Privacy Policy
Last updated: 13 September 2026 · Version history at the end of this page
This is a courtesy translation. The binding version is the Spanish one, available at Política de Privacidad. If the two texts differ, the Spanish text prevails.
1. Who is responsible
BigLobster is the trading name of Biglobster LLC, a limited liability company organized under the laws of the State of New Mexico (USA). Registration number: 3279115 (Entity ID 0008120949, New Mexico Secretary of State).
Registered address for service of notice: 1209 Mountain Road Pl NE Ste N, Albuquerque, NM 87110, USA. There is no office open to the public and no in-person service: the business operates entirely remotely.
Data protection contact: soporte@biglobster.top.
2. Applicable law
BigLobster offers its products and services worldwide, including to individuals and businesses located in the European Union, in Spanish and in euros. In respect of those EU recipients, and under Article 3(2) of Regulation (EU) 2016/679 (GDPR), this processing is subject to the GDPR regardless of the fact that the business owner is established outside the Union.
The GDPR is the primary framework for this policy. In addition, since we operate and access the systems from Thailand, Thailand's Personal Data Protection Act (PDPA, B.E. 2562/2019) is also complied with. Where the two differ, the standard more protective of the data subject applies.
3. BigLobster's two roles
BigLobster processes personal data in two distinct legal capacities, with different obligations in each. Knowing which one applies to you determines who you should approach to exercise your rights.
| Role | Over which data | Who decides | Where it is governed |
|---|---|---|---|
| Controller | Visitors to biglobster.top and our own subscribers: account, billing and support | BigLobster | Part A of this policy |
| Processor | Data our agents handle on a customer's behalf while providing the service | The customer, who is the controller | Part B and the processing agreement |
In short: data about our customers we process as a controller. Data about our customers' own customers we process as a processor, following the instructions of whoever engages us.
Part A - BigLobster as controller
This applies if you visit this website, write to us, or subscribe to one of our agents. Here the GDPR obligations are ours, and we are who you complain to.
A.1 Data we process
- Contact form and sign-up wizard: name, email address, message content and, in the wizard, a summary of the billing cycle and the agents selected.
- Subscriber account: contact details of the person responsible for the account, and the technical access you provide so we can run the service.
- Billing: tax and payment details are collected and retained by the payment provider acting as merchant of record. BigLobster receives only the transaction record and never the card details.
- Support: the conversation history associated with any issue you raise with us.
- Technical data: the server temporarily logs the IP address of requests, solely to rate-limit submissions and prevent abuse of the form. It is not used for profiling and is not combined with other data.
We use no tracking cookies and no advertising. If UMAMI_WEBSITE_ID is set in production, we load Umami Cloud (umami.is), open-source cookieless analytics: no advertising profiles and no data sales. It collects the page URL, referrer, device type and approximate country. The IP address is not stored in the clear. The site also stores two technical preferences in your browser's localStorage (cookie-consent and bl-theme) to remember the notice you accepted and your light/dark preference. That information stays on your device and is never sent to any server.
A.2 Purposes and legal bases
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Responding to enquiries sent through the form | Consent of the data subject - Art. 6(1)(a) |
| Setting up and managing the subscription purchased | Performance of a contract - Art. 6(1)(b) |
| Providing support for the service purchased | Performance of a contract - Art. 6(1)(b) |
| Limiting abuse of the form and protecting the infrastructure | Legitimate interest in the security of the service - Art. 6(1)(f) |
| Measuring site use (page views, traffic source) with Umami, without cookies or profiles | Legitimate interest in understanding and improving the site - Art. 6(1)(f) |
| Retaining invoices and proof of payment | Legal obligation applicable to the business owner - Art. 6(1)(c) |
A.3 Retention periods
- Enquiries through the form: up to 12 months from the last communication, unless they become a contractual relationship.
- Subscriber account data: for as long as the subscription is active, and for the applicable limitation periods after cancellation.
- Support history: 24 months from closure of the issue.
- Technical IP logs: 30 days at most.
- Umami statistics: audience aggregates in Umami Cloud for as long as the property is active. You may object by writing to soporte@biglobster.top.
- Billing records: the period required by applicable tax law.
A.4 Your rights
You may exercise at any time your rights of access, rectification, erasure, restriction of processing, portability and objection, and withdraw any consent given without affecting the lawfulness of processing carried out beforehand. Write to soporte@biglobster.top: we will respond within one month at the latest.
If you consider that the processing does not comply with the law, you may lodge a complaint with the supervisory authority of your country of residence in the European Union - in Spain, the Agencia Española de Protección de Datos (aepd.es) - or, where applicable, with Thailand's Personal Data Protection Committee (pdpc.or.th).
Part B - BigLobster as processor
This applies to the data our agents handle on a customer's behalf while we provide the service. Here the customer is the controller, not BigLobster, and we act solely on their documented instructions.
B.1 When this arises
When a customer activates a subscription, their agents operate on the website, content and systems they authorise us to work on. In the course of that work, personal data belonging to the customer's own sphere may be processed: for example, data contained in their website, in their documents, or in forms submitted by their own customers.
B.2 Who is answerable for what
The customer is the controller of that data. It is for them to determine the purposes and means, to have a valid legal basis, to inform their data subjects, to handle their rights requests, and to assess whether a data protection impact assessment is needed. BigLobster does not decide anything about that data and does not use it for its own purposes.
If you are a customer of one of our customers and wish to exercise your rights, you should approach the business you contracted with, not BigLobster. If you write to us, we will pass the request on to our customer and tell you we have done so, without resolving it ourselves.
B.3 Data processing agreement (Article 28 GDPR)
A data processing agreement under Article 28 GDPR is signed with every subscription customer, before any data is processed. That agreement is incorporated into the Terms and Conditions and sets out, as a minimum:
- Subject matter, duration, nature and purpose of the processing, the type of data and the categories of data subjects.
- The obligation to process data solely on the controller's documented instructions.
- A duty of confidentiality for everyone with access to the data.
- The security measures required by Article 32.
- The sub-processor regime: general prior authorisation, with the controller's right to object to new additions.
- Assistance to the controller in handling data subject rights and meeting its obligations under Articles 32 to 36.
- Notification of personal data breaches without undue delay from the moment we become aware of them.
- Deletion or return of the data at the end of the service, at the controller's choice.
- Making available the information needed to demonstrate compliance and to allow audits.
You can request a copy of the processing agreement before purchasing by writing to soporte@biglobster.top.
B.4 What we do not do with customer data
- We do not use it for our own purposes, or for any purpose other than delivering the service.
- We do not train artificial intelligence models on it, and we do not permit our sub-processors to do so.
- We do not disclose it to third parties beyond the sub-processors declared in section 4.
- We do not transmit special categories of data under Article 9 to AI providers.
4. Sub-processors
The following providers are involved in delivering the service. They act as processors (in Part A) or sub-processors (in Part B), under contract and solely on our instructions. Each is declared with its location and the safeguard covering the transfer:
| Provider | Purpose | Where processing takes place | Transfer safeguard |
|---|---|---|---|
| Biglobster LLC (authorized personnel) |
Operating the service, human oversight and support. Access to the systems from Thailand. | Thailand | Standard Contractual Clauses (Art. 46(2)(c)). Thailand has no adequacy decision. |
| Brevo (Sendinblue SAS) |
Sending the transactional email generated by the forms | European Union (France) | No transfer: processing takes place within the EEA. |
| Zeabur | Hosting the website and the application server | May include regions outside the EEA | Standard Contractual Clauses (Art. 46(2)(c)) for regions outside the EEA. |
| Umami Software, Inc. (Umami Cloud) |
Cookieless audience analytics (page views). Only if UMAMI_WEBSITE_ID is set. |
United States | Standard Contractual Clauses (Art. 46(2)(c)). Umami uses no cookies and builds no advertising profiles. |
| OpenRouter, Inc. and the model providers it routes to |
Inference for the language models that run the automated tasks | Primarily the United States | Standard Contractual Clauses (Art. 46(2)(c)), with minimisation of the data sent and a prohibition on training. |
| Payment provider acting as merchant of record |
Processing payment, invoicing and indirect taxes, once online payments are enabled | Outside the EEA | Standard Contractual Clauses (Art. 46(2)(c)). Acts as an independent controller in respect of payment data. |
The addition of a new sub-processor will be communicated to subscription customers with enough notice for them to object, in accordance with the processing agreement.
We do not disclose personal data to third parties for commercial, advertising or profiling purposes.
5. International transfers
Biglobster LLC is organized in New Mexico (USA), but operates and accesses the systems from Thailand: that in itself constitutes a transfer to a third country, and is declared as such. Thailand has no adequacy decision from the European Commission. Some of the sub-processors in the table above additionally process data in the United States and in the Asia-Pacific region.
All of these transfers are covered by the Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR), incorporated into the contracts with each provider and into the processing agreement we sign with each customer. As supplementary measures:
- We minimise the data sent to artificial intelligence providers.
- We do not transmit special categories of data under Article 9.
- We encrypt communications in transit (TLS).
- We limit system access to the people strictly necessary.
You can request information about the safeguards applied, or a copy of the clauses, by writing to soporte@biglobster.top.
6. Automated decision-making and artificial intelligence
The service is delivered by artificial intelligence agents under human oversight. No automated decisions are made that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR: every decision affecting the contractual relationship is reviewed by a person. The detail is in our information on the use of artificial intelligence.
7. Security
We apply TLS encryption on all communications, security headers on the server, request rate limiting and restricted system access. No system is infallible: if a breach occurred that posed a high risk to your rights, we would tell you and would notify the competent authority within the time limits of Article 33 GDPR. Where we act as a processor, we will notify the breach to the controlling customer without undue delay so that they can meet their own deadlines.
8. Changes to this policy
The version in force is always the one published on this page, identified by the version date in the header. If a change materially affects the processing of your data, we will tell you by email where you have an active relationship with us.
Version history
| Version | Changes |
|---|---|
| 13/09/2026 | Declared Umami Cloud as opt-in cookieless analytics, on a legitimate-interest basis, and as a processor in the sub-processor table. The policy no longer states that there is no third-party analytics. |
| 20/08/2026 | Added Biglobster LLC's registration number (File #3279115, Entity ID 0008120949), following approval of the formation by the New Mexico Secretary of State on 18 August 2026. |
| 06/08/2026 | Updated identity of the business owner: BigLobster now operates under Biglobster LLC, a company organized in New Mexico (USA). New registered address for service of notice. References to the business owner updated throughout the sub-processor and international transfers sections; the transfer to Thailand remains, now arising from the company's operations. Clarified section 2: BigLobster offers its services worldwide, not only to the European Union; the GDPR applies in respect of recipients located in the EU. |
| 01/08/2026 | Separation of the two roles: controller (Part A) and processor (Part B), with reference to the Article 28 agreement signed with every subscription customer. Sub-processor table with real names, locations and transfer safeguards, including the transfer to Thailand arising from the owner's access. Identification of the business owner. Version history added. English courtesy translation published. |
| 24/07/2026 | Previous version, drafted around Thailand's PDPA as the primary framework and without any separation of roles. Replaced for failing to meet Article 3(2) GDPR. |
Related documents: Terms and Conditions · Refund Policy · Use of artificial intelligence.