New: turn your website into today’s ranked growth actions
Legal · Privacy

Privacy policy

How BIU collects, uses, discloses, and retains personal information across the website, platform, integrations, and AI features. Written to be readable; this page is not legal advice.

On this page

Effective Date: July 18, 2026
Last Updated: July 18, 2026

This Privacy Policy explains how TCQ AI, LLC, a Delaware limited liability company doing business as BIU ("BIU," "we," "us," or "our"), collects, uses, discloses, retains, and otherwise processes personal information in connection with:

  • the BIU website at biu.ai and other websites that link to this Policy;
  • the BIU software platform, applications, workspaces, APIs, AI features, agents, integrations, and related services;
  • customer support, sales, billing, security, and business communications; and
  • public-web analysis and other processing described below.

This Policy also serves as our general Notice at Collection for United States privacy laws. Shorter, contextual notices may appear when you create an account, connect an integration, enable an agent, submit information, or make a privacy choice.

BIU is operated by:

TCQ AI, LLC d/b/a BIU
Email: hello@biu.ai

1. Scope and important distinctions

1.1 Business service

BIU is intended for business and professional use. It is not intended for personal, family, or household use, and it is not directed to children.

1.2 When BIU acts for itself

BIU acts as a controller, business, or equivalent responsible organization when we determine why and how personal information is processed. This generally includes information used for account administration, authentication, billing, website operation, security, support, product analytics, legal compliance, and BIU's own business operations.

1.3 When BIU acts for a customer

A business customer may submit or connect data to a BIU workspace and instruct BIU to process it on the customer's behalf. For that data, the customer generally acts as the controller or business, and BIU generally acts as a processor, service provider, contractor, or data intermediary under the Data Processing Addendum included in our Terms of Service or another agreement with the customer.

When BIU processes personal information solely for a customer:

  • the customer is responsible for its own privacy notices, legal bases, permissions, and instructions;
  • the customer's privacy policy, not this Policy, primarily governs the customer's independent use of that information; and
  • a person seeking to exercise rights concerning that information should ordinarily contact the relevant customer first. We will assist the customer as required by applicable law and our agreement.

1.4 Third-party services

This Policy does not govern third-party websites, platforms, AI providers, integrations, or services that publish their own privacy notices, except to the extent BIU is responsible for selecting and using a provider as our processor or subprocessor.

2. Plain-language summary

BIU processes information needed to provide an AI-powered platform for website analysis, SEO and technical SEO, AI-search visibility, content generation, competitor monitoring, analytics, recommendations, workflows, integrations, and AI agents.

In particular:

  • We process account, workspace, prompt, output, integration, public-web, usage, device, support, and billing information.
  • At a customer's direction, we may crawl or analyze publicly accessible pages belonging to the customer or third parties, including competitors.
  • We send relevant information to infrastructure, security, analytics, payment, support, and AI-model providers that help operate the Service.
  • Under our standard Service, we do not use Customer Content, prompts, outputs, integration data, or Google User Data to train generalized AI models unless the customer separately and affirmatively opts in.
  • We do not sell personal information or share it for cross-context behavioral advertising, and we do not use personal information for targeted advertising.
  • We use safeguards designed to protect information, but no online service can guarantee absolute security.
  • Depending on applicable law, individuals may have rights to access, correct, delete, obtain, restrict, object to, or port personal information, withdraw consent, or appeal a denied request.

This summary does not replace the full Policy.

3. Notice at Collection: personal information we process

The table below describes the categories of personal information BIU may collect or process, representative examples, sources, purposes, and default retention criteria. We collect only categories reasonably necessary and proportionate for the disclosed purposes.

CategoryRepresentative examplesMain sourcesMain purposesDefault retention
Account and identity informationName, business email, organization, title or role, profile details, user ID, workspace membership, invitation records, identity-provider ID, authentication settings, account status, and age or eligibility confirmationsYou; your employer or workspace administrator; identity providersCreate and administer accounts; authenticate users; manage access and permissions; communicate about the Service; prevent abuseAccount term, then generally up to 30 days in active systems; limited contract, security, suppression, and legal records may be retained longer as described in Section 11
Authentication and security informationPassword hash if native login is offered, multifactor-authentication status, login timestamps, IP address, device identifiers, session identifiers, security events, access logs, OAuth state, and fraud indicatorsYou; your device; identity providers; security providersAuthenticate; protect accounts; detect fraud, misuse, and attacks; investigate incidentsGenerally 12 months, or longer where reasonably necessary for an active incident, legal obligation, or claim
Customer and workspace contentWebsites and sources configured by a customer; prompts; instructions; chats; uploaded files; company memories; drafts; generated content; recommendations; citations; scores; forecasts; reports; audits; workflow rules; agent instructions; approval records; action history; CMS content; repository content; code; pull-request drafts; and customer-provided metadataYou; authorized users; customer systems; configured integrations; public sourcesProvide the Service; generate and evaluate output; operate workflows and agents; maintain workspace history; support users; secure and troubleshoot the ServiceWhile the account or workspace is active and until deleted by an authorized user; after termination, generally up to 30 days in active systems and up to 90 additional days in protected backups, subject to legal and security exceptions
Integration dataData obtained through Google Analytics, Google Search Console, CMS providers, GitHub, social platforms, messaging systems, publishing tools, analytics tools, and other integrations; provider account IDs; authorized scopes; imported records; synchronization status; and action resultsThird-party services you choose to connectProvide the requested integration; retrieve, analyze, synchronize, draft, publish, or otherwise perform authorized functions; troubleshoot; maintain audit recordsImported data follows the applicable Customer Content period; tokens are retained while needed for the connection and removed or rendered unusable after revocation or termination, subject to short-lived logs and backups
Authorization tokens and credentialsOAuth access and refresh tokens, API keys supplied by a customer, webhook secrets, and technical credentials used to maintain a connectionYou; your administrator; connected serviceOperate authorized integrations and agents; authenticate API requests; prevent unauthorized accessWhile the integration is active; deleted or rendered unusable after disconnection or termination, subject to limited security logs and backup cycles
Public-web and third-party source informationPublicly accessible page content, author names, business contact information, titles, URLs, links, technical metadata, publication dates, structured data, source citations, public comments, repository information, search results, rankings, and information derived from those materialsPublic websites; search results; public APIs; customer-selected sources; sources BIU discovers while performing a configured taskAnalyze a customer, market, competitor, citation, ranking, or technical condition; create reports, recommendations, alerts, and company memories; provide source referencesWhile relevant to an active workspace or configured monitoring task; generally deleted with the related workspace under the periods above, unless retained as a security, legal, or deidentified record
Usage, device, and diagnostic informationIP address, approximate location derived from IP, browser and device type, operating system, language, referring and exit pages, timestamps, feature use, page views, API calls, model and feature selections, credit consumption, latency, crash data, error traces, diagnostic events, and audit logsYour browser or device; the Service; cookies and similar technologies; infrastructure and analytics providersOperate, secure, meter, support, debug, and improve the Service; capacity planning; fraud prevention; billing measurement; analyticsGenerally up to 24 months in identifiable form, unless a shorter period is configured; deidentified or aggregated statistics may be retained longer
Billing and commercial informationPlan, subscription term, invoice details, billing contact, payment status, transaction IDs, tax status, credit balance, usage entitlements, discounts, and purchase history. Payment-card details are ordinarily collected directly by our payment processor and are not stored by BIU in fullYou; your organization; payment and tax providersProcess payments; administer subscriptions and credits; collect amounts due; prevent fraud; maintain tax and accounting recordsGenerally up to seven years after the relevant transaction or account termination, or another period required by applicable tax, accounting, or legal rules
Support, sales, and communications informationSupport tickets, emails, call or meeting details, feedback, survey responses, troubleshooting materials, sales notes, and records of our communicationsYou; your organization; support and communications providersRespond to requests; provide support; manage customer relationships; troubleshoot; improve documentation; establish and defend legal claimsGenerally three years after resolution or the end of the customer relationship, unless a longer period is needed for a legal claim or obligation
Marketing and preference informationNewsletter choices, event registrations, campaign interactions, business interests, referral source, cookie choices, privacy choices, and opt-out recordsYou; your device; business partners; publicly available business sourcesSend permitted business communications; measure communications; respect preferences; maintain suppression listsUntil you opt out or the information is no longer needed; suppression records may be retained as long as necessary to honor the opt-out
Derived information and inferencesCompany or website classifications, content themes, technical findings, likely priorities, quality signals, relevance scores, forecasts, recommendations, and other conclusions derived from the information aboveBIU's analysis of Customer Content, public sources, integration data, and usageProvide reports, scoring, recommendations, prioritization, monitoring, and Service functionalityFollows the retention period of the underlying workspace or data from which it was derived
Legal, compliance, and corporate recordsPrivacy requests, consents, policy acceptance records, contract records, sanctions screening results, legal notices, litigation holds, and records relevant to disputes, investigations, or corporate transactionsYou; your organization; authorities; advisers; transaction counterpartiesComply with law; document consent and contract formation; enforce agreements; protect rights; complete corporate transactionsFor the period required by law or reasonably necessary for the relevant matter, including applicable limitation periods

3.1 Sensitive personal information

The standard Service is not designed to receive highly sensitive personal information. Do not submit or connect the following unless BIU has expressly agreed in a signed Enterprise Order Form and appropriate safeguards have been implemented:

  • health, genetic, or biometric information;
  • precise geolocation;
  • government identification numbers;
  • payment-card or bank-account numbers;
  • passwords or authentication secrets for third-party systems, except through an approved integration mechanism;
  • information about children;
  • criminal-offense information;
  • information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, sex life, or sexual orientation; or
  • protected health information, regulated financial information, educational records, or other data subject to sector-specific law.

Account login credentials and the contents of private communications may be treated as sensitive personal information under some laws. We use such information only as reasonably necessary to authenticate users, provide requested features, secure the Service, comply with law, and perform other uses permitted without a separate right to limit.

3.2 Information we do not intentionally collect

BIU does not intentionally collect biometric templates, scan faces or voices for identification, collect precise location through the standard web application, or obtain full payment-card numbers. If such information is submitted contrary to our instructions, we may delete or restrict it.

4. Sources of personal information

We obtain personal information from:

  1. You and other authorized users, including information entered into forms, prompts, chats, settings, support requests, and workspaces.
  2. Your organization and workspace administrators, including account invitations, role assignments, connected sources, and organization-level settings.
  3. Connected services, when an authorized user enables an integration and grants specific permissions.
  4. Public and third-party sources, including public websites, search results, repositories, directories, public APIs, social or community platforms, and sources selected or discovered during a configured task.
  5. Devices and use of the Service, including logs, cookies, security tools, and analytics technologies.
  6. Service providers and business partners, including authentication, payment, fraud-prevention, support, communications, and referral providers.
  7. Professional advisers, authorities, and transaction parties, where relevant to legal compliance, claims, financing, or a corporate transaction.

5. How and why we use personal information

We use personal information only for disclosed purposes that are reasonably necessary and proportionate in context. For people in the European Economic Area, United Kingdom, and other jurisdictions requiring a legal basis, the principal bases are shown below.

PurposeWhat this includesPrincipal legal basis where required
Provide and administer the ServiceCreate accounts; authenticate users; operate workspaces; process prompts; crawl configured sources; generate output; run reports, scoring, monitoring, integrations, workflows, and agents; maintain histories and permissionsPerformance of a contract; steps requested before entering a contract; our legitimate interest in providing a requested business service
Process customer instructions as a processorProcess Customer Personal Data on behalf of a customer according to the agreement and documented instructionsThe customer's legal basis; BIU acts under the Data Processing Addendum rather than selecting an independent basis for the customer's processing
Billing and commercial administrationProcess subscriptions, usage entitlements, credits, invoices, payments, tax, collections, renewals, and cancellation recordsPerformance of a contract; legal obligations; legitimate interests in receiving payment and administering our business
Security, integrity, and abuse preventionAuthenticate; detect suspicious activity; prevent fraud, spam, scraping abuse, malware, credential misuse, unauthorized access, and violations; investigate incidentsLegitimate interests in protecting BIU, customers, users, and third parties; legal obligations; establishment and defense of claims
Support and communicationsRespond to support, privacy, security, sales, and account requests; send service, billing, policy, security, and administrative noticesPerformance of a contract; legitimate interests in supporting users and managing relationships; legal obligations
Product operations, analytics, and improvementDiagnose errors; monitor reliability and capacity; understand feature use; test changes; evaluate model and feature performance; improve usability, safety, and documentationLegitimate interests in operating and improving a secure business service; consent where required for non-essential cookies or similar technologies
AI processingSend relevant inputs to model providers; generate, classify, summarize, score, or evaluate output; detect abuse; route tasks among modelsPerformance of a contract; customer instructions; legitimate interests in operating the Service; consent for any optional training program
Public-source analysisAnalyze publicly accessible business, author, technical, citation, competitor, search, repository, and community information to provide customer-requested analysisLegitimate interests in providing business intelligence and website analysis, balanced against individual rights; performance of a contract with the customer; other bases where applicable
MarketingSend permitted product news, event invitations, and business communications; measure engagement; maintain opt-outsConsent where required; otherwise legitimate interests in business-to-business marketing, subject to applicable electronic-marketing law and the right to object
Legal and compliance purposesRespond to lawful process; comply with tax, accounting, sanctions, export, privacy, and regulatory duties; enforce agreements; prevent harm; establish or defend claimsLegal obligations; legitimate interests; vital interests in exceptional circumstances
Corporate transactionsEvaluate or complete a financing, merger, acquisition, reorganization, asset sale, insolvency, or similar transactionLegitimate interests in corporate administration and transactions; legal obligations; consent where specifically required

5.1 Contractual necessity

If account, authentication, billing, or core workspace information is required to provide the Service and you do not provide it, we may be unable to create or maintain the account or provide the requested feature.

5.2 Legitimate interests

Where we rely on legitimate interests, those interests include operating a reliable business service, securing systems, preventing misuse, supporting customers, improving features, conducting appropriate business-to-business marketing, analyzing public business sources, administering our company, and establishing or defending legal claims. We consider the nature of the information, the context, reasonable expectations, potential effects, and safeguards. You may have a right to object as described below.

6. AI systems, model providers, and training

6.1 AI processing

BIU uses machine-learning and generative-AI systems to analyze information and produce drafts, summaries, scores, recommendations, forecasts, classifications, citations, code, and other output. Relevant Customer Content and instructions may be transmitted to model and infrastructure providers listed in our Subprocessor List.

AI output is probabilistic. It may be inaccurate, incomplete, outdated, biased, offensive, insecure, non-unique, or unsuitable. It may contain fabricated facts, measurements, code, sources, or citations. Our Terms require appropriate human review before output is relied on, published, deployed, or used to take action.

6.2 Generalized-model training

Under BIU's standard Service:

  • BIU does not use Customer Content, prompts, outputs, integration data, or Google User Data to train generalized AI models for BIU or a third party; and
  • BIU does not authorize its standard model providers to use that information to train generalized models.

A customer may participate in a separate, optional improvement or training program only through a distinct, affirmative choice or signed Order Form that explains the data involved, purpose, recipients, retention, withdrawal method, and effect of withdrawal. A customer's authorization is not treated as an individual's consent where applicable law requires consent from that individual; BIU and the customer must establish an appropriate legal basis and exclude information that may not lawfully be used. Refusing or withdrawing from an optional program will not reduce the core Service purchased, except that a feature specifically dependent on the program may become unavailable after clear notice.

We may use deidentified or aggregated service telemetry to operate, secure, evaluate, and improve the Service, provided we take reasonable measures to prevent the information from being associated with an individual or customer and do not attempt to reidentify it.

6.3 Provider retention and abuse monitoring

A model or infrastructure provider may retain limited information for security, abuse detection, debugging, or legal compliance according to the provider configuration and contract applicable to BIU. Our Subprocessor List describes the relevant provider, processing purpose, location, and material retention terms. We select and configure providers with the goal of limiting their independent use of Customer Data.

6.4 Human access

BIU personnel and contractors may access Customer Content only where reasonably necessary and authorized for support requested by a customer, security and abuse investigation, legal compliance, service maintenance, or another purpose disclosed in this Policy and permitted by the agreement. Access is limited by role and confidentiality obligations. Where Google Limited Use requirements apply, human access is further restricted as described in Section 8.

6.5 Automated decisions about individuals

BIU does not use personal information in its capacity as a controller to make decisions based solely on automated processing that produce legal or similarly significant effects about an individual. The Service is not designed or authorized for customers to make high-impact decisions about individuals in employment, housing, education, credit, insurance, healthcare, legal services, essential services, or similar contexts without a separate written agreement and legally required safeguards.

7. Public-web crawling and public-source information

At a customer's direction, BIU may retrieve, crawl, or analyze publicly accessible pages associated with the customer, competitors, search results, citations, repositories, communities, news, directories, and other relevant sources. We may process page content, names and business contact information shown on a page, URLs, links, timestamps, technical configuration, structured data, and derived findings.

Public accessibility does not mean that information is unregulated, unowned, accurate, or available for every use. BIU does not authorize customers to bypass authentication, paywalls, CAPTCHAs, access controls, or other technical restrictions. We may decline, limit, or stop collection based on law, third-party rights, technical instructions, security, provider terms, source requests, or operational risk.

If personal information about you appears in public-source material processed by BIU, you may contact us at hello@biu.ai. We will evaluate the request in light of BIU's role, the relevant customer's role, applicable law, freedom of expression and information, legal claims, source integrity, and other permitted exceptions. Where law requires direct notice concerning indirectly collected information and no exception applies, we will provide that notice.

8. Connected services and Google API data

8.1 What happens when you connect a service

When an authorized user connects a third-party service, the authorization screen identifies the provider and requested permission scopes. BIU receives only the data and permissions associated with the scopes granted. Depending on the integration, BIU may be able to read data, synchronize records, create drafts, transmit content, publish, modify a configured resource, or perform another action shown in the authorization or setup flow.

We may store access or refresh tokens in protected form to maintain the connection. You can ordinarily disconnect through BIU settings or revoke access through the provider. Revocation prevents future access to the extent technically supported, but it does not automatically delete information already imported into a workspace, action logs, security records, or backup copies. Those materials follow this Policy's retention rules.

Before enabling an integration or agent, review the requested scopes, intended actions, destinations, and the provider's terms and privacy notice. Workspace administrators may control organization-level integrations and may have access to information imported by authorized users.

8.2 Google User Data

If you connect a Google service, BIU may access the Google User Data associated with the scopes you authorize, such as Google Analytics property and reporting data, Google Search Console property and search-performance data, identity information used for sign-in, and other data specifically identified in the Google authorization flow.

BIU uses Google User Data only to provide or improve user-facing features that are visible and relevant within BIU, maintain the authorized connection, protect security, comply with law, and perform other uses expressly permitted by applicable Google policies. BIU does not use Google User Data for advertising, retargeting, creditworthiness, data brokerage, surveillance, or generalized-model training.

BIU transfers Google User Data only to subprocessors reasonably necessary to provide or secure the requested user-facing feature, as directed or consented to by the user, as required by law, or in another circumstance permitted by Google's applicable policies. We do not permit humans to read Google User Data except with the user's affirmative agreement for specific support, where necessary for security or abuse investigation, where required by law, or where the data is aggregated for permitted internal operations.

BIU's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements, where applicable.

Disconnecting Google access prevents future API access after revocation becomes effective. Previously imported Google User Data is deleted according to the workspace and retention controls described in this Policy, unless a shorter provider-specific rule or user instruction applies.

9. How we disclose personal information

We disclose personal information only for the purposes described in this Policy, as directed by a customer, or as otherwise permitted by law. Recipient categories include:

9.1 Service providers and subprocessors

We use providers for cloud hosting, storage, databases, content delivery, networking, authentication, cybersecurity, observability, error monitoring, customer support, communications, payments, tax, analytics, and AI models. They process information under contracts intended to restrict their use and protect confidentiality and security. Our current Subprocessor List is available on request by emailing hello@biu.ai.

9.2 Customer-selected integrations and destinations

We disclose information to a third-party service when an authorized user connects or directs BIU to use that service, such as a CMS, analytics service, repository, social platform, messaging service, or publishing destination. The third party's own terms and privacy notice apply to its independent processing.

9.3 Your organization and workspace administrators

Administrators may access, manage, export, restrict, or delete information in the organization's workspace; manage users and roles; connect organization-level services; view usage and billing; and receive account or security information. If you use a business email address, the organization controlling that domain may be able to assume administrative control after appropriate verification.

9.4 Professional advisers and business operations

We may disclose information to lawyers, accountants, auditors, insurers, financing sources, consultants, and other professional advisers subject to appropriate confidentiality obligations.

We may disclose information where we reasonably believe disclosure is necessary to comply with law or lawful process; respond to regulators or authorities; enforce agreements; collect amounts due; investigate fraud, abuse, or security incidents; protect the rights, safety, or property of BIU, customers, users, or others; or establish, exercise, or defend legal claims.

9.6 Corporate transactions

Information may be reviewed or transferred in connection with a proposed or completed financing, merger, acquisition, reorganization, asset sale, insolvency, or similar transaction. We will use safeguards appropriate to the transaction and provide notice or seek consent where required. Google User Data will be transferred in a corporate transaction only as permitted by applicable Google policies.

We may disclose information for another purpose that is clearly explained when you direct the disclosure or provide legally valid consent.

10. No sale, sharing, or targeted advertising

BIU does not sell personal information for money or other valuable consideration. BIU does not share personal information for cross-context behavioral advertising and does not process personal information for targeted advertising as those terms are defined under applicable United States state privacy laws.

BIU does not knowingly sell or share personal information of individuals under 16.

We may use analytics providers acting under contractual restrictions to measure our own websites and Service. We do not permit those providers to use BIU data for cross-context behavioral advertising. If our practices change, we will update this Policy, provide required notice and choices, and honor applicable opt-out preference signals before the changed practice begins.

Where legally applicable, we treat a recognized Global Privacy Control or similar universal opt-out signal as a request to opt out of sale, sharing, or targeted advertising. Because BIU does not engage in those practices under this Policy, the signal ordinarily will not change how we process your information.

11. Retention and deletion

We retain personal information only for as long as reasonably necessary and proportionate for the purposes described, including to provide the Service, maintain security, comply with law, resolve disputes, and enforce agreements. The default periods are stated in the Notice at Collection table and summarized below.

11.1 Active account and workspace data

Customer Content is generally retained while the relevant account or workspace is active and until an authorized user deletes it. Deleting an item may remove it from active user interfaces before it is removed from all operational replicas.

11.2 After termination or workspace deletion

Unless an Order Form states otherwise, BIU generally deletes Customer Content from active systems within 30 days after the applicable workspace is terminated or scheduled for deletion. Protected backup copies may persist for up to 90 additional days before aging out through ordinary backup rotation. Backup copies are isolated from ordinary use and are not restored except for disaster recovery, security, or legal necessity.

11.3 Integration tokens

We delete, revoke, or render unusable integration tokens when the integration is disconnected or the relevant account terminates, subject to provider behavior, short-lived operational replicas, security logs, and protected backups.

11.4 Logs and diagnostics

Security logs are generally retained for 12 months, and usage and diagnostic information for up to 24 months in identifiable form. We may retain specific records longer where reasonably necessary for an active security event, fraud investigation, legal claim, or obligation.

Billing, tax, contract, consent, and transaction records may be retained for up to seven years or another period required by applicable law. Privacy request and complaint records may be retained for at least three years or as otherwise required. Marketing suppression records may be retained as long as necessary to honor an opt-out.

We may retain information longer where required by law, court order, regulator, litigation hold, security need, fraud prevention, or the establishment or defense of legal claims. We may retain deidentified or aggregated information that cannot reasonably be linked to an individual or customer, provided we do not attempt to reidentify it.

11.7 Account closure is not immediate deletion

Closing an account stops ordinary access but does not necessarily delete every record immediately. Authorized users should export needed information before closure. Privacy rights and lawful deletion exceptions remain available as described below.

12. Cookies and similar technologies

BIU and our providers use cookies, local storage, pixels, and similar technologies for:

  1. Strictly necessary functions, such as authentication, security, load balancing, fraud prevention, session continuity, and saving privacy choices.
  2. Functional preferences, such as language, workspace settings, and user-interface choices.
  3. Analytics, such as understanding website and feature use, diagnosing performance, and improving the Service.

BIU does not use advertising cookies or similar technologies for cross-context behavioral or targeted advertising under this Policy.

If BIU introduces technologies that require prior consent under applicable law, it will implement a consent mechanism and update this Section before those technologies load. Where consent has been given and later withdrawn, withdrawal does not affect processing that occurred lawfully before withdrawal.

Browser controls may block or delete cookies, but blocking necessary technologies may prevent features from working. Some browsers offer a legacy “Do Not Track” setting for which no uniform industry response standard exists. BIU does not respond to legacy Do Not Track signals, but honors legally applicable opt-out preference signals as described in Section 10.

13. Security

BIU maintains administrative, technical, and organizational safeguards reasonably designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Depending on the system and risk, safeguards may include access controls, least-privilege permissions, authentication controls, encryption in transit and at rest, logging, monitoring, vulnerability management, secure-development practices, backups, incident response, vendor review, and personnel confidentiality obligations.

No system, network, transmission, model, or storage method is completely secure. We cannot guarantee that unauthorized parties will never defeat safeguards or that information will never be lost, altered, or disclosed. Users are responsible for protecting credentials, enabling available security features, limiting integration permissions, maintaining appropriate backups, and notifying us promptly of suspected unauthorized access.

Additional information is available in our Security Overview at /security. A security overview is informational unless an Order Form expressly makes a specific commitment contractual.

14. International processing and transfers

BIU is based in the United States and uses providers that may process information in the United States and other countries listed in our Subprocessor List. Those countries may have privacy laws different from the law where you live.

Where applicable law requires a transfer mechanism, BIU uses one or more of the following as appropriate:

  • an adequacy decision;
  • the European Commission's Standard Contractual Clauses;
  • the United Kingdom International Data Transfer Addendum or International Data Transfer Agreement;
  • contractual, consent-based, certification, or other legally recognized safeguards; or
  • another lawful derogation or mechanism available for the transfer.

Our Data Processing Addendum provides additional terms for Customer Personal Data. If BIU or a recipient relies on a certification framework, we will identify that reliance only while the relevant certification is active and covers the processing.

For transfers from Canada, Australia, Singapore, and other jurisdictions, we use contractual and organizational measures intended to provide a level of protection required by applicable law and remain accountable to the extent the law requires.

15. Your privacy rights

Depending on your location and the nature of the processing, you may have rights to:

  • know whether and how we process your personal information;
  • access personal information and receive a copy;
  • correct inaccurate personal information;
  • delete personal information;
  • obtain portable information in a usable format;
  • restrict or object to processing;
  • withdraw consent prospectively;
  • opt out of sale, sharing, targeted advertising, or certain profiling;
  • limit certain uses of sensitive personal information;
  • appeal a denied request;
  • receive information about certain automated processing; and
  • complain to a regulator or data-protection authority.

These rights are subject to applicable definitions, verification, scope, and exceptions. For example, we may retain information needed for security, fraud prevention, tax, legal compliance, claims, or the rights of others.

15.1 How to submit a request

Submit a request by emailing hello@biu.ai.

Describe the right you wish to exercise and the account, email address, workspace, or information involved. Do not send passwords, private keys, or full payment-card information. We will respond within the period required by applicable law and will notify you if a legally permitted extension is needed.

15.2 Verification and authorized agents

We may take reasonable steps to verify identity and authority, considering the sensitivity of the information and risk of unauthorized access, deletion, or correction. We may ask an authorized agent to provide proof of authority and may verify the request directly with the individual where permitted.

15.3 Customer-controlled information

If the request concerns information BIU processes solely for a customer, we may identify or refer you to that customer and will assist the customer as required by law and our agreement. We will not disclose one customer's confidential workspace information in response to a request concerning another person.

15.4 Appeals and complaints

If applicable law gives you a right to appeal a denied request, reply to our decision with the subject line Privacy Appeal within the period stated in the decision. We will review the appeal through a person or process different from the initial decision where required.

You may submit a complaint about our handling of personal information through the same channels. For complaints governed by United Kingdom law, we will provide an electronic route, acknowledge the complaint within 30 days, and respond without undue delay, subject to applicable law.

15.5 Non-discrimination

We will not unlawfully discriminate against you for exercising a privacy right. A feature may be unavailable if the information is genuinely necessary to provide it, but we will not deny service, charge a different price, or provide a different level of service merely because you exercised a right except as permitted by law.

16. United States state privacy disclosures

This section supplements the rest of the Policy for residents of California and other United States states with comprehensive privacy laws.

16.1 Categories collected and disclosed

During the preceding 12 months, BIU may have collected the categories described in Section 3, which correspond generally to the following statutory categories:

  • identifiers;
  • customer records and business contact information;
  • commercial information;
  • internet or other electronic network activity;
  • geolocation limited to approximate location derived from IP;
  • professional or employment-related information;
  • contents of communications and account credentials where submitted or generated;
  • inferences; and
  • other information that identifies, relates to, describes, or can reasonably be linked with an individual.

BIU may disclose each relevant category to service providers and contractors for the business purposes described in Sections 5 and 9. BIU may also disclose information to customer-selected integrations, workspace administrators, advisers, authorities, and corporate transaction parties as described above.

BIU has not sold personal information or shared it for cross-context behavioral advertising during the preceding 12 months under the practices described in this Policy.

16.2 California rights

Subject to the California Consumer Privacy Act and its exceptions, California residents may request access to categories and specific pieces of personal information; correction; deletion; information about sources, purposes, and recipient categories; and portability. Where applicable, they may opt out of sale or sharing and limit certain uses of sensitive personal information. BIU does not sell or share personal information and does not use sensitive personal information for purposes that trigger a separate right to limit under the practices described here.

A California request may cover information collected on or after January 1, 2022, subject to applicable limits. We retain request records as required and do not use information submitted for verification for unrelated purposes.

16.3 Other state rights

Residents of other states may have similar rights, including rights to opt out of targeted advertising, sale, or profiling in furtherance of decisions producing legal or similarly significant effects and to appeal a request denial. BIU does not engage in targeted advertising or sale and does not use personal information in its controller capacity for such significant-decision profiling under this Policy.

16.4 Financial incentives

BIU does not offer a financial incentive or price or service difference in exchange for collecting, retaining, selling, or sharing personal information. Ordinary plan pricing, trials, referral programs, and feature differences are not intended to be privacy-based financial incentives. If BIU introduces a covered incentive, we will provide a separate notice before enrollment.

16.5 California “Shine the Light”

BIU does not disclose personal information to third parties for their own direct-marketing purposes in a manner that requires a separate disclosure under California's “Shine the Light” law.

17. European Economic Area, Switzerland, and United Kingdom

17.1 Controller identity

For processing where BIU determines the purposes and means, TCQ AI, LLC is the controller. For Customer Personal Data processed solely on a customer's documented instructions, the customer is the controller and BIU is the processor, subject to the Data Processing Addendum.

17.2 Rights

Subject to applicable law, individuals may have rights of access, rectification, erasure, restriction, portability, objection, and consent withdrawal, and rights concerning certain automated decisions. Where processing is based on legitimate interests, you may object based on your particular situation. You may object to direct marketing at any time.

17.3 Complaints

You may lodge a complaint with the supervisory authority where you live, work, or believe an infringement occurred. In the United Kingdom, the supervisory authority is the Information Commissioner's Office. We encourage you to contact us first so we can attempt to address the concern.

17.4 Representatives

BIU is established in the United States. Any representative appointed or required under applicable European Economic Area, United Kingdom, or Swiss data-protection law will be identified in this Section.

BIU's privacy contact is hello@biu.ai. Unless BIU formally designates a Data Protection Officer under applicable law, that address is a privacy contact and should not be interpreted as a statutory DPO designation.

18. Canada

Subject to applicable Canadian law, individuals may request access to and correction of personal information and may challenge our compliance. We identify purposes at or before collection where required, seek meaningful consent where consent is the appropriate basis, limit collection and use to appropriate purposes, use safeguards proportionate to sensitivity, and remain accountable for personal information transferred to processors outside Canada.

Information may be processed in the United States and other countries listed in our Subprocessor List and may be accessible to courts, law enforcement, or authorities under local law. To ask about our policies, cross-border processing, access, correction, or a complaint, contact hello@biu.ai.

18.1 Quebec

Where Quebec private-sector privacy law applies, BIU's Privacy Officer oversees applicable privacy-governance policies, complaint handling, confidentiality-incident records, and privacy impact assessments. BIU conducts assessments required before certain information-system projects or communications of personal information outside Quebec and uses written contractual safeguards where required.

Subject to applicable conditions and exceptions, a person may also request that BIU cease disseminating personal information or de-index or re-index a link associated with the person, and may request portable computerized personal information collected from the person in a structured, commonly used technological format. Where BIU makes a decision based exclusively on automated processing and Quebec law requires notice and review rights, BIU will provide the required information and an opportunity to submit observations to a person able to review the decision. BIU does not currently make such decisions in its controller capacity as stated in Section 6.5.

Additional provincial requirements may apply, including in Alberta and British Columbia.

19. Australia

Where Australia's Privacy Act applies, this Policy is intended to describe the kinds of personal information BIU collects and holds; how it is collected and held; the purposes for which it is used and disclosed; how an individual may seek access or correction; and how to make a complaint.

BIU may disclose personal information to overseas recipients in the United States and the other countries identified in our Subprocessor List. We take reasonable contractual and organizational steps concerning overseas processing where required. BIU does not currently use personal information in its controller capacity to make automated decisions that are reasonably expected to significantly affect an individual's rights or interests. If that practice changes, we will describe the kinds of personal information used and the kinds of decisions involved as required by Australian law. Complaints may be submitted to hello@biu.ai. We will investigate and respond within a reasonable period. An individual may also complain to the Office of the Australian Information Commissioner where entitled.

20. Singapore

BIU designates its privacy function, reachable at hello@biu.ai, as the contact for data-protection questions under Singapore's Personal Data Protection Act where applicable. Subject to that law, individuals may request access to and correction of personal data and may withdraw consent where consent is the applicable basis, subject to legal and contractual consequences explained at the time.

BIU uses contractual and organizational measures intended to ensure that personal data transferred outside Singapore receives protection comparable to that required under applicable Singapore law. Requests and complaints may be directed to hello@biu.ai.

21. Marketing communications

You may opt out of marketing email by using the unsubscribe link or contacting hello@biu.ai. Opting out of marketing does not stop service, security, billing, legal, or other non-promotional communications relating to an account or transaction.

We do not send marketing messages where prohibited and use consent where required by applicable electronic-marketing law. Workspace administrators may still receive organization-level administrative communications.

22. Children

BIU is not directed to children and does not permit individuals under 18 to create an account. We do not knowingly collect personal information from children under 13 through a child-directed service or knowingly process children's information for sale, sharing, or targeted advertising.

If you believe a child provided personal information in violation of this section, contact hello@biu.ai. We will investigate and take appropriate action, which may include deleting the information or the account, subject to law and preservation requirements.

The Service may link to, retrieve information from, or publish to third-party websites and services. BIU does not control those parties' independent privacy, security, content, or data-retention practices. Review their notices before connecting an account or directing BIU to transmit information.

24. Changes to this Policy

We may update this Policy prospectively to reflect changes in law, technology, vendors, or the Service. The revised Policy will state its effective date. We will provide additional notice of material changes where required, such as by email, an in-product notice, or a prominent website notice.

We will not materially expand our use of Google User Data or use previously collected personal information for a materially incompatible new purpose without providing the notice and obtaining the consent required by applicable law and provider policy.

25. Contact, requests, and complaints

TCQ AI, LLC d/b/a BIU
Privacy Contact: hello@biu.ai

For security reports, use the contact method stated in our Security Overview at /security. Do not include exploit code, credentials, or personal information in an ordinary support message unless requested through a secure channel.