mentions from each stored answer, so Anthropic receives answer text from every engine, not only its own.

Which of these apply to you depends on your plan and on which engines you have enabled. You can disable an included engine for your account at any time.

Infrastructure and operations

Subprocessor What they receive Purpose Location
Caspio All customer data The database holding every BotSay record United States
Railway Data in transit through the running application Hosting the application and the scheduled worker United States (US West)
Railway (buckets) Compressed copies of measurement records Storage of measurement history United States (US West)
Stripe Billing contact details and card details, provided by you directly to Stripe Taking payment. Card details do not pass through our systems United States
Resend Recipient email addresses and message content Sending summary and service email United States
Cloudflare Bot-check signals from the free report form Preventing automated abuse Global

Planned, not yet active

HubSpot. We plan to send customer account data to HubSpot, our customer relationship management system: the workspace as a company, its admins and members as contacts, the plan, the account state and its dates. Never the questions, answers, mentions, citations or figures in a customer's account.

This subprocessor is not yet in use. Section 9's general authorisation and 30 day notice apply to it like any other addition, and this table must be updated, and the notice period must run, before this sync is switched on.