Controller
BIK AI Technologies, S.L.U., Tax ID B75890202, Av. San Antonio. Contact: admin@biklabs.ai.
Scope and roles
This policy covers biklabs.ai and biklabs.es, platform accounts, communications with BIKLABS, and operational data needed to provide and protect the service.
Where an organization submits personal data in projects, work items, pages, prompts, integrations, or results, that organization determines the purpose and essential means and acts as controller. BIK AI Technologies, S.L.U. processes that content on its instructions as processor unless a legal obligation requires otherwise.
Data we collect
The contact form requires an email address and message; name, company, and topic are optional. If a waitlist is enabled, it may collect email, optional company, source, user-agent, and referrer. IP addresses are used for abuse prevention and are not part of the persistent lead record.
If you accept analytics, Matomo and, when configured, PostHog may process technical identifiers, visited URL, device, approximate country, and navigation events. We do not use this data for behavioural advertising.
Data sources and required fields
We receive data directly from the individual, the organization administering their account, integrations that organization connects, and technical activity generated through service use. Where a customer submits another person's data, the customer is responsible for providing notice and establishing a valid legal basis.
Fields marked as required are needed to answer a request, create an account, or provide the relevant feature. Without them, we may be unable to complete that activity; optional fields may be left blank without losing basic access.
Account and customer content
To create and administer an account, we may process professional name and email, organization, role, workspace membership, configuration, preferences, billing information, and support communications.
Customer content may include projects, tasks, documents, comments, files, decisions, prompts, instructions, retrieved sources, responses, and outputs. The customer controls what it submits and must have a valid basis for processing data about its users, collaborators, and third parties.
BIA, agents, and integrations
To execute a request, we may process authorised context, the identity of the person or agent, selected model, available tools, calls made, timestamps, status, usage, cost, result, and approval decisions. These records support delivery, traceability, error investigation, abuse prevention, permissions, and gates.
An integration enabled by the customer may send data to an external provider or retrieve data from it. The configuration screen, contract, or applicable documentation should identify the scope; the customer can withdraw access by disconnecting the integration or revoking its credentials.
Model training, evaluation, and improvement
Customer content is not treated as authorized for model training merely because BIKLABS is used. Any training, fine-tuning, or evaluation beyond service delivery, security, and support must be identified in the order form, DPA, configuration, or a separate authorization.
Where a customer selects a model or provides its own credentials, it must review whether that provider uses inputs or outputs to improve its services. BIKLABS cannot independently change the terms or controls of an external provider selected directly by the customer.
Purposes and legal bases
We process enquiries to respond and take pre-contractual steps; maintain security and prevent abuse under legitimate interests; comply with legal obligations where applicable; and enable non-essential analytics only with consent.
We do not make decisions with legal or similarly significant effects based solely on automated processing of your public-site activity.
Providers and transfers
We use AWS, primarily in eu-west-3 (Paris), for infrastructure and email; Cloudflare for network protection; self-hosted Matomo; and PostHog only after consent and when configured. Providers act under their applicable terms and safeguards.
BIKLABS may orchestrate customer-provided models or third-party model services. Provider identity, region, retention, and use of content depend on configuration and contracted terms; the current subprocessor annex identifies providers applicable to the contracted service.
Where a provider may process data outside the EEA, we require a valid GDPR Chapter V mechanism such as an adequacy decision or Standard Contractual Clauses.
Retention and security
We retain enquiries for as long as needed to handle them and manage the resulting relationship, then for applicable limitation periods. Analytics data follows each tool's configured period and is deleted or aggregated when no longer needed.
Customer content is retained while the account or contract remains active and through the technical return, deletion, and backup cycles defined in the applicable agreement. Security, execution, and billing logs may have different periods where needed to protect the service, resolve disputes, or comply with law.
The documented technical baseline includes encryption in transit and AWS-managed encryption at rest. Roles, agent identities, scoped tokens, activity, backups, and incident response apply according to the capability, rollout status, and contracted scope; the current security annex is the contractual reference.
Accuracy, review, and automated decisions
Models may produce incorrect information or reproduce data included in their context. BIKLABS introduces permissions, activity, and gates according to each capability and rollout status; the organization must decide when human review is required and how to correct or withdraw a result.
BIK AI Technologies, S.L.U. does not use public-site activity to make solely automated decisions with legal or similarly significant effects. If a customer configures automated processes inside its workspace, it is responsible for assessing lawful basis, transparency, oversight, and routes to challenge a decision.
Children and special-category data
The platform is intended for organizations and professionals, not children. We do not intentionally request children's data through the public website. If an organization needs to process children's, health, or other special-category data, it must tell us before contracting and verify that the agreed scope, legal basis, and safeguards are appropriate.
Changes and versions
We publish the current version and update date on this page. Where a material change affects account processing or requires a new choice, we will provide appropriate notice before it takes effect when required by law.
Your rights
You may request access, rectification, erasure, restriction, objection, or portability, and withdraw consent, by emailing admin@biklabs.ai. You may also complain to the Spanish Data Protection Agency (aepd.es).