Skip to content

Product

Let’s talk
Back to the home page

Privacy Policy

How we handle the personal data of people who visit this site, who contact us, and who use LBD Business Communicator. Drawn up under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

Last updated September 19, 2026·LBD S.r.l.

This policy separates two situations that are easy to confuse. When you visit b-comm.io or write to us, we are the data controller. When your data ends up inside the product because you messaged a company that uses it, that company is the controller and we are only its processor: in that case you need to go to them, and below we explain why, and what we do to protect you anyway.

01Data controller

LBD S.r.l., Via Maso della Pieve 4C, 39100 Bolzano (BZ), Italy — VAT 03305620217, REA BZ-249001.

For anything concerning personal data: [email protected], or +39 0471 362875 (Monday to Friday, 09:00–13:00 CET). We have not appointed a Data Protection Officer, as the conditions in Art. 37 GDPR do not apply; requests sent to that address are handled by the controller.

02Scope

This policy covers: (a) browsing b-comm.io; (b) the contact you send us by email or telephone; (c) managing the contractual relationship with our customers.

It does not cover the processing a customer company carries out through the product on its own contacts’ data: for that, the controller is the company you are talking to, and it must give you its own privacy notice. The section "When we are a processor, not a controller" explains what we do in that case.

03Data processed on this website

Browsing data

The systems serving the site automatically record some technical data needed for operation and security: IP address, date and time of the request, page requested, response status, browser and operating system type, preferred language. This data is not used to identify you or to profile you, and is not combined with other sources.

Data you give us

There is no contact form on this site: if you want to write to us you do it from your own mailbox, at [email protected]. In that case we process the data you chose to include in the message — typically name, email address, company and the content of the enquiry. The same goes for phone calls: we record any notes taken during the call, not the call itself.

Cookies and similar technologies

The site uses technical cookies only, described in detail in the Cookie Policy. There are no profiling cookies and no third-party analytics; should we introduce any in future, they will be activated only with your prior consent collected through the banner.

04Purposes and legal bases

PurposeLegal basisRetention
Serving the website and keeping it secure and workingLegitimate interest (Art. 6.1.f) in the security and continuity of the serviceTechnical logs: 12 months maximum
Answering enquiries and preparing a possible offerPre-contractual steps at the data subject’s request (Art. 6.1.b)24 months from the last contact, if nothing follows
Managing the customer agreement and supportPerformance of a contract (Art. 6.1.b)Term of the agreement plus 10 years for civil-law obligations
Meeting tax, accounting and other legal obligationsLegal obligation (Art. 6.1.c)10 years (Art. 2220 Italian Civil Code)
Establishing or defending a legal claimLegitimate interest (Art. 6.1.f) in protecting our rightsUntil the dispute and any appeal deadlines are exhausted
Sending product update notices to active customersLegitimate interest (Art. 6.1.f), with the right to object at any timeUntil you object or the relationship ends

Providing data is voluntary. Without the minimum necessary data, however, we cannot answer an enquiry or manage an agreement: the only consequence of declining is that we cannot deliver what was asked for.

05Who receives the data

Data may be accessed by LBD’s authorised staff, instructed under Art. 29 GDPR, and disclosed to suppliers acting as processors appointed under Art. 28 GDPR. We do not sell personal data and do not disclose it to third parties for their own marketing purposes.

Data may also be disclosed to tax and legal advisers, to banks for collection, and to authorities where required by law or by an order.

06Suppliers and sub-processors

The suppliers currently used to run the site and the product are listed below. Some are involved only if the customer activates the corresponding feature.

SupplierRoleLocation
Hetzner Online GmbHServer infrastructure and storageGermany (EU)
Cloudflare, Inc.DNS, content delivery, attack protectionEU / United States
Amazon Web Services EMEA SARLSending and receiving the product’s emailEuropean Union
Anthropic PBCArtificial intelligence models for repliesUnited States
Voyage AI, Inc.Semantic indexing of contentUnited States
OpenAI, L.L.C.Semantic indexing, as a fallback onlyUnited States
Meta Platforms Ireland LtdWhatsApp Business, Messenger and Instagram channelsIreland (EU)
Aircall SASTelephone channel, if activated by the customerFrance (EU)
Google Ireland LtdPush notifications in the app and maps for location messagesIreland (EU)

The list is current as at the date of this policy. Customers who have signed the DPA receive advance notice of changes to sub-processors and may object within the terms set out there.

07Transfers outside the European Union

The main infrastructure and the product data reside in the European Union. Some of the suppliers listed above are based in the United States: transfers to them rely on the Standard Contractual Clauses approved by the European Commission (Decision 2021/914) and, where applicable, on the supplier’s certification under the EU–US Data Privacy Framework, together with supplementary measures such as encryption in transit and minimisation of the data transmitted.

Artificial intelligence providers receive only the content strictly necessary to generate the reply. That content is not used to train their models.

08Retention

Retention periods are set out in the purposes table. At the end of the period, data is deleted or irreversibly anonymised, unless a legal provision requires longer retention or the data is needed to establish, exercise or defend a legal claim.

09Your rights

You may exercise the rights under Articles 15–22 GDPR at any time:

  • access: find out whether we process your data and obtain a copy of it;
  • rectification: correct inaccurate data or complete incomplete data;
  • erasure: have data deleted, in the cases provided by law;
  • restriction: ask that data be stored but not further processed;
  • portability: receive data in a structured, machine-readable format, or have it transmitted to another controller;
  • objection: object to processing based on legitimate interest, including direct marketing, at any time and without giving reasons;
  • withdrawal of consent: where processing is based on consent, withdraw it, without affecting the lawfulness of processing already carried out.

To exercise them, write to [email protected]. We reply without undue delay and in any case within one month, extendable by two months for complex requests, in which case we explain why. Exercising your rights is free, except for manifestly unfounded or excessive requests.

You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — garanteprivacy.it) or with the supervisory authority of the Member State where you live.

10Automated decision-making and profiling

We do not take decisions based solely on automated processing that produce legal effects or similarly significantly affect people, within the meaning of Art. 22 GDPR.

The product includes an artificial intelligence agent that drafts automated replies to incoming messages. That agent does not take decisions about people: when a request falls outside the configured perimeter, the conversation is handed to a human agent. The hand-off rules are configured by the customer company, which remains the controller.

11When we are a processor, not a controller

If you wrote to a company that uses LBD Business Communicator — on its website, on WhatsApp, by email or from its app — your data is in that company’s workspace. That company decides why and how it is processed, and it is the one to approach to exercise your rights. We process it only on its instructions, to make the service work for it.

If you write to us anyway, since we cannot dispose of that data ourselves, we will forward your request to the controlling company where we are able to identify it, and tell you that we have done so.

With our customers we apply a Data Processing Agreement compliant with Art. 28 GDPR, covering instructions, confidentiality, security measures, use of sub-processors, assistance with data subject requests, breach notification, audits, and return or deletion of data at the end of the relationship.

12Security measures

We adopt technical and organisational measures appropriate to the risk, including:

  • encryption of traffic in transit on all public channels;
  • separation of data between customer companies enforced by the database itself, as well as by the application;
  • separation of content between the different audiences each customer configures;
  • agent authentication through a dedicated identity system, with granular roles and permissions;
  • audit logs of the operations agents perform;
  • system access limited to authorised staff, on a least-privilege basis;
  • periodic backups and restore procedures;
  • regular updating of software components and monitoring of known vulnerabilities.

13Personal data breaches

In the event of a personal data breach we notify the supervisory authority within 72 hours of becoming aware of it, where the legal conditions are met, and inform data subjects where the breach is likely to result in a high risk to their rights and freedoms. Where we act as processor, we inform the controlling customer without undue delay so that it can meet its own obligations.

14Children

The site and the product are aimed at professionals and businesses and are not intended for children under 16. We do not knowingly collect children’s data. If you believe a child has given us personal data, write to us and we will delete it.

15Changes to this policy

We may update this policy to reflect changes in the service, in our suppliers or in the law. The version in force is always the one published on this page, with its last-updated date. We inform customers by email of material changes.