Privacy Policy Τελευταία ενημέρωση: Σεπτέμβριος 2026

niboto Privacy Policy

This Privacy Policy explains how niboto (the "Service") collects, uses, stores, and shares data when:

  • you visit our website or web app,
  • you use our APIs or embedded chatbots,
  • you contact us (e.g., email, contact forms), or
  • you receive informational or transactional messages from us.

The Service is intended exclusively for individuals aged 18 and over. By using niboto, you confirm that you are at least 18 years old.

This policy should be read together with the Terms of Use and the Cookies Policy.

Summary: We mainly collect:

  • Account data (email, settings, tenant id).
  • Content you upload or create (files, conversations, embeddings in Qdrant).
  • Technical data and usage logs (IP, user agent, timestamps, errors, tokens).
  • Billing data via Stripe (we do not store card details).

We use Google Cloud / Vertex AI / Gemini, Qdrant, Stripe, an SMTP provider, and Google Analytics 4 (only with consent via the banner).

We do not use your data to train AI models. Your data is used only to provide the Service and to technically optimize its operation.

You have rights of access, rectification, erasure, restriction, objection, and data portability under the GDPR. You can exercise these rights at any time by contacting hello@niboto.ai.

1) Data Controller

The data controller for the personal data described in this Policy is niboto.

2) Scope and roles

This Policy applies when you use the niboto website, web app, APIs, and embedded chatbots, as well as when you contact us (e.g., contact form, email).

The Service is intended for adult users (18+). If you use niboto on behalf of an organization (e.g., a company, office, or entity), you confirm you are authorized to provide us with the necessary data.

Role as Data Controller: For your account data, technical logs, billing details, and other data related to the use of the Service, niboto acts as the Data Controller.

Role as Data Processor: For the content (files, text, knowledge bases) uploaded and managed by a customer-tenant, the customer is the Data Controller and niboto acts as the Data Processor, under the data processing agreement (DPA) incorporated into the Terms of Use.

If you upload or connect files that contain third-party data (e.g., customers, employees, partners, students, or family members), you assume the role of Data Controller for that data and warrant that you have the appropriate legal basis and any required notice and/or consent from the data subjects.

3) What data we collect

The data we collect depends on how you use the Service. In general, it falls into the following categories:

Account data

  • Email, user id, tenant id, account settings, and interface preferences.
  • Credentials stored with secure hashing (e.g., passwords, API keys you provide to us).

Content & conversations

  • Files you upload (e.g., PDF, DOCX, TXT, MD) and basic metadata (size, type, page count).
  • Snippets/embeddings of your content in a vector database (Qdrant) for search and Q&A purposes.
  • Conversation text with the chatbots (session logs), including prompts and responses.

The files and texts you upload may contain personal data about you or third parties (e.g., customers, partners, family members). You are responsible for ensuring you have a lawful basis to process such data and that your use of niboto complies with your obligations as a Data Controller, where applicable.

You can delete files, collections, or conversations from the niboto environment at any time. This deletion applies to active systems and, within a reasonable period of time, to backups, in accordance with the "Retention periods" section.

Technical & usage data

  • IP address, user agent, timestamps, tokens, device/session identifiers.
  • Errors, security logs, limits/quotas, information about the Service’s performance.
  • Aggregated usage statistics (e.g. frequency of use, core flows).

Billing & invoicing

  • For payments, we use Stripe as an independent provider; we do not store card numbers or CVV.
  • We receive billing reports, transaction status, and invoicing details from Stripe, which we store for accounting, support, and fraud detection purposes.

Contact & support

  • The content of emails you send us and any accompanying details (name, signature, organization).
  • Data from contact forms or feedback (subject, message, request type).

Special categories of data & sensitive files: We do not seek to collect special categories of data (e.g. health data, data relating to criminal convictions, political or religious beliefs, trade union membership, biometric data).

Examples of such data include medical histories or reports, criminal case information, documents revealing political or religious beliefs, as well as files containing full payment card details, passwords, or other highly sensitive financial information.

niboto is not designed to be used as a permanent repository for medical records, employee files, or other highly sensitive data without a specific written agreement (e.g. a dedicated DPA/SLA). If you choose to process such data through the Service, you must ensure you have an appropriate legal basis, have informed the data subjects, and have implemented additional safeguards.

Especially when the content concerns minors (e.g. children, students), the organization or individual uploading the data bears full responsibility for GDPR compliance and any required parental/guardian consent.

Data from third-party sources: We do not buy or receive personal data from commercial providers (data brokers). When you connect external content sources (e.g. files, databases, your organization’s systems), processing is performed on your behalf as the customer-tenant.

5) Cookies & tracking technologies

We use cookies and similar technologies (e.g. local storage, pixels) so the Service can operate, to maintain security, and—only with consent—for analytics and optimization.

  • Strictly necessary cookies: are required for core operation (e.g. session, CSRF, authentication). Without them, the Service cannot function properly.
  • Functional cookies: may be used to store preferences (e.g. interface language).
  • Analytics (optional): we use Google Analytics 4 for aggregated traffic statistics only if you provide consent via the cookies banner. You can change your preferences at any time.

Before statistics consent, we keep only aggregate usage metrics without visitor_id or a persistent analytics cookie. Visitor journey, product analytics with visitor_id and Google Analytics are activated only if you choose statistics cookies.

Details about the cookies we use, their categories, and their duration can be found in the Cookies Policy.

Some browsers and operating systems support “Do Not Track” (DNT) signals. At present there is no unified standard for DNT support, and we do not separately tailor our processing based on such signals; however, you can always manage cookies via the preferences banner and your browser settings.

6) Processors & third-party providers

We work with third-party service providers who process data on our behalf, under data processing agreements (DPAs) and, where required, Standard Contractual Clauses (SCCs).

Google Cloud Platform — cloud infrastructure and storage; Vertex AI / Gemini (LLM & embeddings)
Qdrant — vector database for embeddings and content search
Stripe — payment processing & billing (we do not store card details)
SMTP / email provider — sending transactional and support emails
Google Analytics 4 — aggregated traffic analytics (consent required)

These providers are contractually required to process the data only according to our instructions, to protect it appropriately, and not to use it for their own purposes beyond what is contractually permitted or required by law.

7) Artificial Intelligence (AI) products & features

niboto is an AI-powered service. We use large language models (LLMs) and vector search to answer questions and process content.

How AI processing works

  • The text you submit (prompts, file content, conversation history) may be sent to AI providers (e.g. Google Vertex AI / Gemini) to generate responses.
  • Your content embeddings are stored in Qdrant for fast search and better context in responses.
  • We use this data to provide and technically improve our AI features (e.g. performance, reliability) without changing the original purpose of processing.

What AI answers are NOT

  • Responses are generated automatically by AI models and may contain errors or omissions.
  • They do not constitute legal, medical, financial, tax, or other professional advice.
  • You are responsible for reviewing the content before using it in production or critical environments.

Niboto AI Assistant Chrome Extension

If you use the Niboto AI Assistant Chrome Extension, the extension processes content only after a clear user action, such as selecting text, using the right-click menu, opening the side panel, or clicking a button to generate a reply draft or extract stay details.

  • Selected text from emails, reviews, customer messages, or reservation text may be sent to Niboto.
  • If the Create Stay from Text feature is used, the selected text may include or be used to extract details such as guest name, email, phone number, check-in/check-out dates, room type, room number, and number of guests.
  • The selected content may include personal data intentionally chosen by the user for processing, such as contact details, booking details, customer messages, or review content.
  • The extension does not automatically send emails, publish replies, make bookings, submit forms, or perform external actions.

Generated replies and extracted stay details are shown to the user for review and editing before copying, inserting, importing, or saving. The extension requires an active Niboto account session and does not store tenant API keys.

We do not use your data to train AI models. We do not train or improve AI models (ours or third parties’) using your data, beyond what is necessary to provide the Service’s features and in accordance with the settings and agreements we have with our providers.

Third-party AI providers (e.g. Google Cloud / Vertex AI) process data under their own privacy policies and terms of use, which we recommend you review for details about their practices.

8) International data transfers

Your data may be stored or processed outside the European Economic Area (EEA), depending on where the infrastructure and service providers we use are located.

In such cases, we implement appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (SCCs) and supplementary technical and organizational measures, so that the level of protection is equivalent to that of the GDPR.

9) Retention periods

We retain your personal data only for as long as necessary for the purposes described in this Policy or as required by law.

  • Tenant files & content collections: are retained until you delete them through the Service or your contract/business relationship ends. A technical backup buffer may remain for up to 30–90 days.
  • Conversations (session logs): are retained for up to 12 months for support, auditing, and service improvement, unless you request earlier deletion where feasible.
  • Technical & security logs: are typically retained for up to 6 months (or longer where required for security or by law).
  • Billing & tax records: are retained for the period required by tax/accounting laws.

When there is no longer a legal or business need to retain specific data, we delete it or anonymize it. If certain data remains temporarily in backups, it is isolated from any active processing until it is permanently deleted.

10) Security

Our goal is to protect your data through appropriate technical and organizational security measures.

Indicative security measures

  • Encryption in transit (TLS) and, where possible, at rest.
  • Least-privilege principle and role-based access control.
  • Logical tenant separation and data-collection isolation.
  • Event logging and alerts to detect suspicious activity.
  • Regular backups of metadata and critical information.

Incident management

Despite our efforts, no technology is 100% secure. In the event of a data breach that may affect your rights, we will notify you without undue delay and, where required, within 72 hours from the time we became aware, in accordance with the GDPR.

We also recommend using strong, unique passwords, enabling 2FA where available, and avoiding use of the Service on unsecured networks.

11) Your rights under the GDPR

If you are in the European Economic Area (EEA), the United Kingdom, or another jurisdiction with similar rules, you have specific rights regarding your personal data.

  • Right of access: to receive confirmation as to whether we process personal data concerning you and to obtain a copy of that data.
  • Right to rectification: to request correction of inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten"): to request deletion of data when it is no longer necessary or when you withdraw your consent, provided there is no other lawful reason for retention.
  • Right to restriction of processing: to request restriction of processing in specific cases (e.g., when you contest the accuracy of the data).
  • Right to object: to object to processing based on legitimate interest, including any profiling based on that legal basis.
  • Right to data portability: to receive your data in a structured, commonly used, machine-readable format and to transfer it to another provider, where technically feasible.
  • Right to withdraw consent: when processing is based on your consent (e.g., analytics, marketing), you can withdraw it at any time without affecting the lawfulness of processing carried out before the withdrawal.
  • Right to lodge a complaint with a supervisory authority: if you believe your rights are being infringed, you can file a complaint with the competent Data Protection Authority (e.g., the Hellenic DPA in Greece).

To exercise the above rights, you can contact us at hello@niboto.ai.

12) Children

The Service is intended exclusively for individuals aged 18 and over and is not intended for children. We do not knowingly collect data from individuals under 18 and we do not allow minors to create accounts.

If we learn that we have collected personal data from an individual under 18, we will take steps to deactivate the relevant account and delete the related data, to the extent technically feasible and unless retention is required for legal reasons. If you believe we may have received a child’s data without proper consent, please inform us at hello@niboto.ai.

13) Automated decisions & profiling

We use automated processing technologies (e.g., AI, analytics) to provide niboto’s functionality and improve the user experience.

  • We do not make automated decisions that produce legal (or similarly significant) effects. no decisions producing legal effects or significantly affecting you (e.g., rejecting a service request) are made solely based on automated processing.
  • Aggregated analytics: usage statistics and performance metrics are analyzed in aggregated, anonymized, or pseudonymized form, where possible, to improve the Service.
  • AI answers: AI-generated responses are assistive and are not used as a basis for autonomous decisions against you.

If you have questions about any form of automated processing that concerns you, you can contact us and, where required by law, request human intervention or additional explanations.

14) Changes to this Policy & Do Not Track signals

We may update this Privacy Policy from time to time to reflect changes in the Service, legislation, or our providers.

The most recent version will always be available on our website and will be identified by the “Last updated” notice at the beginning of the page. In case of material changes, we may notify you in a more prominent way (e.g., banner or email, where appropriate).

As also noted in the Cookies section, some browsers/systems provide Do Not Track (DNT) settings. Until a unified technical standard is established, we do not independently adjust our processing based on these signals; however, you can set your cookie preferences via the relevant banner and your browser settings.

15) Contact

For questions about this Policy or to exercise your rights, you can contact us using the details above. This text does not constitute legal advice; if your organization is subject to increased regulatory requirements (e.g., healthcare, financial services, public sector), it is recommended that you seek specialized legal support and enter into a dedicated DPA/SLA.