Legal
We treat privacy as a technical requirement, not a compliance checkbox. This policy explains what we collect, how it's handled, and the rights you have over it.
Last updated February 19, 2026
To operate the runtime and HiveLang, we categorize data as follows:
For account registration, billing, security, fraud prevention, platform analytics, and support, Bothive generally acts as a data controller because we decide why and how that information is used to operate the Service.
For prompts, uploaded files, workflow payloads, end-user conversations, integration data, bot memory, and agent actions that you configure, Bothive generally acts as a processor or service provider on your behalf. You are responsible for making sure you have a lawful basis, required notices, permissions, and consents before sending personal data into bots, integrations, or third-party models.
Bothive acts as an orchestration layer between your agents and large language models (Groq, Gemini, OpenAI, Anthropic).
You should not send sensitive personal data, regulated records, children's data, payment-card data, health information, biometric identifiers, or government-issued identifiers into an agent unless you have a lawful reason, clear user notice, and the right safeguards for that use case.
In transit: TLS 1.3 · At rest: AES-256-GCM
Database: Supabase / PostgreSQL with Row-Level Security
Isolation: per-tenant access policies
We share data only with a verified set of essential processors:
| Partner | Purpose |
|---|---|
| Supabase | Infrastructure, identity, and core storage. |
| OpenAI / Anthropic | LLM inference and agent reasoning. |
| Groq / Gemini | Fast inference and fallback routing. |
| Paystack | Marketplace transactions and billing. |
Some providers may process data outside Nigeria or outside your country. Where applicable law requires transfer safeguards, we rely on contractual, security, and operational safeguards appropriate to the type of data and the provider involved.
Bothive uses technical-only tracking — no third-party advertising trackers or pixels. See our Cookie Policy for detail.
Where the Nigeria Data Protection Act, 2023 or related Nigeria Data Protection Commission requirements apply, we process personal data only where we have an appropriate lawful basis, such as consent, contract performance, legal obligation, legitimate interests, or another basis recognized by applicable law.
We design our handling of personal data around purpose limitation, data minimization, access control, security safeguards, retention limits, and accountability. If we identify a privacy or security incident that legally requires notification, we will assess it and make required notices to affected users, customers, regulators, or other parties as applicable.
Under GDPR (Article 17) and CCPA you have the right to be forgotten. On request, we purge all interaction history and credentials from our active databases within thirty (30) days. Encrypted backups may persist for up to ninety (90) days in an offline state.
If Nigerian data-protection law applies to you, you may also have rights to:
These rights are not absolute; for example, we may retain limited records where needed for security, fraud prevention, tax, accounting, dispute handling, or other legal obligations.
We disclose user data to law enforcement only when required by a valid, binding subpoena or court order, and we'll notify you unless legally prohibited from doing so.
For questions about your data or to exercise your rights, email privacy@bothive.cloud.