Legal document
Privacy Policy
Last updated:
July 22, 2026
Welcome to builderbot.cloud. Below, we explain how we collect, use, and protect your personal data. Use of the service is also governed by our Terms and Conditions. This document is complemented by our GDPR notice and, where applicable, our Data Processing Agreement (DPA) and our Standard Contractual Clauses (SCCs).
Data Controller and Roles
Data controller for your account data and use of the platform:
BuilderBot Cloud, LLC
1111b South Governors Avenue, STE 23416, Dover, DE 19904, United States
Email: support@builderbot.cloud
- When you create an account and use builderbot.cloud, BuilderBot Cloud acts as the controller of your identification, contact, billing, and platform configuration data.
- When you use the Service to process personal data of your own end users (for example, WhatsApp or Instagram conversations with your customers), you are the controller of that data and BuilderBot Cloud acts as the processor, under our DPA.
Information We Collect
Depending on how you use our services, we collect the following types of information:
A. Data provided directly by the user
- First and last name.
- Email address.
- Profile information (photo, description).
- Information entered when creating chatbots or conversation flows within the platform.
B. Information collected through the WhatsApp API (Meta)
For the proper operation of Chatbot services and integration with WhatsApp Business, we process the following specific data:
- WhatsApp Business Account (WABA) information: Account identifiers, associated phone numbers, and display names.
- Messaging data: Recipient and sender phone numbers, message content (text, images, documents, audio), and message status (sent, delivered, read).
- Message templates: Information about templates created and their approval status with Meta.
This data is strictly necessary to transmit communications between your business and your end users.
C. Information collected through the Instagram API (Meta)
For the proper operation of Chatbot services and integration with Instagram, we process the following specific data based on the permissions granted:
| Permission | Data accessed | Purpose |
|---|---|---|
instagram_basic | Username, biography, profile photo, follower count, post count, website, account type | Identify and configure the connected Instagram Business account on the platform |
instagram_manage_comments | Comments on the user's posts, comment replies | Enable the chatbot to read, reply to, and, when necessary, delete comments on business posts in an automated manner |
instagram_manage_messages | Direct messages (DMs) received from users who have initiated a conversation with the business account | Enable the chatbot to process and reply to direct messages in real time |
This data is strictly necessary to automate the business's interactions with its audiences on Instagram.
Important: builderbot.cloud only accesses direct messages from users who have previously initiated a conversation with the business account. We do not access private conversations between third parties or messages unrelated to interaction with the business.
D. Google Integrations (Optional)
If you choose to connect your Google account, we access only the data necessary for the requested functionality:
| Data type | Scope | Access | Purpose |
|---|---|---|---|
| Basic profile information (name, email, photo) | openid, email, profile | Always | Authentication / sign-in |
| Google Drive (files) | https://www.googleapis.com/auth/drive.readonly | Read-only | Read Google Drive files to use them as a knowledge source in chatbot flows |
| Google Sheets (spreadsheets) | https://www.googleapis.com/auth/spreadsheets.readonly | Read-only | Read spreadsheet data to process it in chatbot flows |
| Google Docs (documents) | https://www.googleapis.com/auth/documents.readonly | Read-only | Read Google Docs documents to use them as a knowledge source in chatbot flows |
Important: All Google permissions are strictly read-only. builderbot.cloud never modifies, creates, or deletes files, spreadsheets, or documents in the user's Google account.
We never access Google data without the user's explicit consent.
Compliance with the Google API Services User Data Policy
builderbot.cloud's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This means that:
- Data obtained from Google APIs is used solely to provide the functionality the user explicitly requested.
- We do not use Google data for advertising.
- We do not sell, transfer, or share Google data with third parties, except for infrastructure providers strictly necessary to operate the service.
- We do not allow human access to a user's Google data, except for technical support with explicit consent or legal requirements.
- All Google data is transmitted over encrypted connections (HTTPS/TLS) and stored securely at rest, with access restricted to authorized personnel only.
Compliance with the Instagram API (Meta) Data Policy
builderbot.cloud's use of information received from Meta's Instagram APIs adheres to the Meta Platform Terms and the Instagram Platform Policy. This means that:
- Data obtained from the Instagram API is used solely to provide the automation functionality the user explicitly configured.
- We do not use Instagram data for advertising.
- We do not sell, transfer, or share Instagram data with third parties, except for infrastructure providers strictly necessary to operate the service.
- We do not allow human access to a user's Instagram data, except for technical support with explicit consent or legal requirements.
- All Instagram data is transmitted over encrypted connections (HTTPS/TLS) and stored securely at rest, with access restricted to authorized personnel only.
How We Use Data
We use the information collected for the following purposes:
General Purposes
- Enable access to and use of the builderbot.cloud platform.
- Provide automation and artificial intelligence features.
- Improve the performance, stability, and security of the service.
- Internal testing, quality control, and improvement of the Service when we process data on the Customer's behalf, under the terms of DPA §4.
Specific Use of WhatsApp Permissions
We use information obtained through Meta APIs to:
- Sending and receiving messages (
whatsapp_business_messaging): Enable your chatbot to process user inquiries and respond automatically in real time. - Account management (
whatsapp_business_management): Enable you to manage your business assets, create and manage message templates, and configure your business profile directly from our platform.
Important Note: We do not use the content of your messages or your contact data for our own advertising purposes, nor do we sell this data to third parties.
Specific Use of Instagram Permissions
We use information obtained through the Instagram API (Meta) exclusively to:
- Account profile (
instagram_basic): Identify the user's Instagram Business account within the platform, display connection information, and verify the integration status. - Comment management (
instagram_manage_comments): Enable the user's chatbot to read comments on their posts, generate automated replies, and, if the user configures it, delete comments that violate their policies. - Direct message management (
instagram_manage_messages): Enable the chatbot to process direct messages received on the business account and reply to users automatically in real time.
Instagram data use restrictions:
- We do not use Instagram data for our own or third-party advertising.
- We do not sell, transfer, or share Instagram data with third parties, except for infrastructure providers strictly necessary to operate the service.
- Instagram data is processed only in the context of automation configured by the business account holder.
Instagram data retention: Instagram messages, comments, and profile data are stored only for as long as necessary to operate the configured automation flows. The user may request deletion of this data at any time in accordance with the procedure described in the "Your Rights" section.
Legal Bases for Processing
We process your personal data on one or more of the following legal bases under Article 6 of the GDPR:
- Performance of a contract: to provide the service you have subscribed to (creation, hosting, and management of chatbots).
- Consent: when you give it expressly, for example when connecting your Google, WhatsApp, or Instagram account.
- Legitimate interest: to improve the security, performance, and functionality of the platform; to prevent abuse or fraud; and to measure marketing-site usage, campaigns, and attribution via analytics/advertising cookies and pixels (for example, Meta Pixel and Google Tag Manager / Analytics), as described in the Cookies section. You may object to processing based on legitimate interest under "Your Rights"; that does not constitute a technical opt-out of the marketing measurement described, which remains active.
- Legal obligation: when we must retain or disclose information to comply with applicable law.
Your Rights
Under the GDPR and Meta Platform policies, you have the right to:
- Access: obtain confirmation of whether we process your data and a copy of it.
- Rectification: correct inaccurate or incomplete data.
- Erasure ("right to be forgotten"): request deletion of your personal data.
- Restriction of processing: request that we restrict use of your data in certain cases.
- Portability: receive your data in a structured, commonly used format, or request transmission to another controller.
- Objection: object to processing based on legitimate interest.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
- Not be subject to automated decisions that produce significant legal effects concerning you, without human involvement.
How to Exercise Your Rights
Account holders (when BuilderBot Cloud acts as Controller of your identification, contact, billing, or configuration data): you may exercise any of these rights by emailing support@builderbot.cloud, stating the right you wish to exercise and the information needed to verify your identity. We will respond within a maximum of 30 days.
End users of a Customer's chatbot: if you interact with a chatbot operated by a BuilderBot Cloud customer, that Customer is the Controller of your data. Direct your request to that Customer. BuilderBot Cloud, as Processor, only assists the Customer as set out in DPA §10 and does not replace the Customer's response.
Data Deletion (User Data Deletion)
To request deletion of your BuilderBot Cloud account data:
- Send an email to support@builderbot.cloud with the subject line: "Data Deletion Request".
- Include your registered phone number or the email address associated with the account.
- We will delete your data (including message history, bot configurations, and access tokens) within no more than 30 days, confirming via the same channel.
If you are an end user of a Customer's chatbot, request deletion from that Customer.
Instagram-specific deletion: If you wish to delete only data linked to your Instagram integration, state this expressly in the email. We will disconnect your Instagram account and delete associated tokens and data within the same 30-day period.
If you believe processing of your data infringes the GDPR, you may lodge a complaint with the data protection authority of your country of residence in the European Union. More detail is in our GDPR notice.
Sharing Data with Third Parties
We do not sell, rent, or share the personal data we collect with third parties for marketing or resale purposes, except the campaign and attribution measurement tools on the marketing site described in the Cookies section and in the GDPR notice (for example, Meta Pixel and Google Tag Manager / Analytics).
We rely on the following external providers for infrastructure and AI services:
- Marketing website: Vercel.
- Application: self-hosted server on Hetzner (European Union).
- Artificial intelligence microservice: Microsoft Azure virtual machine (European Union).
- Databases and storage: MongoDB (European Union), MongoDB Atlas (European Union, independent database for the AI microservice), AWS S3 (document storage, European Union).
- Artificial Intelligence: Microsoft Azure OpenAI (European Union); Google Cloud Platform (Vertex AI — European Union or United States depending on the selected model); Parasail (European Union or United States depending on the selected model); Fireworks AI (United States); ElevenLabs and Inworld AI (voice / text-to-speech, United States).
- Other providers: Cal.com (appointment scheduling), Cloudflare (anti-bot protection at sign-in), Resend (transactional email delivery), Stripe (payment processing), and PostHog (product analytics).
- Messaging and authentication platforms: Meta (WhatsApp and Instagram), when you enable such integrations.
By using our service, you acknowledge that data processing through AI tools is subject to the terms of such providers.
If you use the database agent functionality to connect your own PostgreSQL database, that database is infrastructure owned by you or of your choosing; it is not a sub-processor of BuilderBot Cloud, and you are responsible for its security and configuration.
The full list of authorized sub-processors, including location, is set out in our Data Processing Agreement (DPA).
International Data Transfers
Some of our infrastructure and AI providers are located outside the European Economic Area (EEA), primarily in the United States (for example, Vercel, Fireworks AI, Stripe, PostHog, or Vertex AI / Parasail models labeled USA). We distinguish two layers:
- Customer (EEA) → BuilderBot Cloud, LLC (you as Controller, we as Processor): SCCs Module 2, which form part of the DPA.
- BuilderBot Cloud → sub-processors in the U.S. or other third countries: the provider's DPF if certified, SCCs or other contracts with that provider, or other adequacy mechanisms. The Module 2 text at
/sccdoes not cover those onward transfers.
The geographic zone of AI processing is determined by the model you select (labeled EU or USA). Not all models are available in Europe. If you select a USA model or another configuration outside the EEA, that choice constitutes your documented instruction and you are solely responsible for assessing the lawfulness of that transfer with respect to your end users. The EU/USA label governs generative AI processing; other platform, voice, or payment sub-processors may process data in the United States pursuant to DPA §7.
Cookies
We continuously use necessary cookies and analytics/advertising cookies and pixels to measure site usage, campaigns, and attribution, including Google Tag Manager / Google Analytics and Meta Pixel. We show an informational notice; the measurement described remains active. Categories:
- Necessary: essential for the site to function.
- Analytics: measure site usage (for example, Google Analytics / GTM or PostHog in-product).
- Advertising: measure campaigns and attribution (for example, Meta Pixel).
More detail in our GDPR §13 notice.
Contact Information
For any questions about this Privacy Policy, please contact us:
BuilderBot Cloud, LLC
- Address: 1111b South Governors Avenue, STE 23416, Dover, DE 19904 US
- Email: support@builderbot.cloud