Botkeep is currently a local frontend prototype. This document separates current behaviour from production commitments so it does not claim processing or safeguards that are not active yet.
1. Controller and scope
The controller for Botkeep account, website, commercial, support and security processing is M.O. Società a Responsabilità Limitata Semplificata, registered at Piazza Montessori 11, 80011 Acerra (NA), Italy. Contact: info@movara.it; PEC: mosrls@pec.cgn.it.
This notice covers botkeep.cloud, the account and dashboard, onboarding, source imports, hosted workloads, support and abuse channels when those features are available. External websites opened through a link apply their own privacy information.
No Data Protection Officer contact is published because no appointment has been confirmed for Botkeep. If a DPO is appointed or becomes legally required, this notice will be updated before that contact is used.
| Company detail | Information |
|---|---|
| Legal name | M.O. Società a Responsabilità Limitata Semplificata |
| Registered office | Piazza Montessori 11, 80011 Acerra (NA), Italy |
| Operating office | Viale dei Platani 14, 80040 Cercola (NA), Italy |
| VAT identification number | IT09508751212 |
| Italian tax code | 09508751212 |
| REA / Chamber of Commerce | NA - 1037249 / Naples |
| Share capital | EUR 2,500.00, approved, subscribed and fully paid |
| General and privacy contact | info@movara.it |
| Certified email (PEC) | mosrls@pec.cgn.it |
2. Current prototype boundary
The current Botkeep dashboard is a frontend prototype. Demo account information, bots, files, settings and masked secret placeholders are stored only in the user’s browser. Passwords entered in prototype mode are checked only for minimum length and are not persisted. Discord and GitHub buttons create local demo identities and do not contact those providers.
Do not enter real tokens, personal data, confidential source code or production files in the prototype. The web server may still receive ordinary connection data required to deliver the site. This policy must be reviewed and updated against the real backend, processors, regions and retention controls before live hosting is opened.
3. Categories of personal data
- Technical data: IP address, date and time, requested resource, response status, user-agent, request or security identifiers and diagnostic events generated by web and infrastructure protocols.
- Account data: name, email, account identifier, authentication method, session state and security events when real accounts are enabled.
- Provider data: Discord or GitHub identifiers, profile information, authorisations and repository metadata only when the user deliberately connects that provider.
- Service data: bot name, runtime, branch, command, configuration, deploy history, usage, logs, files and source archives supplied or generated through the Service.
- Secrets: bot tokens and other values explicitly designated as secrets when production secret storage is enabled. The prototype stores only a mask and not the submitted value.
- Communications: support requests, privacy requests, abuse notices, appeals and other information voluntarily sent to official contacts.
- Commercial data: plan, order, invoice, tax and payment-reference information only if paid services are introduced. Botkeep does not currently collect payment data.
- Device storage: the local keys listed in the Cookie Policy, used for the prototype session, workspace and privacy notice.
4. Sources of data
- Directly from the user during registration, configuration, upload, support or reporting.
- From Discord or GitHub after the user starts and authorises an integration.
- From web, network, hosting and security systems during delivery and protection of the Service.
- From an organisation or administrator that lawfully invites or authorises a user to manage a shared resource.
5. Purposes and legal bases
Where Botkeep relies on legitimate interests, it considers necessity, reasonable expectations and impact on individuals and applies proportionate safeguards. You may object on grounds relating to your particular situation. Consent may be withdrawn at any time without affecting earlier lawful processing.
| Purpose | Typical data | Legal basis |
|---|---|---|
| Provide website, account and requested hosting features | Account, provider, bot, files, configuration, logs | Contract or pre-contractual steps, Art. 6(1)(b) GDPR |
| Protect accounts, users and infrastructure; prevent fraud and abuse | Technical, security and activity data | Legitimate interests, Art. 6(1)(f); legal duties where applicable |
| Reply to support, privacy and pre-sales requests | Contact and communication data | Contract/pre-contractual steps or legitimate interests |
| Handle illegal-content notices, disputes and authority requests | Report, account, content and evidence data | Legal obligation, Art. 6(1)(c), and legitimate interests, Art. 6(1)(f) |
| Accounting, invoicing and tax compliance if paid plans launch | Identity, order, invoice and payment reference | Contract and legal obligation, Art. 6(1)(b) and (c) |
| Optional product communications | Email and communication preference | Consent, Art. 6(1)(a), or existing-customer rules where legally available |
6. Required and optional information
Data marked as required are necessary to create or secure an account, provide a requested feature, investigate a valid report or comply with law. Without them, Botkeep may be unable to provide that function. Connecting Discord or GitHub, adding optional profile information and receiving promotional updates are optional unless a selected deployment source technically requires the connection.
7. Controller and processor roles
Botkeep is controller for its own account, billing, security, support, abuse-prevention and service-management purposes. A customer is normally controller for personal data that its bot independently collects or stores. For that customer data, Botkeep acts as processor only to the extent it handles the data on documented customer instructions to supply hosting.
Customers must provide their own notices and identify a lawful basis for data collected by their bots. The Data Processing Addendum governs Botkeep’s processor role and does not make Botkeep controller for the customer’s bot logic or purposes.
8. Recipients and authorised access
Data may be accessed by authorised personnel and by providers supplying hosting, infrastructure, authentication, repository integration, communications, security, payment or professional services, limited to the relevant purpose and governed by appropriate agreements. Public authorities or rights holders receive data only where disclosure is legally required or another valid legal basis exists.
The current prototype has no Botkeep API, OAuth connection, payment processor or analytics provider. The production processor and subprocessor inventory must be published before those services are activated.
9. International transfers
The local prototype does not transmit demo account or workspace content to Botkeep. If production providers process personal data outside the European Economic Area, Botkeep will use an applicable adequacy decision or appropriate safeguards under Chapter V GDPR, such as Standard Contractual Clauses, together with supplementary measures where required. The relevant provider, location and safeguard will be recorded before activation.
Opening an external link or deliberately authorising Discord or GitHub may cause the external provider to process data under its own notice and transfer framework.
10. Retention
A production retention schedule is an operational control, not only a policy statement. Botkeep will not open live hosting until deletion jobs, backup expiry and documented exceptions match the published periods.
| Data | Current or intended retention rule |
|---|---|
| Prototype account and workspace | In localStorage until sign-out, prototype reset, browser deletion or manual removal as described in the Cookie Policy |
| Web and security logs | Only as long as necessary for delivery, security and investigation; the production maximum must be fixed with the hosting provider before launch |
| Production account and bot data | For the account or bot lifetime, followed by a documented deletion and backup-expiry window to be published before production |
| Support and privacy requests | For the time needed to answer and document the request, then only for applicable limitation or legal periods |
| Invoices and accounting records | For mandatory Italian tax and civil-law periods if paid services are introduced |
| Abuse and legal evidence | For the investigation and the period necessary to establish, exercise or defend legal claims or comply with authority orders |
11. Security and breach response
Botkeep will apply measures appropriate to the risk, including access control, separation of duties, encrypted transport, secret redaction, least privilege, tenant isolation, logging, backup controls, patching and incident procedures. Exact claims will be limited to controls that have been implemented and tested.
A personal-data breach will be documented and assessed. Where required, the controller will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of it; high-risk breaches will also be communicated to affected individuals unless a lawful exception applies. A processor will notify the relevant controller without undue delay.
12. Automated decisions and profiling
The current prototype performs no profiling and no decision based solely on automated processing that produces legal or similarly significant effects. Future security rules may flag suspicious use for review, but any material automated decision and available safeguards must be disclosed before deployment.
13. Children
Botkeep is not directed to children. Account use by a minor requires the involvement described in the Terms and must respect applicable age rules. If personal data were collected from a child without a valid basis, contact the Operator so the circumstances can be investigated and appropriate action taken.
14. Your rights
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction, portability and information about recipients; object to processing based on legitimate interests; withdraw consent; and lodge a complaint with the Garante per la protezione dei dati personali. You also have the right not to be subject to a qualifying solely automated decision.
Send requests to info@movara.it or mosrls@pec.cgn.it. Botkeep may request only the information reasonably necessary to verify identity and protect account data. Requests are normally answered within one month, subject to the GDPR rules on extensions and manifestly unfounded or excessive requests.
15. Updates and complaint
This notice will be updated before a material new processing activity, provider or transfer begins. Earlier versions and the effective date should be retained for accountability. A complaint may be lodged with the Garante per la protezione dei dati personali or another competent supervisory authority, without prejudice to other remedies.