Privacy Policy
Last updated: 1 August 2026 · Version history at the end of this page
This is a courtesy translation. The binding version is the Spanish one, available at Política de Privacidad. If the two texts differ, the Spanish text prevails.
1. Who is responsible
BigLobster is the trading name under which Francisco Brais Nieto Romero carries on business, as an independent professional (a natural person) tax resident in Thailand. It is not a registered company.
Address for tax and service of notice: 88 Charan Sanit Wong Rd, Bang Yi Khan, Bang Phlat, Bangkok 10700, Thailand. There is no office open to the public and no in-person service: the business operates entirely remotely.
Data protection contact: soporte@biglobster.top.
2. Applicable law
BigLobster offers its products and services to individuals and businesses located in the European Union, in Spanish and in euros. Accordingly, and under Article 3(2) of Regulation (EU) 2016/679 (GDPR), this processing is subject to the GDPR regardless of the fact that the business owner is established outside the Union.
The GDPR is the primary framework for this policy. In addition, given the owner's residence, Thailand's Personal Data Protection Act (PDPA, B.E. 2562/2019) is also complied with. Where the two differ, the standard more protective of the data subject applies.
3. BigLobster's two roles
BigLobster processes personal data in two distinct legal capacities, with different obligations in each. Knowing which one applies to you determines who you should approach to exercise your rights.
| Role | Over which data | Who decides | Where it is governed |
|---|---|---|---|
| Controller | Visitors to biglobster.top and our own subscribers: account, billing and support | BigLobster | Part A of this policy |
| Processor | Data our agents handle on a customer's behalf while providing the service | The customer, who is the controller | Part B and the processing agreement |
In short: data about our customers we process as a controller. Data about our customers' own customers we process as a processor, following the instructions of whoever engages us.
Part A — BigLobster as controller
This applies if you visit this website, write to us, or subscribe to one of our agents. Here the GDPR obligations are ours, and we are who you complain to.
A.1 Data we process
- Contact form and sign-up wizard: name, email address, message content and, in the wizard, a summary of the billing cycle and the agents selected.
- Subscriber account: contact details of the person responsible for the account, and the technical access you provide so we can run the service.
- Billing: tax and payment details are collected and retained by the payment provider acting as merchant of record. BigLobster receives only the transaction record and never the card details.
- Support: the conversation history associated with any issue you raise with us.
- Technical data: the server temporarily logs the IP address of requests, solely to rate-limit submissions and prevent abuse of the form. It is not used for profiling and is not combined with other data.
We use no tracking cookies and no third-party analytics. The site stores two technical preferences in your browser's localStorage (cookie-consent and bl-theme) to remember the notice you accepted and your light/dark preference. That information stays on your device and is never sent to any server.
A.2 Purposes and legal bases
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Responding to enquiries sent through the form | Consent of the data subject — Art. 6(1)(a) |
| Setting up and managing the subscription purchased | Performance of a contract — Art. 6(1)(b) |
| Providing support for the service purchased | Performance of a contract — Art. 6(1)(b) |
| Limiting abuse of the form and protecting the infrastructure | Legitimate interest in the security of the service — Art. 6(1)(f) |
| Retaining invoices and proof of payment | Legal obligation applicable to the business owner — Art. 6(1)(c) |
A.3 Retention periods
- Enquiries through the form: up to 12 months from the last communication, unless they become a contractual relationship.
- Subscriber account data: for as long as the subscription is active, and for the applicable limitation periods after cancellation.
- Support history: 24 months from closure of the issue.
- Technical IP logs: 30 days at most.
- Billing records: the period required by applicable tax law.
A.4 Your rights
You may exercise at any time your rights of access, rectification, erasure, restriction of processing, portability and objection, and withdraw any consent given without affecting the lawfulness of processing carried out beforehand. Write to soporte@biglobster.top: we will respond within one month at the latest.
If you consider that the processing does not comply with the law, you may lodge a complaint with the supervisory authority of your country of residence in the European Union — in Spain, the Agencia Española de Protección de Datos (aepd.es) — or, where applicable, with Thailand's Personal Data Protection Committee (pdpc.or.th).
Part B — BigLobster as processor
This applies to the data our agents handle on a customer's behalf while we provide the service. Here the customer is the controller, not BigLobster, and we act solely on their documented instructions.
B.1 When this arises
When a customer activates a subscription, their agents operate on the website, content and systems they authorise us to work on. In the course of that work, personal data belonging to the customer's own sphere may be processed: for example, data contained in their website, in their documents, or in forms submitted by their own customers.
B.2 Who is answerable for what
The customer is the controller of that data. It is for them to determine the purposes and means, to have a valid legal basis, to inform their data subjects, to handle their rights requests, and to assess whether a data protection impact assessment is needed. BigLobster does not decide anything about that data and does not use it for its own purposes.
If you are a customer of one of our customers and wish to exercise your rights, you should approach the business you contracted with, not BigLobster. If you write to us, we will pass the request on to our customer and tell you we have done so, without resolving it ourselves.
B.3 Data processing agreement (Article 28 GDPR)
A data processing agreement under Article 28 GDPR is signed with every subscription customer, before any data is processed. That agreement is incorporated into the Terms and Conditions and sets out, as a minimum:
- Subject matter, duration, nature and purpose of the processing, the type of data and the categories of data subjects.
- The obligation to process data solely on the controller's documented instructions.
- A duty of confidentiality for everyone with access to the data.
- The security measures required by Article 32.
- The sub-processor regime: general prior authorisation, with the controller's right to object to new additions.
- Assistance to the controller in handling data subject rights and meeting its obligations under Articles 32 to 36.
- Notification of personal data breaches without undue delay from the moment we become aware of them.
- Deletion or return of the data at the end of the service, at the controller's choice.
- Making available the information needed to demonstrate compliance and to allow audits.
You can request a copy of the processing agreement before purchasing by writing to soporte@biglobster.top.
B.4 What we do not do with customer data
- We do not use it for our own purposes, or for any purpose other than delivering the service.
- We do not train artificial intelligence models on it, and we do not permit our sub-processors to do so.
- We do not disclose it to third parties beyond the sub-processors declared in section 4.
- We do not transmit special categories of data under Article 9 to AI providers.
4. Sub-processors
The following providers are involved in delivering the service. They act as processors (in Part A) or sub-processors (in Part B), under contract and solely on our instructions. Each is declared with its location and the safeguard covering the transfer:
| Provider | Purpose | Where processing takes place | Transfer safeguard |
|---|---|---|---|
| Francisco Brais Nieto Romero (owner of BigLobster) |
Operating the service, human oversight and support. Access to the systems from Thailand. | Thailand | Standard Contractual Clauses (Art. 46(2)(c)). Thailand has no adequacy decision. |
| Brevo (Sendinblue SAS) |
Sending the transactional email generated by the forms | European Union (France) | No transfer: processing takes place within the EEA. |
| Zeabur | Hosting the website and the application server | May include regions outside the EEA | Standard Contractual Clauses (Art. 46(2)(c)) for regions outside the EEA. |
| OpenRouter, Inc. and the model providers it routes to |
Inference for the language models that run the automated tasks | Primarily the United States | Standard Contractual Clauses (Art. 46(2)(c)), with minimisation of the data sent and a prohibition on training. |
| Payment provider acting as merchant of record |
Processing payment, invoicing and indirect taxes, once online payments are enabled | Outside the EEA | Standard Contractual Clauses (Art. 46(2)(c)). Acts as an independent controller in respect of payment data. |
The addition of a new sub-processor will be communicated to subscription customers with enough notice for them to object, in accordance with the processing agreement.
We do not disclose personal data to third parties for commercial, advertising or profiling purposes.
5. International transfers
The business owner resides in Thailand and accesses the systems from there: that in itself constitutes a transfer to a third country, and is declared as such. Thailand has no adequacy decision from the European Commission. Some of the sub-processors in the table above additionally process data in the United States and in the Asia-Pacific region.
All of these transfers are covered by the Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR), incorporated into the contracts with each provider and into the processing agreement we sign with each customer. As supplementary measures:
- We minimise the data sent to artificial intelligence providers.
- We do not transmit special categories of data under Article 9.
- We encrypt communications in transit (TLS).
- We limit system access to the people strictly necessary.
You can request information about the safeguards applied, or a copy of the clauses, by writing to soporte@biglobster.top.
6. Automated decision-making and artificial intelligence
The service is delivered by artificial intelligence agents under human oversight. No automated decisions are made that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR: every decision affecting the contractual relationship is reviewed by a person. The detail is in our information on the use of artificial intelligence.
7. Security
We apply TLS encryption on all communications, security headers on the server, request rate limiting and restricted system access. No system is infallible: if a breach occurred that posed a high risk to your rights, we would tell you and would notify the competent authority within the time limits of Article 33 GDPR. Where we act as a processor, we will notify the breach to the controlling customer without undue delay so that they can meet their own deadlines.
8. Changes to this policy
The version in force is always the one published on this page, identified by the version date in the header. If a change materially affects the processing of your data, we will tell you by email where you have an active relationship with us.
Version history
| Version | Changes |
|---|---|
| 01/08/2026 | Separation of the two roles: controller (Part A) and processor (Part B), with reference to the Article 28 agreement signed with every subscription customer. Sub-processor table with real names, locations and transfer safeguards, including the transfer to Thailand arising from the owner's access. Identification of the business owner. Version history added. English courtesy translation published. |
| 24/07/2026 | Previous version, drafted around Thailand's PDPA as the primary framework and without any separation of roles. Replaced for failing to meet Article 3(2) GDPR. |
Related documents: Terms and Conditions · Refund Policy · Use of artificial intelligence.