DRAFT FOR COUNSEL REVIEW. This text was written from the BSS data inventory and has not been approved. Every [[COUNSEL:field]] marker is an input that counsel and the owner must supply before this document can be approved.
BSS is operated by [[COUNSEL:controller-legal-name-and-address]] ("BSS", "we"). This policy explains what personal data BSS collects through bss.iq, app.bss.iq, admin.bss.iq and the BSS mobile app, why, who receives it, how long it is kept, and what you can do about it.
What we collect
We collect only what the service needs. The categories below match the data we store.
Account and sign-in data
Your name, email address, verified phone number, role, account type, language, governorate and city, and profile image. When you create an account we also record which version of the Terms of Service and this policy you accepted, and when. Your password is stored only as a hash. Sign in with a password is the only sign-in method in this version.
Security and session data
When you sign in we store a session: its token, its expiry, the IP address and the user agent of the device. Staff accounts also hold a two-factor secret and backup codes. One-time verification values (email links, phone codes) are kept until they are used or expire.
Abuse prevention data
To stop automated abuse we keep counters keyed by IP address, by device identifier and by email hash. The device identifier is a random value generated on your device. It is not used for advertising or tracking. Phone verification keeps the last four digits of your number, the status of the message and its identifier. The full number is sent to our SMS provider to deliver the code.
Company and verification data
If you represent a company: its name, contact details, description, logo, gallery and the verification documents you upload. Documents are stored in a private bucket and are seen only by BSS staff. Images can contain location data in their metadata.
Listings and reviews
The text, location coordinates, contact phone and email, and media of a listing you submit, and the notes of the staff who review it. A listing is public only when it is published.
Investor and service provider profiles
Investment ranges, interests, experience and coverage areas that you choose to enter. Other members can see them according to their membership tier. BSS staff can see them too.
Requests for information
When you ask the owner of a project for information we store your message and the contact method you share. The listing owner or company receives them. BSS staff see requests for listings that BSS manages.
Membership and payment records
Your membership tier and dates, and the payment record: amount, currency, transaction identifier, and for manual payments the reference and proof you provide. Card details are entered at our payment provider and are never seen by BSS.
Contact messages
If you write to us through the contact page: your name, email, phone number if you give it, your message and your language. We use them to answer you.
Saved items and notifications
The listings you save and the notifications we send you inside the service.
Staff accountability records
When staff change data, we record who did it and what changed. These records can contain member data and are kept for accountability.
Device push tokens
If you allow notifications in the mobile app, we store the push token of your device and an installation identifier.
How we use it
- To create and secure your account, and to verify your email and phone number.
- To verify companies, review and publish listings, and let members contact owners.
- To sell and manage memberships, and to keep the payment records the law requires.
- To prevent abuse and keep the service secure.
- To answer your messages and give support.
- To notify you about your account, listings, requests and membership.
We do not sell your data. We do not use it for advertising and we do not track you across other sites or apps.
Who receives your data
Some data is visible to other people by design. If you publish a listing or a company profile, the public sees what you publish. If you send a request for information, the listing owner or company receives your message and the contact details you chose to share. Investor and service provider profiles are visible to other members according to their tier.
We use these processors to run the service. They act on our instructions.
Convex
Convex hosts our database and server functions and therefore holds all the data described above. [[COUNSEL:convex-region-and-transfer-basis]]
Cloudflare
Cloudflare provides DNS, protection for our sites, storage for files and documents, and the bot check on some forms. It sees your IP address and request headers.
Vercel
Vercel hosts our websites. It sees your IP address and request logs.
Resend
Resend delivers our transactional email. It receives the recipient address and the content of the message.
OTPIQ
OTPIQ delivers phone verification codes by message. It receives your phone number.
Wayl
Wayl is the payment provider for memberships. It receives the amount, the transaction and the details you enter on its payment page.
Sentry
Sentry receives scrubbed error reports from our servers so that we can fix faults. Reports do not contain request bodies.
Expo push service
If you allow notifications in the mobile app, the Expo push service receives your device push token to deliver them.
Your data is processed outside Iraq, in the regions of these providers. [[COUNSEL:cross-border-transfer-wording]]
Cookies and device identifiers
We do not use advertising or analytics cookies and we show no cookie banner.
- bss.iq sets one cookie,
bss_locale, that remembers the language you chose. It is a functional cookie and is set only when you pick a language. - app.bss.iq sets
bss_locale, a session cookie that keeps you signed in, and a device cookie that holds the random device identifier used to prevent abuse. - admin.bss.iq sets staff session cookies.
The mobile app stores the device identifier and your session in secure storage on your device.
Retention
| Data | How long we keep it |
|---|---|
| Account and profile data | For the life of your account |
| Session records | Until the session expires, then cleaned up. [[COUNSEL:session-ip-retention]] |
| Abuse prevention counters | [[COUNSEL:rate-limit-retention]] |
| Phone and email verification records | Until used or expired. [[COUNSEL:otp-retention]] |
| Company data and documents | For the life of the company or account |
| Listings | Until archived or deleted |
| Requests for information | [[COUNSEL:lead-retention-days]] |
| Membership and payment records | [[COUNSEL:payment-record-retention]] |
| Contact messages | [[COUNSEL:contact-retention-days]] |
| Staff accountability records | [[COUNSEL:audit-retention]] |
| Queued delivery jobs (SMS, email, payment notices) | Until the job completes, plus a short period set by the job queue. [[COUNSEL:job-argument-retention]] |
| Email delivery records | For the delivery record window of the email component. [[COUNSEL:mail-record-window]] |
| Provider logs (Cloudflare, Vercel, Sentry) | According to each provider. [[COUNSEL:provider-log-retention]] |
Your rights
You can see and correct most of your data in your profile. You can ask us to give you a copy of your data, to correct it, or to delete it, by writing to the support mailbox listed on the support page from the email address on your account. [[COUNSEL:statutory-rights-wording]]
Deleting your account
You can delete your account yourself. In the mobile app open Settings and choose Delete account. On the web open Settings and choose Account. You confirm with your password.
When you delete your account, your profile is scrubbed and your account is closed. Your listings are archived and their contact details and media are cleared. Your investor or service provider profile, saved items and notifications are deleted. Payment and membership records are kept, with your user reference removed. Staff accountability records are kept as an identifier, with member data redacted. Messages you sent to listing owners are scrubbed.
Children
BSS is for adults. We do not knowingly collect data from anyone under [[COUNSEL:minimum-age]]. If you believe a child has given us data, write to support and we will delete it.
Contact
For questions about this policy or your data, use the support page.
Changes to this policy
When we change this policy we publish the new version here with a new version number and effective date. If a change affects your rights we tell you inside the service. The version in force is shown at the top of this page.