Privacy policy
1. Scope of this policy
This privacy policy (the "Policy") explains how personal data is collected, used, stored, shared and otherwise processed when you visit https://bi-enterprises.com and its language versions (the "Website"), when you contact us, when you interact with our advertising on third-party platforms, and when you or your organisation become our client.
This Policy is the information we provide to you under Articles 13 and 14 of the UK General Data Protection Regulation ("UK GDPR") and of Regulation (EU) 2016/679 ("EU GDPR", together the "GDPR"), the UK Data Protection Act 2018, the UK Privacy and Electronic Communications Regulations 2003 ("PECR"), Directive 2002/58/EC ("ePrivacy Directive") and, for visitors in Greece, Greek Law 4624/2019 and Law 3471/2006.
Simply browsing the Website does not require you to give us any personal data. However, some information is collected automatically (section 3.1) and, if you consent, through analytics and advertising technologies (section 3.5 and section 5).
This Policy applies only to the Website. The Website links to client projects and other third-party websites. We are not responsible for their content or their privacy practices, and we recommend that you read their own policies.
2. Controller and contact details
The Website is operated by Bogdan Group LTD, a private company limited by shares registered in England and Wales, trading as BI-Enterprises ("BI-Enterprises", "we", "us", "our"). We are the controller of the personal data described in this Policy, except where section 3.7 states that we act as a processor for our clients. Our company details are set out in the legal notice.
For any question about this Policy or to exercise your rights, email info@bi-enterprises.com or use the contact form, writing "Data protection" in your message. We have not appointed a Data Protection Officer because we are not legally required to do so; requests are handled directly by the management of the company.
3. What personal data we collect
3.1 Data collected automatically when you visit the Website
Whenever you visit the Website, our hosting provider automatically records certain technical information in its server logs, which may identify you directly or indirectly:
- your IP address;
- the type and version of your browser and operating system, and your device type;
- the date and time of access and the pages requested;
- the referring page (the page you came from);
- HTTP status codes and the amount of data transferred.
These logs are needed to deliver the Website, keep it secure and investigate faults or attacks. They are not used to build profiles of individual visitors.
3.2 Data you give us through the contact form
- full name and email address (required);
- telephone number and company or website (optional);
- the services you are interested in and your indicative budget (optional);
- the content of your message (free text);
- confirmation that you have read this Policy;
- technical data recorded with the submission: date and time, language version used and IP address (to protect the form against spam and abuse).
3.3 Data from email, telephone and social media communications
When you contact us by email, telephone, WhatsApp/Viber, or through our accounts on social networks such as Instagram, Facebook or LinkedIn, we process your contact details, the content of the communication and any files you send, only as far as needed to handle your request. The processing carried out by each platform itself is governed by that platform's own terms and policies.
3.4 Data of clients and prospective clients
If you or your organisation request a proposal or become our client, we also process: the names, roles and business contact details of your representatives; billing details (company name, registered address, VAT or tax number, invoicing email); contract and project information; payment records; and access credentials or account permissions that you grant us to your platforms (for example hosting, Shopify, Google Ads or Meta Business accounts) for the performance of the work.
We do not store payment card details. Payments are made by bank transfer or through the payment provider you choose, under its own terms.
3.5 Data collected through analytics and advertising technologies (only with your consent)
If you accept the relevant categories in our cookie banner, the Website loads technologies provided by Google, Meta, TikTok, LinkedIn and Microsoft (section 5). Through cookies, pixels, tags, local storage and similar technologies, these may collect:
- online identifiers: cookie identifiers, device and advertising identifiers, and the IP address (which Google Analytics 4 does not log or store);
- click identifiers added to links in our ads (for example gclid, gbraid, wbraid, fbclid, ttclid, li_fat_id, msclkid);
- browsing activity on the Website: pages viewed, time on page, scrolling, clicks, the source of the visit (for example which ad or campaign), and events such as starting or submitting the contact form;
- approximate location derived from the IP address (country or city level), language, browser, operating system and screen size;
- for Microsoft Clarity only: anonymised mouse movements, clicks and scrolling used to produce heatmaps and session replays. Text you type into forms is masked and is never recorded.
Where you have consented to marketing and you submit the contact form, we may also send to Google, Meta, TikTok or LinkedIn a hashed (SHA-256, irreversible) version of your email address and telephone number, so that the platform can match the enquiry to an ad interaction ("enhanced conversions", "Conversions API", "Events API"). The platforms use the hash only for matching and for measurement under their terms.
3.6 Data we receive from third parties
- Advertising platforms: aggregated and statistical reports on the performance of our campaigns. These reports do not normally identify individuals.
- Lead forms on social platforms: if you fill in a lead form within an ad on Facebook, Instagram, LinkedIn or TikTok, the platform passes us the details you entered (for example name, email, telephone, company).
- Referrals and public sources: business contact details from a person who recommends you to us, or from your company's website or public business registers, when we prepare for a meeting you requested.
3.7 Data we process on behalf of our clients
When we build, host, maintain or manage advertising for our clients' websites and online stores, we process the personal data of their customers and visitors (for example orders, newsletter subscribers, pixel data or customer lists) as a processor, only on our clients' documented instructions and under a data processing agreement in accordance with Article 28 GDPR. In those cases the client is the controller, and its own privacy policy applies. Requests relating to that data should be addressed to the client; if they reach us, we will forward them.
3.8 Special categories of data
We do not ask for, and we ask you not to send us, special categories of personal data (such as information about health, religion, political opinions or sexual orientation) or data about criminal convictions. If you include such data in a message, we will use it only to the extent necessary to reply and will delete it when no longer needed.
4. Purposes and legal bases
We process personal data only where there is a legal basis and only for specific, explicit and legitimate purposes:
a) Performance of a contract or steps at your request before entering into a contract [Art. 6(1)(b) GDPR], in particular to: reply to your enquiry and prepare a proposal; plan, deliver and support the services you ordered; manage access to your accounts and platforms; communicate about the project; and invoice and collect payment.
b) Compliance with legal obligations [Art. 6(1)(c) GDPR], in particular to: keep accounting and tax records; respond to lawful requests from courts, tax and supervisory authorities; and keep records of consents and of requests to exercise data protection rights.
c) Our legitimate interests [Art. 6(1)(f) GDPR], provided your interests and fundamental rights do not override them, in particular to: keep the Website, our systems and the contact form secure and prevent fraud, spam and abuse (server logs, anti-spam checks); reply to communications that are not linked to a contract; establish, exercise or defend legal claims; manage our business relationship with the representatives of our corporate clients and suppliers; and send business-to-business information about similar services to existing clients, where the law allows and with the option to object in every message.
d) Your consent [Art. 6(1)(a) GDPR, Regulation 6 PECR, Art. 5(3) ePrivacy Directive and Art. 4(5) Law 3471/2006], in particular for:
- storing or reading non-essential cookies and similar technologies on your device;
- website analytics through Google Analytics 4 and Microsoft Clarity;
- conversion tracking and measurement of the effectiveness of our ads (Google Ads, Meta, TikTok, LinkedIn, Microsoft Advertising);
- remarketing, meaning showing our ads on other websites and platforms to people who visited the Website, and creating lookalike or similar audiences;
- sending hashed contact details for enhanced conversions and Conversions or Events API matching;
- uploading hashed contact lists to advertising platforms for matching (Customer Match, Custom Audiences, Matched Audiences), where you have agreed to receive marketing from us;
- sending newsletters or promotional emails where prior consent is required.
You can withdraw your consent at any time, as easily as you gave it, through the cookie settings link at the bottom of every page or the unsubscribe link in our emails. Withdrawal does not affect the lawfulness of processing before it. When you withdraw consent for analytics or marketing, the Website deletes the related first-party cookies from your browser and stops loading those technologies.
e) Profiling and automated decisions. Advertising technologies analyse browsing behaviour to measure ad performance and, with your consent, to group visitors into audiences for showing relevant ads. This is profiling within the meaning of Article 4(4) GDPR and is carried out only with your consent. You can object to profiling for direct marketing at any time. We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR).
5. Analytics and advertising technologies in detail
None of the technologies in this section is loaded until you give consent in the cookie banner. We use Google Consent Mode v2 in its basic form: all Google consent signals (analytics_storage, ad_storage, ad_user_data, ad_personalization) are set to "denied" by default, and Google tags are not loaded at all unless you consent. Ad data redaction is enabled. A full list of cookies, their duration and their providers is in our cookie policy.
5.1 Google
Google Analytics 4 (consent category: Analytics) helps us understand how visitors find and use the Website. Google Analytics 4 does not log or store IP addresses, and we have disabled Google signals and ads personalisation in Analytics. Data retention in Analytics is set to 14 months. Google acts as our processor under the Google Ads Data Processing Terms.
Google Ads (consent category: Marketing) measures which ads lead to visits and enquiries (conversion tracking, including enhanced conversions) and allows remarketing to past visitors. For these purposes Google acts as an independent controller under the Google Ads Controller-Controller Data Protection Terms. You can control ad personalisation at My Ad Center. Information on how Google uses data from sites that use its services: policies.google.com/technologies/partner-sites.
Google Tag Manager loads and manages the above tags. It does not itself set cookies to profile you.
5.2 Meta (Facebook and Instagram)
The Meta Pixel and the Conversions API (consent category: Marketing) record visits and events on the Website (for example a page view or a contact form submission) and send them to Meta so we can measure our ads on Facebook and Instagram, show ads to past visitors and build similar audiences.
For the collection and transmission of this data to Meta, we and Meta Platforms Ireland Limited are joint controllers under Article 26 GDPR, as set out in the Meta Controller Addendum (facebook.com/legal/controller_addendum). Meta is responsible for providing you with information about its own processing and for handling your rights in relation to the data after transmission, and is the sole controller of that further processing. You can manage your ad preferences in your Meta account and read Meta's privacy policy at facebook.com/privacy/policy.
5.3 TikTok
The TikTok Pixel and Events API (consent category: Marketing) measure the results of our ads on TikTok and allow remarketing. For collection and transmission, we and TikTok (TikTok Technology Limited in the EEA, TikTok Information Technologies UK Limited in the UK) are joint controllers under TikTok's business terms; TikTok is solely responsible for its further processing. TikTok's privacy policy: tiktok.com/legal/privacy-policy-eea.
5.4 LinkedIn
The LinkedIn Insight Tag (consent category: Marketing) measures conversions from our LinkedIn campaigns, enables retargeting and provides us with aggregated, non-identifying reports on the professional characteristics of visitors (for example industry or job function). Under LinkedIn's Joint Controller Addendum, we and LinkedIn Ireland Unlimited Company are joint controllers for collection and transmission. LinkedIn's privacy policy: linkedin.com/legal/privacy-policy.
5.5 Microsoft
Microsoft Advertising Universal Event Tracking (UET) (consent category: Marketing) measures the results of our ads on Bing and the Microsoft network. Microsoft Clarity (consent category: Analytics) creates heatmaps and anonymised session recordings so we can find usability problems; form input is masked. Microsoft's privacy statement: privacy.microsoft.com.
5.6 Changes to the tools we use
We may add, replace or stop using a tool within the categories described above. Before any new provider is activated, we update this Policy and the cookie policy. If a change goes beyond what you consented to, we will ask for your consent again.
6. Recipients of personal data
We do not sell or rent your personal data. We disclose it only as far as necessary for the purposes in this Policy and on the corresponding legal basis, to the following recipients:
| Provider | Entity (for EEA/UK users) | Role | What it does for us | Transfer safeguard |
|---|---|---|---|---|
| Hostinger | Hostinger International Ltd (Cyprus) | Processor | Website hosting, server logs, storage of enquiries (EU data centres) | Data stays in the EEA |
| Zoho Mail | Zoho Corporation B.V. (Netherlands) | Processor | Business email (EU data centres) | Data stays in the EEA |
| Google Analytics 4, Google Tag Manager | Google Ireland Limited | Processor | Website statistics and tag management | EU–U.S. Data Privacy Framework, UK Extension, SCCs |
| Google Ads (incl. remarketing, enhanced conversions) | Google Ireland Limited | Independent controller | Conversion measurement and advertising | EU–U.S. Data Privacy Framework, UK Extension, SCCs |
| Meta Pixel, Conversions API, Custom Audiences | Meta Platforms Ireland Limited | Joint controller for collection and transmission; independent controller afterwards | Advertising on Facebook and Instagram, conversion measurement | EU–U.S. Data Privacy Framework, SCCs |
| TikTok Pixel, Events API | TikTok Technology Limited (Ireland) and TikTok Information Technologies UK Limited | Joint controller for collection and transmission; independent controller afterwards | Advertising on TikTok, conversion measurement | SCCs and UK IDTA |
| LinkedIn Insight Tag, Matched Audiences | LinkedIn Ireland Unlimited Company | Joint controller for collection and transmission; independent controller afterwards | B2B advertising, conversion measurement, aggregated audience insights | EU–U.S. Data Privacy Framework, SCCs |
| Microsoft Advertising (UET), Microsoft Clarity | Microsoft Ireland Operations Limited | Independent controller (Advertising); processor (Clarity) | Advertising on Bing, usage heatmaps and session analytics | EU–U.S. Data Privacy Framework, SCCs |
- our accountants, tax advisers, lawyers and other professional advisers, who are bound by professional secrecy, where needed for their services or for our compliance;
- freelancers and subcontractors who work with us on a specific project, only to the extent their role requires and under confidentiality and data processing obligations;
- public, tax, judicial, supervisory or other competent authorities, where disclosure is required by law or by a binding order;
- potential or actual buyers, investors and their advisers in the event of a sale, merger, restructuring or similar transaction, under appropriate confidentiality safeguards. If such a transaction changes the controller, we will inform you as the GDPR requires.
Processors act only on our documented instructions and are bound by the contractual obligations of Article 28 GDPR. Where a provider acts as an independent or joint controller, as shown in the table, its own privacy policy also applies.
7. International transfers
We are established in the United Kingdom. The United Kingdom and the European Union each recognise the other as providing an adequate level of data protection, so data can flow between them.
Some providers in section 6, in particular Google, Meta, TikTok, LinkedIn and Microsoft, or their sub-processors, may process data in countries outside the UK and the European Economic Area, including the United States. Every such transfer takes place in accordance with Chapter V of the GDPR, on the basis of:
- an adequacy decision (Article 45 GDPR), including the EU–U.S. Data Privacy Framework and its UK Extension for organisations certified under it;
- the European Commission's Standard Contractual Clauses (Article 46(2)(c) GDPR), together with the UK International Data Transfer Addendum where UK data is involved; or
- another valid mechanism under Articles 46 to 49 GDPR.
Where needed, supplementary technical and organisational measures are applied. You can ask us for more information about these safeguards and for a copy of them where the law provides.
8. Cookies and similar technologies
The Website uses strictly necessary storage without consent, and analytics and marketing technologies only with your consent. Full details of each cookie, its provider, purpose and duration, and how to change your choice, are in our cookie policy.
9. How long we keep personal data
We keep personal data only for as long as necessary for the purpose for which it was collected and then for as long as the law requires or as needed for the establishment, exercise or defence of legal claims. In particular:
- Enquiries that do not lead to a project: deleted within 12 months of our last contact.
- Client, contract and invoicing records: six years after the end of the financial year to which they relate, as UK law requires, or longer where another applicable law requires it.
- Access credentials to client platforms: revoked or deleted at the end of the project or at the client's request.
- Server logs: held by our hosting provider for a limited period, normally not longer than 30 days, unless needed to investigate a security incident.
- Google Analytics 4 data: 14 months, after which event-level data is deleted automatically.
- Microsoft Clarity recordings: 30 days; heatmap aggregates up to 13 months.
- Cookies and similar technologies: for the durations stated in the cookie policy, or until you delete them or withdraw consent.
- Your cookie choice: stored in your browser for 12 months, after which we ask you again.
- Data held by advertising platforms as independent or joint controllers: according to their own retention policies.
- Hashed contact lists uploaded for matching: used only for matching and deleted by the platform after matching under its terms; we remove you from such lists if you withdraw consent or object.
- Marketing email subscriptions: until you unsubscribe or object, after which we keep only the minimum needed to respect your choice (a suppression list).
- Records of data protection requests: for as long as needed to demonstrate compliance, normally three years.
After these periods, data is securely deleted or anonymised. You may ask for deletion earlier under Article 17 GDPR, subject to the legal exceptions.
10. Security of personal data
We apply appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, in particular: HTTPS encryption across the Website; storage of enquiries in a location that cannot be reached from the web; access restricted to people who need it; individual accounts with strong passwords and two-factor authentication where available; and regular updates and backups.
No transmission or storage over the internet is entirely secure, and we cannot guarantee absolute security. If you believe that your interaction with us is no longer secure, please contact us immediately. If a personal data breach is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required, you.
11. Children
The Website and our services are intended for businesses and professionals and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we have done so, please contact us and we will delete it promptly.
12. Your rights
Under the GDPR you have, as applicable, the right to:
- access your personal data and receive a copy (Art. 15);
- rectification of inaccurate or incomplete data (Art. 16);
- erasure ("right to be forgotten") (Art. 17);
- restriction of processing (Art. 18);
- data portability for data processed by automated means on the basis of consent or contract (Art. 20);
- object to processing based on legitimate interests, and at any time to processing for direct marketing, including related profiling (Art. 21);
- withdraw consent at any time, without affecting earlier processing (Art. 7(3)).
To exercise your rights, email info@bi-enterprises.com or use the contact form. We may ask for information to confirm your identity. We reply within one month of receipt. Where a request is complex or we receive many requests, this period may be extended by up to two further months, and we will tell you why within the first month. Requests are free of charge unless manifestly unfounded or excessive.
For data that advertising platforms process as joint or independent controllers, you can also exercise your rights directly with them. You can limit interest-based advertising through Google My Ad Center, your Facebook and Instagram ad preferences, your TikTok and LinkedIn ad settings, and youronlinechoices.eu.
You have the right to lodge a complaint with a supervisory authority: in the UK, the Information Commissioner's Office (ico.org.uk, 0303 123 1113); in Greece, the Hellenic Data Protection Authority (Kifisias 1-3, 115 23 Athens, dpa.gr); or the authority of the EU country where you live or work. We would appreciate the chance to deal with your concern first.
13. Changes to this Policy
We may update this Policy when our services, the technologies we use or the law change. The current version is always published here with its date. If we make material changes, in particular adding new purposes or advertising providers, we will highlight them on the Website and, where your consent is needed, ask for it again through the cookie banner.