Legal · 2026
Privacy Policy & GDPR Notice
talkinbio takes the privacy and security of your personal data seriously. This page explains how we collect, use and protect your data in accordance with the General Data Protection Regulation (GDPR) and applicable privacy laws.
1. Data Controller
talkinbio is currently operated as a sole proprietorship while formal company incorporation is in progress; the registered data controller identity (company name, registration number) will be updated on this page once incorporation is complete. Personal data collected through the platform is processed in accordance with applicable data protection law, including the GDPR. Contact: info@talkinbio.com
Important distinction: business owners using the talkinbio platform (our customers) are the data controller for data they collect from their own visitors/end customers (e.g. conversations with Saule, lead information) — talkinbio acts as a data processor for that data. For the account holder's own data (name, email, account information), talkinbio is the data controller.
2. Personal Data We Collect
talkinbio provides an AI assistant (Saule) that chats 24/7 with visitors to your social media bio page. Two separate categories of data are processed:
Your data as a business owner (account holder): • Identity data: Full name • Contact data: Email address • Account data: Business name, username, industry/category • Usage and metering data: Login timestamps, in-platform actions, AI usage volume (credit/token consumption)
Data belonging to visitors to your page (your end customers) — for this data, you are the data controller and talkinbio is the data processor: • Transcripts of conversations with Saule (including messages the visitor writes) • Lead information: name, contact details, preferred appointment time • A session cookie named visitor_session_id (used to match a visitor to their own conversation history)
Saule is an AI assistant; when a visitor asks directly, it honestly discloses this. These conversations may be read by the business owner providing the service and are sent to an AI provider to generate responses (see Section 4).
3. Legal Basis for Processing
We process your personal data under the following legal bases under GDPR Article 6:
• Account creation and authentication → Performance of a contract (Art. 6(1)(b)) • Providing platform services (page hosting, Saule/Beiwe assistants) → Performance of a contract (Art. 6(1)(b)) • AI-assisted visitor communication (Saule answering questions, collecting appointments/leads) → Performance of a contract + legitimate interests (Art. 6(1)(b), 6(1)(f)) • Security and audit logs → Legitimate interests (Art. 6(1)(f)) • Product development, error analysis and usage metering (credit/token consumption) → Legitimate interests (Art. 6(1)(f)) • Legal compliance (invoicing, accounting records) → Legal obligation (Art. 6(1)(c)) • Marketing communications → Consent (Art. 6(1)(a)) — only where you have given explicit consent
4. Data Transfers
To provide our service, your personal data is transferred to the following technical infrastructure providers (acting as data processors):
• Supabase — database, authentication and file storage • Vercel — application hosting • Anthropic — the AI model provider powering Saule's and Beiwe's responses; conversation content is sent to Anthropic (based in the United States) for this purpose • Resend — sending system and notification emails
Some of these providers are located outside the European Economic Area. Where data is transferred outside the EEA, we ensure appropriate safeguards are in place in accordance with GDPR Chapter V, including Standard Contractual Clauses where applicable. Data may also be transferred to competent public authorities where legally required.
5. Data Retention
We retain your personal data as follows:
• Account and platform data: for as long as your account is active; deleted or anonymized within 90 days of account closure. • Saule conversation transcripts and lead data: retained for as long as the related business account is active (accessible to the business owner); deleted within 90 days of account closure. • Invoicing and accounting records: retained for the period required by applicable tax law. • Security and audit logs: retained for up to 12 months.
If a visitor requests deletion of their conversation data, the request is directed to the relevant business owner (the data controller); talkinbio, as data processor, carries out the technical deletion.
6. Your Rights Under GDPR
Under GDPR, you have the following rights:
• Right of access — to obtain a copy of your personal data • Right to rectification — to correct inaccurate or incomplete data • Right to erasure ('right to be forgotten') — to request deletion of your data • Right to restriction of processing • Right to data portability • Right to object — including to processing based on legitimate interests • Rights related to automated decision-making and profiling
To exercise any of these rights, please contact us at info@talkinbio.com. We will respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority.
7. Cookies
The talkinbio platform currently uses only strictly necessary cookies for session management and security (e.g. the visitor_session_id cookie used to match a visitor to their own conversation history, and login session cookies). We do not currently use analytics or marketing cookies; if this changes, a consent banner will be added before any such cookie is set. You can manage your cookie preferences through your browser settings.
8. Changes to This Policy
talkinbio reserves the right to update this Privacy Policy. Significant changes will be communicated to your registered email address. The current version is always available on this page.
9. Contact
For all privacy-related requests and GDPR inquiries, please contact us at: info@talkinbio.com