European Economic Area & UK Privacy Notice

BizLiveGo GDPR / EEA Privacy Notice

Detailed statutory disclosure for residents of the European Economic Area (EEA), United Kingdom (UK), and Switzerland pursuant to Regulation (EU) 2016/679 (GDPR). Defining our Data Controller capacities, Article 6 legal grounds, Chapter V cross-border transfer safeguards, and full Chapter III Data Subject Rights.

Data Controller: BizLiveGo | DPO: Joshim Biswas | Operational Location: Malda, WB, India - 732206 | Version: 2026.1

1. Controller Identity

Who Controls Your Data (Art. 4(7))

Under the GDPR, BizLiveGo (operated by MD Joshim Biswas, Masimpur, Post-Mosimpur, P.S. Kaliachak, Malda, West Bengal, India - 732206) acts as the Data Controller for personal data collected through your account registration, service subscription, and direct profile usage.

Where users upload third-party client materials, BizLiveGo functions as a Data Processor, processing data solely pursuant to the customer’s lawful directives.

2. Territorial Applicability

Article 3(2) Territorial Scope

This Notice applies strictly to individuals located in the European Union (EU), European Economic Area (EEA), the United Kingdom, and Switzerland when accessing our platform, where:

  • BizLiveGo offers goods, profile services, or templates to individuals in the EEA/UK.
  • Monitoring of visitor behavior takes place through dynamic QR code scans or telemetry.
3. Legal Architecture

Lawful Bases for Processing Under GDPR Article 6

BizLiveGo never processes EEA personal data without an established statutory legal basis:

Contractual Necessity

Article 6(1)(b)

Processing necessary to perform our contract with you:

  • Publishing your live URL
  • Resolving dynamic QR links
  • Generating digital PDF CVs
  • Account authentication

Explicit Consent

Article 6(1)(a)

Freely given, specific, and unbundled affirmative opt-in:

  • Analytics cookies (GA4)
  • Meta Pixel ad attribution
  • Public search indexing
  • Marketing newsletters

Legal Obligation

Article 6(1)(c)

Mandatory statutory compliance frameworks:

  • Preserving tax invoices
  • Statutory accounting audits
  • Responding to court orders
  • Sanction list compliance

Legitimate Interests

Article 6(1)(f)

Balanced against your fundamental rights:

  • DDoS attack mitigation
  • Web Application Firewall rules
  • Preventing platform fraud
  • Securing server clusters
Article 9 Special Category Safeguard

4. Exclusion of Prohibited Identifiers & Special Category Data

BizLiveGo strictly prohibits uploading high-risk personal identifiers and sensitive records under Article 9 of the GDPR:

Strictly Prohibited Identifiers

Our platform never requests, stores, or processes:

  • National identification numbers, passport numbers, or tax registration documents.
  • Unredacted identification card scans, citizen cards, or biometric data files.
  • Raw banking card CVVs, PIN numbers, OTPs, or authentication credentials.

Voluntary Special Profile Fields (Art. 9(2)(a))

Voluntary fields in blood donor registries or matrimonial biodata profiles:

  • Processed strictly upon explicit affirmative consent for public display.
  • Isolated from marketing pixels and commercial advertising networks.
  • Instantly expunged upon user deletion request without residual retention.
5. Data Subject Rights

Your Statutory Rights Under Chapter III of the GDPR

As an EEA or UK resident, you possess comprehensive statutory rights regarding your personal records:

1. Right to Access (Art. 15)

Obtain confirmation of processing and a copy of all personal records, purposes, categories, recipients, and retention periods in an intelligible format.

2. Right to Rectification (Art. 16)

Request immediate correction of inaccurate personal data or completion of incomplete information via self-service dashboards or DPO tickets.

3. Right to Erasure (Art. 17)

Demand the permanent deletion of your data and live profile links ("Right to be Forgotten") where data is no longer necessary or consent is revoked.

4. Restriction of Processing (Art. 18)

Temporarily restrict processing if you contest the accuracy of data, consider processing unlawful, or require records for legal claims.

5. Data Portability (Art. 20)

Receive your personal profile data in a structured, commonly used, machine-readable format (JSON, CSV) or direct transfer to another controller.

6. Right to Object (Art. 21)

Object at any time to processing based on legitimate interests or direct marketing. Upon objection, marketing processing ceases immediately.

7. Rights Related to Automated Decision-Making & Profiling (Art. 22)

BizLiveGo does not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you. All profile verification decisions and terms enforcement involve human oversight.

6. International Transfers

Cross-Border Data Transfers Outside the EEA (Chapter V)

How BizLiveGo ensures adequate protection when routing data to primary databases in India or global edge nodes:

1. Standard Contractual Clauses

Transfers of personal data from the EEA/UK to our primary servers in India or third-party infrastructure providers are governed by European Commission approved Standard Contractual Clauses (SCCs) (Module 1 and Module 2) pursuant to Article 46(2)(c).

2. Supplementary Technical Measures

In accordance with the European Data Protection Board (EDPB) recommendations post-Schrems II, we implement robust supplementary safeguards: TLS 1.3 encryption in transit, AES-256 encryption at rest, and isolated hardware-backed key management (KMS).

3. Derogations for Profile Hosting

Where dynamic profile pages and QR codes are made publicly accessible across global internet nodes, cross-border transmission occurs pursuant to Article 49(1)(b) (contractual necessity) and explicit user directive.

7. Request Timelines

Fulfillment SLA: One Month / 7–15 Days

Under GDPR Article 12(3), we respond to Data Subject Requests without undue delay and at the latest within one calendar month.

  • Expedited Operational SLA: Most access, rectification, and erasure requests are executed within our standard 7 to 15 working days SLA.
  • Authentication: Registered email handshake required prior to releasing personal archives to prevent profile hijacking.
  • Zero Cost: All statutory GDPR requests are fulfilled completely free of charge.
8. Supervisory Escalation

Right to Lodge a Complaint (Art. 77)

If you believe our processing infringes the GDPR, you possess the absolute legal right to lodge a formal complaint with an authorized Supervisory Authority:

  • In the EU Member State of your habitual residence or place of work.
  • In the place of the alleged infringement.
  • UK residents may contact the Information Commissioner's Office (ICO) at ico.org.uk.
Quick Summary

GDPR / EEA Privacy Notice Quick Reference

Consolidated review of European data subject protections, lawful bases, and transfer mechanisms:

Compliance Dimension BizLiveGo Implementation Standard GDPR Legal Reference
Data Controller BizLiveGo (MD Joshim Biswas, Malda, West Bengal, India - 732206). Article 4(7)
Primary Lawful Bases Contract performance (Art. 6(1)(b)), Consent (Art. 6(1)(a)), Legal Obligation (Art. 6(1)(c)). Article 6(1)
Cross-Border Transfer Instrument European Commission approved Standard Contractual Clauses (SCCs) + AES-256. Article 46(2)(c)
Prohibited Identifiers National ID numbers, unredacted passports, and raw card credentials are barred. Data Minimization (Art. 5)
Data Subject Rights Full entitlement to Access, Rectification, Erasure, Restriction, Portability, and Objection. Articles 15–21
Automated Decision-Making Zero automated profiling or algorithmic decisions producing legal effects. Article 22
Response Window Statutory one-month maximum; standard operational completion within 7 to 15 working days. Article 12(3)
Supervisory Recourse Unconditional right to lodge complaints with local EU/EEA DPAs or UK ICO. Article 77

Exercise Your GDPR Rights Today

To submit an Article 15 Subject Access Request, exercise your Right to Erasure, request a copy of our Standard Contractual Clauses, or reach out to our Data Protection Officer, contact our privacy desk.

Data Protection Officer: Joshim Biswas | Location: Masimpur, Kaliachak, Malda, West Bengal, India - 732206