Legal
Data Processing
Last updated: August 1, 2026
1. Purpose and scope
This page describes how Bosla processes personal data on behalf of sellers ("you") when you use the Service to communicate with your customers and manage orders. It supplements our Privacy Policy and applies wherever Bosla acts as a data processor on your behalf. Sellers who need a signed Data Processing Agreement for their own compliance can request one at the contact below.
2. Roles of the parties
You are the data controller for the personal data of your customers that you route through Bosla — you decide what data to collect and why. Bosla is the data processor, acting only on your instructions (given through your use of the Service and its settings) to provide the Service.
3. Nature and purpose of processing
We process the personal data below solely to provide the Service:
- Categories of data — customer names, phone numbers, addresses, order details, and message content exchanged across connected channels.
- Categories of data subjects — your customers and, incidentally, people they mention in conversation.
- Purpose — operating the unified inbox, generating AI-assisted replies, syncing orders, and sending order-related notifications.
- Duration — for as long as your account is active, per the retention terms in our Privacy Policy.
4. Your instructions
We process personal data only as necessary to provide the Service and as instructed by you through your configuration of the platform (e.g. enabling AI auto-reply, connecting a channel or store). We will tell you if an instruction appears to conflict with data protection law.
5. Confidentiality
Bosla staff who can access customer data are bound by confidentiality obligations and access is limited to what's needed to provide support or operate the Service, with access logging in place.
6. Security measures
We apply encryption in transit and at rest, encrypted per-seller integration credentials, tenant-level data isolation, role-based access control, MFA, and a security incident response process, as described in our Privacy Policy.
7. Sub-processors
We engage sub-processors (cloud hosting, messaging platforms, AI model providers, email/SMS providers) strictly to operate the Service, each bound by data protection terms at least as protective as this page. A current list is available on request.
8. Data breach notification
If we become aware of a security incident affecting your customers' personal data, we will notify you without undue delay and provide the information reasonably needed for you to meet your own notification obligations.
9. Data return and deletion
When you disconnect an integration or close your account, we delete or anonymize the associated personal data within the timeframe described in our Privacy Policy, except where retention is required by law.
10. Contact us
To request a signed Data Processing Agreement or ask questions about our processing on your behalf, contact us at [email protected].