Privacy Policy
What Biznitos LTD does with personal information across the Curator platform, the sites we host, and our Meta advertising and messaging integrations.
Last updated: 19 July 2026. This policy replaces all previous versions.
This policy explains what Biznitos LTD ("Biznitos", "we", "us") does with personal information. It covers the Curator platform, every website we host or operate, our integrations with Meta and other advertising and messaging platforms, and our own business communications.
We are a technology provider. Much of the data we touch belongs to our business customers and to the people who contact them. Section 2 explains which hat we are wearing, and it matters for the rest of this policy.
1. Who we are and how to reach us
Biznitos LTD is a company incorporated in Jamaica. We operate remotely, with team members in Jamaica, the United States, Canada, Thailand, and Vietnam.
- Privacy questions and data requests: [email protected]
- Legal and contractual matters: [email protected]
- Security vulnerabilities and incidents: [email protected]
We answer privacy requests within 30 days. If a request is complex we will tell you inside that window and explain how long we need.
2. Our two roles
We handle personal information in two distinct capacities, and your rights differ depending on which applies.
We are the controller
For information about our own customers and prospects: account details, billing records, support conversations, and the people who contact Biznitos directly. We decide why and how this is processed, and this policy governs it.
We are a processor, acting for our customer
For information that flows through a customer's site, forms, campaigns, connected advertising accounts, and messaging channels. Here our customer is the controller and we act only on their instructions. We do not use this data for our own purposes.
If you are an end user who submitted a form, subscribed to a list, or messaged a business we work with, and you want your data corrected or deleted, you can contact us at [email protected] and we will act on it or route it to the responsible business promptly. You may also contact that business directly.
3. What we collect
3.1 Information you give us
- Account and billing: name, business name, email, phone, address, and payment details handled by our payment processors.
- Form and lead submissions: name, email, phone, message content, scheduling and location details, uploaded files, and any custom fields the form asks for.
- Member accounts on hosted sites: name, email, phone, photo, and optional profile details such as occupation, organisation, date of birth, gender, and address, where a site collects them.
- Support and sales correspondence: what you write to us, and our replies.
3.2 Information we collect automatically
- Usage and analytics: pages viewed, clicks, conversion events such as tapping a phone or messaging button, referring URL, and landing page.
- Device and connection: IP address, user agent, browser and operating system, approximate location derived from IP, and a visitor identifier.
- Marketing attribution: campaign parameters such as source, medium, campaign, term, and content.
- Email engagement: opens, clicks, and delivery outcomes for messages we send on a customer's behalf.
- Server logs, kept for security, debugging, and abuse prevention.
3.3 Information from third parties
- Payment confirmations and status from our payment processors. We never receive or store full card numbers.
- Data from connected platforms, described in section 4.
4. Data from Meta
Biznitos acts as a technology provider for businesses that connect their Meta assets to the Platform. We access those assets only on behalf of, and at the direction of, the business that owns them.
4.1 What we receive, by product
- Facebook Pages: page identifiers, access tokens, page and post metrics, and content our customer publishes or schedules.
- Ads and Business Manager: ad account identifiers, campaign structure, spend, delivery and performance metrics, and audience configuration. We do not receive the personal details of the individuals in a Meta audience.
- Instagram professional accounts: account identifiers, media, publishing and insight metrics, and messages where our customer has enabled that.
- WhatsApp Business Platform: business account and phone number identifiers, message templates, delivery status, and the content of messages sent and received through our customer's account.
- Pixel and Conversions API: website and offline events our customer configures, which may include hashed identifiers used for matching.
- Facebook Login: where a person chooses to sign in with Facebook, we receive the identifier, name, and email address that the person authorises, and nothing more.
4.2 How we use it
We use data from Meta solely to deliver the service our customer asked for: publishing and scheduling content, reporting on campaigns, sending and receiving messages, measuring conversions, and authenticating people who choose to sign in with Facebook.
4.3 What we do not do with it
We do not:
- Sell, licence, or purchase data obtained from Meta.
- Use it to train or improve machine learning or artificial intelligence systems. This applies in particular to WhatsApp message content.
- Use it to build or augment profiles of individuals beyond what the person and our customer have agreed to.
- Use it to discriminate against people, or to promote discrimination, on the basis of race, ethnicity, colour, national origin, religion, age, sex, sexual orientation, gender identity, family status, disability, or medical or genetic condition.
- Use it to decide anyone's eligibility for housing, employment, insurance, education, credit, government benefits, or immigration status.
- Use it to operate, facilitate, or provide surveillance tools.
- Attempt to decrypt, re-identify, or reverse engineer it.
- Use it for any purpose Meta's developer documentation does not permit.
4.4 Separation, retention, and deletion
Each customer's Meta data is kept logically separated from every other customer's. We keep it only as long as it is needed for the purpose it was collected for. We delete it when our customer asks, when the customer stops using the integration, when it is no longer needed, when Meta requires it in order to protect people, or when the law requires it. If we ever receive Meta data in error we report it to Meta, delete it, and keep a record.
To request deletion of data associated with your Facebook or Instagram account, follow the steps at Data Deletion Instructions.
5. Why we process, and our legal bases
| Purpose | Legal basis |
|---|---|
| Providing the Platform and hosting sites | Performance of a contract |
| Handling leads, bookings, and enquiries | Contract, or the controller's legitimate interest in responding to an enquiry |
| Billing, collections, and record keeping | Contract, and legal obligation |
| Marketing email and campaigns | Consent, or legitimate interest for existing customers where the law allows |
| Analytics and measurement | Consent where cookies or similar require it, otherwise legitimate interest |
| Advertising and conversion measurement | Consent, obtained by the business running the campaign |
| Security, fraud prevention, and abuse handling | Legitimate interest, and legal obligation |
| Complying with law and platform obligations | Legal obligation |
Where we rely on legitimate interest, we have considered whether our interest is overridden by your rights, and we have concluded it is not. You can object at any time using the contacts in section 1.
6. Who we share with
We do not sell personal information, and we do not share it for cross-context behavioural advertising on our own account.
We share it with:
- Our customers, where we processed it on their behalf.
- Service providers listed in section 7, each bound in writing to use it only for us and only to deliver the service we asked for, to bind their own subcontractors to the same terms, and to delete it when our relationship ends.
- Connected platforms such as Meta, where our customer has directed us to send data.
- Authorities, where the law requires it. We record the basis for every such disclosure.
- An acquirer, if our business is sold or reorganised. We will give notice before your data becomes subject to a different policy.
7. Service providers
We use the following categories of provider. We update this list when it changes, and material additions are announced on this page.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Application hosting and file storage | United States |
| Cloudflare | Content delivery, image processing, network security | Global edge network |
| Meta Platforms | Pages, Instagram, advertising, WhatsApp messaging, conversion measurement | United States and Ireland |
| Web fonts, search console, site verification | United States | |
| Stripe | Card payment processing | United States |
| PayPal | Payment processing | United States |
| Inkress | Payment processing for Jamaican businesses | Jamaica |
| OpenAI, Groq, Anthropic, and xAI | Content generation and assistant features, where a customer enables them | United States |
Where a provider processes data on our behalf we have a written agreement in place covering purpose limitation, confidentiality, security, subcontracting, and deletion. You can request the current list, with contact details, at [email protected].
8. International transfers
We are based in Jamaica and our team and providers are spread across several countries, so your information will be transferred internationally. Where we move personal information out of the European Economic Area or the United Kingdom, we rely on Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, together with the technical safeguards in section 10. Ask us at [email protected] for details of the mechanism covering a particular transfer.
9. How long we keep things
| Category | Retention |
|---|---|
| Account and customer records | For the life of the account, then 7 years for tax and accounting |
| Billing and payment records | 7 years, as accounting law requires |
| Leads and form submissions | As directed by the customer who controls them, and deleted within 90 days of that customer's account closing |
| Data obtained from Meta | Only while needed for the service, and deleted on request, on disconnection, or when Meta requires |
| WhatsApp message content | 24 months, unless the customer sets a shorter period |
| Analytics and event data | 26 months, then aggregated or deleted |
| Server and security logs | 12 months |
| Marketing subscriber records | Until unsubscribe, plus a suppression record kept indefinitely so we do not contact you again |
| Backups | Expire on their normal cycle, within 90 days |
10. Security
We maintain administrative, physical, and technical safeguards designed to meet or exceed industry standards for the sensitivity of the data we hold. These include:
- Encryption of data in transit using TLS 1.2 or above, and encryption of stored data at rest.
- Access limited to staff who need it, reviewed at least annually and revoked when no longer required.
- Multi-factor authentication on remote administrative access.
- Automated review of application event logs, at least weekly.
- Penetration testing or vulnerability scanning at least once every 12 months.
- A documented incident response procedure with defined escalation steps.
- Access tokens and application secrets stored separately from application data, and never shared beyond the providers who help us run the service.
No system is perfectly secure, and we cannot guarantee absolute security. If you find a vulnerability, please report it to [email protected]. We investigate every report, and we will not pursue action against good-faith research that respects people's privacy and does not degrade the service.
11. Breach notification
If a breach affects personal information we hold, we will notify the affected customer without undue delay and in any case within 72 hours of becoming aware of it, tell you what we know about scope and impact, and keep you updated as we remediate. We notify regulators and affected individuals where the law requires it, and we report qualifying incidents to the platforms whose data is involved.
12. Your rights
12.1 If you are in the EEA or the UK
You have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent at any time without affecting processing already carried out. Contact [email protected]. We will not charge you or treat you differently for exercising these rights.
You also have the right to complain to your local supervisory authority. We would appreciate the chance to address your concern first.
12.2 If you are in California or another US state with a privacy law
You have the right to know what we collect and why, to access and delete it, to correct it, and to opt out of sale or sharing. We do not sell personal information, and we do not share it for cross-context behavioural advertising on our own account, so there is nothing to opt out of with us. If a business we work with does so through its own site, that business is the one to contact.
We do not use or disclose sensitive personal information beyond the purposes permitted without an opt-out. We will not discriminate against you for exercising your rights.
You can submit a request by emailing [email protected] or by using the contact form on the site of the business concerned. We verify requests by matching details against our records, and we may ask for confirmation from the email address on file. An authorised agent may act for you with written permission that we can verify.
If you are in Colorado, Connecticut, or Virginia and we decline a request, you may appeal by replying to our decision. We will respond to an appeal within 45 days.
12.3 Everyone else
Wherever you live, you can ask us what we hold about you, ask us to correct it, and ask us to delete it. We apply the same process regardless of location.
13. Deleting your data
To delete data linked to a Facebook or Instagram login, follow the Data Deletion Instructions.
To delete anything else, email [email protected] from the address on the record, and tell us what you want removed. We confirm within 30 days. We may keep the minimum needed to meet a legal obligation, resolve a dispute, or enforce our agreements, and we will tell you if that applies and why.
14. Cookies and similar technologies
We use cookies and similar technologies to keep you signed in, remember preferences, measure how sites are used, and support advertising measurement where a business has enabled it.
- Strictly necessary: sessions, authentication, security, and load balancing. These cannot be switched off.
- Analytics: page views, clicks, and conversion events, used to understand how a site performs.
- Advertising and measurement: the Meta pixel and similar tags, where the business running the site has enabled them.
Where the law requires consent, sites we operate ask for it before setting non-essential cookies, and you can change your choice at any time. You can also clear or block cookies in your browser, though strictly necessary ones are needed for sites to work.
15. Automated decisions and AI
We do not make decisions with legal or similarly significant effects about you by automated means alone.
Some Platform features use AI models to draft content, summarise enquiries, or answer questions on a business's behalf, and a customer chooses whether to switch them on. Where those features are used, output is a suggestion rather than a decision about a person. We do not use customer data, lead data, or message content obtained through Meta to train AI models, whether ours or a provider's.
16. Children
The Platform is built for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact [email protected] and we will delete it.
17. Changes to this policy
We may update this policy. The date at the top always shows the current version. If a change materially affects your rights we will give notice by email or in the admin interface before it takes effect. We review this policy at least annually.
18. Contact
Biznitos LTD
Registered in Jamaica
Privacy and data requests: [email protected]
Legal: [email protected]
Security: [email protected]
See also our Terms of Use and Data Deletion Instructions.