Privacy Policy
Updated: 6 August 2026
What we hold, why, for how long, and who else sees it. No clauses that hide the answer.
Two kinds of people in this document
- A business using b1z — our customer. The data they enter is theirs, and we process it on their behalf.
- A customer of that business — someone who left their details or received a service. You signed nothing with us, and the business you dealt with is responsible for your data. If you want it deleted, contacting them is the fastest route; you can also contact us and we will pass it on.
What we hold
- Contact details for leads and customers: name, phone, email, address.
- Communication history: WhatsApp messages, SMS, emails, and transcripts and summaries of phone calls.
- Business activity: appointments, technician routes, quotes, invoices and payments.
- System data: who signed in and when, what they changed, and IP addresses — for security and fault diagnosis.
We do not hold card details. Payments go to a payment provider who holds those; we keep the last four digits and nothing else.
Why
To run the service the business bought: to show leads, send a reminder, book an appointment, produce an invoice. We do not sell data, do not rent it, and do not use it to advertise to anyone else.
Artificial intelligence
Some capabilities — a draft reply, a call summary, quote lines — go through an external model provider. What is sent is the minimum the task requires, it is not used to train models, and the providers we work with are contractually bound to that.
Who else sees it
Infrastructure providers without which the service does not work, each seeing only what it needs:
- Hosting and database servers.
- Communication providers — telephony, SMS, WhatsApp, email.
- A payment provider, for payments.
- A language-model provider, for the features marked as such.
Beyond that — only where the law requires it. In that case, and if we are permitted to, we will tell the business that its data was demanded.
Where it sits
Our servers are in Germany. Some communication providers also process data outside the European Union; those transfers are made under the standard contractual protections.
For how long
- Customer data — for as long as the account is active, plus 30 days after it ends.
- Audit log (who did what) — 12 months.
- Billing documents — 7 years, because the law requires it.
- Recordings and transcripts — as configured by the business; the default is 12 months.
Your rights
To see, correct, delete, receive a copy in a portable format, and object to a particular use. Write to privacy@b1z.ai — we answer within 30 days. If you are a customer of a business that uses us, we will pass the request to them and confirm that it was handled.
Security
- Encryption in transit (TLS) and at rest.
- Full separation between customers at the database level — not only in code.
- Daily backups, with restores that are tested.
- Two-factor authentication available to every user, and a complete record of sign-ins.
In a security incident affecting personal data we notify the affected businesses within 72 hours of becoming aware, with what is known and what we are doing about it.
Cookies
A sign-in cookie, and a record of your light or dark theme preference. No advertising cookies and no cross-site tracking.
Contact
privacy@b1z.ai for any privacy question.