Legal

GDPR Data Protection Policy

Last updated: February 17, 2026

011. Commitment to Data Protection

C5S Technology Limited ("Company"), operator of the BiVelio platform, together with Chronos Technology SLU, the group holding entity based in Andorra and owner of the BiVelio brand, are committed to protecting the personal data of all individuals whose data is processed through our Service, in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Andorran Data Protection Act (Llei 29/2021), and all applicable data protection legislation.

This GDPR Policy supplements our Privacy Policy and provides specific information about how we comply with the GDPR when processing personal data of individuals in the European Economic Area (EEA), the United Kingdom, and Andorra.

022. Roles and Responsibilities

2.1 As Data Controller

When processing personal data of our users (account holders), we act as the Data Controller. This includes:

2.2 As Data Processor

When processing data on behalf of our clients (their customers' data, leads, conversations, etc.), we act as the Data Processor. In this capacity:

2.3 Data Protection Officer

We have designated a Data Protection Officer (DPO) who can be contacted at:

033. Lawful Basis for Processing

We process personal data under the following lawful bases as defined in Article 6 of the GDPR:

Processing ActivityLawful BasisGDPR Article
Account creation & authenticationContract performanceArt. 6(1)(b)
Service delivery & featuresContract performanceArt. 6(1)(b)
Payment processingContract performanceArt. 6(1)(b)
Security monitoring & fraud preventionLegitimate interestArt. 6(1)(f)
Analytics & service improvementLegitimate interestArt. 6(1)(f)
Marketing communicationsConsentArt. 6(1)(a)
Tax & financial record keepingLegal obligationArt. 6(1)(c)
AI processing of user dataContract performanceArt. 6(1)(b)
Third-party integration data sharingConsentArt. 6(1)(a)

044. Data Subject Rights

Under the GDPR, data subjects have the following rights. We are committed to facilitating the exercise of these rights within the statutory timeframes:

4.1 Right of Access (Article 15)

You may request a copy of all personal data we hold about you. We will provide this within 30 days in a commonly used electronic format.

4.2 Right to Rectification (Article 16)

You may request correction of inaccurate personal data or completion of incomplete data. You can also update most data directly through your account settings.

4.3 Right to Erasure (Article 17)

You may request deletion of your personal data when:

Note: We may retain certain data where required by law (e.g., tax records, audit logs).

4.4 Right to Restriction (Article 18)

You may request restriction of processing while we verify the accuracy of your data, resolve an objection, or when processing is unlawful but you prefer restriction over erasure.

4.5 Right to Data Portability (Article 20)

You may request your data in a structured, commonly used, machine-readable format (JSON, CSV). We provide data export functionality within the Service.

4.6 Right to Object (Article 21)

You may object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.

4.7 Rights Related to Automated Decision-Making (Article 22)

Where we use automated processing (including AI) that significantly affects you, you have the right to:

4.8 How to Exercise Your Rights

Submit requests to privacy@bivelio.com. We will:

055. Data Processing Agreements

In compliance with Article 28 of the GDPR, we enter into Data Processing Agreements (DPAs) with:

DPAs include:

066. Sub-Processors

We use the following categories of sub-processors:

CategoryPurposeLocation
Cloud InfrastructureHosting, database, and compute servicesEU / US (with SCCs)
AI Model ProvidersNatural language processing, classificationUS (with SCCs)
Payment ProcessorBilling and subscription managementUS (with SCCs)
Email Service ProviderTransactional and notification emailsUS (with SCCs)
Analytics ProviderUsage analytics and product improvementEU

We will notify clients of any changes to our sub-processor list at least 30 days in advance, providing the opportunity to object.

077. International Transfers

As our corporate structure spans Hong Kong and Andorra, personal data may be transferred internationally. We ensure compliance through:

088. Technical and Organizational Measures

In accordance with Article 32 of the GDPR, we implement the following measures:

8.1 Technical Measures

8.2 Organizational Measures

099. Data Protection Impact Assessments

We conduct Data Protection Impact Assessments (DPIAs) in accordance with Article 35 of the GDPR for processing activities that are likely to result in high risk to data subjects, including:

1010. Data Breach Notification

In the event of a personal data breach, we will:

1111. Records of Processing Activities

In compliance with Article 30 of the GDPR, we maintain comprehensive records of all processing activities, including:

1212. AI and Automated Processing

BiVelio uses AI for various processing activities. Our approach to AI complies with GDPR requirements:

1313. Children's Data

BiVelio is a B2B service not intended for individuals under 16 years of age. We do not knowingly collect or process personal data of children. If we discover that we have inadvertently collected data of a child under 16, we will immediately delete such data and notify the relevant supervisory authority if required.

1414. Complaints and Supervisory Authority

If you believe your data protection rights have been violated, you may:

  1. Contact our DPO at privacy@bivelio.com to resolve the matter directly.
  2. Lodge a complaint with the competent supervisory authority:

1515. Policy Updates

This GDPR Policy is reviewed and updated annually, or more frequently when required by changes in legislation, our processing activities, or organizational structure. All updates will be published on this page with a revised "Last updated" date.

1616. Contact

For any questions regarding this GDPR Policy or to exercise your rights: