Bizzmon Privacy Policy
Effective Date: September 23, 2026 • Last Revised: September 2026 • Version 2.1
1. Corporate Entity & Scope of Policy
This Privacy Policy governs the manner in which Bizzmon Technologies Inc. ("Bizzmon", "we", "us", or "our"), operating the primary web domain bizzmon.com (often referenced in commercial search contexts as Bizmon, Bizz Monitor, or Business Monitor), collects, processes, maintains, stores, and discloses information gathered from registered users, website visitors, and corporate account holders ("User", "you", or "your").
By accessing bizzmon.com, registering an account, connecting third-party analytics telemetry through our authorized OAuth protocols, or submitting experimental hypotheses to our platform, you acknowledge and agree to the data collection and processing practices described within this document. If you do not agree with the terms outlined herein, you must immediately terminate platform access and revoke API authorizations.
2. Categories of Information We Collect
Bizzmon collects both direct personal information and indirect telemetry data strictly required to calculate before-and-after baseline metrics, execute observation windows, and dispatch conclusive milestone evaluations:
- Account Authentication Credentials: Full legal name, professional email address, account password hashes (encrypted via Argon2id), billing company identifiers, and contact preferences.
- Read-Only Search Console & Analytics Telemetry: Aggregated search performance metrics retrieved through official Google Search Console API scopes (clicks, impressions, average click-through rate, and average keyword positions grouped at the URL level). We do not request or possess write access to your webmaster properties.
- YouTube Reporting & Analytics Telemetry: Video-level performance metrics retrieved through official Google OAuth read-only scopes (video identifiers, publication timestamps, impression click-through rate, total views, and average view duration). We never request permissions to edit videos, manage channels, or post community commentary.
- User-Logged Experiment Records: Modification timestamps, URLs under observation, categorical intervention types (title rewrites, meta revisions, content pruning operations, schema additions, internal linking adjustments, or thumbnail replacements), and custom hypothesis notes.
- Technical Session Logs: Internet Protocol (IP) addresses, browser type, operating system details, referring URLs, device telemetry, and timestamped API interactions gathered for rate limiting, DDoS mitigation, and platform integrity enforcement.
3. Purpose of Data Processing
We process collected information under legitimate business interests, contractual necessity, and user consent for the following explicit purposes:
- Establishing Frozen Day 0 Baselines: Mathematically locking a 30-day pre-intervention performance snapshot to serve as the uncorrupted control standard for your website or video experiment.
- Executing Scientific Observation Windows: Continuously aggregating post-change telemetry across 7, 14, 30, and 60-day cycles to evaluate statistical significance and trajectory deltas.
- Generating Automated Milestone Reports: Synthesizing causal attribution summaries and delivering completed checkpoint assessments directly to user-designated email addresses or team messaging endpoints.
- Filtering Search Engine Macro Shocks: Correlating your monitored metrics against global Google Broad Core Updates to separate algorithmic volatility from your internal optimizations.
- Billing & Account Administration: Processing monthly subscription fees through PCI-DSS Level 1 compliant merchant payment gateways, managing tier quotas, and verifying beta participant entitlements.
4. Absolute Data Isolation & Zero Selling Pledge
Bizzmon adheres to a strict data isolation policy designed to protect publishers and creators from competitive surveillance. We enforce the following non-negotiable standards:
- No Data Selling or Monetization: We never sell, rent, license, trade, or distribute your private website URLs, keyword rankings, traffic volumes, or experimental outcomes to third-party data brokers, advertising aggregators, or marketing competitors.
- Zero Cross-Account Data Leakage: Your telemetry is isolated inside tenant-partitioned database tables. The experiments of Company A are strictly invisible to Company B.
- White-Label Data Ingestion: Telemetry ingested from official APIs is processed through isolated processing pipelines without retaining unencrypted customer payload logs.
5. Stealth Mode & Cryptographic Redaction
Bizzmon provides a proprietary Stealth Case Study Sharing engine allowing practitioners to demonstrate verified percentage wins without sacrificing trade secrets:
When a user exports or shares an experiment report in Stealth Mode, the Bizzmon platform automatically strips all top-level domains, exact URL paths, brand entity identifiers, and specific keyword strings. The exported infographic or summary card retains mathematical percentage gains (+53.5% clicks, +85.7% CTR) alongside an immutable cryptographic verification hash, confirming the legitimacy of the experiment without exposing your commercial niche or proprietary tactics.
6. Security Safeguards & Storage Architecture
We implement defense-in-depth technical and organizational security controls to protect your data against unauthorized access, loss, destruction, or alteration:
- Encryption in Transit: All data transmitted between your browser, our Cloudflare edge nodes, and our origin infrastructure is encrypted using Transport Layer Security (TLS 1.3) protocols.
- Encryption at Rest: All database records, user profiles, API OAuth tokens, and historical experiment snapshots are stored using AES-256 bit hardware-level encryption.
- OAuth Token Isolation: Third-party OAuth tokens granted for Google Search Console and YouTube Analytics are stored in dedicated encrypted key vaults with restricted programmatic access. Tokens can be revoked by the user at any instant directly through their Google Account permissions dashboard.
7. International Data Protection Rights (GDPR & CCPA Compliance)
Regardless of your geographic location, Bizzmon affords all account holders comprehensive data privacy rights in full alignment with the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA):
- Right to Access: You have the right to request a complete machine-readable copy (JSON or CSV format) of all personal data, connected properties, and experiment records held by Bizzmon.
- Right to Rectification: You have the right to modify or update inaccurate personal identifiers or property assignments through your account dashboard.
- Right to Erasure ("Right to be Forgotten"): You may request permanent deletion of your account, API tokens, and historical baseline records. Upon receipt of a verified deletion request, all tenant data is permanently wiped from production databases within 30 business days.
- Right to Restrict Processing & Revoke Consent: You retain the perpetual right to disconnect connected digital properties and revoke API access at will.
8. Data Retention Schedules & Automated Pruning
Bizzmon enforces strict data minimization protocols. We retain telemetry and personal information only as long as necessary to provide active tracking services and fulfill statutory compliance mandates:
- Active Experiment Telemetry: Frozen Day 0 baseline checkpoints, URL metadata, and milestone delta records are maintained for the active duration of the user account plus twelve (12) months following subscription cancellation, allowing seamless historical resumption upon reactivated billing.
- OAuth Refresh Tokens: Stored securely in encrypted key vaults until explicitly disconnected by the user or invalidated by the issuing provider (Google). Upon disconnection, tokens are purged immediately from memory and permanent storage within twenty-four (24) hours.
- Edge Gateway & Firewall Logs: IP addresses and HTTP request metadata captured at our Cloudflare edge proxies are retained for thirty (30) days for intrusion detection and DDoS monitoring, after which they are permanently overwritten.
9. Authorized Third-Party Subprocessors
To deliver edge-accelerated static delivery, encrypted database storage, and transactional notification routing, Bizzmon engages a limited roster of certified enterprise subprocessors. Every subprocessor is bound by strict Data Processing Addendums (DPAs) guaranteeing equivalent privacy protections:
- Cloudflare Inc. (United States & Global Edge): Global content delivery network, edge security, DDoS mitigation, and SSL/TLS termination. Certified under SOC 2 Type II and ISO 27001.
- PostgreSQL Enterprise Infrastructure: Isolated database hosting with AES-256 disk encryption at rest, automated multi-zone failover, and strict tenant access isolation.
- Transactional Communication Infrastructure: Direct SMTP/API email delivery used exclusively to dispatch requested milestone reports and account verification links. No subscriber data is made available for commercial advertising or promotional mailing lists.
10. Security Breach Notification Protocol
In the unlikely event of a confirmed security incident impacting the confidentiality, integrity, or availability of personal data, Bizzmon maintains an emergency response protocol complying with European Union GDPR Article 33 requirements:
We will notify affected account holders and relevant supervisory authorities without undue delay and, where feasible, not later than seventy-two (72) hours after becoming aware of the incident. Such notification will describe the nature of the breach, the categories of data affected, the likely consequences, and the remediation measures deployed.
11. Cookie Notice & Local Storage
Bizzmon utilizes strict session cookies and local storage tokens solely for authentication persistence, session security, and user interface preferences (such as light/dark theme toggles or active property selections). We do not deploy third-party advertising tracking cookies, cross-site profiling scripts, or behavioral data broker beacons.
12. Contact the Data Protection Officer
If you have questions regarding this Privacy Policy, wish to exercise your statutory privacy rights, or need to report a security inquiry, please contact our designated privacy and legal team:
Bizzmon Technologies Inc.
Attention: Data Protection & Legal Affairs
Email: privacy@bizzmon.com
Secondary Inquiries: legal@bizzmon.com
Headquarters: bizzmon.com • Primary Domain Infrastructure