Ir al contenido

Nuevo: el chatbot de e-commerce — recomendaciones, carrito y seguimiento de pedidos en la conversación.Descubrir

Legal

Privacy Policy

Version 1.1 — Last updated: 3 August 2026

1. Introduction

Botello is an intelligent conversational assistant that brands integrate on their website, or offer through WhatsApp messaging — in particular as part of a concierge service — to respond to their visitors and customers in real time. An administration console lets the brand manage the assistant's content, monitor conversations, capture contacts and view analytical reports.

This policy describes how Botello collects, uses, shares and protects your personal data, as well as the rights you have over it.

It applies to anyone who visits the botello.ch site, uses our administration console available at admin.botello.ch, interacts with a Botello assistant integrated on a client brand's site or via WhatsApp messaging, or contacts us by email or any other means.

Botello complies with the Swiss Federal Act on Data Protection (FADP), the European Union General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), and the UK GDPR for data subjects located in the United Kingdom. As from 2 August 2026, Botello also applies the transparency obligations of the European Artificial Intelligence Regulation (AI Act, Regulation (EU) 2024/1689) applicable to conversational artificial-intelligence systems.

2. Data controller

Botello Sàrl (UID: CHE-337.160.438), registered with the commercial register of the canton of Vaud on 24 June 2026.
c/o Fiduciaire Longchamp Sàrl, En Chamard 55B, Case postale 81, 1442 Montagny-près-Yverdon, Switzerland.

Represented by its managing partner and chairman, Marius Perriard.

The full identification details of the publisher appear in our legal notice.

Data-protection contact: contact@botello.ch

3. Our dual role: controller and processor

Depending on the context, Botello acts in two distinct legal roles.

Botello is the controller when you visit botello.ch, when you contact us, when you create an account on the administration console, or when you are invited by a client to use that console. In these situations, Botello determines the purpose and means of processing your data.

Botello is a processor when you interact with a Botello assistant integrated on a client brand's site. In that case, the brand is the controller, and Botello processes your data on behalf of that brand, on its instructions, under a processing agreement compliant with art. 9 FADP and art. 28 GDPR, detailed in our Data Processing Agreement (DPA).

To exercise your rights in this second case, contact directly the brand whose site you visited. Botello will assist it in handling your request. If you cannot identify the brand, write to us at contact@botello.ch and we will direct you.

This policy nonetheless describes, for information, how Botello technically processes data in this second role, so that you understand the full flow.

4. Categories of data subjects and data collected

4.1. Visitors and prospects of botello.ch

When you visit our institutional site or contact us, Botello acts as controller.

DataSourceNature
IP address, browser type, pages visited, visit durationAutomatic (server logs)Statistical
Name, email, message when you fill in a contact formYouVoluntary
Email when subscribing to the newsletter or requesting a demonstrationYouVoluntary

4.2. Administration console users

When you create an account or are invited to the administration console, Botello acts as controller.

DataNature
Email address, used as login identifierMandatory
Password, hashed with bcrypt at 12 rounds and never stored in clear textMandatory
Display nameMandatory
Profile photoOptional
Time zoneConfigurable
Interface preferences such as languageConfigurable
Role in the organisation: Owner, Admin, Member or ViewerDefined by your organisation
Login and usage logs: IP address, timestamps, actionsAutomatic

4.3. Visitors to client sites using a Botello assistant

When you interact with a Botello assistant integrated on a brand's site, Botello acts as that brand's processor.

DataNatureStored by Botello
Pseudo-anonymous session identifierAutomaticYes
Full content of messages exchanged with the assistantYouYes
Technical metadata such as detected language, browser and device type, or the context usedAutomaticYes
Feedback on responses, positive or negativeYouYes
Data submitted via the chat contact form: name, email, phone, notesYouYes

4.4. Data accessed from the client's online store

When the client brand has connected its online store, for example Shopify, to Botello, the assistant can consult certain data in real time to answer your questions, such as order tracking or product availability.

DataStored by Botello
Order number, status, contents, amountNo, read on the fly
Customer email (to match an order to its buyer during a tracking request)No, read on the fly
Products, prices, availabilityNo, read on the fly
Promotional codesTemporarily cached for performance purposes only

Botello never writes to the client's online store. Our access is strictly read-only. For Shopify, the scopes used are the following: read_orders, read_products, read_inventory, read_fulfillments, read_locations and read_discounts. We cannot modify, delete or order anything on your behalf.

When accessing this data, Botello acts as the brand's processor and complies with Shopify's requirements on Protected Customer Data: access limited to what is strictly necessary, encryption, and deletion on request or on disconnection of the store (see section 8).

4.5. Users interacting via WhatsApp (concierge service)

When a client brand or establishment activates the Botello concierge service, you can chat with a Botello assistant via WhatsApp messaging, for example after scanning a QR code made available in an accommodation or establishment. In that case, Botello acts as that establishment's processor, and messaging transits through Meta's WhatsApp Business API (see section 6.2).

DataNatureStored by Botello
WhatsApp phone numberAutomatic (from WhatsApp)Yes
WhatsApp profile nameAutomatic (from WhatsApp)Yes
Full content of messages exchanged with the assistantYouYes
Stay or booking dates that you provideYouYes
Accommodation or establishment concernedAutomatic (QR code scan)Yes
Technical metadata such as detected languageAutomaticYes

This data comes from the Meta (WhatsApp) platform and is used exclusively to answer your requests and provide the concierge service. It is never used for targeted advertising, is never resold, and is not used to train artificial-intelligence models (see sections 5 and 13.4).

To exercise your rights, contact directly the establishment concerned. You may also write to us at contact@botello.ch and we will direct you. Deletion of this data can be requested at any time, in accordance with our data deletion procedure.

5. Purposes and legal bases of processing

PurposeCategory concernedLegal basis
Provide the Botello service to our brand clientsConsole users, client-site visitorsPerformance of the contract (art. 6(1)(b) GDPR) or legitimate interest
Authenticate console usersConsole usersPerformance of the contract
Enable brands to respond to their visitorsClient-site visitorsProcessing on behalf of the client, legal basis set by the client
Improve the service through anonymised statistical analysesAllLegitimate interest (art. 6(1)(f) GDPR)
Prevent fraud, abuse and security attacksAllLegitimate interest and legal obligation
Send commercial communications and demonstrationsProspects who have given their consentConsent (art. 6(1)(a) GDPR), revocable at any time
Keep accounts and billingBotello clientsLegal obligation (art. 957 et seq. Swiss CO)
Respond to contact requestsPeople contacting usLegitimate interest or pre-contractual measures

Botello does not use your data for targeted advertising and never sells it to third parties.

6. Recipients of your data

Botello shares your data with a limited number of recipients.

6.1. Sub-processors

We rely on carefully selected providers to operate our service. The list of our sub-processors is as follows.

ProviderFunctionLocation
HostingerServer hosting (VPS)France (EU)
InfomaniakTransactional email (SMTP)Switzerland
Google (Gemini API)Main artificial-intelligence engine and embeddingsUnited States
Google (Places API)Location autocomplete (concierge)United States
Google (Analytics)Audience measurement of the botello.ch siteUnited States
SentryApplication error monitoringGermany (EU)
StripeSubscription billingUnited States and Ireland

Each of these sub-processors is contractually bound to comply with the GDPR and the FADP, and to process your data only on our instructions.

6.2. Third-party integrations, activated at the client's request

When the client brand activates them, the assistant can read or transmit certain data to third-party tools that are the brand's own accounts. Botello then acts solely on the brand's instructions; the brand remains responsible for its own contractual and data-protection relationship with these providers.

ToolFunctionLocation
ShopifyOnline store (read-only)United States and Canada
Meta (WhatsApp Cloud API)WhatsApp messagingUnited States
KlaviyoNewsletter and marketingUnited States
GorgiasSupport and helpdeskUnited States

6.3. Our brand clients, when Botello is a processor

The conversations you have with a Botello assistant on a brand's site are accessible to that brand via the administration console. This access is necessary to the very operation of the service.

6.4. Competent authorities

If required by law, for example by judicial requisition or court order, we may be required to disclose certain data. In that case, we will limit disclosure to what is strictly requested and, where the law permits, we will inform you.

6.5. Business transfer

If Botello were subject to a business transfer, your data could be transferred to the acquirer, in compliance with the applicable legal framework and with prior information.

7. International transfers

Some of our sub-processors are located outside Switzerland, the European Economic Area and the United Kingdom, mainly in the United States and Canada. In these cases, we implement the following safeguards.

Canada benefits from an adequacy decision of the European Commission and the Swiss Federal Council. No additional safeguard is required.

The United Kingdom and Switzerland mutually recognise an adequate level of protection.

For the United States, where the sub-processor is certified under the Data Privacy Framework — the EU-US Data Privacy Framework, its UK Extension, and the Swiss-US Data Privacy Framework, recognised by the Swiss Federal Council since 15 September 2024 — we rely primarily on that certification. Absent certification, we use the European Commission's Standard Contractual Clauses of 4 June 2021 (Decision (EU) 2021/914), supplemented by the UK Addendum issued by the ICO and by the Swiss Annex of the Federal Data Protection and Information Commissioner.

For each transfer outside an adequacy area, Botello carries out a transfer impact assessment in accordance with the Schrems II case law.

You can ask us for a copy of the safeguards in place by writing to contact@botello.ch.

8. Retention periods

Data categoryRetention period
Conversations exchanged with an assistantUp to 24 months after the last interaction, according to the settings agreed with the client
Contacts captured via formUp to 24 months after the last interaction
Technical logs (server, access, errors)90 days
Administration console accountsTerm of the contract plus 30 days
Accounting and billing data10 years, in accordance with art. 958f Swiss CO
Prospect data and commercial contactsUntil your deletion request, and at most 3 years without interaction
Technical backupsMaximum 30 days after the main deletion
Customer data read from a connected store (orders, emails, addresses)Not retained — read on the fly. Promotional codes are temporarily cached for performance purposes only.

Beyond these periods, your data is permanently deleted or irreversibly anonymised.

Deletion of data from a connected store. Botello does not retain the order data read from the store (number, status, buyer email): it is consulted on the fly. On disconnection or uninstallation of the integration, and upon receipt of a deletion request from the brand or from Shopify (webhooks customers/redact and shop/redact) or an access request (customers/data_request), Botello revokes the connection and deletes or anonymises, as soon as possible, the data associated with that store that we store, including any captured contacts and the content of conversations attached to that customer.

9. Your rights over your data

You have the following rights, guaranteed by the FADP, the GDPR and the UK GDPR.

  • Right of access: obtain confirmation that we process your data and receive a copy of it.
  • Right to rectification: correct inaccurate data or complete incomplete data.
  • Right to erasure, known as the right to be forgotten: obtain the deletion of your data, subject to legal obligations, in particular accounting ones.
  • Right to restriction of processing: request that your data be used only for storage, without further processing.
  • Right to portability: receive your data in a structured, commonly used format, and transmit it to another provider.
  • Right to object: object to processing on legitimate grounds, in particular to profiling and commercial prospecting.
  • Right to withdraw your consent: where processing is based on your consent, withdraw it at any time and without retroactive effect.
  • Right not to be subject to a solely automated decision: request human intervention. See section 13 on artificial intelligence.
  • Right to lodge a complaint with a supervisory authority. See section 16.

How to exercise your rights

Send your request to contact@botello.ch from the email associated with your account, or by proving your identity by any equivalent means. We undertake to respond within a maximum of 30 days within the meaning of the GDPR and the UK GDPR, and as soon as possible under the FADP.

Exercising your rights is free. We may however charge a reasonable amount for manifestly unfounded or excessive requests, in accordance with art. 12(5) GDPR.

If your data is processed by Botello as a processor, that is, when an assistant is integrated on a client site, address your request directly to the brand concerned. If you write to us at contact@botello.ch, we will forward your request to the right point of contact.

10. Security of your data

Botello implements appropriate technical and organisational measures to protect your data against loss, unauthorised access, alteration or disclosure, in accordance with art. 8 FADP and art. 32 GDPR.

The main measures in place are as follows.

  • Encryption in transit via TLS 1.2 or higher on all domains, using Let's Encrypt with one-year HSTS.
  • Encryption of integration tokens in AES-256-GCM with a randomised initialisation vector.
  • Password hashing with bcrypt at 12 rounds, compliant with OWASP recommendations.
  • Authentication via JWT sessions with possible revocation.
  • Role-based access control and granular permissions in the administration console.
  • Timing-safe HMAC-SHA256 verification of Shopify webhooks.
  • Rate limiting to prevent brute-force attacks and abuse.
  • Systematic input validation on all our API routes, using Zod schemas.
  • Strict CORS policy with an explicit allowlist of authorised domains.
  • HTTP security headers with a Helmet configuration, including Content Security Policy and X-Frame-Options.
  • Logs with automatic redaction of sensitive fields such as passwords and tokens.
  • Application monitoring via Sentry and alerts in case of anomaly.
  • Encrypted backups stored separately from production.
  • Mandatory contractual confidentiality undertaking for staff.

In the event of a personal data breach likely to create a risk to your rights and freedoms, Botello will notify the competent supervisory authority within 72 hours in accordance with the GDPR and the UK GDPR, and will inform you as soon as possible where the risk is high.

11. Cookies and local storage

11.1. On botello.ch

The institutional site botello.ch uses only cookies strictly necessary for its operation.

Audience measurement. With your consent, we use Google Analytics 4 (Google Ireland Ltd.) to measure the audience of the botello.ch site: pages viewed, visit source, country, interactions (form submission, opening of the assistant). IP addresses are anonymised (anonymize_ip). No measurement cookie is placed without your agreement, and you can withdraw your consent at any time via « Manage cookies » at the bottom of the page. Data may be transferred to the United States under the Data Privacy Framework.

Your consent choice is remembered in botello-consent (browser cookie and local storage), so as not to ask you for your preference again on each visit; it is kept for about one year.

11.2. On the administration console

The administration console uses seven cookies, all strictly necessary for your login, for remembering your preferences and for your ease of use.

Cookie namePurposeDuration
botello_tokenAuthentication token (JWT)7 days
botello_userDisplay information for your account7 days
botello-localeInterface language1 year
sidebar_stateSidebar state (open or collapsed)7 days
botello_last_workspaceLast workspace opened30 days
botello_last_projectLast project opened (legacy)30 days
botello_last_module_<slug>Last module opened per workspace90 days

These cookies are necessary for the operation of the service you have explicitly requested. They are exempt from prior consent under art. 5(3) of Directive 2002/58/EC, known as ePrivacy.

The last four (sidebar_state, botello_last_workspace, botello_last_project and botello_last_module_<slug>) are strictly functional: they remember your display and navigation preferences in the console and serve no audience measurement or advertising tracking.

11.3. On the assistant integrated on client sites

The Botello assistant sets no cookie. It uses only the visitor's browser localStorage, for two strictly necessary purposes: a session identifier allowing the conversation history to be retrieved across page reloads, and a local cache of exchange rates for performance purposes. The session identifier is kept in localStorage until it is cleared by the visitor (clearing the browser storage); it has no automatic expiry.

This data is strictly necessary for the operation of the chat explicitly initiated by the visitor. It falls under the exemption provided by art. 5(3) of the ePrivacy Directive and does not require a consent banner.

12. Minors

The Botello service is intended for professional users in a B2B context. We do not knowingly collect data from persons under 16.

When a Botello assistant is integrated on a website likely to be visited by minors, it is for the client brand, as controller, to implement the appropriate protections, in particular parental consent.

If you believe that a minor under 16 has provided us with data without the required consent, write to us at contact@botello.ch. We will delete the data concerned as soon as possible.

13. Artificial intelligence and automated decisions

13.1. You are interacting with an artificial intelligence

Botello assistants rely on language models. When you chat with a Botello assistant, you are communicating with an artificial-intelligence system, not with a human person.

In accordance with art. 50(1) of the European Artificial Intelligence Regulation, applicable from 2 August 2026, the assistant clearly indicates its nature at the beginning of each conversation.

13.2. Limits of generated responses

Generative artificial intelligence may produce inaccurate, incomplete or misleading responses. Botello does not warrant the accuracy or completeness of the content generated by the assistant. For any important decision such as a purchase, a payment or legal, medical or financial advice, we invite you to verify the information from an official source or to ask to speak to a human. Most of our assistants have a mechanism to transfer to the brand's human team.

13.3. No solely automated decision

Botello makes no decision producing legal or significant effects concerning you by solely automated means within the meaning of art. 22 GDPR and art. 21 FADP.

13.4. No training of models on your data

Conversations, captured contacts and, more generally, your data are never used to train or improve artificial-intelligence models, either by Botello or by its sub-processors. We use the models via their programming interfaces in standard inference mode, with non-training options activated where they exist.

14. Marketing and commercial communications

We send commercial communications (information about our services and news, invitations to demonstrations or events) only to persons who have given specific consent for that purpose, by means of a dedicated, non-pre-ticked checkbox, in accordance with art. 3(1)(o) of the Swiss Federal Act against Unfair Competition (UCA) and art. 6(1)(a) GDPR. Merely filling in a contact form or requesting a demonstration does not constitute consent to commercial prospecting.

Messages strictly related to your contractual relationship (invoices, service alerts) are not prospecting and do not require your consent.

You can unsubscribe at any time via the link in each email, or write to us at contact@botello.ch.

15. Changes to this policy

Botello may need to modify this policy to reflect legal, technical or service developments. Any significant change will be signalled by updating the date at the top of the page, by a notification in the administration console or by email for the users concerned, and by reasonable notice where the changes affect your rights.

Continued use of our services after modification of the policy constitutes acceptance of the updated version.

16. Contact, complaints and supervisory authorities

For any question about this policy or to exercise your rights, contact us at contact@botello.ch or by post at the address indicated in point 2.

You may also refer the matter to a supervisory authority.

  • In Switzerland: Federal Data Protection and Information Commissioner (FDPIC).
  • In the European Union: the data protection authority of your country of residence, for example the CNIL in France, the AEPD in Spain, the Garante in Italy, the BfDI in Germany or the APD in Belgium.
  • In the United Kingdom: Information Commissioner's Office (ICO).

You have the right to lodge a complaint with one of these authorities, without having to contact us first.