
Botpress and GDPR
CertReports found no public GDPR evidence for Botpress as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 24 Aug 2023
- Expires or valid through
- 23 Jul 2027
- Scope
- Botpress processes personal data under the EU-U.S., UK Extension to the EU-US DPF and Swiss-U.S. DPF for various purposes, including service delivery, technical support, product improvement, marketing, communication as well as legal and compliance. The data processed includes customer data (e.g. email address), visitor data (e.g. IP address, browsing behavior) and data related to service usage, website interactions, and user communications. Botpress uses this data to operate and secure its services, respond to requests, and improve its products. Personal data may be shared with service providers and Botpress affiliates under strict confidentiality and security measures. End-user data is also shared with each customer controlling the customer chatbot where applicable. Data transfers outside the EEA, UK, or Switzerland are safeguarded by compliance with relevant data protection standards. Botpress shares personal data with employees who require access to perform their duties. They are bound by confidentiality agreements. Botpress also shares data with its customers, particularly regarding end-users interacting with customer-controlled bots, where the customer acts as the data controller. Service providers may receive personal data to enhance operational efficiency, provided they maintain confidentiality and implement robust security measures. Additionally, Botpress may share data with affiliates or third parties when legally required, during legal proceedings, or in the event of a business sale or restructuring, with a commitment to maintaining confidentiality.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Botpress: Active: EU-US Certification, UK Extension Certification, SW-US Certification | Live pagesha256 2f8fb7015a |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Botpress GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the AI assistants category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No AI assistants vendor has GDPR evidence in the index yet.