Legal

Data processing addendum

The addendum that applies whenever BotForge processes personal data on a customer's behalf under the GDPR, UK GDPR, or comparable laws.

Last updated 12 June 2026

1. Roles of the parties

Customer is the controller and BotForge is the processor for personal data contained in bot subscribers, conversation content, and delivery records. Where Customer is itself a processor, BotForge acts as subprocessor.

2. Subject matter and duration

Processing lasts for the subscription term plus the thirty-day export window and covers the provision of the BotForge platform as described in the agreement.

3. Categories of data subjects

Telegram users who interact with Customer bots, and Customer personnel who administer the workspace.

4. Types of personal data

Telegram user identifiers, usernames, display names, language codes, message content submitted to flows, collected form responses, segment attributes, and delivery and error metadata.

5. Processor obligations

BotForge processes personal data only on documented instructions, ensures personnel are bound by confidentiality, implements the security measures in Annex II, and assists Customer with data subject requests and impact assessments.

6. Subprocessors

Customer authorises the subprocessors listed on our subprocessors page. We give thirty days’ notice of additions and Customer may object on reasonable data protection grounds.

7. Security measures (Annex II)

TLS 1.2+ in transit with HSTS; AES-256-GCM encryption at rest for Telegram bot tokens and two-factor secrets, decrypted only at the point of use and never logged; scrypt password hashing; httpOnly session cookies with CSRF protection; optional TOTP two-factor authentication; role-based access control enforced server-side; rate limiting on authentication endpoints; append-only audit logging of account, bot, billing and staff actions, including any staff impersonation; encrypted nightly database backups with a documented restore procedure; and a documented incident response process. A full description is published at /security, including controls we have not yet implemented.

8. Personal data breach

BotForge notifies Customer without undue delay and within 72 hours of becoming aware of a personal data breach, with the information available at the time and updates as the investigation proceeds.

9. International transfers

The Standard Contractual Clauses (Module Two and, where relevant, Module Three) are incorporated, with the UK Addendum and Swiss amendments as applicable.

10. Audit

BotForge is not currently certified under SOC 2 or ISO 27001. We make available a completed security questionnaire on request and respond to reasonable due-diligence enquiries. Enterprise customers may request an audit once per year with reasonable notice. Where certification is a procurement requirement, please raise it before purchase.

11. Deletion and return

On termination, Customer may export data for thirty days, after which BotForge deletes it from production systems within thirty days. Encrypted backups are retained on a rolling schedule and deleted on expiry of that schedule, currently thirty-five days.

12. Availability

The service runs in a single region. There is no automated cross-region failover; recovery from a total infrastructure failure is performed by restoring the most recent encrypted backup, which may entail data loss of up to twenty-four hours.

Questions about this document? Write to legal@botforge.com and we will respond within five business days.