WhatIBot🌍

Privacy Policy

Last updated: 27 April 2026 · Effective date: 27 April 2026

This Privacy Policy explains how WhatIBot ("we", "us") collects, uses, stores and shares personal data when you use the SaaS platform at whatibot.com (the "Service"). It is written to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the Spanish LOPDGDD, the Italian Codice Privacy, the Moroccan Law 09-08, and applicable laws in Lithuania and France.

1. Data Controller

WhatIBot is the data controller for the personal data of customers who sign up for the Service. WhatIBot acts as data processor for personal data of your end-users (people who chat with your bot) — you, the customer, are the controller for that data. Contact: whatibotsupport@gmail.com.

2. Data We Collect

From customers (account holders)

From end-users (people chatting with your bot)

3. How We Use Data

4. Subprocessors

We use the following subprocessors to deliver the Service. Each is bound by a data-processing agreement (DPA) and appropriate safeguards (Standard Contractual Clauses for non-EU transfers).

5. International Transfers

Some subprocessors are based outside the EU/EEA (notably Anthropic, Meta and Cloudflare in the US). These transfers are protected by Standard Contractual Clauses approved by the European Commission and supplementary measures including encryption in transit and at rest.

6. Data Retention

7. Security

We use HTTPS/TLS 1.3 for all data in transit, AES-256 encryption at rest for credentials, role-based access control with row-level security in our database, and audit logging for sensitive operations. Customer credentials (third-party API keys, tokens) are encrypted with envelope encryption before storage.

8. Your Rights (GDPR)

You have the right to:

Submit requests to whatibotsupport@gmail.com. We respond within 30 days (extendable to 90 days for complex requests).

9. Automated Decision-Making & AI Disclosure

The Service uses large-language-model AI (Anthropic Claude) to generate replies to messages. This processing produces probabilistic, automated responses but does not produce decisions that have legal or similarly significant effects on individuals within the meaning of GDPR Article 22. Customers may configure the bot to escalate sensitive interactions to a human operator. Anthropic does not use Service inputs or outputs to train its models, per our data-processing agreement with Anthropic.

10. Data Breach Notification

In the event of a personal-data breach likely to result in a risk to the rights and freedoms of natural persons, we notify the relevant supervisory authority within 72 hours of becoming aware (GDPR Art. 33) and notify affected customers and end-users without undue delay (GDPR Art. 34). We maintain an internal incident-response procedure and security audit log.

11. California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, grants you additional rights:

To exercise these rights, email whatibotsupport@gmail.com with "California Privacy Request" in the subject. We verify identity before fulfilling. Authorized agents must provide written authorization.

12. Other US State Rights (VA, CO, CT, UT, TX)

Residents of Virginia, Colorado, Connecticut, Utah, Texas and other states with comprehensive privacy laws have similar rights of access, deletion, correction, portability and opt-out of targeted advertising. Same procedure as §11.

13. End-User Data (Sub-Processing)

When customers' bots talk to end-users, the customer is the data controller for those conversations and WhatIBot is the data processor. Customers are responsible for obtaining valid consent from their end-users before initiating chats. We sign a Data Processing Agreement with every customer on request.

14. Cookies & Tracking

Our website uses strictly necessary cookies for authentication, language preference, and CSRF protection. We do not use third-party advertising cookies and do not track visitors across other websites. We use privacy-friendly, cookieless analytics (Plausible / self-hosted) for traffic measurement.

15. Children

The Service is intended for businesses and is not directed at children under 16 (or under 13 in the United States, per COPPA). We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal information, contact whatibotsupport@gmail.com and we will delete it promptly.

16. Do Not Track

We do not track visitors with persistent identifiers across third-party sites and we honour Global Privacy Control (GPC) and Do Not Track signals where technically applicable.

17. Changes to this Policy

We may update this Privacy Policy. Material changes will be notified by email or in-app banner at least 30 days before they take effect. The "Last updated" date at the top reflects the latest revision. Historical versions are available on request.

18. Contact & Data Protection

This Privacy Policy is written in English. Translations are provided for convenience; in case of conflict, the English version prevails.

Privacy Policy — WhatIBot | WhatIBot