Ir al contenido

Nuevo: el chatbot de e-commerce — recomendaciones, carrito y seguimiento de pedidos en la conversación.Descubrir

Legal

Data Processing Agreement

Data Processing Agreement (DPA) — art. 28 GDPR and art. 9 FADP

Version 1.1 — Last updated: 3 August 2026

1. Object and roles of the parties

This Agreement (the “DPA”) governs the processing of personal data carried out by Botello on behalf of the client brand in the provision of the Botello service (conversational assistant integrated on the brand's site or messaging, and associated administration console).

The Client (the brand subscribing to the service) acts as controller (art. 4(7) GDPR, art. 5(j) FADP). Botello acts as processor (art. 4(8) GDPR, art. 5(k) FADP) and processes the data only on behalf of, and on the instructions of, the Client.

This Agreement supplements the General Terms of Service. In case of contradiction regarding the processing of personal data, it prevails. It does not cover processing for which Botello acts as controller (console accounts, botello.ch visitors, prospecting), described in the Privacy Policy.

2. Definitions

The terms “personal data”, “processing”, “controller”, “processor”, “data subject” and “data breach” have the meaning given by the GDPR, the FADP and, where applicable, the UK GDPR. “Sub-processor” means any provider engaged by Botello to process data on behalf of the Client.

3. Description of the processing (Annex I)

Nature and purposeHosting, indexing and processing of the content necessary for the assistant to operate: responding to the brand's visitors and customers, capturing contacts, monitoring conversations and producing analytical reports, on behalf of the Client.
DurationThe term of the contract, plus the retention periods in section 11.
Data subjectsVisitors and customers of the brand interacting with the assistant (website or WhatsApp), and persons whose data appears in the knowledge base provided by the Client.
Categories of dataPseudo-anonymous session identifier, message content, technical metadata, response feedback, contact details submitted via the form (name, email, phone, notes), and for WhatsApp concierge: number and profile name, stay dates.
Sensitive dataThe service is not intended to process special categories of data (art. 9 GDPR) or sensitive data under the FADP. The Client undertakes not to introduce any.

4. Processing on documented instructions

Botello processes personal data only on the Client's documented instructions, including for transfers outside Switzerland, the EEA or the UK, unless legally required (in which case Botello informs the Client, unless legally prohibited).

Subscription, configuration of the assistant and use of the console constitute the Client's instructions. Any further instruction is sent to contact@botello.ch. Botello informs the Client if, in its opinion, an instruction breaches applicable law.

5. Confidentiality of personnel

Botello ensures that persons authorised to process the data are bound by confidentiality or an appropriate statutory duty, and that access is limited to what is strictly necessary.

6. Security of processing

Botello implements appropriate technical and organisational measures (art. 32 GDPR, art. 8 FADP): encryption in transit (TLS 1.2+), integration-token encryption (AES-256-GCM), password hashing (bcrypt 12 rounds), MFA mandatory for staff and infrastructure access, role-based access control, input validation (Zod), HMAC verification of webhooks, rate limiting, security headers, log redaction, Sentry monitoring and encrypted backups.

The detailed list is in the “Security” section of the Privacy Policy.

7. Sub-processors

The Client authorises Botello to use the sub-processors below (general prior written authorisation, art. 28(2) GDPR).

ProviderFunctionLocation
HostingerServer hosting (VPS)France (EU)
InfomaniakTransactional email (SMTP)Switzerland
Google (Gemini API)Main AI engine and embeddingsUnited States
Google (Places API)Location autocomplete (concierge)United States
SentryApplication error monitoringGermany (EU)
StripeSubscription billingUnited States and Ireland

Botello contractually imposes on each sub-processor obligations equivalent to those of this Agreement and remains fully responsible to the Client for their performance.

Botello informs the Client of any addition or replacement of a sub-processor at least 30 days in advance, allowing time to object. On an unresolved legitimate objection, the Client may terminate under the GTS.

Third-party integrations activated at the Client's request (Shopify, Meta/WhatsApp, Klaviyo, Gorgias) are the Client's own accounts: the Client remains responsible for them and contracts directly with those providers.

8. Assistance with data-subject rights

Botello assists the Client, by appropriate measures and to the extent possible, in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection). The console allows the relevant conversations and contacts to be searched, exported and deleted.

If a data subject addresses a request directly to Botello, Botello transfers it to the Client without undue delay and does not answer it itself, unless instructed.

9. Assistance with the Client's security obligations

Botello assists the Client in meeting its obligations of security, breach notification, data-protection impact assessment (DPIA) and prior consultation of the authority, taking into account the nature of the processing (art. 28(3)(f) GDPR).

10. Personal data breaches

Botello notifies the Client of any breach affecting it without undue delay after becoming aware, and at the latest within 48 hours, so as to leave the Client time to meet its own 72-hour deadline towards the supervisory authority (art. 33 GDPR). The notification describes the nature of the breach, the categories and approximate number of data subjects concerned, the likely consequences and the measures taken.

11. Retention, return and deletion

At the end of the service, Botello, at the Client's choice, deletes or returns the data processed on its behalf and destroys copies, subject to legal retention. Failing instruction within 30 days, Botello deletes.

In-term retention: conversations and contacts up to 24 months after the last interaction, technical logs 90 days, backups max 30 days after the main deletion. Data read on the fly from a connected store is not retained.

12. Audits and provision of information

Botello makes available the information necessary to demonstrate compliance with art. 28 GDPR and allows audits (reasonable notice, business hours, no disproportionate disruption, confidentiality of other clients, at most once a year save an incident or authority requirement).

13. International transfers

For any sub-processor outside Switzerland, the EEA or the UK, Botello frames the transfer: adequacy decision (e.g. Canada), Data Privacy Framework certification (EU-US, UK Extension, Swiss-US), or Standard Contractual Clauses (Decision (EU) 2021/914) with the UK (ICO) and Swiss (FDPIC) addenda.

14. Artificial intelligence and non-training

Data processed on behalf of the Client is never used to train or improve AI models, by Botello or its sub-processors. Models are used in standard inference mode, with non-training options activated where they exist. The assistant indicates its artificial nature in accordance with art. 50 of the AI Act.

15. United States — State privacy laws (CCPA/CPRA and others)

This section applies only, and to the extent, that the Client is subject to the California Consumer Privacy Act as amended by the CPRA (“CCPA/CPRA”) or to another US state privacy law (including Virginia, Colorado, Connecticut, Utah, Texas). For any Client not subject to such laws, this section has no effect.

With respect to personal information processed on behalf of the Client, Botello acts as a “Service Provider” (CCPA/CPRA) / “Processor”, and the Client as the “Business” / “Controller”. Botello processes such information solely to perform the service (the “Business Purpose”).

Botello does not “sell” or “share” the personal information, does not retain, use or disclose it for any purpose other than performing the service, nor outside the direct business relationship, and does not combine it with information from other sources except as permitted by the CCPA/CPRA. Botello certifies that it understands and will comply with these restrictions.

Botello assists the Client in responding to consumer requests (access, know, correct, delete, opt out of sale/sharing), notifies the Client if it can no longer meet its obligations, and imposes these same obligations on its sub-processors. The Client may take reasonable steps to monitor compliance (the audit mechanism of section 12 suffices). De-identified data is not re-identified.

16. Term, liability and miscellaneous

The Agreement takes effect on subscription and remains in force as long as Botello processes data on behalf of the Client. Liability is governed by the GTS. The Agreement is subject to Swiss law, without prejudice to the mandatory provisions of the GDPR and UK GDPR; jurisdiction is that of the GTS.

Botello may update this Agreement to reflect legal or service developments; significant changes are signalled by updating the date at the top and, where applicable, by a notification in the console.

17. Contact

For any question or instruction: contact@botello.ch.

The processor under this Agreement is Botello Sàrl (UID CHE-337.160.438), registered with the commercial register of the canton of Vaud on 24 June 2026, c/o Fiduciaire Longchamp Sàrl, En Chamard 55B, Case postale 81, 1442 Montagny-près-Yverdon, Switzerland.