Privacy policy

Last updated: October 2026

1. Overview

BotparkAI is software that companies use to build AI chatbots from their websites, documents and databases and offer them on their own websites or under their own address. Pursuant to Articles 13 and 14 of the General Data Protection Regulation (GDPR), this policy explains which personal data we process when you

  • visit our website botparkai.com,
  • create an account as a customer or team member and use the dashboard (app.botparkai.com), or
  • chat with a chatbot operated by one of our customers using BotparkAI (chat.botparkai.com, embedded chat windows and customers' own addresses).

2. Controller

Nils Oborny Sole proprietorship Rippoldsauer Str. 3 70372 Stuttgart Germany

Phone: +49 152 3207 1777 Email: info@orderpark.de

We have not appointed a data protection officer as there is no legal obligation to do so (Art. 37 GDPR, Section 38 BDSG). For data protection questions, please contact us at the email address above.

3. Roles: when we are controller and when we are processor

We are the controller within the meaning of Art. 4(7) GDPR for our website, customer accounts, contract handling and the security of our service.

Chatbot content and conversations with visitors, however, are processed on behalf of the customer operating the chatbot (processing on behalf pursuant to Art. 28 GDPR, see section 12). The controller for these data is the company on whose website or under whose name the chatbot is offered. Please therefore direct requests regarding your chat data primarily to that company; we support it in responding. If you send your request to us, we forward it to the company concerned.

4. Hosting and server logs

The website, dashboard and chatbots run on a server operated by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, in a data centre in Germany. All connections are encrypted with TLS; certificates are issued by the non-profit certificate authority Let's Encrypt, to which no visitor data is transmitted.

When you access our services, the server necessarily processes your IP address, date and time, the requested address, the status code and browser and operating system information. These data are stored in error and operating logs in order to detect and fix malfunctions and attacks, and are automatically deleted after no more than 14 days. The legal basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR).

5. Our website

On botparkai.com we do not use cookies, analytics or tracking tools, or advertising services. Fonts and all other components are loaded from our own server; no data is transferred to third parties such as Google when you visit.

If you contact us by email or phone, we process your details to answer your enquiry (Art. 6(1)(b) GDPR for enquiries relating to a contract, otherwise Art. 6(1)(f) GDPR). We delete them once the enquiry has been dealt with and no statutory retention obligations apply.

6. Customer account and dashboard

When you create an account or are invited to a team, we process:

  • account data: email address, name, password (only as a cryptographic hash) and sign-in times,
  • organisation data: the company's name, chosen address and logo, plan, settings, and team members' roles and permissions,
  • usage data: which bots, knowledge content and settings you create or change, a change log (who changed what and when), your availability for live chats and the messages you send to visitors as an agent; your name is shown to visitors as their contact person,
  • invitations: the role and a note; the invitation link is stored only as a hash and expires automatically.

The purpose is to provide the dashboard and perform the contract with your company (Art. 6(1)(b) GDPR). If you are invited as a team member, processing is based on your company's and our legitimate interest in the joint use of the service (Art. 6(1)(f) GDPR). The change log serves traceability and security (Art. 6(1)(f) GDPR).

Emails to confirm your address and to reset your password are sent via the authentication service of our provider Supabase (see section 10).

We store account data for as long as the account exists. When a company deletes its organisation, all associated bots, knowledge content, conversations and memberships are deleted immediately. Records we must keep for tax and commercial law reasons (in particular invoices) are retained for up to ten years (Section 147 AO, Section 257 HGB).

7. Cookies and browser storage

In the dashboard we only use technically necessary cookies that keep you signed in. In addition, we store settings such as your chosen appearance (light/dark) and recently opened views in your browser's local storage.

In chat windows we store a random visitor ID, your appearance choice and – only if the operating company has enabled it – your previous conversations in your browser's local storage so that you can continue them on your next visit. The embedded chat window also remembers for the duration of the session whether you closed the hint next to the chat button. We do not set advertising or analytics cookies.

This storage is strictly necessary for the functions you explicitly request (Section 25(2) no. 2 TDDDG). You can delete it in your browser at any time; in the chat window you can also remove your conversations yourself.

8. Chatbots: visitor data

Chatbots for visitors are labelled as AI. When you chat with such a chatbot, we process on behalf of the operating company:

  • the messages you enter and the chatbot's answers including the sources used,
  • a random visitor ID, the language, the channel (embedded or chat page), the address of the website where the chat is embedded, and timestamps,
  • your rating of individual answers (thumbs up/down), if you give one,
  • an automatic evaluation of the conversation (topic, sentiment, whether the question was answered) and questions the chatbot could not answer – so that the company can improve its service,
  • if you are handed over to an agent: the conversation with the company's agent,
  • if you fill in a contact form in the chat: name, email address, phone number and your message.

We do not store your IP address. To protect against abuse (e.g. mass requests or manipulation attempts), it is merely converted into a salted, irreversible hash used to count requests and temporarily block attackers. These counters are deleted after one day at the latest. The legal basis is our and the company's legitimate interest in a secure service (Art. 6(1)(f) GDPR).

Companies can choose to mask email addresses, phone numbers and IBANs in messages before they are stored and before they are passed on to AI services.

Conversations, contact requests and open questions are automatically deleted after the period set by the company, by default after 90 days. The company can delete or export conversations at any time before then.

The legal basis for processing chat data is the relationship between you and the operating company, usually answering your enquiry (Art. 6(1)(b) GDPR) or its legitimate interest in customer communication (Art. 6(1)(f) GDPR). Details can be found in the company's privacy policy. Please do not enter particularly sensitive data (e.g. health data) in the chat unless necessary for your request.

9. Use of AI services

To enable the chatbot to answer, your message, the conversation so far and matching excerpts from the company's knowledge are transmitted to a language model. For this we use the AI Endpoints of OVH SAS (France), which provide the language model and the generation of search vectors (embeddings) in data centres in France.

For safety and quality, a separate decision model (JEV) by TypeSafe AI, Inc. checks inputs, ingested content and answers for manipulation attempts, ranks search results by relevance and evaluates conversations. TypeSafe AI processes these data in the USA (see section 11) and, according to its own statement, does not use them to train AI models.

The AI generates answers based on the company's content. It does not make decisions that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). Answers may be inaccurate; binding information is available from the company itself.

10. Recipients and sub-processors

We only share personal data with service providers we need for operation and with whom we have concluded data processing agreements pursuant to Art. 28 GDPR. For customer data, these providers are also sub-processors within the meaning of section 12:

  • IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany – server operation (hosting). Location: Germany.
  • Supabase, Inc. – database, authentication and file storage, and sending of sign-in emails. Data are stored in a data centre in Frankfurt am Main (infrastructure by Amazon Web Services EMEA SARL). Supabase is a US company (see section 11).
  • OVH SAS, 2 rue Kellermann, 59100 Roubaix, France – language model and embeddings (AI Endpoints). Location: France.
  • TypeSafe AI, Inc., USA – decision model for safety and quality checks, ranking of search results and evaluation of conversations. Location: USA (see section 11).

Within a customer company, the team members authorised by the company can see conversations and contact requests. Beyond that, we only disclose data where we are legally obliged to do so.

11. Transfers to third countries

TypeSafe AI, Inc. processes data in the USA; Supabase, Inc. is headquartered in the USA but stores data in the EU (Frankfurt am Main). Where data are transferred to the USA or may be accessed from there, this takes place on the basis of an adequacy decision of the European Commission (EU-US Data Privacy Framework, Art. 45 GDPR) where the recipient is certified under it, and otherwise on the basis of the standard contractual clauses adopted by the European Commission (Art. 46(2)(c) GDPR) with supplementary safeguards. You can obtain a copy of the safeguards on request at the email address above.

All other data are processed exclusively in Germany and France.

12. Processing on behalf of our customers (Art. 28 GDPR)

For companies using BotparkAI, the following terms apply to the processing of personal data on their behalf. They form part of the contract for the use of BotparkAI.

  • Subject matter and duration: provision of the chatbot software including storage of knowledge content, conversations and contact requests for the term of the contract.
  • Nature and purpose: storing, searching and evaluating content, generating answers with AI, routing conversations to agents, deletion according to the configured periods.
  • Data subjects: chatbot visitors, the customer's contact persons and staff, and persons whose data are contained in content provided by the customer (websites, documents, databases).
  • Types of data: chat messages, contact details from contact forms (name, email address, phone number), visitor IDs, usage and evaluation data, and any personal data the customer stores or connects as knowledge.
  • Instructions: we process the data only on documented instructions from the customer; the contract, the dashboard settings and instructions in text form count as instructions. If we believe an instruction infringes data protection law, we will inform the customer.
  • Confidentiality: persons with access to the data are bound to confidentiality.
  • Security: we implement the technical and organisational measures described in section 13 (Art. 32 GDPR) and adapt them to the state of the art.
  • Sub-processors: the customer authorises the providers listed in section 10. We inform customers of intended changes in advance by email; the customer may object within 14 days for an important data protection reason and, if no solution is found, terminate the contract. We contractually bind sub-processors to the same data protection obligations.
  • Assistance: we assist the customer with data subject requests – in particular through the export and deletion functions in the dashboard – and with its obligations under Art. 32 to 36 GDPR.
  • Personal data breaches: we notify the customer without undue delay after becoming aware of a breach affecting its data.
  • End of processing: after the contract ends or when the customer deletes its organisation, all of the customer's data are deleted unless there is a legal obligation to retain them. The customer can export its data beforehand.
  • Evidence and audits: we provide the customer with the information necessary to demonstrate compliance with these obligations and allow audits by prior arrangement.

13. Technical and organisational measures

  • Encrypted transmission of all connections (TLS); credentials of connected databases are stored encrypted.
  • Strict separation of different customers' data in the application and additionally at database level (row level security).
  • Role and permission concept for team members, passwords and invitation links only as hashes, change log.
  • Server access only via cryptographic keys, regular security updates.
  • Storage in data centres in Germany, automatic deletion periods, export and deletion functions.
  • Abuse protection: request limits, detection of manipulation attempts, quarantine of suspicious content, checking of all answers.
  • Connected databases are used read-only and only with queries defined by the customer.

14. Your rights

Vis-à-vis the respective controller, you have the right to

  • access to the data stored about you (Art. 15 GDPR),
  • rectification of inaccurate data (Art. 16 GDPR),
  • erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • withdraw consent with effect for the future (Art. 7(3) GDPR),
  • lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.

Right to object (Art. 21 GDPR)

Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.

An informal message to info@orderpark.de is sufficient for all requests.

15. Obligation to provide data

An email address and password are required to use the dashboard; without them we cannot create an account. Using a chatbot is voluntary; you only provide details in a contact form if you wish to be contacted.

16. Changes

We update this privacy policy when our service or the legal situation changes. The version published here applies.