BioCV US Privacy Notice
LISA — IoT Hardware, Software & API
Contents
This notice is provided at or before the point of collection (for example, at sign-up) and applies to LISA services provided by BioCV Inc. under the US Terms of Service (including any successor full Terms). It is a short-form notice for business use.
Who we are
BioCV Inc., 1805 Collaboration Place, Suite 1250, Ames, Iowa 50010, provides the LISA hardware, software, and API for livestock operations. Contact: privacy@biocv.org.
What we collect
-
Account and contact details (name, business email, organization, role).
-
Login credentials and authentication data. BioCV uses Firebase Authentication supporting email/password and passwordless email-link sign-in; email verification is required. We do not use Google, social-media, phone/SMS or other external login providers, and we do not have access to your plaintext password.
-
Usage and log data (how the Software and API are used, device and connection information). Diagnostic logs may contain technical device identifiers such as MAC addresses.
-
Livestock telemetry and operational data from BioCV Hardware associated with your account. Sensor and telemetry data without a direct name is device-linked / pseudonymous — not anonymous — where it can be associated with a customer, device, animal or Site through Firestore or another identifier.
-
Support content and any information you submit in tickets or notes.
We ask that you not submit sensitive personal information except account credentials and any categories identified in your Order or the Documentation as necessary to provide the Services.
Why we use it (purposes)
-
To create and administer accounts and authenticate users.
-
To provide, maintain, secure, and support the Services (including ingesting and displaying telemetry, analytics, and alerts).
-
To process billing and subscription records.
-
To investigate misuse and security incidents and to comply with law.
-
To create aggregated data for analytics and product improvement (this does not identify you, your farm, or any individual).
How long we keep it (retention)
We apply the following periods: production-stream objects are automatically deleted after 30 days; account-export files are deleted after 30 days; active account data is deleted when you delete the account; residual account backup copies expire within no more than approximately 30 days; Firestore backups are taken weekly and retained approximately 22 days; Cloud SQL backups and transaction logs are retained seven days; ordinary application and diagnostic logs are retained 30 days; required Google Cloud audit/security logs are retained 400 days. After contract termination, related customer data is deleted or de-associated no later than three months after termination (BigQuery has no automatic table expiration, so this is met through our documented manual termination procedure). If a backup is restored, previously completed deletion requests are reapplied.
You can request an export or deletion by sending a verified request to support@biocv.org; there is no self-service export portal. Exports are delivered manually in CSV, JSON or another structured, machine-readable format and cover retained customer-attributable account, device, animal, configuration, sensor/product and related-service data available across Firestore, Cloud SQL, BigQuery and Cloud Storage, subject to lawful exclusions.
Who we share it with
We share personal information with service providers that process it on our behalf (for example, cloud hosting and platform operations, and business/support/privacy e-mail), each under contract and only to provide the Services. Hosting and platform operations for BioCV Inc.'s U.S. customers are provided by BioCV GmbH, which owns and operates the LISA backend. We do not sell or 'share' personal information for cross-context behavioral advertising. We do not currently send your prompts or personal information to an AI provider; no customer-facing AI functionality is enabled in this release, and any future AI processing will be enabled only after the provider, purpose, location, retention, disclosure and safeguards are approved and this notice is updated. A current list of subprocessors is published at https://biocv.info/legal/subprocessors.
Your choices and rights
Your rights depend on your state of residence, the law that applies, and the capacity in which you interact with us; not every right exists in every state. For example, the Iowa Consumer Data Protection Act applies to individuals acting in a personal or household context (it excludes individuals acting in a commercial or employment context) and provides rights of access, deletion, data portability, and appeal, but not a general right of correction; California law, where it applies, provides additional rights, including correction and opt-out rights. Where BioCV processes personal information on a customer's behalf, we act as a service provider/processor and will direct requests to that customer. To make a request, contact privacy@biocv.org.
Scope of U.S. state privacy laws
U.S. state privacy laws apply according to their own scope and thresholds. Where the California Consumer Privacy Act (CCPA, as amended) applies, we provide the disclosures it requires at or before collection — the categories we collect, our purposes and our retention periods are set out above — and we honor the applicable rights and opt-out mechanisms. Where another state's privacy law applies to you, we honor the rights that law actually provides, as described above. To make a request or ask which law applies to your situation, contact privacy@biocv.org.
Security
We maintain administrative, technical, and organizational measures appropriate to the risk to protect personal information. No method of transmission or storage is perfectly secure.
Hosting locations and international processing
Primary LISA hosting is in the EU on Google Cloud / Firebase (Firestore in the eur3 location, infrastructure in Frankfurt and Belgium, EU Cloud Storage, EU BigQuery and EU backups), operated by BioCV GmbH. Not all processing occurs exclusively in the EEA: Google Cloud logging uses globally located log buckets, and diagnostic logs may contain technical device identifiers such as MAC addresses; Pub/Sub messages containing device identifiers are configured for persistence in specified EU regions. Where a data-transfer mechanism is legally required, we implement an appropriate one.
Changes and contact
We may update this notice; the current version will be made available at or before collection. Questions: privacy@biocv.org, BioCV Inc., 1805 Collaboration Place, Suite 1250, Ames, Iowa 50010.
Short-form privacy notice. The Terms of Service and the Data Processing Agreement (Annex B) govern the contractual data-protection obligations.
BioCV US Privacy Notice — Version 1.6, effective 10 August 2026. Contracting entity: BioCV Inc..
