Privacy Policy

Last updated: 29 July 2026

Biz Lab AI ("we", "us") operates the labbizai.com platform: a service that helps salons, clinics and other small businesses talk to their own customers — appointment notifications, campaigns and live chat across WhatsApp, SMS and other channels, with optional AI assistance. This policy explains what personal data we handle, on what legal basis, who else is involved, how long we keep it and how to have it deleted.

1. Two roles: controller and processor

OUR CUSTOMER is the business that registers an account. For its own account data we act as the CONTROLLER. THE CUSTOMER'S CLIENTS are the people that business messages through us. For their data the business is the controller and we are only its PROCESSOR: we act on the business's documented instructions, we never message anyone on our own initiative, and we never use one business's data for another business or for our own marketing.

2. What we collect

Account data: business name, e-mail, phone, address, working hours, plan and payment status, and the actions taken inside the dashboard.

Client base: names, phone numbers, e-mails, languages, appointment history and other fields the business uploads or syncs from its own systems (for example Altegio or iCount).

Message content: the texts, images and delivery statuses of messages sent and received through the connected channels, so the business can see its own correspondence.

Technical data: server logs, IP addresses, connection identifiers and error reports needed to run and secure the service. We do not use advertising trackers.

3. Why and on what legal basis

Performance of a contract (GDPR Art. 6(1)(b)): running the account, delivering the messages the business asks us to deliver, showing its history and reports.

Legitimate interests (Art. 6(1)(f)): keeping the platform available, secure and free of abuse; anti-spam protections for connected numbers; product diagnostics.

Legal obligation (Art. 6(1)(c)): accounting, tax and lawful requests.

Consent, where the law requires it: the business is responsible for obtaining the consent of its own clients before messaging them, and we require it in our Terms of Service.

4. WhatsApp Business Platform and other channels

When a business connects a WhatsApp number we store its account identifiers and access token (encrypted at rest) and exchange messages with Meta on that business's behalf; Meta processes those messages under its own terms and acts as a sub-processor. The same applies to every other channel a business connects — SMS aggregators, telephony, CRM systems: each connection is made by the business itself and can be disconnected at any moment, which deletes the stored credentials immediately.

5. AI processing

AI features are optional and are switched on by the business. When used, the relevant text — a message, a template, a document from the business's own knowledge base — is sent to our AI provider for processing and the result is returned to the dashboard. Our AI providers do not train their public models on this content. No automated decision-making with legal effects is performed.

6. Sub-processors

We share data only with the providers that make the service work, each strictly for its part:

· Hosting and infrastructure — servers in European data centres;

· Messaging channels the business connected — Meta Platforms (WhatsApp Business Platform), SMS aggregators, telephony providers;

· AI providers — for the optional AI features;

· E-mail delivery and error monitoring;

· A payment processor, when the account is paid. We publish material changes to this list before they take effect. We never sell data and never share it for advertising.

7. International transfers

Our servers are in the EU. Some sub-processors (for example Meta and the AI providers) may process data outside the EU; such transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision. Israel, where our business is established, is recognised by the European Commission as providing an adequate level of protection.

8. Retention

Account data — while the account is active and up to 90 days after it closes;

Client base and correspondence — while the business keeps them; deleted with the account, or earlier on the business's instruction;

Delivery journals — up to 24 months, so the business can investigate its own campaigns;

Technical logs — up to 90 days; accounting records — as tax law requires.

9. Security

Traffic is encrypted in transit (TLS); access tokens, keys and credentials are encrypted at rest; access is limited to the people who operate the platform and is logged; backups are encrypted; every workspace is isolated from every other at the data level. If a breach affects personal data we notify the affected businesses without undue delay and the competent authority within 72 hours where the law requires it.

10. Your rights and data deletion

You may request access, correction, erasure, restriction, portability, or object to processing. A business can export or delete its data from the dashboard, disconnect any integration (credentials are deleted at once), or ask us to delete the whole account by writing to privacy@labbizai.com — deletion is completed within 30 days. A client of a business may ask that business directly, or write to us at the same address: we pass the request to the business and confirm the outcome. Complaints may also be addressed to your local supervisory authority, or in Israel to the Privacy Protection Authority.

11. Unsubscribing from messages

Every marketing message we deliver carries an unsubscribe instruction. A reply asking to stop removes that person from the business's campaign audience immediately and permanently on our side, regardless of what the business does next.

12. Data processing agreement

For the client data a business entrusts to us, this policy together with our Terms of Service forms the data processing agreement required by GDPR Art. 28: we process only on the business's instructions, keep our staff under confidentiality, apply the security measures described above, engage sub-processors under equivalent obligations, assist with data-subject requests, and delete or return the data when the service ends. A separate signed DPA is available on request at privacy@labbizai.com.

13. Children

The service is meant for businesses. We do not knowingly collect data from children under 16 on our own initiative.

14. Changes and contact

If this policy changes materially we will say so on this page and, for account-affecting changes, by e-mail. Questions, requests and complaints: privacy@labbizai.com.