Legal
Privacy Policy
Effective 15 September 2026
Botes & Co. is committed to handling personal information responsibly, transparently and securely.
This Privacy Policy explains how Botes & Co. (“Botes & Co.”, “we”, “us” or “our”) collects, uses, stores and shares personal information when you visit our website, contact us, work with us or authorise access to third-party platforms through services such as the Botes & Co. Control Room.
Botes & Co. is a founder-led marketing strategy practice based in Dubai, United Arab Emirates.
For privacy enquiries, contact: hello@botesandco.com
Where required for legal or regulatory purposes, Botes & Co. acts as the controller of personal information collected through this website and our own business activities.
Where we process information on behalf of a client through the Botes & Co. Control Room or another client engagement, the client may act as the controller and Botes & Co. may act as a processor or service provider on that client's instructions.
Information we collect
The information we collect depends on how you interact with Botes & Co.
Information you provide directly
You may provide information including:
- your name
- company name
- job title
- email address
- telephone number
- information submitted through contact forms
- correspondence with Botes & Co.
- project briefs
- business and marketing information
- information necessary to provide consulting services
- information you choose to share during a client engagement
Please do not submit sensitive personal information through our general contact form unless it is genuinely necessary and we have agreed to receive it.
Website and technical information
When you use our website, we or our technology providers may collect technical information such as:
- IP address
- browser and device information
- approximate geographic region
- referring website or campaign
- pages viewed
- interaction with the website
- timestamps
- diagnostic and security logs
- cookie or consent preferences
Where required by applicable law, non-essential analytics and advertising technologies will only operate after appropriate consent has been obtained.
Client platform information
Where a client authorises Botes & Co. to access marketing, advertising, analytics or related systems, we may process information from platforms including Google Ads, Google Analytics and other authorised client systems.
Depending on the service and permissions granted, this may include:
- account and property identifiers
- campaign structures
- advertising performance
- spend and budget information
- impressions, clicks and conversions
- search terms and keyword information
- website and analytics performance
- event and conversion data
- attribution information
- audience or aggregated performance information
- account configuration
- recommendations or diagnostic information
- changes made through the authorised platform
We access only the information reasonably necessary to provide the authorised service.
How we use information
We may use information to:
- respond to enquiries
- assess potential client engagements
- provide marketing strategy and consulting services
- develop positioning, narrative and go-to-market strategies
- analyse marketing and advertising performance
- operate and improve the Botes & Co. Control Room
- identify marketing opportunities, anomalies or issues
- prepare recommendations
- implement actions expressly authorised by a client
- verify the outcome of approved actions
- provide reporting
- maintain records relating to client work
- administer our website and business
- protect our systems and prevent fraud or misuse
- comply with contractual, legal or regulatory obligations
- improve our services using appropriately aggregated or de-identified information
We do not sell personal information.
We do not sell client marketing data.
We do not use client data to build unrelated advertising audiences for Botes & Co. or other clients.
Botes & Co. Control Room
The Botes & Co. Control Room is a marketing intelligence and execution system used to support Botes & Co. client engagements.
With a client's authorisation, the Control Room may connect to selected marketing and analytics platforms to retrieve authorised information, analyse performance, identify issues, prepare recommendations and support approved marketing actions.
Our intended operating model is:
Control Room operating model
Analyse → Recommend → Human Approval → Execute → Verify
Technology assists with analysis and execution. Material decisions remain subject to human review and approval.
Technology, automation and artificial intelligence may assist with research, analysis, diagnostics and execution.
They do not replace Botes & Co.'s responsibility for professional judgement.
Where a proposed action could materially affect a client's marketing activity, advertising configuration or spend, Botes & Co. intends to use appropriate human review and authorisation controls before execution.
Google-connected services and Google API data
Where a client authorises Botes & Co. or the Botes & Co. Control Room to access Google services, we may receive information through Google APIs, including where applicable Google Ads and Google Analytics information.
We use Google-connected information only to provide or improve the services the client has authorised, such as:
- retrieving marketing and advertising performance
- analysing account performance
- diagnosing issues
- preparing recommendations
- creating reports
- implementing authorised advertising changes
- verifying whether approved changes produced the intended result
We request only the permissions reasonably necessary for the functionality being provided.
Access may be read-only or may permit account management depending on the service requested and the permissions the client has expressly granted.
Google-connected information is not sold.
Google-connected information is not used for unrelated advertising.
Google-connected information is not provided to data brokers.
Google API information will not be used to train or improve general-purpose machine-learning or artificial-intelligence models.
Where artificial-intelligence tools assist Botes & Co. in providing an authorised client service, Botes & Co. will seek to minimise the information shared and use providers, settings and contractual arrangements designed to prevent client information from being used to train general-purpose models.
Botes & Co.'s use of information received from Google APIs is intended to comply with the Google API Services User Data Policy, including its Limited Use requirements.
Clients may revoke Google account access using the relevant Google account, Google Ads or Google Analytics access controls or by contacting Botes & Co.
Revoking access stops future authorised API access but may not automatically delete information that Botes & Co. is legally or contractually required to retain. Requests for deletion may be submitted using the contact details in this policy.
Artificial intelligence and automated tools
Botes & Co. uses modern technology and may use artificial-intelligence-assisted tools as part of its work.
These tools may assist with tasks such as:
- research
- summarisation
- data analysis
- performance diagnostics
- pattern detection
- drafting
- recommendation development
- approved operational execution
We apply data minimisation and do not intentionally provide an AI service with more client or personal information than is necessary for the relevant task.
Where appropriate, information may be aggregated, pseudonymised or redacted before processing.
Botes & Co. does not sell client information to AI providers.
Botes & Co. does not permit Google API data to be used to train general-purpose artificial-intelligence models.
Material client decisions remain subject to human judgement and applicable approval controls.
Legal basis for processing
The legal basis on which we process personal information depends on the applicable law, the information concerned and the context in which it is collected.
Depending on the circumstances, we may process information:
- with your consent
- where processing is necessary to provide a service or perform a contract
- where processing is necessary to take steps requested before entering into a contract
- where necessary for legitimate business interests that do not improperly override individual privacy rights
- where required to comply with legal obligations
- where another lawful basis is available under applicable data-protection law
Where we rely on consent, you may withdraw that consent where applicable.
Client confidentiality and separation
Botes & Co. works with multiple businesses.
Client information is used only for the relevant engagement and authorised purposes.
We do not intentionally disclose one client's confidential information, advertising data, strategic information or credentials to another client.
The Botes & Co. Control Room is designed to separate client workspaces and permissions.
Access to client information is limited to people and systems that reasonably require it to provide the authorised service.
International transfers
Botes & Co. is based in the United Arab Emirates and may use technology providers or specialist service providers operating in other countries.
As a result, information may be processed outside the country in which it was originally collected.
Where required, we use appropriate safeguards for international transfers and select providers that maintain suitable privacy and security measures.
Data retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected and to satisfy applicable contractual, accounting, security, legal or regulatory requirements.
Our intended retention approach is:
- General enquiries
- Normally up to 24 months after the most recent meaningful interaction unless an engagement begins or continued retention is appropriate.
- Client records
- For the duration of the client relationship and afterwards for the period reasonably necessary to meet contractual, professional, accounting or legal obligations.
- Connected platform information
- Only for as long as required to provide the authorised service or maintain agreed reporting/history, after which information will be deleted, aggregated or anonymised where reasonably practicable and subject to client agreements and legal requirements.
- Security and technical logs
- Retained for an appropriate period based on their security and operational purpose.
- Consent records
- Retained for as long as reasonably necessary to demonstrate and respect the individual's privacy choices.
Where a client relationship ends, Botes & Co. will remove or anonymise unnecessary client data according to the applicable agreement and retention requirements.
Security
We use reasonable administrative, organisational and technical safeguards intended to protect information against:
- unauthorised access
- loss
- disclosure
- misuse
- alteration
- destruction
Measures may include:
- encryption in transit
- encryption of sensitive credentials at rest
- access controls
- authentication
- restricted permissions
- separation of client environments
- secure credential management
- audit and activity logging
- software and dependency updates
- backup and recovery processes
No system can guarantee absolute security.
If we become aware of a material personal-data incident, we will take appropriate steps in accordance with applicable law and contractual obligations.
Your privacy rights
Depending on where you live and the law that applies, you may have rights in relation to your personal information.
These may include rights to:
- request information about how your data is processed
- request access to personal information we hold about you
- correct inaccurate or incomplete information
- request deletion in applicable circumstances
- object to or restrict certain processing
- withdraw consent where processing depends on consent
- request transfer or portability of information where applicable
- raise a complaint with an appropriate regulator or authority
To exercise a privacy right, contact: hello@botesandco.com
We may need to verify your identity before completing a request.
Where information is processed by Botes & Co. solely on behalf of a client, we may refer the request to that client as the relevant controller.
Marketing communications
We may contact existing or prospective clients where permitted by applicable law.
Where consent is required, marketing communications will only be sent with appropriate consent.
You can unsubscribe from marketing emails using the unsubscribe function provided or by contacting us.
Service, contractual or security messages relating to an active client engagement are not marketing communications and may still be sent where necessary.
Third-party websites
Our website may link to third-party websites and services.
Botes & Co. is not responsible for the privacy practices or content of independent third parties.
We recommend reviewing the privacy information provided by those services.
Children
Botes & Co. provides business-to-business professional services and is not intended for children.
We do not knowingly seek to collect personal information from children through the website.
If you believe a child has provided personal information to us inappropriately, please contact us so that we can take appropriate action.
Changes to this policy
We may update this Privacy Policy as Botes & Co., our technology or applicable requirements develop.
The latest version will always be published on this page and will state its effective date.
Where a change materially affects how we use information already collected, we will take any additional steps required by applicable law.
Questions about privacy?
For questions about privacy, our handling of information, Google-connected data or requests relating to your personal information, contact: