Built On Strong Data Protection, By Design
OttBot handles customer conversations and contact data for businesses across the UK, EU and US โ so data protection isn't an afterthought, it's built into how every product works.
GDPR Compliance
We process personal data in line with the UK GDPR and the EU GDPR. We only collect what we need, we have a lawful basis for every use of data, and we do not keep it for longer than necessary. Our full Privacy Policy explains exactly what we collect, why we collect it, and how long we keep it.
When you use OttBot to talk to your own customers, we act as your data processor and will sign a Data Processing Agreement (DPA) on request. For our own website visitors, leads and account holders, we are the data controller. You can read more about these roles in section 7 of our Privacy Policy.
Anyone whose data we hold has the right to access, correct, delete, export or object to the use of their personal data, and to withdraw consent where consent applies. We also comply with PECR, the UK's e-privacy rules, for electronic marketing and communications. See your data protection rights for the full list.
US Privacy Regulations
For customers and end users in the US, we align with the California Consumer Privacy Act (CCPA) and its amendment the CPRA, along with the newer state privacy laws now in force, including Virginia, Colorado, Connecticut and Utah. These laws give people the right to know what personal data is collected about them, request its deletion, and opt out of having it sold or shared.
We do not sell personal data. Where a state law gives people the right to opt out of data sharing for targeted advertising, we honour that request. Our Privacy Policy sets out what we collect and how to make a request.
Microsoft Azure Infrastructure
OttBot runs on Microsoft Azure, hosted in the UK. Your content, conversations and contact records in OttBot Data sit on Azure's enterprise-grade cloud infrastructure.
Azure is independently certified to leading security standards, including ISO/IEC 27001 and SOC 1, 2 and 3, and runs data centres with physical security, redundancy, backups and continuous monitoring. Hosting in the UK keeps data residency close to home. Where our providers process data in other countries, those transfers are covered by appropriate safeguards such as the UK International Data Transfer Agreement (IDTA) and Standard Contractual Clauses, as explained in international data transfers.
PCI-DSS Compliant Payments With Stripe
All card payments are processed by Stripe, a PCI-DSS Level 1 certified payment provider, the highest level of certification in the payments industry.
Your card details are captured and handled directly by Stripe's secure, compliant systems. We never see or store your full card number, CVV or full payment card details. Keeping card data out of our systems reduces risk and keeps every payment inside Stripe's certified PCI-DSS environment.
Encrypted Data Transmission
Data is encrypted in transit using HTTPS (TLS) to increase transfer security, so information stays protected as it moves between your browser, our products and the services they connect to.
Data is also encrypted at rest where appropriate, and access to customer data is limited to the people who need it, with role-based permissions, logging and monitoring throughout. You can read our full approach in section 14 (Security) of our Privacy Policy.
Practical Safeguards, Not Just Policy
Encryption everywhere
Data is encrypted in transit over HTTPS (TLS) and at rest, so information stays protected on the way in, in storage, and on the way out.
Access controls
Access to customer data is limited to the people who need it to do their job, with role-based permissions throughout.
Data minimisation
We only collect and retain what's needed to deliver the service, and we delete it when it's no longer needed.
Vetted sub-processors
Any third-party tool we rely on is reviewed for its own data protection and security standards before we use it.
Breach notification
If something ever goes wrong, we have a process to identify, contain and notify affected parties promptly, as required by law.
Team training
Everyone on the team is trained on data handling and privacy practices, not just the engineers who build the product.
Every Channel And Tool, In One Connected Runtime
OttBot Connect plugs straight into the channels your customers already use: messaging, social media, email and your website.
Connect The Tools Your Team Already Lives In
OttBot connects to the everyday tools your team already relies on, covering scheduling, CRM, payments and email, with new Integration (MCP) connections added all the time. Every connection runs over secure, authenticated channels.
Have A Question About Your Data?
This page is a summary of our approach, not the full legal text. For the complete detail, read our Privacy Policy. If you need our Data Processing Agreement, have a question about a specific request, or want to report a concern, get in touch and we'll respond promptly.