Data Act Transparency Statement
International Access to and Transfer of Non-Personal Data
Contents
This is the public statement referenced in Section D.7 (Annex D) of the BioCV LISA European Union B2B Terms. This statement is available at https://biocv.info/legal/data-act; it is not attached to invoices or Orders.
1. Who We Are
This statement is issued by BioCV GmbH, Rüsingstrasse 45, 44894 Bochum, Germany (registered with the commercial register of the Amtsgericht Bochum under HRB 18787; VAT ID DE335774940) (“BioCV”). Questions about this statement can be sent to the contact below.
Data Act contact: privacy@biocv.org; BioCV GmbH, Attn: Data / Legal, Rüsingstrasse 45, 44894 Bochum, Germany.
2. Purpose and Scope
This statement provides the information required by Regulation (EU) 2023/2854 (the “Data Act”) regarding (a) the jurisdiction of the information and communications technology (ICT) infrastructure used to process data in connection with the LISA connected products (BioTag, BioNode) and related services, and (b) the technical, organizational, legal, and contractual measures BioCV applies to prevent or challenge unlawful or unauthorized access to, or transfer of, non-personal data by third-country governmental authorities.
This statement concerns non-personal data. Personal data is governed separately by BioCV's Privacy Notice and the Data Processing Agreement (Annex B of the applicable Terms), including the international-transfer safeguards described there. Where a governmental request concerns personal data, BioCV additionally applies Chapter V GDPR and the transfer safeguards in the DPA.
3. Jurisdiction of the ICT Infrastructure
BioCV primarily processes and stores LISA product and related-service data on Google Cloud / Firebase infrastructure located within the European Economic Area (EEA): Firestore in the eur3 (Europe) location, infrastructure in Frankfurt and Belgium, EU Cloud Storage, EU BigQuery, and EU backups. BioCV does not claim that all processing occurs exclusively within the EEA: Google Cloud logging uses globally located log buckets, and diagnostic logs may contain technical device identifiers such as MAC addresses; Pub/Sub messages containing device identifiers are configured for persistence in specified EU regions. That limited global logging is addressed in Section 5.
The current list of infrastructure providers and processing locations is kept up to date in BioCV's Subprocessor List, available at https://biocv.info/legal/subprocessors and updated when providers or locations change.
4. Measures Against Unlawful International Governmental Access
BioCV maintains reasonable measures designed to prevent, and to allow it to challenge, access to or transfer of non-personal data that would conflict with Union or Member State law. These measures include:
Legal and procedural measures.
-
Processing is arranged so that non-personal data is, by default, held on EEA-based infrastructure under the control of BioCV or its EEA-based (or adequacy-covered) providers.
-
Any request or order from a third-country authority for access to or transfer of data is escalated to a designated internal function for legal review before any action is taken.
-
BioCV complies with such a request only where it is based on an international agreement (for example a mutual legal assistance treaty) in force between the requesting third country and the Union or the relevant Member State, or is otherwise required by a legally valid and binding order that is compatible with Union and Member State law.
-
Where a request appears unlawful, overbroad, or in conflict with Union or Member State law, BioCV seeks to challenge, narrow, suspend, or resist it through available legal channels, and will seek the opinion of a competent body or authority where the Data Act so provides.
Technical measures.
-
Encryption of data in transit and, where appropriate to the risk, at rest, with key management arranged to limit exposure.
-
Access controls, authentication, and least-privilege permissions restricting who can access data and from where.
-
Logging and monitoring of access to production systems and stored data.
Key management: encryption keys are Google-managed encryption keys provided through the Google Cloud / Firebase platform; BioCV does not currently maintain separate BioCV-controlled, EEA-only customer-managed encryption keys. Encryption in transit and at rest is applied as provided by the platform.
Organizational measures.
-
Internal policies and staff training on handling governmental access requests.
-
A defined request-handling procedure covering assessment, minimization, documentation, and (where lawful) notification of affected customers.
-
Periodic review of infrastructure locations and provider commitments.
Contractual measures.
-
Providers and subprocessors are contractually required to apply equivalent safeguards, to notify BioCV of governmental access requests where legally permitted, and to challenge unlawful requests.
-
Where any provider is located in, or subject to the jurisdiction of, a third country, appropriate contractual safeguards (including, for personal data, EU Standard Contractual Clauses and a transfer impact assessment) are put in place before data is made available to that provider.
5. Third-Country Providers, If Any
If BioCV uses any provider that is located in, or subject to the jurisdiction of, a country outside the EEA, the following applies:
BioCV does not use a separate third-country hosting provider for LISA product or related-service data; primary hosting and storage are in the EEA as described in Section 3. Known processing outside the EEA includes Google Cloud logging, which uses globally located log buckets and may hold diagnostic logs containing technical device identifiers (such as MAC addresses). More generally, Google Cloud processing locations are governed by the Google Cloud Data Processing Addendum and its location and transfer commitments; any processing outside the EEA is operated by BioCV's EEA-contracted cloud provider under the safeguards in Section 4 and the transfer mechanism identified in the Subprocessor List. BioCV will update this statement and the Subprocessor List before introducing any further third-country provider.
6. Handling of Government Access Requests
On receiving a request from a governmental authority for non-personal data, BioCV will assess the legal basis and validity of the request, disclose only the minimum data legally required, document the request and its handling, and, where legally permitted, inform the affected customer so that the customer may exercise its own rights. BioCV will use reasonable available legal means to challenge a request that is unlawful or exceeds what Union or Member State law permits.
7. Updates
BioCV may update this statement to reflect changes in infrastructure, providers, or legal requirements. The version and date are shown at the top of this statement. Material changes will be reflected here and, where relevant, in the Subprocessor List.
Data Act Transparency Statement — Version 1.9, effective 10 August 2026. Contracting entity: BioCV GmbH.
