This notice explains what personal data BizOS collects, why we use it, who processes it for us, and what rights you have.
Duty Group LLC, a limited liability company doing business as BizOS, is the controller of the personal data described here. This notice covers bizos.cc, app.bizos.lol and the Services.
It does not cover how you handle the personal data of your own customers, leads and visitors. For that data, you are the controller and we act on your instructions — writing your own privacy notice and collecting the consents you need is your responsibility (Terms, section 3.C).
You give us: your name and email, account and authentication data, your organisation and business details, everything you type or upload — prompts, documents, files, briefs, brand material — your settings and permissions, your support messages, and the billing data you provide to our payment providers.
We collect automatically: IP address, approximate location derived from it, device and browser data, pages viewed, features used, actions taken, timestamps, session and diagnostic data, error reports and stack traces, and cookies and similar technologies.
Your agent collects for you: whatever it retrieves while executing your tasks — data from connected accounts, advertising metrics and creatives, leads submitted through your forms, publicly available research, and content from sites it visits on your behalf.
Third parties give us: sign-in data when you use Google, profile and account data from the services you connect, advertising performance and attribution data, and subscription and payment status from our billing providers.
We never ask for and do not want: your card number, your government ID or your bank details. Those go directly to Stripe or Whop, who handle payment and identity verification. We do not store full card numbers.
| Purpose | Legal basis (GDPR) |
|---|---|
| Provide the Services, run your agents, execute your tasks | Performance of a contract |
| Authenticate you and keep your account secure | Contract; legal obligation |
| Process subscriptions and platform fees | Contract; legal obligation |
| Prevent fraud, abuse and misuse; protect shared assets | Legitimate interests |
| Debug, monitor, measure and improve the Services | Legitimate interests |
| Send service and operational communications | Contract |
| Send marketing communications | Consent (withdrawable at any time) |
| Non-essential cookies and analytics | Consent |
| Comply with law, respond to authorities, defend claims | Legal obligation; legitimate interests |
Running an agent means sending content to third-party AI model providers. Your prompts, the context your agent assembles (documents, business data, task history, connected-account data) and the outputs generated are transmitted to and processed by the providers listed in section 5. We select providers that offer business terms, and we do not sell your content.
| Provider | What it does for us | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage | Account, organisation and business data, uploaded files |
| Vercel | Application hosting, edge network, sandboxed code execution | Request and log data, application and generated code |
| Upstash | Caching, queues and rate limiting | Session and technical operational data |
| Cloud compute providers | Servers running agent workloads | Task context and execution data |
| OpenRouter, Groq, Anthropic, Google | AI model execution | Prompts, agent context, generated outputs |
| Whop | Subscription sales and billing (merchant of record) | Identity, contact and transaction data |
| Stripe | Payment processing, connected accounts, identity verification | Transaction, payout and KYC data |
| Meta | Advertising delivery, lead forms, conversion measurement | Campaign data, creatives, leads, hashed identifiers |
| Sign-in and optional connected services | Authentication and account data | |
| Resend and email delivery providers | Transactional and outbound email | Email addresses, message content, delivery metadata |
| PostHog | Product analytics | Usage events, pseudonymous identifiers |
| Sentry | Error monitoring | Errors, stack traces, technical telemetry |
We also disclose data to professional advisers, to authorities where the law requires it, and to a counterparty in a merger, acquisition or asset sale. Additionally, your agent transmits data to any third-party platform you connect or instruct it to use — that transmission is directed by you.
We do not sell personal data, and we do not share it for cross-context behavioural advertising as those terms are defined by California law.
We are established in the United States, and several providers process data outside the European Economic Area. Where personal data is transferred out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, the UK Addendum, or an adequacy decision, together with the safeguards those providers put in place.
We keep personal data for as long as your account is active and for as long as we need it for the purposes above. After you delete your account, we delete or anonymise your personal data within 30 days, except where we must keep it longer: accounting, tax and transaction records for the period required by law, and records needed to prevent fraud, enforce our Terms or defend a legal claim, which we keep for as long as that purpose lasts.
We encrypt data in transit, encrypt third-party credentials and tokens at rest, isolate each organisation's data, restrict internal access to what is necessary, and log administrative actions. No system is perfectly secure, and we cannot guarantee absolute security. Protecting your own credentials, and the permissions you grant your agent, is your responsibility.
If the GDPR applies to you, you have the right to access your data, to have it corrected, to have it erased, to restrict or object to its processing, to receive it in a portable format, to withdraw consent at any time without affecting prior processing, and to give directives about what happens to your data after your death. You can also lodge a complaint with your national data protection authority — in France, the CNIL (cnil.fr).
If you are a California resident, you have the right to know what we collect and why, to obtain a copy, to have it deleted, to have it corrected, and to be free from discrimination for exercising those rights. We do not sell personal data or share it for cross-context behavioural advertising, so there is nothing to opt out of.
To exercise any of these rights, email contact@bizos.lol. We will verify who you are before we act, and we will respond within the time the law allows. You may use an authorised agent where the law provides for one.
The Services are for adults. They are not directed at anyone under 18, and we do not knowingly collect data from anyone under 18. If we learn we have, we delete it.
We may update this notice. We will change the date above and, for material changes, make a reasonable effort to notify you before they take effect.
Duty Group LLC. Privacy and general enquiries: contact@bizos.lol.
Policy version: 2026-08-16 · © 2026 Duty Group LLC