GDPR & International Data Rights
Effective: 30 April 2026
|All Jurisdictions
|Version 3.1
Supplements the main Privacy Policy · SCCs per EU Commission Decision 2021/914
Purpose
This page details your specific data protection rights by jurisdiction. It supplements the main Privacy Policy. SCCs per EU Commission Decision 2021/914 govern all applicable EU/UK international data transfers.
Overview
BOTVEE (PRIVATE) LIMITED serves users globally from Pakistan. We respect applicable data protection laws in every jurisdiction we operate in or serve users from.
EU Users — GDPR (Regulation 2016/679)
2.1 Your Rights
| GDPR Article | Right | Description | Our Deadline |
|---|---|---|---|
| Art.15 | Access | Copy of all personal data we hold in CSV/JSON format | 30 days |
| Art.16 | Rectification | Correct inaccurate or incomplete data | 30 days |
| Art.17 | Erasure | Delete data subject to legal retention obligations | 30 days |
| Art.18 | Restriction | Pause processing while a dispute is resolved | 30 days |
| Art.20 | Portability | Structured machine-readable data export | 30 days |
| Art.21 | Object | Object to legitimate interest processing or marketing | 30 days / Immediate for marketing |
| Art.22 | Automated Decisions | Human review of significant automated decisions | 30 days |
| Art.77 | Complaint | Lodge complaint with your national supervisory authority | N/A — contact your DPA |
2.2 EU Data Transfer Safeguards
| Provider | Purpose | Data Type | Region | Safeguard |
|---|---|---|---|---|
| Stripe | Payments | Billing | USA/EU | PCI-DSS Level 1; EU payments via Stripe Ireland Ltd; SCCs + GDPR DPA in place |
| Supabase | Database/Auth | User data | USA/EU | SOC 2 program; AES-256 at rest; EU region available on request; SCCs + GDPR DPA in place |
| Vercel | Hosting | Technical logs | Global | SOC 2 program; enterprise DDoS protection; GDPR DPA at vercel.com/legal/dpa; SCCs in place |
| OpenAI | AI processing | Prompts | USA | Contractual safeguards; API data not used for training; SCCs applicable for EU data transfers |
- Standard Contractual Clauses (SCCs) per EU Commission Decision 2021/914, Module 2 — signed with all relevant subprocessors for EU/UK data transfers to non-adequate countries
- Transfer Impact Assessments (TIAs) conducted for all transfers to non-adequate countries
- Supplementary measures: AES-256 encryption, pseudonymisation, and strict access controls
2.3 DPA for Business Clients
If you use Botvee to process personal data of EU, UK, or Swiss residents (your end-users), GDPR Art.28 requires a Data Processing Agreement (DPA) between you (data controller) and Botvee (data processor). Our DPA covers all GDPR Art.28 requirements including subprocessor schedules, SCC Module 2 annexures for EU transfers, and UK IDTA annexures for UK data. Request at: www.botvee.ai/dpa or email legal@botvee.ai — Subject: "DPA Request — [Company Name]". Provided within 5 business days.
2.4 EU Supervisory Authorities
EU users may lodge complaints with their national supervisory authority: edpb.europa.eu. We encourage contacting privacy@botvee.ai first for faster resolution.
2.5 Subprocessor Change Notice
Botvee will notify all registered users by email with at least 14 days' prior notice before adding a new subprocessor or making material changes to an existing subprocessor relationship. EU/UK business clients who have executed a DPA with Botvee have the right to object to new subprocessors within this notice period per GDPR Art.28(2). The full and current subprocessor list is maintained at www.botvee.ai/subprocessors.
UK Users — UK GDPR & Data Protection Act 2018
All GDPR rights above apply equally to UK residents under UK GDPR and DPA 2018.
UK Supervisory Authority: Information Commissioner's Office (ICO) — ico.org.uk — 0303 123 1113 — casework@ico.org.uk
UK international transfers: Botvee uses UK International Data Transfer Agreements (IDTAs) or the UK Addendum to EU SCCs — providing equivalent protection for UK data subjects.
California Users — CCPA / CPRA
| Right | Description | How to Exercise | Deadline |
|---|---|---|---|
| Right to Know | What personal data is collected, used, disclosed | Email privacy@botvee.ai | 45 days |
| Right to Delete | Delete personal information (subject to exceptions) | Email privacy@botvee.ai | 45 days |
| Right to Correct | Correct inaccurate personal information | Email privacy@botvee.ai | 45 days |
| Right to Opt-Out of Sale | Botvee does NOT sell personal data — not applicable | N/A | N/A |
| Right to Limit Sensitive Data | Sensitive data used only for contracted services | Email privacy@botvee.ai | 45 days |
| Non-Discrimination | No discrimination for exercising CCPA rights | Automatic | Ongoing |
Authorised agent requests accepted with written proof of consumer authorisation.
Canadian Users — PIPEDA
- Data collected, used, and disclosed only with knowledge and consent for appropriate purposes
- Right to access personal information held by Botvee
- Right to challenge accuracy and have information corrected
- Right to withdraw consent — may affect ability to provide certain services
- Right to file a complaint with the Office of the Privacy Commissioner of Canada
Canada Privacy Commissioner: priv.gc.ca | 1-800-282-1376 | info@priv.gc.ca
Pakistani Users — Applicable Law & Enforcement
| Law | Relevance | Enforcement Body |
|---|---|---|
| Constitution Art.14 | Fundamental right to dignity and privacy | Supreme Court / High Courts |
| PECA 2016 (amended 2025) | Unauthorised data access, cybercrime, data misuse — penalties include imprisonment | FIA Cybercrime Wing |
| PDPB 2023 (pending) | Comprehensive data protection — voluntarily applied by Botvee | National Commission (when enacted) |
| ETO 2002 | Legal validity of electronic contracts and records | Civil courts |
| Income Tax Ordinance 2001 | 7-year financial data retention obligation | Federal Board of Revenue (FBR) |
- FIA Cybercrime Wing: fia.gov.pk/cyber-crime | cybercrime@fia.gov.pk
- PTA: pta.gov.pk
- PKCERT: pkcert.gov.pk
All Other Jurisdictions
For users in countries not specifically listed above, Botvee applies the following minimum protections:
- ISO 29101 privacy architecture principles
- OECD Privacy Guidelines (2013 edition and updated principles)
- APEC Privacy Framework — for Asia-Pacific region users
- UN General Assembly Resolution 68/167 — Right to Privacy in the Digital Age
All users globally have the right to: access their personal data, correct inaccuracies, request deletion subject to legal limits, object to direct marketing at any time, and receive clear information about how their data is processed.
Rights Request Procedure
- Email privacy@botvee.ai — Subject: "Data Rights Request — [Jurisdiction] — [Account Email]"
- Clearly state the specific right(s) you are exercising
- Provide your full name and account email address
- Government-issued ID may be required to verify your identity and protect your data
- We will acknowledge within 3 business days
- We will respond fully within 30 calendar days (45 days for CCPA requests)
- If a request cannot be fully fulfilled, we will provide a written explanation
- No charge unless requests are clearly excessive, unfounded, or repetitive
Contact
Privacy Officer
Legal / DPA
Phone
+92 319 3981020
Company
BOTVEE (PRIVATE) LIMITED (SECP: 0326112)