Privacy Policy
BIO-LOGIQ is the data controller for personal data processed through the app and website. We process the minimum data needed to run the service, we tell you how long we keep it, we name the third parties we share it with, and we explain how to exercise your rights under GDPR.
Controller and contacts
Axes AS (organisasjonsnummer 911 726 696), Storgata 121, 2615 Lillehammer, Norway, trading as BIO-LOGIQ, is the data controller for personal data processed through the BIO-LOGIQ app and related services.
For privacy questions: privacy@bio-logiq.com. For data-rights requests, see Page 9.
Personal data we process
We may process:
- Account data: name, email address, language preference.
- Subscription and transaction data: plan, billing dates, payment status (we do not store full payment-card numbers).
- Technical and usage data: device type, browser, app interactions, session start and end events, preset selection, errors.
- Support communications.
- Referral, affiliate, or partner-access data.
- In future product phases, self-reported wellness preferences (for example, an onboarding goal answer such as "I want to feel calmer" that would be used to tailor recommendation copy). BIO-LOGIQ does not collect this data in the current product phase.
- In future product phases, health-related data such as breathing metrics, mobility tracking, or recovery information — see the separate Health Data Processing Consent.
Why and on what basis we process
We process personal data to:
- Create and manage your account (contract).
- Provide the Services and deliver content (contract).
- Process subscriptions and payments (contract, legal obligation for accounting under bokforingsloven).
- If BIO-LOGIQ later introduces an onboarding-goal feature, we would personalize recommendation copy from your onboarding answers on the basis of our legitimate interest in making BIO-LOGIQ relevant to you, supported by an internal Legitimate Interests Assessment kept on file from the launch of that feature. This basis would apply only to tailoring in-app recommendation copy. Any later use for marketing, advertising, pricing, or analytics would move to explicit consent. The onboarding-goal feature is not active in the current product phase.
- Provide customer support (contract, legitimate interest).
- Detect and prevent fraud, abuse, and security incidents (legitimate interest, legal obligation).
- Manage referral and partner programs (contract, legitimate interest).
- Improve the platform (legitimate interest).
- Send service communications relating to your subscription (contract).
- Send marketing communications only where you have given prior consent.
Special-category and health data
Some BIO-LOGIQ features may, in future product phases, process health-related data such as breathing metrics, breath-hold times, mobility tracking, recovery information, or sensor-derived data. Such data is treated as special-category personal data under GDPR Article 9. We will only process it on the basis of your explicit, unbundled consent, recorded through a separate opt-in (never pre-ticked). Where required, we will conduct a Data Protection Impact Assessment (GDPR Art 35) before launching such features and publish a summary at /legal/dpia.
Current product phase: BIO-LOGIQ does not yet store individual biometric measurements on our servers. Session-level usage data (such as "session started" and "session completed") is processed without identifying biometric content. Your reminders are stored only on your device and never sent to our servers in the current phase, as defined by our Reminders Phase 0a security rules.
Recommendation copy and automated decision-making
BIO-LOGIQ does not currently make any automated decisions that produce legal or similarly significant effects (no profiling, no entitlement decisions, no pricing, no advertising).
If BIO-LOGIQ later introduces an onboarding-goal feature, your goal answer would be used to tailor recommendation copy inside the app. The processing would have no legal or significant effect on you, and the lawful basis would be our legitimate interest in making BIO-LOGIQ relevant to you, balanced against your interests in a Legitimate Interests Assessment kept on file from the launch of that feature. You would be able to clear your onboarding answer at any time from your account. Any later use for marketing, analytics, or pricing would move to explicit consent.
Marketing communications
We send marketing communications only with your prior consent. You can withdraw consent at any time using the unsubscribe link in every marketing email or via your account settings. Service communications about your subscription (such as renewal reminders, invoices, and security notices) are not marketing and are sent on the basis of our contract with you.
Who we share data with
We share personal data only with trusted service providers and partners under appropriate safeguards. Our current sub-processors are listed and kept up to date at /legal/sub-processors and include (non-exhaustive):
- Memberstack (identity and billing source of truth).
- Vercel (hosting and edge delivery).
- Cloudflare (DNS, storage R2, security).
- Sentry (error and performance telemetry).
- Resend (transactional email, including affiliate communications).
- Tapfiliate (affiliate attribution; integrated when the affiliate program launches in code).
- A future course platform for SSO-linked courses (planned).
- A future push notification provider for reminders (planned).
We will give reasonable advance notice of additions where consent is the lawful basis. Health-related data will not be shared with insurers, employers, or partners for independent marketing without your explicit consent.
International data transfers
Some of our sub-processors are located outside the EEA. Where personal data is transferred outside the EEA, we rely on European Commission adequacy decisions, on Standard Contractual Clauses with supplementary measures, or on another transfer mechanism recognised under GDPR Chapter V. You can request a copy of the relevant safeguards by emailing privacy@bio-logiq.com.
Retention
We keep personal data only for as long as necessary. Our retention defaults are:
- Account data: until you delete your account, then deleted within 30 days, subject to legal retention obligations.
- Subscription and transaction data: 5 years after the end of the fiscal year in which the transaction occurred (bokforingsloven).
- Support communications: 24 months from the last interaction.
- Technical and analytics data: at most 14 months in aggregated or pseudonymised form.
- Sentry error payloads: 90 days, with no user content beyond a generic error reference (per Security Invariants Addendum D).
- Reminders: device-local only in the current phase, never on our servers.
- Future health-related data: kept only while consent is in force; deleted within 30 days of consent withdrawal or account deletion, subject to legal retention obligations.
Your rights
You may at any time request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. To make a request, see Page 9. You may also complain to Datatilsynet, the Norwegian Data Protection Authority — Postboks 458 Sentrum, 0105 Oslo — datatilsynet.no — postkasse@datatilsynet.no.
Security and breach notification
We apply organisational and technical measures appropriate to the risk of processing. In the event of a personal data breach that may pose a risk to your rights, we will notify Datatilsynet within 72 hours and notify affected users without undue delay where required by law.
Changes to this Policy
We will publish updates to this Policy at /legal/privacy and indicate the version and date at the top of the page. Material changes that affect your rights will be notified to you by email or in-app where required.