OrderBOT Logo
Features Industries ROI Calculator FAQ Contact
Try Demo Get Started
Features Industries ROI Calculator FAQ Contact
Try Demo Get Started
Legal Documents

GDPR Compliance Statement

Last Updated: August 9, 2026

1. GDPR Commitment

The General Data Protection Regulation (GDPR) regulates the processing of personal data of individuals residing in the European Union (EU). OrderBOT is fully committed to aligning our SaaS platform processes and conversational workflows with GDPR requirements, ensuring safety and autonomy for all merchant data controllers and data subjects.

2. Data Processor vs. Data Controller

Under the GDPR guidelines, the division of data responsibility on our platform is defined as follows:

  • Merchant as Data Controller: You (the merchant business) determine the purposes and means of processing personal data collected from customers (e.g. what items are sold, what addresses are collected, or how customer chats are answered).
  • OrderBOT as Data Processor: We process customer personal data (such as WhatsApp chat transcripts, catalog cart selections, and invoice reference values) strictly on behalf of and according to the instructions of the merchant Data Controller.

3. Legal Basis for Processing

We process data under the following legal bases recognized under GDPR Article 6:

  • Performance of a Contract: Necessary to complete purchase orders, food delivery tickets, and calendar appointments initiated by the customer.
  • Consent: Necessary to process messages. Customers must opt-in by initiating communication with the merchant's WhatsApp number. Consent can be withdrawn by typing "STOP" to block further automated messaging.
  • Legitimate Interests: Necessary for monitoring system health, securing the API, and maintaining analytics for business performance.

4. Data Subject Rights

We facilitate data controllers in fulfilling requests from end-users exercising their GDPR rights, including:

  • Right of Access & Portability: Merchants can export a CSV of customer details and conversation logs from their console dashboard.
  • Right to Rectification: If a customer requests a change of delivery address or telephone details, merchants can modify database records directly.
  • Right to Erasure (Forgotten): We provide instant deletion controls in the console. When requested, all conversation logs and contact details associated with a telephone number will be purged from our active databases.

5. Cross-Border Data Transfers

OrderBOT utilizes servers based in India and the European Union. When data is transferred internationally (such as routing messages through Meta's WhatsApp APIs), we ensure that appropriate safeguards are in place. We utilize Standard Contractual Clauses (SCCs) approved by the European Commission for data transfers from the EU to third countries.

6. Data Breach Notifications

In the event of a security breach compromising merchant database records or conversation logs, OrderBOT will notify the affected merchants and respective regulatory authorities within 72 hours of discovering the incident, detailing the extent of compromised records and corrective actions.

7. Contact DPO

If you have any questions about GDPR compliance, data processing practices, or wish to reach our Data Protection Officer, please contact us at dpo@orderbot.in.

OrderBOT Logo

OrderBOT is a product of Cybex Innovation. The conversational commerce engine empowering businesses to sell, schedule, and receive payments directly within WhatsApp.

Product

Features Industries Pricing & ROI WhatsApp Demo

Integrations

Shopify WooCommerce Stripe Google Calendar

Legal

Terms of Service Privacy Policy GDPR Compliance API Terms

OrderBOT is a Product of Cybex Innovation | Privacy Policy | Terms | GSTIN: 29CQJPM7492R1ZI | Udyam: UDYAM-KR-03-0647985

© 2026. OrderBOT is an independent service and has not been authorized, sponsored, or otherwise approved by Meta Platforms Inc.