BioCV EU Privacy Notice
GDPR Articles 13–14
Contents
1. Controller and contact
Controller: BioCV GmbH, Rüsingstrasse 45, 44894 Bochum, Germany (Amtsgericht Bochum HRB 18787; VAT ID DE335774940). Privacy contact: privacy@biocv.org; BioCV GmbH, Attn: Data Protection, Rüsingstrasse 45, 44894 Bochum, Germany.
BioCV has not appointed a Data Protection Officer. The privacy contact above (privacy@biocv.org) is not a DPO contact.
2. What personal data we process
-
Account and contact details (name, business e-mail, organization, role).
-
Login credentials and authentication data. BioCV uses Firebase Authentication supporting email/password and passwordless email-link sign-in; email verification is required. BioCV does not use Google, social-media, phone/SMS or other external login providers, and does not have access to your plaintext password.
-
Usage and log data (how the Software and API are used; device and connection information). Diagnostic logs may contain technical device identifiers such as MAC addresses.
-
Livestock telemetry and operational data from BioCV Hardware associated with the account. Sensor and telemetry data that does not contain a direct name is device-linked / pseudonymous — not anonymous — where it can be associated with a customer, device, animal or Site through Firestore or another identifier.
-
Support content and information submitted in tickets or notes.
3. Providing personal data (required or optional)
Account, business-contact, authentication, billing, and other information identified as required during registration is necessary to establish and administer the business account and provide the Services. If this information is not provided, BioCV may be unable to create the account, authenticate the user, process an Order, or provide the relevant Service. Information not identified as required is optional unless otherwise stated.
4. Purposes and legal bases (Art. 6 GDPR)
-
Providing and administering the Services and authenticating users: Article 6(1)(b) GDPR where the individual is personally the contracting party; otherwise Article 6(1)(f) GDPR, based on the legitimate interests of BioCV and the Customer in administering and performing their business relationship and providing authorized users with access to the Services.
-
Security, fraud prevention, service improvement via aggregated data, and business administration — legitimate interests, Art. 6(1)(f).
-
Billing, tax, accounting, and other legal obligations — Art. 6(1)(c).
-
Any processing based on consent (e.g. optional communications) — Art. 6(1)(a), withdrawable at any time.
Where BioCV GmbH processes personal data on a customer's behalf, it acts as processor under the Data Processing Agreement (Annex B of the Terms) and the customer is the controller for that processing.
5. Recipients and processors
We share personal data with processors that act on our documented instructions (for example, cloud hosting and platform operations, and business/support/privacy e-mail), each under an Art. 28 GDPR contract. A current list of subprocessors and processing locations is published at https://biocv.info/legal/subprocessors. We do not sell personal data. BioCV does not currently send customer prompts or personal data to an AI provider; no customer-facing AI functionality is enabled in this release, and any future AI processing will be enabled only after the provider, purpose, location, retention, disclosure and safeguards are separately approved and this notice is updated.
6. Hosting locations and international transfers
Primary LISA hosting is in the EU on Google Cloud / Firebase, including Firestore in the eur3 (Europe) location, infrastructure in Frankfurt and Belgium, EU Cloud Storage, EU BigQuery, and EU backups. Not all processing occurs exclusively in the EEA: Google Cloud logging uses globally located log buckets, and diagnostic logs may contain technical device identifiers such as MAC addresses; Pub/Sub messages containing device identifiers are configured for persistence in specified EU regions. Any transfer to a third country not covered by an EU adequacy decision is made under appropriate safeguards (Art. 46 GDPR), primarily the EU Standard Contractual Clauses with completed annexes and a transfer impact assessment.
7. Retention
We apply the following periods: production-stream objects are automatically deleted after 30 days; account-export files are deleted after 30 days; active account data is deleted when the customer deletes the account; residual account backup copies expire within no more than approximately 30 days; Firestore backups are taken weekly and retained approximately 22 days; Cloud SQL backups and transaction logs are retained seven days; ordinary application and diagnostic logs are retained 30 days; required Google Cloud audit/security logs are retained 400 days. Following termination of the contract, related customer data is deleted or de-associated no later than three months after termination. BigQuery has no automatic table expiration, so the three-month period is met through BioCV's documented manual termination procedure. If a backup is restored, previously completed deletion requests are reapplied.
8. Your rights
Subject to the GDPR, you have the rights to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and to object (Art. 21); where processing is based on consent, you may withdraw it at any time without affecting prior processing. To exercise any of these GDPR rights, send a verified request to privacy@biocv.org. You may also lodge a complaint with a supervisory authority.
Separately, contractual customer/account data exports and EU Data Act access or third-party data-sharing requests are handled through support@biocv.org under the procedure in Annex D of the Terms. BioCV provides these exports by manual delivery in CSV, JSON or another structured, machine-readable format; there is no self-service export portal. An export covers retained customer-attributable account, device, animal, configuration, sensor/product and related-service data available across Firestore, Cloud SQL, BigQuery and Cloud Storage, subject to lawful exclusions.
The competent supervisory authority for BioCV GmbH is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2-4, 40213 Düsseldorf, Germany (poststelle@ldi.nrw.de; +49 211 38424-0). You may also lodge a complaint with the supervisory authority of your habitual residence or place of work.
How to reach us: GDPR data-subject and privacy requests (access, rectification, erasure, restriction, objection, withdrawal of consent) should be sent to privacy@biocv.org. Contractual customer/account data exports and EU Data Act access or third-party-sharing requests should be sent to support@biocv.org (see Section 8).
9. Source of data (Art. 14)
Where we obtain personal data other than directly from you (for example, from your employer/organization or from Hardware operated under an account), the categories and source are as described above; we provide this notice within the periods required by Art. 14 GDPR.
10. Automated decision-making
We do not carry out solely automated decision-making that produces legal effects concerning an individual or similarly significantly affects an individual.
11. Changes and contact
We may update this notice; the current version is available at the permanent URL at or before collection. For any privacy request, use the contact in Section 1.
BioCV EU Privacy Notice — Version 1.4, effective 10 August 2026. Contracting entity: BioCV GmbH.
