01.Who we are
Bdeo Technologies SL ("Bdeo", "we", "us") is the data controller for personal data processed through our website and the Bdeo platform. You can reach our privacy team at [email protected].
02.Data we collect
We collect only the data we need to run the service:
- Account data — first and last name, email, hashed password.
- Billing data — credit pack purchased, billing period, promo code, currency, payment method (bank transfer details processed by our banking provider).
- Content data — briefs, prompts and generated articles you create in the dashboard.
- Usage data — pages visited, features used, credit consumption, device and browser metadata, IP address.
- Support data — messages you send us by email or chat.
03.How we use your data
- Provide, secure and improve the Bdeo service.
- Process credit purchases, invoices and tax records.
- Send service emails (order status, bank details, security alerts).
- Detect fraud, abuse and violations of the Acceptable Use Policy.
- Comply with legal obligations (accounting, tax, court orders).
We do not sell your personal data, and we do not use your content to train third-party foundation models.
04.Legal bases (GDPR)
We rely on (a) performance of a contract to operate your account and process orders, (b) legitimate interests to secure and improve the service, (c) legal obligations for accounting and tax, and (d) consent for non-essential cookies and marketing emails (which you can withdraw at any time).
06.How long we keep data
Account and content data is kept while your account is active and for up to 12 months after deletion (for backups and dispute resolution). Invoices and tax records are kept for the period required by law (typically 7–10 years). Server logs are kept for up to 90 days.
07.International transfers
Where data is transferred outside the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses and the UK IDTA, together with appropriate technical safeguards.
08.Your rights
You can request access, correction, deletion, portability or restriction of your personal data, object to processing, and withdraw consent. California residents have equivalent rights under the CCPA, including the right to opt out of "sale" or "sharing" — we do neither.
To exercise any right, email [email protected]. You also have the right to lodge a complaint with your local supervisory authority.
09.Security
We use TLS in transit, encryption at rest, hashed passwords (bcrypt/argon2), least-privilege access controls and routine backups. No system is perfectly secure — please use a strong, unique password and enable any future 2FA option.
10.Changes to this policy
We may update this policy from time to time. Material changes will be announced by email or an in-app notice at least 14 days before they take effect.