BizOSbeta

Privacy Notice

Last updated: August 16, 2026

This notice explains what personal data BizOS collects, why we use it, who processes it for us, and what rights you have.

1. Who we are and what this covers

Duty Group LLC, a limited liability company doing business as BizOS, is the controller of the personal data described here. This notice covers bizos.cc, app.bizos.lol and the Services.

It does not cover how you handle the personal data of your own customers, leads and visitors. For that data, you are the controller and we act on your instructions — writing your own privacy notice and collecting the consents you need is your responsibility (Terms, section 3.C).

2. What we collect

You give us: your name and email, account and authentication data, your organisation and business details, everything you type or upload — prompts, documents, files, briefs, brand material — your settings and permissions, your support messages, and the billing data you provide to our payment providers.

We collect automatically: IP address, approximate location derived from it, device and browser data, pages viewed, features used, actions taken, timestamps, session and diagnostic data, error reports and stack traces, and cookies and similar technologies.

Your agent collects for you: whatever it retrieves while executing your tasks — data from connected accounts, advertising metrics and creatives, leads submitted through your forms, publicly available research, and content from sites it visits on your behalf.

Third parties give us: sign-in data when you use Google, profile and account data from the services you connect, advertising performance and attribution data, and subscription and payment status from our billing providers.

We never ask for and do not want: your card number, your government ID or your bank details. Those go directly to Stripe or Whop, who handle payment and identity verification. We do not store full card numbers.

3. What we do with it, and on what basis

PurposeLegal basis (GDPR)
Provide the Services, run your agents, execute your tasksPerformance of a contract
Authenticate you and keep your account secureContract; legal obligation
Process subscriptions and platform feesContract; legal obligation
Prevent fraud, abuse and misuse; protect shared assetsLegitimate interests
Debug, monitor, measure and improve the ServicesLegitimate interests
Send service and operational communicationsContract
Send marketing communicationsConsent (withdrawable at any time)
Non-essential cookies and analyticsConsent
Comply with law, respond to authorities, defend claimsLegal obligation; legitimate interests

4. AI processing — what you should understand

Running an agent means sending content to third-party AI model providers. Your prompts, the context your agent assembles (documents, business data, task history, connected-account data) and the outputs generated are transmitted to and processed by the providers listed in section 5. We select providers that offer business terms, and we do not sell your content.

5. Who processes data for us

ProviderWhat it does for usData involved
SupabaseDatabase, authentication, file storageAccount, organisation and business data, uploaded files
VercelApplication hosting, edge network, sandboxed code executionRequest and log data, application and generated code
UpstashCaching, queues and rate limitingSession and technical operational data
Cloud compute providersServers running agent workloadsTask context and execution data
OpenRouter, Groq, Anthropic, GoogleAI model executionPrompts, agent context, generated outputs
WhopSubscription sales and billing (merchant of record)Identity, contact and transaction data
StripePayment processing, connected accounts, identity verificationTransaction, payout and KYC data
MetaAdvertising delivery, lead forms, conversion measurementCampaign data, creatives, leads, hashed identifiers
GoogleSign-in and optional connected servicesAuthentication and account data
Resend and email delivery providersTransactional and outbound emailEmail addresses, message content, delivery metadata
PostHogProduct analyticsUsage events, pseudonymous identifiers
SentryError monitoringErrors, stack traces, technical telemetry

We also disclose data to professional advisers, to authorities where the law requires it, and to a counterparty in a merger, acquisition or asset sale. Additionally, your agent transmits data to any third-party platform you connect or instruct it to use — that transmission is directed by you.

We do not sell personal data, and we do not share it for cross-context behavioural advertising as those terms are defined by California law.

6. International transfers

We are established in the United States, and several providers process data outside the European Economic Area. Where personal data is transferred out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, the UK Addendum, or an adequacy decision, together with the safeguards those providers put in place.

7. Cookies

We use cookies that are strictly necessary to sign you in, keep your session, secure the Services and remember your preferences. We also use analytics and advertising-attribution cookies, which are subject to your consent where the law requires it. You can withdraw consent or block cookies in your browser; blocking strictly necessary cookies will break the Services.

8. How long we keep it

We keep personal data for as long as your account is active and for as long as we need it for the purposes above. After you delete your account, we delete or anonymise your personal data within 30 days, except where we must keep it longer: accounting, tax and transaction records for the period required by law, and records needed to prevent fraud, enforce our Terms or defend a legal claim, which we keep for as long as that purpose lasts.

9. Security

We encrypt data in transit, encrypt third-party credentials and tokens at rest, isolate each organisation's data, restrict internal access to what is necessary, and log administrative actions. No system is perfectly secure, and we cannot guarantee absolute security. Protecting your own credentials, and the permissions you grant your agent, is your responsibility.

10. Your rights

If the GDPR applies to you, you have the right to access your data, to have it corrected, to have it erased, to restrict or object to its processing, to receive it in a portable format, to withdraw consent at any time without affecting prior processing, and to give directives about what happens to your data after your death. You can also lodge a complaint with your national data protection authority — in France, the CNIL (cnil.fr).

If you are a California resident, you have the right to know what we collect and why, to obtain a copy, to have it deleted, to have it corrected, and to be free from discrimination for exercising those rights. We do not sell personal data or share it for cross-context behavioural advertising, so there is nothing to opt out of.

To exercise any of these rights, email contact@bizos.lol. We will verify who you are before we act, and we will respond within the time the law allows. You may use an authorised agent where the law provides for one.

11. Children

The Services are for adults. They are not directed at anyone under 18, and we do not knowingly collect data from anyone under 18. If we learn we have, we delete it.

12. Changes

We may update this notice. We will change the date above and, for material changes, make a reasonable effort to notify you before they take effect.

13. Contact

Duty Group LLC. Privacy and general enquiries: contact@bizos.lol.

Policy version: 2026-08-16 · © 2026 Duty Group LLC

Privacy Notice — BizOS