Privacy Policy
This policy explains how BizFig AS (“BizFig”, “we”, “us”) processes personal data when you use beta.bizfig.com and related BizFig services, in line with the EU/EEA General Data Protection Regulation (GDPR) and Norwegian privacy law.
1. Data controller
The data controller is BizFig AS, Norway.
Privacy contact: privacy@bizfig.com
General: legal@bizfig.com
2. Personal data we collect
Depending on how you use BizFig, we may process:
- Account & profile: name, email, password (stored as a hash), role, location, headline, bio, skills, industries, looking-for tags, avatar, LinkedIn/website links, phone (optional).
- Waitlist / signup: application details, referral, LinkedIn URL, and the password you choose for sign-in.
- Community content: ventures, events, resources, and other content you create or manage.
- Technical data: IP address, browser/user agent, session identifiers, login timestamps, and security logs needed to operate the service.
- Cookie / preference data: consent choices stored locally or in a preference cookie (see our Cookie Policy).
3. Purposes and legal bases (GDPR)
| Purpose | Legal basis |
|---|---|
| Create and manage your account; enable sign-in and profile | Contract (Art. 6(1)(b)) |
| Operate Connect, Ventures, Events, and member features | Contract (Art. 6(1)(b)) |
| Service security, abuse prevention, and debugging | Legitimate interests (Art. 6(1)(f)) |
| Essential cookies / session needed for the site to work | Legitimate interests / necessity for service |
| Optional analytics or marketing cookies (if enabled) | Consent (Art. 6(1)(a)) |
| Legal compliance and responding to lawful requests | Legal obligation (Art. 6(1)(c)) |
4. Sharing and processors
We do not sell personal data. We may share data with trusted service providers who process it on our instructions (for example hosting and email infrastructure), and when required by law. Profile information you choose to publish (name, photo, headline, location, role, ventures) may be visible to other members and, where the directory is public, to visitors.
5. Transfers outside the EEA
Where tools or infrastructure process data outside the EEA, we use appropriate safeguards such as EU Standard Contractual Clauses or an adequacy decision, as applicable.
6. Retention
- Active member accounts: kept while your account remains open and for a reasonable period afterward for security and dispute handling.
- Deleted accounts: soft-deleted records may be retained briefly, then permanently erased or anonymized where feasible.
- Waitlist records: retained for onboarding/admin purposes, then deleted or anonymized when no longer needed.
- Security logs: retained only as long as needed for security and operations.
7. Your GDPR rights
You may request to:
- Access your personal data
- Rectify inaccurate data
- Erase data (“right to be forgotten”), subject to legal exceptions
- Restrict or object to certain processing
- Receive a portable copy of data you provided (data portability)
- Withdraw consent where processing is based on consent (without affecting prior lawful processing)
Email privacy@bizfig.com. You may also lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) or your local EU/EEA supervisory authority.
8. Security
We use industry-standard measures including hashed passwords, session controls, and access limits for admin tools. No online system is perfectly secure; please use a strong unique password.
9. Children
BizFig is intended for adults in a professional context. We do not knowingly collect data from children under 16.
10. Changes
We may update this policy. The “Last updated” date above will change when we do. Material changes may be highlighted on the site.
Privacy questions?
We respond to GDPR requests as quickly as reasonably possible.
mail Contact privacy