Privacy Policy
Effective date: 1 January 2026
This Privacy Policy explains how BIIPP (“BIIPP”, “we”, “us”) collects, uses and protects information when you use the BIIPP service (the “Service”). We’ve written it to be readable. By using the Service you agree to this Policy.
1. Information we collect
- Account information — your name, email address, organization name and password (stored only as a strong one-way hash).
- Content you add — the items you track, including names, issuers, notes, due dates and reference numbers. Sensitive reference numbers are encrypted at rest.
- Usage and log data — basic technical information such as IP address and timestamps, and an audit record of logins and changes to your organization’s records.
- Cookies — a small number of strictly necessary cookies used to keep you securely signed in.
2. How we use information
We use the information to:
- provide, secure and operate the Service;
- send the reminder and notification emails you configure, and essential account emails such as verification and password reset;
- maintain an audit trail and protect against fraud, abuse and unauthorised access;
- respond to your requests and support enquiries; and
- comply with legal obligations.
We do not sell your personal information, and we do not use your Customer Data for advertising.
3. Organization isolation
BIIPP is multi-tenant and strictly isolated. Your organization’s data is accessible only to verified members of your organization, according to their role. We do not disclose one organization’s data to another.
4. Sharing and sub-processors
We share information only with service providers who help us run the Service, under obligations of confidentiality and only as needed. This includes an email delivery provider used to send the Service’s emails. We may also disclose information where required by law, to enforce our terms, or to protect the rights, safety and security of BIIPP, our users, or the public.
5. Security
We apply reasonable technical and organisational measures to protect information, including transport encryption, one-way password hashing, encryption of sensitive reference fields at rest, role-based access controls, rate limiting and audit logging. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
6. Data retention
We retain Customer Data for as long as your organization’s account is active. An Owner can export their data or permanently delete the organization and its associated data from within the Service. After deletion, data is removed from our active systems; residual copies may persist briefly in routine backups before being overwritten.
7. Your rights
Depending on where you live, you may have rights to access, correct, export or delete your personal information, or to object to or restrict certain processing. You can exercise many of these directly in the app (profile settings, data export, and organization deletion) or by contacting us. We will respond consistent with applicable law.
8. International transfers
We may process and store information in countries other than your own. Where we do, we take steps to ensure an appropriate level of protection consistent with applicable law.
9. Children
The Service is not directed to children and is intended for use by organizations and their adult members.
10. Changes to this Policy
We may update this Policy from time to time. The updated version is indicated by a revised effective date and becomes effective once posted. Significant changes will be communicated through the Service where appropriate.
11. Contact
For privacy questions or requests, contact privacy@biipp.com.