Privacy Policy
Last updated: 10 October 2026
Businessium processes personal data under the EU General Data Protection Regulation (GDPR) and, for users in Türkiye, the KVKK. Below we explain what we process, why, and for how long.
What we process
- Social-ID number — to recognise your account. We do not store your name, e-mail address or phone number.
- Your projects — project names, the text of the nine canvas boxes, the last AI result and when it was produced.
- Daily AI usage — how many scorings you requested on each UTC day (for the free daily limit).
- Reports you send about an AI answer — the reason and your optional note.
- Technical data — the essential cookies listed below. No advertising cookies. On the website, aggregate visit and speed measurement is loaded only if you allow it in the cookie banner.
AI scoring (Anthropic)
Only when you tap “Score my canvas”, the text of your nine boxes is sent to Anthropic PBC (USA), the provider of the Claude AI model, to produce the scores. Your Social-ID number and name are not sent.
Anthropic processes this text as our service provider under its commercial terms (https://www.anthropic.com/legal/commercial-terms). This is a transfer of data to the United States.
Do not write personal data of other people or secrets you do not want to share into the canvas.
Cookies and device storage
- sid_app_session — keeps you signed in (Social-ID). 30 days; deleted when you sign out or delete your account.
- bm_yas16 — records that you confirmed you are 16 or older. 1 year; deleted on sign-out and account deletion.
- sid_oauth_state — single-use security value during sign-in. 10 minutes.
- locale — your chosen language, if you change it. 1 year.
Purposes and legal bases
We process your personal data only for the purposes below, each on the legal basis stated:
- Creating your account and signing you in with SocialID — performance of a contract (GDPR Art. 6(1)(b))
- Cookie-free, aggregate visitor and speed measurement (web only) — loaded only if you allow it; you can switch it off via "Cookie preferences" at the bottom of the page — your consent (GDPR Art. 6(1)(a)) — you can withdraw it at any time
- Storing your projects and canvas texts in your account — performance of a contract (GDPR Art. 6(1)(b))
- Producing AI scores when you request them (sent to Anthropic) — performance of a contract (GDPR Art. 6(1)(b))
- Reviewing reports about AI answers — legitimate interests (GDPR Art. 6(1)(f))
- Where processing is based on consent, you can withdraw it at any time; withdrawal does not affect processing carried out before it.
Whether providing data is required (GDPR Art. 13(2)(e)): You are not legally obliged to provide personal data. The data requested to open an account and use features that require sign-in is necessary to enter into and perform the contract; if you do not provide it, you simply cannot use those features. Technical data sent by your browser or device when you view pages (e.g. your IP address) is necessary to deliver the service technically.
How long we keep your data
Your account and content are kept for as long as your account is open; they are not deleted automatically after a fixed number of days. If you delete your SocialID account, your data here is deleted when SocialID sends its deletion signal. When you delete your account in the app, the following are deleted immediately and permanently: your projects, canvas texts, AI results, daily usage counts and AI-answer reports
Technical logs and automatic backups kept by our hosting and database providers are retained for a limited period set by each provider's own retention cycle and are then deleted automatically. These copies are not used to provide the service.
International transfers
Our hosting provider, Vercel Inc. (United States), may process technical data such as your IP address when delivering the service. Where data is transferred outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses (GDPR Art. 46(2)(c)) contained in the provider's data processing addendum: vercel.com/legal/dpa The providers below (all headquartered in the United States) also receive limited data when the relevant feature is used; for each, our basis for transfers outside the EEA is the European Commission's Standard Contractual Clauses in the provider's published data processing addendum (GDPR Art. 46(2)(c)):
- Vercel Web Analytics and Speed Insights (Vercel Inc., United States) — visitor and page-speed measurement, web only: technical data such as the page visited, referring address, browser/device type, country and page load times is collected without setting cookies and turned into aggregate statistics. The legal basis is your consent (GDPR Art. 6(1)(a); ePrivacy Art. 5(3)): the tool is loaded only if you allow it in the banner at the bottom of the page, and you can withdraw consent at any time via the "Cookie preferences" link in the same place. The data may be transferred to the United States; the transfer mechanism is the European Commission's Standard Contractual Clauses in the provider's data processing addendum (GDPR Art. 46(2)(c)). vercel.com/legal/dpa
- Neon — database hosting (data is kept in an EU region; the provider is headquartered in the United States). Where access from outside the EEA may occur, the provider's data processing addendum (DPA) and Standard Contractual Clauses apply.
- Upstash — request rate limiting (abuse prevention): your IP address is held briefly as a counter key and expires automatically. upstash.com/static/trust/dpa.pdf
- Resend — report/notification e-mail: target type and ID, reason and note (without the reporter's identity) when forwarded to the operator by e-mail. The data is transferred to the United States; the transfer mechanism is the European Commission's Standard Contractual Clauses in the provider's data processing addendum (GDPR Art. 46(2)(c)). resend.com/legal/dpa
KVKK Art. 9 requires an adequacy decision or appropriate safeguards for transfers abroad; the standard contract announced by the Turkish Authority and the notification to the Authority fall within it. The hosting provider's (Vercel Inc., United States) published data processing addendum contains the EU standard contractual clauses (GDPR Art. 46(2)(c)); whether those clauses satisfy KVKK Art. 9 (the Authority's standard contract and notification duty) is subject to legal review. For users in the EU the basis is GDPR Art. 46.
SocialID — a separate controller
Sign-in is provided by SocialID. SocialID's controller is SOSYAL TURİZM BİLİŞİM REKLAM TEKSTİL SANAYİ VE TİCARET LİMİTED ŞİRKETİ, a separate, independent controller from Businessium, established in Türkiye. Your SocialID account data such as e-mail, password and phone number is processed under SocialID's responsibility; for its infrastructure providers and the database region, see SocialID's privacy policy: www.socialid.me/gizlilik. Businessium receives only your SocialID number and display name from SocialID.
If you choose "Sign in with Apple" or "Sign in with Google" in the mobile app, Apple or Google verifies your identity under their own privacy policies; they are separate controllers. Your device passes the verification code or identity token it receives from Apple or Google to SocialID solely to sign you in; we never see the password of those accounts.
SocialID keeps a record of which platforms you have signed in to (including Businessium) until you delete your SocialID account; deleting your account inside Businessium does not remove this record — you can delete it from SocialID's account deletion page: www.socialid.me/hesap/sil.
Even if you delete your SocialID account, SocialID keeps your identity and sign-in records (name, e-mail, phone, platform memberships, sign-in dates and IP addresses) in an encrypted, offline archive for 5 years for legal claims in case of fraud or crime (GDPR Art. 17(3)(e), Art. 6(1)(f)); this archive is accessed only upon a legal request or an order from an authority. Recent sign-ins are shown in the SocialID panel for 90 days.
Data stored on your device
The app stores the following only on your device; it is not sent to our servers:
- While signed out, your canvas is stored only in this browser's local storage (key “businessium:kanvas”); it is never sent to our server.
- Display preferences (theme, text size, accent colour, language) are stored in local storage.
This data is removed when you delete the app; if device backup (e.g. iCloud) is on, it may be included in that backup.
Children's data (GDPR Art. 8)
Businessium is not offered to anyone under 16; this is our own minimum age of use (a product decision). On the age of digital consent, GDPR Art. 8 sets the EU-level default at 16; Member States may set a lower age in their own law, and Bulgaria, where the controller is established, has set it below 16 (ЗЗЛД Art. 25в). Because this service is not offered to anyone under 16, there is no parental-consent route and we do not knowingly collect personal data from anyone under 16.
If we learn that someone under 16 has opened an account, we delete the account and its data and do not collect extra data for that purpose. A parent or guardian who notices a child's account can write to us through our contact page; the request is handled without undue delay.
Automated decision-making and profiling
AI scores are produced automatically from your canvas text (profiling is not involved: the score is about the business idea you wrote, not about you). A score has no legal or similarly significant effect on you (GDPR Art. 22); you decide whether to request one and what to do with it. To contest a result, use “Report this AI answer” or the Support page.
Your rights and how to complain
Under the GDPR you have the following rights over your data:
- Access (GDPR Art. 15), rectification (Art. 16), erasure (Art. 17) and data portability (Art. 20).
- Restriction of processing (Art. 18): while you contest the accuracy of your data, if processing is unlawful, or while your objection is being assessed, your data is only stored and not otherwise used.
- Objection (Art. 21): you can object, on grounds relating to your particular situation, to processing based on legitimate interests (e.g. security, moderation); we then stop unless we demonstrate compelling legitimate grounds.
- You can send your requests via businessium.app/destek; we reply within one month at the latest (GDPR Art. 12(3)).
Complaint to a supervisory authority (GDPR Art. 77): as the controller is established in Bulgaria, the lead authority is the Bulgarian Commission for Personal Data Protection — Комисия за защита на личните данни (КЗЛД), cpdp.bg. You may also complain to the data protection authority of the EU country where you live or work.
Users in Türkiye may also complain to the Turkish Personal Data Protection Board under Art. 14 of Law No. 6698 (KVKK) (www.kvkk.gov.tr).
Data controller
Registered name: SMARTIA OOD (СМАРТИЯ ООД)
Address: Tria City Center, Burgas
Country: Bulgaria