Privacy Notice
Last updated: 2026-07-20
1. Who we are
This Privacy Notice explains how Bixbit AB, a company registered in Sweden ("we", "us"), processes personal data in connection with the Bixbit flow service (the "Service"). Bixbit AB acts as data controller for the personal data described below.
2. Personal data we collect
- Account data — name, email address, login credentials, organization affiliation.
- Profile & preferences — language, currency, role, avatar.
- Content you submit — customers, quotes, agreements, signatures, chat messages, noticeboard posts, uploaded files.
- Usage & telemetry — pages visited, feature usage, error logs, approximate location derived from IP.
- Device & connection data — IP address, browser, device identifiers.
- Support communications — messages you send us.
Payment and billing details (card number, billing address, tax ID) are collected and processed by our reseller and Merchant of Record, Paddle. We receive limited transaction metadata from Paddle (customer ID, subscription status, price, environment).
3. Purposes and legal bases
- Providing the Service (contract performance) — creating your account, delivering features you request.
- Security & fraud prevention (legitimate interest / legal obligation) — protecting the Service, detecting abuse, keeping audit logs.
- Product improvement (legitimate interest) — understanding how features are used, fixing errors.
- Support (contract performance / legitimate interest) — responding to your requests.
- Legal compliance (legal obligation) — tax, accounting, and lawful requests.
- Marketing (consent, where required) — only where you opt in.
4. Recipients and sharing
We share personal data with:
- Service providers / subprocessors — hosting and database (Supabase), application hosting (Lovable / Cloudflare), transactional email (Resend), analytics and error logging providers used by the Service.
- Merchant of Record — Paddle for the sale of the product, subscription management, payments, tax compliance, invoicing, and refunds.
- Professional advisers — legal, accounting, and auditors, when needed.
- Authorities — where required by law.
5. International transfers
Some subprocessors are located outside the EEA/UK. Where personal data is transferred outside the EEA/UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision.
6. Retention
We retain personal data for as long as your account is active and for a reasonable period afterwards to comply with legal obligations, resolve disputes, and enforce our agreements. Content you delete is removed from active systems and purged from backups within their rotation cycle.
7. Your rights
Under applicable data protection laws (including GDPR), you have the right to:
- access the personal data we hold about you;
- request rectification of inaccurate data;
- request erasure ("right to be forgotten");
- request restriction of, or object to, processing;
- data portability;
- withdraw consent at any time where processing is based on consent;
- lodge a complaint with your local data protection authority — in Sweden, the Integritetsskyddsmyndigheten (IMY).
To exercise these rights, contact privacy@bixbit.se. We will respond within one month.
8. Security
We apply appropriate technical and organizational measures to protect personal data, including encryption in transit, access controls, and per-organization data isolation. No system is perfectly secure; report suspected vulnerabilities to privacy@bixbit.se.
9. Cookies
We use strictly necessary cookies to keep you signed in and to remember your preferences. Where analytics or marketing cookies are used, we ask for consent first and you can change your choice at any time.
10. Contact
Bixbit AB
Privacy contact: privacy@bixbit.se