Early access beta — launching soon

You're using a pre-launch test version of BizOpsMate AI. Features may change and you might hit rough edges. The free trial is open — we'd love your feedback before go-live.

Send feedback

Privacy Policy

Last updated 25 July 2026

This policy explains how BizOpsMate AI collects, uses, and protects personal data when you use BizOpsMate AI. We are the data controller for your account information, and we act as a data processor for the customer records you put into the Service.

1. What we collect

Account data. Your name, email address, business name, business registration or VAT number, country, and currency.

Business records you enter. Your customers’ names and contact details, inquiries, quotes, invoices, payments, and reminders. This may include personal data about your customers, for which you are the controller.

Payment data. Your subscription plan and status, and a payment reference from PayHere. We never receive or store your full card number.

AI processing records. For each AI action we store the input, the output, the model used, a confidence score, tokens consumed, and who approved it. This is what makes the audit log possible.

Technical data. Server logs containing IP address, request path, timestamp, and response status, plus error diagnostics.

2. Why we use it

  • To provide the Service and generate the drafts and summaries you ask for.
  • To authenticate you and keep your account secure.
  • To take payment and manage your subscription.
  • To send service messages about your account, billing, and security.
  • To diagnose faults, prevent abuse, and improve reliability.
  • To meet our legal and tax obligations.

3. Legal basis

We process account and business data to perform our contract with you; technical and security data under our legitimate interest in operating a safe and reliable service; and financial records to comply with legal obligations. Where we rely on consent, such as for marketing email, you can withdraw it at any time.

4. How AI processing works

When an agent runs, the relevant text — for example a customer inquiry or invoice details — is sent to Google’s Gemini API to generate a draft. Two points worth being explicit about:

  • Your data is not used to train Google’s models under the paid API terms we operate on.
  • We validate every AI response against a strict schema before it is written to your account, and low-confidence output is held for your approval instead of being acted on.

5. Who we share it with

We use these sub-processors, and only for the purposes shown:

  • Google Cloud Platform — hosting, database, and file storage.
  • Google Gemini API — generating AI drafts and summaries.
  • Clerk — user authentication and team management.
  • PayHere — subscription payment processing.
  • Resend — sending transactional and reminder email.
  • Sentry — error monitoring and diagnostics.

We do not sell personal data. We may disclose data where the law requires it, or to protect our rights and the safety of our users.

6. International transfers

Our infrastructure is hosted in the Asia South (Mumbai) region, and some sub-processors operate elsewhere, including in the United States and Europe. Where data leaves Sri Lanka we rely on the transfer safeguards offered by those providers, such as standard contractual clauses.

7. How we protect it

  • Data is encrypted in transit (TLS) and at rest.
  • Each business’s records are isolated by Postgres row-level security, enforced by the database rather than only by application code.
  • Secrets are held in Google Secret Manager, not in code or configuration files.
  • Access to production is restricted and audited.
  • Sensitive actions are recorded in an audit trail.

8. How long we keep it

  • Account and business records: while your account is active.
  • After cancellation: 90 days, so you can export or reactivate, then deletion on request.
  • Financial records: as long as Sri Lankan tax law requires.
  • Server logs: 30 days.
  • Generated invoice PDFs: up to 24 months.

9. Your rights

You may ask us to:

  • Give you a copy of the personal data we hold about you.
  • Correct data that is inaccurate.
  • Delete your data, where we are not required to keep it.
  • Export your data in a portable format.
  • Stop sending you marketing email.

Write to hello@bizopsmateai.com and we will respond within 30 days.

10. Your responsibilities as a controller

When you upload your customers’ details, you are their data controller. You are responsible for having a lawful basis to hold their information and to contact them, and for honouring their requests. We will assist you where we reasonably can.

11. Cookies

We use only the cookies needed to keep you signed in and to keep sessions secure. We do not use advertising or cross-site tracking cookies.

12. Children

The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect data from children.

13. Changes

We will post any update here and change the date above. For material changes we will notify you by email or in the application.

14. Contact

BizOpsMate AI

Email: hello@bizopsmateai.com
Phone: