← Back Version: 01/08/2026

Privacy Policy

Last updated: 1 August 2026 · Version history at the end of this page

This is a courtesy translation. The binding version is the Spanish one, available at Política de Privacidad. If the two texts differ, the Spanish text prevails.

1. Who is responsible

BigLobster is the trading name under which Francisco Brais Nieto Romero carries on business, as an independent professional (a natural person) tax resident in Thailand. It is not a registered company.

Address for tax and service of notice: 88 Charan Sanit Wong Rd, Bang Yi Khan, Bang Phlat, Bangkok 10700, Thailand. There is no office open to the public and no in-person service: the business operates entirely remotely.

Data protection contact: soporte@biglobster.top.

2. Applicable law

BigLobster offers its products and services to individuals and businesses located in the European Union, in Spanish and in euros. Accordingly, and under Article 3(2) of Regulation (EU) 2016/679 (GDPR), this processing is subject to the GDPR regardless of the fact that the business owner is established outside the Union.

The GDPR is the primary framework for this policy. In addition, given the owner's residence, Thailand's Personal Data Protection Act (PDPA, B.E. 2562/2019) is also complied with. Where the two differ, the standard more protective of the data subject applies.

3. BigLobster's two roles

BigLobster processes personal data in two distinct legal capacities, with different obligations in each. Knowing which one applies to you determines who you should approach to exercise your rights.

RoleOver which dataWho decidesWhere it is governed
Controller Visitors to biglobster.top and our own subscribers: account, billing and support BigLobster Part A of this policy
Processor Data our agents handle on a customer's behalf while providing the service The customer, who is the controller Part B and the processing agreement

In short: data about our customers we process as a controller. Data about our customers' own customers we process as a processor, following the instructions of whoever engages us.

Part A — BigLobster as controller

This applies if you visit this website, write to us, or subscribe to one of our agents. Here the GDPR obligations are ours, and we are who you complain to.

A.1 Data we process

We use no tracking cookies and no third-party analytics. The site stores two technical preferences in your browser's localStorage (cookie-consent and bl-theme) to remember the notice you accepted and your light/dark preference. That information stays on your device and is never sent to any server.

A.2 Purposes and legal bases

PurposeLegal basis (Art. 6 GDPR)
Responding to enquiries sent through the formConsent of the data subject — Art. 6(1)(a)
Setting up and managing the subscription purchasedPerformance of a contract — Art. 6(1)(b)
Providing support for the service purchasedPerformance of a contract — Art. 6(1)(b)
Limiting abuse of the form and protecting the infrastructureLegitimate interest in the security of the service — Art. 6(1)(f)
Retaining invoices and proof of paymentLegal obligation applicable to the business owner — Art. 6(1)(c)

A.3 Retention periods

A.4 Your rights

You may exercise at any time your rights of access, rectification, erasure, restriction of processing, portability and objection, and withdraw any consent given without affecting the lawfulness of processing carried out beforehand. Write to soporte@biglobster.top: we will respond within one month at the latest.

If you consider that the processing does not comply with the law, you may lodge a complaint with the supervisory authority of your country of residence in the European Union — in Spain, the Agencia Española de Protección de Datos (aepd.es) — or, where applicable, with Thailand's Personal Data Protection Committee (pdpc.or.th).

Part B — BigLobster as processor

This applies to the data our agents handle on a customer's behalf while we provide the service. Here the customer is the controller, not BigLobster, and we act solely on their documented instructions.

B.1 When this arises

When a customer activates a subscription, their agents operate on the website, content and systems they authorise us to work on. In the course of that work, personal data belonging to the customer's own sphere may be processed: for example, data contained in their website, in their documents, or in forms submitted by their own customers.

B.2 Who is answerable for what

The customer is the controller of that data. It is for them to determine the purposes and means, to have a valid legal basis, to inform their data subjects, to handle their rights requests, and to assess whether a data protection impact assessment is needed. BigLobster does not decide anything about that data and does not use it for its own purposes.

If you are a customer of one of our customers and wish to exercise your rights, you should approach the business you contracted with, not BigLobster. If you write to us, we will pass the request on to our customer and tell you we have done so, without resolving it ourselves.

B.3 Data processing agreement (Article 28 GDPR)

A data processing agreement under Article 28 GDPR is signed with every subscription customer, before any data is processed. That agreement is incorporated into the Terms and Conditions and sets out, as a minimum:

You can request a copy of the processing agreement before purchasing by writing to soporte@biglobster.top.

B.4 What we do not do with customer data

4. Sub-processors

The following providers are involved in delivering the service. They act as processors (in Part A) or sub-processors (in Part B), under contract and solely on our instructions. Each is declared with its location and the safeguard covering the transfer:

ProviderPurposeWhere processing takes placeTransfer safeguard
Francisco Brais Nieto Romero
(owner of BigLobster)
Operating the service, human oversight and support. Access to the systems from Thailand. Thailand Standard Contractual Clauses (Art. 46(2)(c)). Thailand has no adequacy decision.
Brevo
(Sendinblue SAS)
Sending the transactional email generated by the forms European Union (France) No transfer: processing takes place within the EEA.
Zeabur Hosting the website and the application server May include regions outside the EEA Standard Contractual Clauses (Art. 46(2)(c)) for regions outside the EEA.
OpenRouter, Inc.
and the model providers it routes to
Inference for the language models that run the automated tasks Primarily the United States Standard Contractual Clauses (Art. 46(2)(c)), with minimisation of the data sent and a prohibition on training.
Payment provider
acting as merchant of record
Processing payment, invoicing and indirect taxes, once online payments are enabled Outside the EEA Standard Contractual Clauses (Art. 46(2)(c)). Acts as an independent controller in respect of payment data.

The addition of a new sub-processor will be communicated to subscription customers with enough notice for them to object, in accordance with the processing agreement.

We do not disclose personal data to third parties for commercial, advertising or profiling purposes.

5. International transfers

The business owner resides in Thailand and accesses the systems from there: that in itself constitutes a transfer to a third country, and is declared as such. Thailand has no adequacy decision from the European Commission. Some of the sub-processors in the table above additionally process data in the United States and in the Asia-Pacific region.

All of these transfers are covered by the Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR), incorporated into the contracts with each provider and into the processing agreement we sign with each customer. As supplementary measures:

You can request information about the safeguards applied, or a copy of the clauses, by writing to soporte@biglobster.top.

6. Automated decision-making and artificial intelligence

The service is delivered by artificial intelligence agents under human oversight. No automated decisions are made that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR: every decision affecting the contractual relationship is reviewed by a person. The detail is in our information on the use of artificial intelligence.

7. Security

We apply TLS encryption on all communications, security headers on the server, request rate limiting and restricted system access. No system is infallible: if a breach occurred that posed a high risk to your rights, we would tell you and would notify the competent authority within the time limits of Article 33 GDPR. Where we act as a processor, we will notify the breach to the controlling customer without undue delay so that they can meet their own deadlines.

8. Changes to this policy

The version in force is always the one published on this page, identified by the version date in the header. If a change materially affects the processing of your data, we will tell you by email where you have an active relationship with us.

Version history

VersionChanges
01/08/2026 Separation of the two roles: controller (Part A) and processor (Part B), with reference to the Article 28 agreement signed with every subscription customer. Sub-processor table with real names, locations and transfer safeguards, including the transfer to Thailand arising from the owner's access. Identification of the business owner. Version history added. English courtesy translation published.
24/07/2026 Previous version, drafted around Thailand's PDPA as the primary framework and without any separation of roles. Replaced for failing to meet Article 3(2) GDPR.

Related documents: Terms and Conditions · Refund Policy · Use of artificial intelligence.

WhatsApp