BIOS

Privacy Policy

Effective date: January 1, 2025 · Last updated: June 21, 2026

This Privacy Policy explains how BIOS, operated by Nordix Systems as part of the NCS Group, collects, uses, shares, and protects personal data across its website, platform, and AI assistant runtime.

1. Introduction

BIOS, operated by Nordix Systems as part of the NCS Group, is committed to protecting the privacy and personal data of everyone who interacts with our website (nordixbios.com), application (app.nordixbios.com), API (api.nordixbios.com), platform, and AI assistant runtime (collectively, the "Services").

This Privacy Policy explains what data we collect, how and why we use it, with whom we share it, and the rights you have over your information. It covers our marketing website, our platform for partners, and the AI assistant runtime that operates across messaging channels.

2. Scope and Our Role

We act in different roles depending on the data and the context:

  • As a controller, we decide how and why personal data is processed for our own purposes — for example, data collected through our marketing website, contact and demo forms, the newsletter, partner account registration, billing, and security.
  • As a processor (or sub-processor), we process personal data on behalf of, and under the instructions of, our business partners — for example, the conversation data and per-user identity flowing through the white-label assistant and the AI agents that act on the partner's behalf. In those cases, the partner is the controller and is responsible for the lawful basis of the processing and for its own privacy notice to end users. That processing is governed by our Data Processing Agreement (DPA).

This Privacy Policy describes our practices as a controller, and explains, where relevant, how we support partners when we act as a processor.

3. Data Controller and Contact

The data controller for the purposes of the EU General Data Protection Regulation (GDPR), the UK GDPR, the Brazilian General Data Protection Law (LGPD), and other applicable data-protection laws is:

NCS — Nordic Compute System, operated by Easy Drift AS (Norway), together with Nordix Systems for the BIOS Services.

For any privacy-related inquiry, contact us at privacy@nordixsystems.com. Our Data Protection contact is dpo@ncsengine.com. You may also use the contact form on our website.

4. Data We Collect

Depending on which Services you use, we may collect the following categories of personal data:

Lead and prospect data (controller). When you use our contact, demo-booking, or sales forms, we collect your name, work email, company, phone number, role, a description of the system you want to connect, your message, your preferred demo date and time, and your locale.

Newsletter data (controller). When you subscribe, we collect your email address, your selected topic preferences, source attribution, and an unsubscribe token. The newsletter uses double opt-in; you can unsubscribe at any time.

Demo-lead management (controller). We process and manage demo bookings, including scheduling status and a management token that lets you track or reschedule your demo.

Form metadata (controller). We process request metadata such as the form topic, a CAPTCHA/anti-bot token (Cloudflare Turnstile), and request and idempotency identifiers, to prevent abuse and deduplicate submissions.

Partner account data (controller). When you register a partner account, we collect account and billing details, your connected-software configuration, API keys and credentials (stored in a vault/KMS and shown masked), verification keys, webhook secrets, channel credentials (stored masked), and your white-label branding (assistant name, avatar, tone, languages).

AI runtime conversation data (processor). Through the assistant, we process the messages exchanged by a partner's end users across channels, masked tool request and response data, conversation snippets that originate an operation, and the per-user channel identity passed through from the partner's emulated-authentication webhook. This data is processed on the partner's behalf under the DPA.

Partner end-user channel identifiers (processor). To route and authorize interactions, we process channel-specific end-user identifiers (such as a channel user ID or phone number). Per-user identity is resolved by the partner's webhook and passed through; we do not store it as a standalone end-user profile.

Audit logs. Each operation is logged with the user, channel, tool, masked parameters, masked request/response, and the conversation snippet that originated it.

Technical and security data. We process usage, device, and log data (IP address, browser and device type, timestamps), our published outbound IP addresses, rate-limit and error data, and cookies and anti-bot signals, as described in the Cookies section.

Payment-card and financial-instrument data is collected and processed by our payment processors, not stored in full by us.

5. How We Use Data

Where we act as a controller, we process personal data for the following purposes:

  • Service delivery: to provide, operate, secure, and maintain the website, platform, playground, and AI assistant runtime.
  • Leads and demos: to respond to inquiries, schedule and manage demos, and follow up on sales requests.
  • Accounts and billing: to create and manage partner accounts, process subscriptions and payments (via processors), and prevent payment fraud.
  • Newsletter and communications: to send the newsletter you subscribed to (with double opt-in) and service or transactional notifications.
  • Improvement: to analyze usage and improve the platform, features, and documentation, using aggregated or de-identified data where feasible.
  • Security and abuse prevention: to detect, prevent, and respond to security incidents, fraud, abuse (including via CAPTCHA/Turnstile), and technical issues.
  • Legal compliance: to comply with applicable laws, regulations, and lawful requests.

Where we act as a processor, we process personal data only to provide the Services in accordance with the partner's documented instructions and the DPA.

6. Legal Bases for Processing

Under the GDPR, UK GDPR, and equivalent laws (including the LGPD), we rely on the following legal bases:

  • Contractual necessity: processing required to deliver Services you have requested or contracted.
  • Legitimate interests: improving and securing our Services and conducting B2B marketing, provided these interests do not override your fundamental rights.
  • Consent: where you have given clear consent for specific activities (for example, the newsletter or non-essential cookies). You may withdraw consent at any time.
  • Legal obligation: where processing is required to comply with applicable law.

7. AI and Automated Processing

The Services rely on artificial intelligence, including third-party AI model providers engaged as sub-processors.

  • No training on your data without consent: we do not use Customer Data to train shared or foundation AI models, and our AI sub-processors are engaged under agreements that prohibit using your content to train their models, unless you provide explicit instruction or consent.
  • AI sub-processors: conversation and prompt content may be transmitted to AI model providers solely to generate responses and perform the tasks the partner's configuration requests.
  • Automated agent actions: the assistant acts on a partner's behalf following the partner's configuration, with audit logging available and step-up confirmation for destructive operations. Partners are responsible for maintaining human oversight of high-impact actions.
  • Automated decision-making: we do not use the Services to make decisions producing legal or similarly significant effects on individuals based solely on automated processing without appropriate safeguards.

8. Payments and Financial Data

When you pay for a Service, payment-card and financial-instrument data is collected and processed by licensed, PCI-DSS-compliant third-party payment processors. We receive only limited transaction details (such as a tokenized reference, the last digits of a card, the billing contact, and payment status) needed for billing, accounting, fraud prevention, and support. We do not store full payment-card numbers on our systems. Subscription pricing is denominated in euros (EUR).

9. Cookies and Tracking

Our website uses cookies and similar technologies to:

  • Essential cookies: ensure the website and application function correctly (session management, security, and anti-bot tokens such as Cloudflare Turnstile).
  • Analytics: understand how visitors interact with our website to improve usability. We favor privacy-friendly, cookieless analytics where possible, and any non-essential analytics cookies are activated only with your consent.

We do not use advertising or cross-site tracking cookies on our marketing website. You can manage your preferences through your browser settings or our cookie controls.

10. Data Sharing, Sub-processors, and Transfers

We do not sell personal data. We may share data with:

  • Infrastructure and hosting providers (such as cloud providers) operating under data-processing agreements.
  • Service providers and sub-processors that assist with analytics, email and messaging delivery, payments, AI model processing, anti-bot protection (Cloudflare Turnstile), and support, each bound by contractual confidentiality and data-protection obligations.
  • The channels and software you connect (your application's API, code repositories, and messaging platforms such as WhatsApp/Meta, Twilio, Telegram, Microsoft, and Slack), to which we send data as needed to provide the Services you configure.
  • NCS Group affiliates, to operate and support the Services.
  • Legal authorities, when required by law, court order, or to establish, exercise, or defend legal rights.
  • Business transfers, in connection with a merger, acquisition, or sale of assets, subject to this policy.

We maintain a list of current sub-processors, available on request at privacy@nordixsystems.com. Where data is transferred outside the European Economic Area (EEA) or the UK, we ensure adequate safeguards, including European Commission adequacy decisions or Standard Contractual Clauses (SCCs), together with supplementary measures where required.

11. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law.

  • Lead, demo, and account data is retained for the duration of the relationship and up to 5 years after termination for legal and audit purposes.
  • Newsletter data is retained until you unsubscribe, after which suppression data is kept to honor your opt-out.
  • Conversation, runtime, and audit data processed on behalf of a partner is retained according to the partner's configuration and the DPA.
  • Analytics data is aggregated or anonymized, typically within 26 months.

You may request deletion at any time, subject to legal retention obligations and, where we act as a processor, to the controlling partner's instructions.

12. Your Rights

Under the GDPR, UK GDPR, LGPD, and other applicable data-protection laws, you may have the right to:

  • Access your personal data and obtain a copy.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten") where applicable.
  • Restrict or object to processing in certain circumstances, including direct marketing.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time where processing is based on consent.

To exercise these rights, contact privacy@nordixsystems.com. We will respond within the timeframe required by applicable law (generally within 30 days). Where we process your data on behalf of a partner (as a processor), we will refer your request to that controller and assist them in responding.

13. Security Measures

We implement technical and organizational measures to protect your data, including:

  • Encryption in transit (TLS) and at rest (AES-256).
  • Call signing on the identity bridge: HMAC with timestamp and nonce to prevent replay, and step-up confirmation for destructive operations.
  • Proof-of-possession on the first user-to-channel binding (such as a one-time code) and key/secret rotation for verification keys and webhook secrets.
  • Credentials stored in a managed vault/KMS, shown masked, and never present in logs.
  • Role-based access controls, least privilege, multi-tenant isolation, and full audit logging.
  • A published outbound IP allowlist so you can restrict your firewall, plus rate limiting and abuse monitoring.
  • Incident-response and breach-notification procedures consistent with GDPR Articles 33/34 and equivalent laws.

14. International Users

We operate across multiple jurisdictions and may serve users in the EEA, the UK, Norway, Brazil, and elsewhere. Wherever you are located, we apply the protections described in this policy and the appropriate safeguards for any cross-border transfer.

For users in Brazil, we process personal data in accordance with the LGPD; for users in the UK, in accordance with the UK GDPR; and for users in the EEA and Norway, in accordance with the GDPR and Norwegian implementing law.

15. Children's Privacy

Our Services are designed for business and professional use and are not directed at individuals under the age of 16 (or the applicable age in your jurisdiction). We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us so we can take appropriate action.

16. Third-Party Links and Services

Our website and Services may link to, or integrate with, third-party websites and services that we do not control. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy notices of any third-party service you use or connect.

17. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, Services, or legal requirements. We will post the updated policy with a revised effective date and, where changes are material, provide additional notice through the Services or by email.

18. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at privacy@nordixsystems.com. Our Data Protection contact is dpo@ncsengine.com. You may also use the contact form on our website.

You have the right to lodge a complaint with your local data-protection authority (for example, the Norwegian Datatilsynet, the supervisory authority in your EU/EEA country, the UK ICO, or the Brazilian ANPD) if you believe your data has been processed in violation of applicable law.

Talk to the team