Legal

Privacy Policy

This Privacy Policy explains what personal data Bdeo collects, why we collect it, how we use and protect it, and what rights you have under GDPR, UK GDPR and CCPA.

Last updated: June 25, 2026

01.Who we are

Bdeo Technologies SL ("Bdeo", "we", "us") is the data controller for personal data processed through our website and the Bdeo platform. You can reach our privacy team at [email protected].

02.Data we collect

We collect only the data we need to run the service:

  • Account data — first and last name, email, hashed password.
  • Billing data — credit pack purchased, billing period, promo code, currency, payment method (bank transfer details processed by our banking provider).
  • Content data — briefs, prompts and generated articles you create in the dashboard.
  • Usage data — pages visited, features used, credit consumption, device and browser metadata, IP address.
  • Support data — messages you send us by email or chat.

03.How we use your data

  • Provide, secure and improve the Bdeo service.
  • Process credit purchases, invoices and tax records.
  • Send service emails (order status, bank details, security alerts).
  • Detect fraud, abuse and violations of the Acceptable Use Policy.
  • Comply with legal obligations (accounting, tax, court orders).

We do not sell your personal data, and we do not use your content to train third-party foundation models.

05.Who we share data with

  • Cloud hosting and database providers used to run the platform.
  • Email delivery providers for transactional messages.
  • Banking partners for processing bank-transfer payments.
  • Analytics and error-monitoring providers (aggregated, no content).
  • Professional advisers and authorities where legally required.

06.How long we keep data

Account and content data is kept while your account is active and for up to 12 months after deletion (for backups and dispute resolution). Invoices and tax records are kept for the period required by law (typically 7–10 years). Server logs are kept for up to 90 days.

07.International transfers

Where data is transferred outside the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses and the UK IDTA, together with appropriate technical safeguards.

08.Your rights

You can request access, correction, deletion, portability or restriction of your personal data, object to processing, and withdraw consent. California residents have equivalent rights under the CCPA, including the right to opt out of "sale" or "sharing" — we do neither.

To exercise any right, email [email protected]. You also have the right to lodge a complaint with your local supervisory authority.

09.Security

We use TLS in transit, encryption at rest, hashed passwords (bcrypt/argon2), least-privilege access controls and routine backups. No system is perfectly secure — please use a strong, unique password and enable any future 2FA option.

10.Changes to this policy

We may update this policy from time to time. Material changes will be announced by email or an in-app notice at least 14 days before they take effect.

Questions about this policy? Email [email protected].