Last updated: 14/07/2026 Effective date: 14/07/2026
⚠️ Draft for legal review. This is a well-structured template based on how Boticum works. Before publishing, have it reviewed by a qualified lawyer for your launch market (UAE PDPL — Federal Decree-Law No. 45 of 2021) and any other jurisdictions you operate in (e.g. EU/UK GDPR, Turkey KVKK). Replace every
[BRACKETED]placeholder. Nothing here is legal advice.
1. Who we are
Boticum (“Boticum“, “we“, “us“, “our“) is a customer-relationship-management platform operated by FED DIGITAL MARKETING AND E COMMERCE FZE, a company registered in Sharjah, United Arab Emirates with registered address at Business Center, Sharjah Publishing City Free Zone, Sharjah, Sharjah 00000, United Arab Emirates.
This Privacy Policy explains how we collect, use, share, and protect personal data when you:
- visit our website https://boticum.com (the “Site“);
- create or use a Boticum account (the “Service“); or
- otherwise interact with us.
Contact / Data Protection Officer: info@boticum.com, Business Center, Sharjah Publishing City Free Zone, Sharjah, Sharjah 00000, United Arab Emirates.
2. Our two roles: controller vs processor
Boticum handles personal data in two distinct capacities. This distinction matters for your rights.
- As a data controller. For the personal data of our own account holders — the businesses that subscribe (“Tenants“) and their individual users — we decide why and how the data is processed. This includes account, billing, and Site data. This Policy governs that processing.
- As a data processor. When a Tenant uses Boticum to manage their customers’ data (contacts, conversations, invoices, etc. — “Tenant Customer Data“), the Tenant is the controller and we act on their instructions. Our handling of that data is governed by our Data Processing Agreement (see
data-processing-agreement.md), not primarily by this Policy. If you are a customer of a business that uses Boticum, please contact that business to exercise your rights over your data.
3. What data we collect
3.1 Data you give us (as a Tenant / user)
- Account data: name, work email, password (hashed), company name, role, branch, phone number.
- Billing data: billing contact, VAT/tax number, payment method details (processed by Stripe — we do not store full card numbers), invoices, transaction history.
- Support data: messages you send us, and the contents of support requests.
3.2 Data we process on a Tenant’s behalf (Tenant Customer Data)
When a Tenant connects channels and uses the Service, we process data on their instruction, which may include:
- Contacts: names, phone numbers, email addresses, company details, custom fields defined by the Tenant.
- Conversations & messages: Instagram DM and WhatsApp message content and metadata routed through the Tenant’s connected accounts (via the Meta APIs), notes, tags, and files/media exchanged.
- Sales & invoicing data: deals, leads, invoices the Tenant issues to their customers, and payment status.
- Marketing data: email/WhatsApp campaign engagement (opens, clicks, delivery, opt-outs).
We do not decide the purpose of this data — the Tenant does.
3.3 Data we collect automatically
- Usage & device data: IP address, browser/device type, pages viewed, actions taken, timestamps, approximate location derived from IP.
- Cookies & similar technologies: see
cookie-policy.md. - Logs & security data: authentication events, audit logs of sensitive actions (exports, deletions, invoice edits, add-on changes, logins).
3.4 Data from third parties
- Meta (Instagram/WhatsApp): when a Tenant connects a WhatsApp Business Account or Instagram-linked Page via Meta’s Embedded Signup, we receive account identifiers and access tokens needed to send/receive messages.
- Stripe: payment and subscription status.
4. Why we use your data (purposes & legal bases)
Where a legal basis is required (e.g. under GDPR/KVKK), we rely on the bases indicated.
| Purpose | Examples | Legal basis (where applicable) |
|---|---|---|
| Provide the Service | authenticate you, run the CRM, route messages | Performance of a contract |
| Billing & payments | subscriptions, add-ons, wallet top-ups, invoices | Performance of a contract |
| Security & fraud prevention | audit logs, abuse detection, access control | Legitimate interests / legal obligation |
| Support | responding to your requests | Performance of a contract / legitimate interests |
| Product improvement & analytics | aggregate usage, reliability | Legitimate interests (or consent where required) |
| Marketing to Tenants | product updates, offers (you can opt out) | Consent / legitimate interests |
| Legal compliance | tax records, responding to lawful requests | Legal obligation |
For Tenant Customer Data, the Tenant determines the purposes and legal bases; we process only per their instructions and the DPA.
5. How we share data
We do not sell personal data. We share it only as needed:
- Sub-processors / service providers that help us run the Service (hosting, messaging, payments, email). See the current list in
sub-processors.md. They are bound by contract to protect the data. - Between Tenants — never. Boticum is multi-tenant; strict isolation (database row-level security) prevents any Tenant from accessing another Tenant’s data.
- Legal & safety. Where required by law, court order, or to protect rights, safety, and security.
- Business transfers. In a merger, acquisition, or asset sale, subject to this Policy.
6. International data transfers
We host Tenant data in the United Arab Emirates for our launch market. Where data is transferred across borders (e.g. to a sub-processor in another country), we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms recognized under applicable law. [ADJUST once hosting regions are finalized.]
7. How long we keep data
- Account & billing data: for the life of your account and as required afterward for legal/tax purposes (typically [X] years).
- Tenant Customer Data: retained per the Tenant’s configuration and instructions; deleted or returned on termination as described in the DPA.
- Logs & security data: [X] months.
We apply soft-deletion where appropriate and honor erasure requests as described below.
8. Your rights
Depending on your jurisdiction (UAE PDPL, GDPR, KVKK, and others), you may have the right to:
- access the personal data we hold about you;
- rectify inaccurate data;
- erase your data (“right to be forgotten”);
- restrict or object to certain processing;
- portability — receive your data in a structured, machine-readable format;
- withdraw consent at any time where processing is based on consent;
- lodge a complaint with your local data protection authority.
How to exercise: email info@boticum.com. We respond within the timeframe required by applicable law. If your request concerns data a business manages about you as their customer (Tenant Customer Data), please contact that business directly; we will assist them as their processor.
9. How we protect data
- Encryption: data encrypted in transit (TLS) and at rest (AES-256). Secrets (access tokens, API keys) are stored in a dedicated secrets vault; sensitive personal fields are subject to additional field-level encryption.
- Access control: strict tenant isolation, role- and branch-based permissions, least-privilege access, and audit logging of sensitive actions.
- Operational security: managed, reputable infrastructure providers; regular patching; monitoring.
No system is perfectly secure, but we work continuously to protect your data and will notify you and the relevant authorities of a data breach as required by law.
10. Children
The Service is not directed to children under [16/18] and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.
11. Third-party links
The Site and Service may link to third-party services (e.g. Meta, Stripe). Their privacy practices are governed by their own policies; we are not responsible for them.
12. Changes to this Policy
We may update this Policy from time to time. We will post the new version with an updated “Last updated” date and, for material changes, notify you (e.g. by email or in-app) before they take effect.
13. Contact us
Questions or requests: info@boticum.com · FED DIGITAL MARKETING AND E COMMERCE FZE, Business Center, Sharjah Publishing City Free Zone, Sharjah, Sharjah 00000, United Arab Emirates.