Privacy Policy

Last updated: 23 August 2026

1. Who we are

This Privacy Policy explains how personal data is collected, used, shared and protected in connection with the BiVi CRM platform and the website bivicrm.io (the "Service").

Data controller / operator:
S.R.L. PERFORMANCE CRM ("BiVi CRM", "we", "us")
IDNO: 1026023027360
Registered address: MD-4233, str. Miciurin, Slobozia, Ștefan Vodă, Republic of Moldova
Email: info@bivicrm.io
Phone: +373 68 678 731

This Policy is issued in accordance with Law No. 195/2024 of the Republic of Moldova on the protection of personal data and, where applicable, Regulation (EU) 2016/679 (GDPR).

2. Controller or processor — which role we play

BiVi CRM is a business tool with two distinct data relationships:

  • We are the controller for data about our own customers — the businesses ("Workspaces") that subscribe to the Service, their users, account details, billing records and website visitors.
  • We are the processor for the contact and conversation data our customers manage through the Service. If you are an individual who messaged a business using BiVi CRM, that business is the controller of your data. Please refer to that business's own privacy notice and address your requests to them. We will assist them in responding.

3. What data we process

  • Account and workspace data — name, email address, hashed password, phone number, role, organization name, workspace settings.
  • Contact data managed by our customers — WhatsApp phone numbers, Instagram-scoped IDs (IGSID), Messenger page-scoped IDs (PSID), display names, profile pictures, notes and custom fields added by the business.
  • Message content — messages and media exchanged between our customers and their contacts over WhatsApp, Instagram and Messenger, so we can deliver, display and store conversations.
  • Meta advertising data (only where a customer connects the advertising module) — ad account identifiers, campaign, ad set and ad metrics, lead form submissions retrieved on behalf of the advertiser, and Page insights.
  • Google account data (only if the optional Google Sheets integration is enabled) — the connected account's email address, OAuth access and refresh tokens, spreadsheet identifiers, and the contents of the rows we read or write. See section 7.
  • Billing data — wallet balance, top-ups, per-message charges, invoices. Card details are entered directly with our payment processor (Stripe) and are never stored on our servers; we retain only a payment-provider customer reference.
  • Technical and usage data — log data, IP address, timestamps, browser and device information, diagnostic information.

We do not intentionally collect special categories of personal data (health, biometrics, political opinions, and the like). Customers must not use the Service to process such data without an appropriate legal basis and adequate safeguards.

4. Why and on what legal basis we process data

  • Providing the Service (account creation, message delivery, storage, inbox functionality) — performance of a contract, art. 6(1)(b) GDPR and art. 6(1)(b) Law 195/2024.
  • Processing payments, calculating charges, managing wallets, issuing invoices — performance of a contract; legal obligation under accounting and tax law.
  • AI-assistant features enabled by the customer — performance of a contract.
  • Optional integrations (Google Sheets, advertising) enabled by the customer — performance of a contract; consent where the customer grants third-party access.
  • Security, abuse prevention, service integrity, log retention — legitimate interest, art. 6(1)(f), in protecting our infrastructure and users.
  • Customer support and communication about the Service — performance of a contract; legitimate interest.
  • Marketing emails to prospects and customers — consent, or legitimate interest for existing customers, with an opt-out in every message.
  • Legal, tax and regulatory compliance — legal obligation, art. 6(1)(c).

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before it.

5. Meta Platforms (WhatsApp, Instagram, Messenger, Ads)

BiVi CRM integrates with the official Meta APIs — the WhatsApp Business Cloud API, the Instagram Messaging API, the Messenger Platform and the Marketing API. When a customer connects a channel, message, contact and advertising data is exchanged with Meta Platforms, Inc. in order to deliver the Service.

Our use of information received from Meta APIs ("Platform Data") adheres to Meta's Developer Policies and Platform Terms, including all applicable limited-use requirements. Specifically:

  • We use Platform Data solely to provide the Service to the business that authorized the connection.
  • We do not sell Platform Data, and we do not share it with data brokers or information resellers.
  • We do not use message content for advertising or ad targeting.
  • We do not use Platform Data to build user profiles for purposes unrelated to the Service.
  • We do not use Platform Data to train generalized or foundational AI models, whether ours or any third party's.
  • Platform Data is isolated per tenant and is never shared between workspaces.
  • We delete Platform Data when a channel is disconnected, when a workspace is deleted, or upon request, as described in section 10 and in our data deletion instructions.

6. AI features

Certain optional features (assistant replies, intent classification, audio transcription, ad copy generation) process content through AI service providers acting on our behalf, solely to generate the output requested by the customer's workspace.

  • Content is not used to train third-party public models; we select providers offering a no-training option and configure it.
  • Content sent to AI providers is limited to what is necessary to produce the requested output.
  • Google user data (section 7) is excluded from AI features and is never sent to AI model providers.
  • Customers remain responsible for the content they submit and for the lawfulness of automated replies sent to their contacts.

7. Google Sheets integration

BiVi CRM offers an optional integration allowing a Workspace to connect its own Google account so the Service can maintain customer records in a Google Spreadsheet. The integration is off until an administrator explicitly connects a Google account, and can be disconnected at any time.

Scopes requested and why:

  • openid, email — to identify the connected Google account and display it in your settings.
  • .../auth/spreadsheets — to create spreadsheets, set properties such as the title, and read and write contact rows.
  • .../auth/drive.file — a per-file permission granting access only to files BiVi CRM creates or that you explicitly select through a Google file picker. We cannot list, browse or access any other file in your Drive, and we do not request broader Drive scopes.

How we use Google user data: solely to provide the spreadsheet features you enabled — creating the spreadsheet, keeping its title in sync, writing contact rows, and reading rows back for display inside BiVi CRM.

We do not use Google user data to train, develop or improve any generalized or non-personalized AI or machine-learning model. Spreadsheet contents are not sent to our AI model providers. We do not sell Google user data, share it with data brokers, or use it for advertising. We do not allow humans to read Google user data, except with your explicit consent for a specific purpose (for example resolving a support request), where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymized.

Storage and transmission: refresh tokens are encrypted at rest and stored against your Workspace record. Access tokens are short-lived and requested on demand. Where a Workspace enables the integration for an AI agent, a short-lived access token may be placed on an internal, access-controlled message queue within our own infrastructure; these tokens are never shared with model providers or any third party. All traffic to Google APIs uses TLS.

Limited Use: BiVi CRM's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking access: disconnect at any time from Settings → General. Disconnecting asks Google to revoke our token and deletes the stored refresh token. You may also revoke access at myaccount.google.com/permissions. Revoking does not delete the spreadsheets themselves, which remain in your Google Drive.

8. Recipients and subprocessors

We share data only with providers that help us operate the Service, under written data processing agreements:

  • Meta Platforms Ireland Ltd / Meta Platforms Inc. — message delivery and advertising APIs (Ireland / USA)
  • Google LLC — Google Sheets and Drive APIs, optional integration (USA)
  • Stripe — payment processing (USA / Ireland)
  • Cloud hosting providers — infrastructure and databases
  • AI model providers — optional AI features
  • Transactional email provider — invitations, receipts, notifications
  • BiVi support personnel — authorised staff, only with your consent, bound by confidentiality, fully logged (see section 12)

An up-to-date list of subprocessors, naming each provider and its location, is available on request from info@bivicrm.io. We notify customers before engaging a new subprocessor, and customers may object on reasonable data protection grounds.

We may also disclose information where required by law, to establish or defend legal claims, to protect our rights or the safety of others, or in connection with a merger, acquisition or asset transfer, in which case we will notify affected customers.

9. International transfers

Our infrastructure and some of our providers are located outside the Republic of Moldova and outside the European Economic Area, including in the United States. Where we transfer personal data internationally, we rely on:

  • an adequacy decision, where one applies to the destination country or the certified provider (for example the EU–US Data Privacy Framework);
  • otherwise, Standard Contractual Clauses approved by the European Commission, together with supplementary technical measures (encryption in transit and at rest, access controls); and
  • the corresponding transfer mechanisms recognised under Law No. 195/2024 for transfers from the Republic of Moldova.

A copy of the safeguards used can be requested at info@bivicrm.io.

10. Retention

  • Account and workspace data — for the duration of the subscription and 30 days after workspace deletion.
  • Conversations, messages and media — for the duration of the subscription, or a shorter period configured by the customer; deleted within 30 days of workspace deletion or channel disconnection.
  • Contact records — until deleted by the customer, or within 30 days of workspace deletion.
  • Meta Platform Data — deleted within 30 days of channel disconnection or workspace deletion.
  • Google credentials — deleted immediately on disconnection.
  • Billing records and invoices — 5 years, as required by Moldovan accounting and tax law.
  • Server and security logs — 30 days.
  • Backups — rolling backups purged within 90 days.

After these periods data is deleted or irreversibly anonymized, except where longer retention is required by law or necessary to establish, exercise or defend legal claims. Step-by-step deletion instructions are published at bivicrm.io/Home/DataDeletion.

11. Your rights

Subject to applicable law, you have the right to:

  • be informed about how your data is processed;
  • access your personal data and obtain a copy;
  • rectify inaccurate or incomplete data;
  • erasure ("right to be forgotten");
  • restrict processing;
  • data portability, in a structured, commonly used, machine-readable format;
  • object to processing based on legitimate interests, and to object at any time to direct marketing;
  • withdraw consent at any time where processing is based on consent;
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not carry out such decision-making.

How to exercise your rights: write to info@bivicrm.io from the email address associated with your account. We respond within 30 days; this period may be extended by a further 60 days for complex requests, in which case we will inform you. Exercising your rights is free of charge, unless requests are manifestly unfounded or excessive.

If you are a contact of a business using BiVi CRM, please address your request to that business, as it is the controller of your data.

Right to complain: you may lodge a complaint with the National Centre for Personal Data Protection of the Republic of Moldova (Centrul Național pentru Protecția Datelor cu Caracter Personal, str. Serghei Lazo 48, Chișinău, MD-2004, centru@datepersonale.md, https://datepersonale.md) or, if you are in the European Union, with the supervisory authority of your country of residence.

12. Security

We apply technical and organizational measures appropriate to the risk, including:

  • TLS encryption in transit and encryption at rest;
  • hashed and salted passwords; encrypted storage of channel and integration access tokens;
  • strict per-workspace (multi-tenant) data isolation;
  • role-based access control and the principle of least privilege;
  • webhook signature validation and audit logging of administrative access;
  • regular backups, monitoring and vulnerability management.

Support access to your workspace. Authorised BiVi support personnel may access workspace data solely to resolve support requests, and only with your consent. A support request names the reason and a ticket reference, and you choose how long access lasts; nothing is accessible until you approve it, and you can end an approved access at any time from Settings → Support access. During such a session support cannot send messages to your customers, and cannot delete conversations or contacts. Every request, answer and page opened is logged in full and kept for at least twelve months and no longer than twenty-four. You can view that log yourself, and we email the workspace owner when access is requested, answered and ended. You can also turn off support access requests entirely.

No method of transmission or storage is completely secure, but we work continuously to protect your information.

Personal data breaches: where a breach is likely to result in a risk to the rights and freedoms of individuals, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and we notify affected customers without undue delay so that they may in turn notify their own data subjects.

13. Cookies

We use strictly necessary cookies to keep you signed in and to secure the Service — session and anti-forgery cookies — which do not require consent and cannot be disabled without breaking the Service.

Any analytics or marketing cookies are used only with your prior consent, and that consent can be withdrawn at any time. You can also block or delete cookies through your browser settings.

14. Children

The Service is intended for businesses and is not directed to individuals under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact info@bivicrm.io and we will delete it.

15. Changes

We may update this Policy. Material changes will be notified by email to workspace administrators and by updating the "Last updated" date at least 15 days before they take effect.

16. Contact

S.R.L. PERFORMANCE CRM
IDNO 1026023027360
MD-4233, str. Miciurin, Slobozia, Ștefan Vodă, Republic of Moldova
info@bivicrm.io · +373 68 678 731