Skip to content
  • How it works
  • Product
  • FAQ
  • Contact
Book a demo
EnglishEN ქართულიქა
Book a demo

Legal

Privacy Policy

Draft. Effective date: 9 October 2026. Last updated: 9 October 2026.

Draft for review. This text has not yet been reviewed by a qualified lawyer in Georgia.

On this page

  1. Who we are
  2. Our two roles: controller and processor
  3. Information we collect
  4. Connected Meta services: Messenger, Instagram and WhatsApp
  5. How we use information and our legal bases
  6. How we use AI
  7. Service providers and other recipients
  8. International transfers
  9. How long we keep information
  10. Security
  11. Cookies and similar technologies
  12. Children
  13. Your rights
  14. How to request deletion
  15. Changes to this policy
  16. Contact us

This Privacy Policy explains how Bototo Technology LLC collects, uses, shares and protects personal data in connection with BOTOTO: our website at bototo.ge, our sales and support communications, and the BOTOTO platform that businesses use to manage customer conversations and appointments.

BOTOTO is in development. Some features described here, including every messaging channel, are planned and not yet available. Where we describe a planned feature, we explain how we will handle personal data once it is in use.

Who we are

BOTOTO is a product and brand of Bototo Technology LLC (შპს ბოტოტო ტექნოლოჯი), a limited liability company registered in Georgia with identification code 405891343, with its registered address at 63 Anna Politkovskaya St., Apt. 23, Vake District, Tbilisi, Georgia. In this policy, "BOTOTO", "we", "us" and "our" mean Bototo Technology LLC.

BOTOTO helps clinics and other appointment-based businesses manage customer conversations, business information, booking requests, customer records, calendars and handoff to their own staff. An automated assistant answers routine questions and organises requests. The business's team reviews decisions and can take over any conversation.

  • Privacy questions and requests: info@bototo.ge
  • General support: info@bototo.ge
  • Phone: +995 598 60 73 02
  • Post: Bototo Technology LLC, 63 Anna Politkovskaya St., Apt. 23, Vake District, Tbilisi, Georgia

We process personal data in line with the data protection laws that apply to us, including the Law of Georgia on Personal Data Protection and, where it applies, the EU General Data Protection Regulation (GDPR).

Our two roles: controller and processor

Data protection law separates two roles. A controller decides why and how personal data is processed. A processor handles personal data on a controller's behalf and follows its instructions. We are a controller for our own website, business accounts, sales and support. We are a processor when a business, such as a clinic, uses BOTOTO to talk to its customers and manage appointments: the business is the controller of that information.

InformationOur roleWho to contact first
Website visits, enquiries and demo requestsControllerUs
Business accounts, staff user accounts, sales and supportControllerUs
Customer conversations, booking requests, appointments and customer records handled for a businessProcessor for the business, which is the controllerThe business
Business information a business gives the assistant, such as services, prices, schedules and staff profilesProcessor for the businessThe business
Messages received through a business's connected Messenger, Instagram or WhatsApp accountProcessor for the business. Meta is a separate controller for its own platforms.The business

If you are a customer of a business that uses BOTOTO, for example because you messaged a clinic, that business decides how your information is used and its own privacy notice applies. Please contact the business first. If you contact us instead, we will pass your request to the business promptly and help it respond.

Our agreement with each business, including its data processing terms, requires us to process customer data only on the business's documented instructions, keep it confidential and secure, and keep each business's data separate from every other business's data.

Information we collect

Website visitors

Our website has no accounts, sets no cookies and uses no analytics, advertising pixels or other tracking tools. Fonts and other files are served from our own website, so a visit does not send requests to third-party services. Like any website, our hosting provider, Cloudflare, Inc., receives technical information when your browser requests a page and may record it in server access logs: your IP address, the date and time, the page requested, the referring page, your browser and device type, and whether the request succeeded.

Source: automatically from your browser.

People who contact us or request a demo

If you email us or use the form on our contact page, we receive your name, email address, business name and role, your phone number if you give it, your message, and anything you choose to tell us about your business. The contact form currently opens your own email app with your message filled in. Nothing you type is stored on our website, and we receive it only if you send the email. Emails are held by our email provider, which processes them on our behalf.

Source: directly from you, or from a contact who introduces you to us.

Business customers and their staff users

  • Account details: the business's name and address, and the name, work email, phone number and role of the people who manage the account.
  • Staff user details: the name, work email, role and permissions of each invited team member, and the sign-in information needed to access BOTOTO.
  • Activity records: sign-ins and actions in BOTOTO, such as taking over or resolving a conversation, editing business information or changing a booking, including a change history of who changed what and when.
  • Business information: services, prices, opening hours, branches, rooms, schedules, policies, frequently asked questions and practitioner profiles (for example name, languages and a short biography). We process personal data in this information on the business's behalf.
  • Channel connection details: account identifiers and access credentials for connected messaging channels (see Connected Meta services).
  • Communications and contract records: support requests, feedback, the agreement and related administrative records.

Sources: the person who sets up the account, staff users themselves, use of the service, and Meta when a business connects a Meta account.

People who message a business that uses BOTOTO

BOTOTO is planned to work first through a web chat that a business adds to its own website, and later through Messenger, Instagram and WhatsApp, subject to Meta's review and approval. None of these channels is live yet. Once they are, we will process the following on the business's behalf, depending on the channel and how the business sets up BOTOTO:

  • Conversation content: messages you send and receive, attachments you send, buttons you select and message times.
  • Contact and identity details: your name, phone number, preferred language and channel identifier. Before using anything from your customer record, the assistant may ask you to confirm who you are, for example with your phone number and year of birth.
  • Booking information: the service, preferred dates and times, branch or practitioner, booking status, changes and cancellations, and whether a booking was made by the assistant or by staff.
  • Customer record: what the business keeps about you, such as contact details, family members you book for (for example a parent booking for a child), appointments and staff notes.
  • Handoff information: the conversation's status (for example "Assistant handling", "Waiting for human" or "Resolved"), the summary the assistant prepares when it hands over to staff, the reason for the handoff, and draft replies for staff to review.
  • Technical information: for web chat, details such as IP address, browser type and a session identifier.

Sources: directly from you; from the business's own records; from the messaging platform you use, such as Meta; and from BOTOTO itself, such as summaries the assistant writes for staff.

Administration only. BOTOTO supports administration and communication. It is not an emergency service and does not give medical advice. Businesses must not use it to collect or process health information beyond what is needed to arrange appointments, and must set it up accordingly. In an emergency, contact your local emergency services. Please do not share health details, payment card numbers, bank details or identity document numbers in a chat.

Because booking with a clinic can itself reveal something about a person's health, the law may treat some appointment information as a special category of data. The business, as controller, is responsible for having a valid legal basis for it.

Connected Meta services: Messenger, Instagram and WhatsApp

BOTOTO is planned to connect to Facebook Messenger, Instagram messaging and WhatsApp. These connections are not live. They depend on Meta's review and approval, and BOTOTO is not approved, certified, endorsed by or partnered with Meta. This section explains how we will handle information once a business connects one of these services.

An authorised person at the business connects its own Facebook Page, Instagram professional account or WhatsApp Business account through Meta's own authorisation screens and chooses which permissions to grant. Messages people send to that business on that service are then delivered to the business's BOTOTO inbox, and replies from the assistant or staff are sent back through Meta.

What we receive

ServiceInformation about people who message the business
MessengerMessage content; attachments the person sends; a Page-scoped ID (a number Meta assigns to that person for that Page only); timestamps; message IDs; delivery and read status; buttons the person selects.
InstagramMessage content; attachments the person sends; an Instagram-scoped ID (a number Meta assigns to that person for that account only); timestamps; message IDs; delivery status; notice when a message is unsent.
WhatsAppMessage content; attachments the person sends; the person's WhatsApp phone number and profile name; timestamps; message IDs; delivery and read status of the business's messages.

We also receive connection details: identifiers of the connected Page, Instagram account, WhatsApp Business account and phone number; access tokens issued by Meta; the permissions granted; the identity of the person who authorised the connection; and, for WhatsApp, the business's message templates.

How we use it

We use information received through Meta services only to provide BOTOTO to the business that connected the account: to show incoming messages in its inbox, let the assistant answer routine questions and organise booking requests, hand conversations to its staff and send their replies, keep its conversation and appointment records, keep the service secure, and meet Meta's requirements, such as acting on deletion requests. We process it in line with the Meta Platform Terms, Meta's Developer Policies and the WhatsApp Business policies, and nothing in this policy is intended to conflict with them.

  • We do not sell, rent or license it.
  • We do not use it for advertising or ad targeting, or share it with advertisers or data brokers.
  • We do not use it to profile people, make eligibility decisions or discriminate against anyone.
  • We do not share one business's data with another business, or one customer's conversation with another customer.
  • We do not use it for any other purpose, except where the law requires us to.

We share it only with service providers who help us run BOTOTO, such as hosting and AI model providers, under written agreements limiting them to providing their services to us.

Health businesses on Meta channels

Meta does not allow Messenger or Instagram messaging to be used for direct conversations between people and healthcare providers, or to send or collect patient data from healthcare providers. Clinics connecting these services must keep them to front-desk matters such as opening hours, location, services and booking requests. On WhatsApp, businesses must not use the service for telemedicine or for health information where the law requires more protective systems.

Disconnecting

A business can disconnect a Meta service in BOTOTO or remove BOTOTO's access in its Facebook, Instagram or WhatsApp settings. We then stop receiving new messages from that account. Disconnecting does not by itself delete information already stored. It stays part of the business's records until it is deleted under our retention rules, at the business's request, or after a deletion request. See Data deletion.

How we use information and our legal bases

As controller, we use personal data only for these purposes and on these legal bases, as recognised by the Georgian law and, where it applies, the GDPR:

PurposeInformation usedLegal basis
Running the website and keeping it secureServer access log dataLegitimate interests in keeping the website working and protected
Answering enquiries and demo requestsContact details and your messageSteps you ask us to take before a contract; legitimate interests
Providing business accounts and staff accessAccount, staff user and connection detailsContract with the business; legitimate interests for staff users
Customer support and service messagesContact details, support communications, activity recordsContract; legitimate interests
Security, preventing misuse and keeping change historyActivity records, technical logsLegitimate interests; legal obligation where the law requires it
Improving BOTOTOHow business accounts use features, not the content of customer conversationsLegitimate interests in developing our product
Sending business contacts news about BOTOTOName and work emailConsent where the law requires it, otherwise legitimate interests; you can opt out at any time
Meeting legal duties and handling legal claimsAny relevant informationLegal obligation; legitimate interests

As processor, we process customer conversations, booking requests, appointments, customer records and business information only to provide BOTOTO to the business, on its instructions. The business decides its own legal basis, such as taking the steps a customer asks for, consent (written consent where the law requires it), or legitimate interests.

Where we rely on legitimate interests, you can object (see Your rights). Where we rely on consent, you can withdraw it at any time without affecting earlier processing.

How we use AI

BOTOTO's assistant uses AI language models from third-party providers, reached through a model gateway, to understand messages and write replies. We are still choosing these providers, and we will name them here before the assistant handles real customer messages. We send them:

  • When someone messages a business: the new message and recent messages in the conversation; the business information needed to answer, such as hours, prices and policies; instructions that define how the assistant behaves; scheduling information, such as available times and the booking being prepared; and the conversation's status. Only after a person confirms their identity may relevant details from their customer record also be sent, such as name, year of birth, family members they book for, and appointments.
  • When a business sets up BOTOTO: text it pastes in, such as price lists or schedules, so the assistant can organise it into business information.
  • When staff ask for help: the conversation and business information needed for a handoff summary or a draft reply.

We use AI to answer routine questions from the business's own information, organise booking requests, prepare handoff summaries and draft replies that staff edit before sending. The assistant is designed to answer only from information the business provides, not to invent prices or availability, not to give medical advice, and to pass anything outside routine matters to the business's team.

Human review and automated decisions

The business's team can see conversations and take over at any time. People can ask to speak to staff, and the assistant then stops replying until staff hand the conversation back. Businesses must tell people when they are talking to an automated assistant and how to reach a person.

BOTOTO does not make decisions with legal or similarly significant effects about people based solely on automated processing. The assistant suggests available times, a booking is recorded only after the customer confirms it, and the business's team remains responsible for its calendar and can review, change or cancel any booking.

AI provider terms

We will only use AI providers that have agreed in writing to process data solely to provide their service to us, on our instructions, and whose terms do not allow them to use data sent through BOTOTO to train their models and limit their storage of that data to what they need to provide the service and prevent abuse. AI replies can be wrong. If something the assistant tells you looks incorrect, please check with the business.

Service providers and other recipients

Our service providers may process personal data only to provide their services to us, under written agreements requiring confidentiality and security.

RecipientPurpose
Cloudflare, Inc.Hosting and delivering this website, including server logs
Cloud hosting providersHosting the BOTOTO service and its data
AI model providers, including any model gatewayProcessing messages and business information to produce replies, summaries and drafts
Other service providersEmail, data storage, backups and support tools

We may also share personal data with:

  • the business you are dealing with, which controls its customers' information in BOTOTO;
  • Meta, when replies are sent through Messenger, Instagram or WhatsApp. Meta handles that information as an independent controller under its own terms and privacy policies;
  • professional advisers under duties of confidentiality;
  • public authorities, courts or regulators when the law requires it;
  • a buyer or successor if our business is reorganised, merged or sold, subject to this policy.

We do not sell personal data. You can ask for a current list of our service providers at info@bototo.ge.

International transfers

Some service providers may process personal data outside Georgia, or outside your country, including in the United States and the European Union. When personal data goes to a country that the applicable law does not recognise as providing adequate protection, we use the safeguards that law requires, such as contractual clauses with the provider and, where Georgian law requires it, a permit from the State Audit Office of Georgia. You can ask us about these safeguards, or for a copy, at info@bototo.ge.

How long we keep information

We keep personal data only as long as needed for the purposes in this policy or as the law requires. For information we process for a business, the business's instructions and our agreement decide how long it is kept, and at the end of the agreement we delete or return it as the agreement sets out.

CategoryRetention period
Website server access logs30 days
Enquiries and demo requests24 months after our last contact
Business account and staff user detailsWhile the account is active, then 12 months
Contract and administrative recordsThe period required by accounting and tax law
Customer conversations, including messages received through Meta servicesAs set by the business, and at most 24 months after the last message
Appointments and customer recordsAs set by the business; deleted or returned within 30 days after the agreement ends
Meta connection details and access tokensDeleted or revoked when the connection is removed
Technical and security logs, including AI request logs30 days
Change historyWhile the account is active
BackupsOverwritten within 35 days
Records of privacy and deletion requests3 years

We may keep information longer where the law requires it or to establish, exercise or defend legal claims, keeping only what is necessary.

Security

We use technical and organisational measures designed to protect personal data against loss, misuse and unauthorised access, appropriate to the risk. Subject to confirmation before launch, these include:

  • limiting access to people who need it for their work, under confidentiality duties;
  • keeping each business's data separate from other businesses' data;
  • keeping channel access credentials on our servers, not in browsers or client-side code;
  • recording who changes business information and bookings;
  • requiring service providers to protect data under written agreements;
  • a process to detect, investigate and respond to security incidents.

If a personal data breach affects information we process for a business, we will tell that business without undue delay. Where we are the controller, we will notify the supervisory authority and affected people when the law requires it. No system is completely secure: please keep your sign-in details confidential and tell us at info@bototo.ge if you think your account has been misused.

Cookies and similar technologies

Our website does not use cookies or similar technologies such as analytics scripts, advertising pixels, social media plugins or device fingerprinting, and it does not load content from third-party services. If this changes, we will update this policy first and, where the law requires it, ask for your consent before using any non-essential cookie or similar technology.

Children

Our website and business accounts are for adults acting for businesses. We do not knowingly collect personal data directly from children for our own purposes. If you believe a child has given us personal data, contact us and we will delete it. A business's customers may include children, for example when a parent books an appointment for a child. The business, as controller, is responsible for handling that information lawfully, including any consent required from a parent or guardian.

Your rights

Subject to the conditions and exceptions in the law that applies to you, you have the right to:

  • be informed about how your personal data is processed;
  • access your personal data and receive a copy;
  • rectification of inaccurate or incomplete data;
  • erasure of your data;
  • restriction (blocking) of its use;
  • object to processing based on legitimate interests, and to direct marketing at any time;
  • portability: receive data you gave us in a structured, commonly used format, or have it sent to another organisation;
  • withdraw consent at any time, where processing is based on consent;
  • not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you;
  • complain to a supervisory authority or go to court.

How to exercise your rights

For information we hold as controller, email info@bototo.ge or write to us at 63 Anna Politkovskaya St., Apt. 23, Vake District, Tbilisi, Georgia, saying which right you want to use and giving enough detail for us to find your information. For information a business holds about you in BOTOTO, such as your conversations or appointments with a clinic, contact that business first. If you contact us, we will pass your request on promptly and help the business respond.

We may need to confirm your identity before acting, for example by asking you to reply from the email address we hold or to confirm details of a conversation. We will ask only for what we need and use it only to handle your request.

We will reply within 10 working days. If we need more time or cannot meet your request in full, we will tell you why. Requests are free, except where the law allows a fee for clearly unfounded or excessive requests.

Complaints

Please contact us first so we can try to resolve your concern. You can also complain to the supervisory authority. In Georgia, this is the State Audit Office of Georgia, which supervises personal data protection. Where the GDPR applies, you can complain to the data protection authority in the EU country where you live, work or believe your rights were infringed.

How to request deletion

Anyone can ask us to delete their personal data, whether or not they have a BOTOTO account. Our Data deletion page explains the steps, including for messages sent to a business through Messenger, Instagram or WhatsApp.

In short, email info@bototo.ge with the subject "Data deletion request", naming the business you contacted (if any), the channel you used and the details that identify you on it, such as your phone number. If the information belongs to a business that uses BOTOTO, we will send your request to that business and help it act on it. If some information must be kept, for example because the law requires it, we will tell you what is kept and why. Blocking a business or deleting a chat in your messaging app does not delete the copy the business holds in BOTOTO.

Changes to this policy

We may update this policy as BOTOTO develops, for example when a planned feature or channel becomes available, or when the law changes. We will publish the new version here with a new effective date. For significant changes, we will also tell business customers directly before they take effect, and we will ask for consent where the law requires it.

Contact us

For questions about this policy or how we handle personal data:

  • Privacy: info@bototo.ge
  • Support: info@bototo.ge
  • Phone: +995 598 60 73 02
  • Post: Bototo Technology LLC, 63 Anna Politkovskaya St., Apt. 23, Vake District, Tbilisi, Georgia

You can also use our contact page. See also our Terms of Service and Data deletion page.

Back to top

Oto answers your customers' messages and turns them into booking requests, for clinics and appointment-based businesses in Georgia.

No cookies. No tracking.

Product

  • How it works
  • Features
  • Availability
  • FAQ

Company

  • Contact
  • Book a demo

Legal

  • Privacy Policy
  • Terms of Service
  • Data Deletion

BOTOTO is a brand operated by Bototo Technology LLC (შპს ბოტოტო ტექნოლოჯი), 63 Anna Politkovskaya St., Apt. 23, Vake District, Tbilisi, Georgia.

Support: info@bototo.ge · Phone: +995 598 60 73 02

© 2026 Bototo Technology LLC. All rights reserved.