Last updated: September 11, 2026
How Botchi protects accounts, business data, and AI workflows.
Sealo S.r.l., Strada Trossi 41, 13871 Verrone (BI), Italy, VAT number IT 02777410024, REA BI-310965 operates Botchi. This page summarizes the measures Botchi uses to protect access, credentials, and data. The Privacy Policy describes purposes, retention, and rights; the subprocessor page lists providers and service-specific AI controls.
| Control | How Botchi handles it |
|---|---|
| Access control | Workspace access is role-based. Business dashboard roles separate viewer, editor, and owner permissions, with sensitive governance actions reserved for owners. |
| Encryption | Traffic is protected with TLS. Sensitive credentials and selected business records are encrypted at rest, with account-scoped encryption controls where supported by the product architecture. |
| Credential handling | OAuth tokens and custom credentials are stored for the connected tools users enable and are protected with encryption and least-privilege service access. |
| Logging discipline | Operational logs are used for reliability, security, usage limits, and billing. Botchi aims to avoid logging raw prompts, outputs, files, secrets, or tool payload bodies. |
| Human oversight | AI outputs can be inaccurate. Botchi is designed for review and approval workflows, especially before external actions such as sending messages or changing connected systems. |
Sealo manages the security of Botchi components within its responsibility, respect for permissions, and correct routing. Customers protect devices and credentials, keep roles and access current, review content, and configure automations appropriately. Model availability does not certify suitability for every type of data or purpose.
Model or provider selection requires Customer assessment only for options actually available and based on the conditions shown for each route. Automatic provider selection stays within the conditions shown for the selected route. Those conditions are the ones declared by each provider: Botchi enforces them at request level and relies on the provider's commitments. The Provider's mandatory obligations remain applicable.
Botchi sends the context needed for the requested feature or automation. Recipients depend on the model and service used, choices available to the user, and account settings.
Controls may include allowed-provider selection, prompt-training restrictions, zero data retention, and log minimization. Their scope depends on the service and endpoint: a protection applied to inference does not automatically extend to transcription, document reading, or other tools. Configurations for Vercel AI Gateway, OpenRouter, Amazon Bedrock, Google Vertex AI, Mistral AI, and Deepgram are described on the subprocessor page.
Sensitive information may be submitted to AI features only where a specific feature or written agreement expressly permits it. See the AI processing section of the Privacy Policy for the categories concerned.
Processing location depends on the feature, service, and configuration used. Botchi does not promise EU-only processing under the standard configuration. Specific requirements for location, retention, or excluding certain countries must be evaluated and agreed separately.
Technical controls do not replace applicable data processing agreements and transfer safeguards. See the Privacy Policy for the general framework and the subprocessor page for provider notes.
Encryption does not apply identically to all data: credentials and protected categories use architecture-specific controls, while certain instructions, histories, and operational records are stored in a form readable by authorized services. We do not claim universal end-to-end conversation encryption.
Support and administration access must be limited to operational needs and authorized roles. Histories may contain instructions, outputs, and action results necessary to reconstruct activity. Log minimization does not mean the product stores no content.
Active-data deletion, backups, and legal retention are described in the Privacy Policy and deletion procedure. These measures do not promise continuous availability, absence of incidents, or recovery of every item; any SLA must be expressly agreed.
For security concerns, privacy requests, or suspected improper disclosure of data, contact hello@botchi.ai. Include the affected workspace, approximate time, and a concise description of the issue.
Sealo assesses reports, takes necessary containment and recovery measures, and handles required communications. For data processed as processor, it informs the customer without undue delay under the DPA. Authority and data-subject notifications follow statutory conditions and deadlines. Reports should not include passwords, keys, or other users' data.
This page describes measures and limitations and is not an ISO certification, SOC attestation, or statement of conformity for every regulated use.