Dashboard privacy notice

Updated 9 September 2026 · PerBiotiX s. r. o.

Who is responsible

PerBiotiX s. r. o., Palárikova 2657, 022 01 Čadca, Slovakia, company ID 53074980, is the controller of personal data used in iProbio Dashboard. Contact us at admin@iprobio.sk about your data or this notice.

This notice covers our internal dashboard and its social-media integrations, including the Meta app named Cost Import (app ID 515143702894133). It covers staff and dashboard users, customers whose orders are imported, business contacts and people whose public social content is analysed. Our online shop has its own privacy notice.

What data the dashboard uses

  • Accounts and security: name, email, password hash, role and permissions, login times and IP addresses, verification records and trusted-device identifiers.
  • Orders and business reporting: customer names and emails, source identifiers, purchased items, order dates, amounts, discounts, refunds and payment or fulfilment status; customer segments and estimates of repeat purchasing.
  • Marketing and social media: connected account and Page identifiers, names and access tokens; campaign and ad information; public post text, links, images or available video, dates and engagement counts; aggregate advertising, website, email and audience statistics; internal content plans, notes and reports.
  • People administration: employee names, contact details, photos, roles, employment dates and working hours, onboarding, attendance, leave requests and approvals. Some absence categories, such as sickness or a doctor visit, can reveal health-related information.
  • Operations: partner and supplier contacts, invoices and costs, inventory and issue records, and the identities of people creating or approving records.

We receive these records from authorised users, company business systems and connected services, including our order feed, Meta, Google advertising and analytics, Microsoft Clarity and Klaviyo. Public social content comes from the relevant social network or publicly accessible sources. The data available depends on the integrations and permissions in use.

Why we process it

We use the dashboard to administer company access, measure sales and marketing, manage orders and business relationships, plan social content, and administer employment and attendance.

The applicable legal basis depends on the record and purpose: performance of contracts for customer, supplier and employment administration; legal obligations for required accounting and employment records; and our legitimate interests in securing our systems, understanding business performance and evaluating public marketing content. Where processing requires consent, it must be obtained for that specific use and can be withdrawn. Necessary employment-related health information is handled only within the applicable employment and social-protection conditions.

Account details are needed to provide dashboard access. Required transaction and employment records support the relevant contract or legal obligation. Connecting a social account is optional; without it, the corresponding integration cannot retrieve data.

Meta connections and trend scanning

Facebook authorisation lets an authorised person select business Pages and associated Instagram accounts for the dashboard. Access tokens are used on the server to request data permitted by Meta. We use public posts and aggregate performance information to identify themes, compare content and prepare reference links and internal recommendations. Access to public content from Pages we do not manage depends on Meta granting the relevant feature.

The scanner uses server rules to select sources and prioritise posts. Google Gemini assesses available post content and metrics for relevance, explains its recommendation and may suggest a content adaptation. The service may receive captions, links, metrics and available images or video for that assessment. New qualifying findings can appear in the dashboard and be sent to the designated internal email recipient. Staff decide what to publish.

The dashboard also calculates customer groups and repeat-purchase estimates from order history. These are decision-support tools; they do not themselves approve or refuse a service, change employment terms or make another decision with legal or similarly significant effects.

The separate Meta reviewer area uses an expiring access code and session. Facebook connections made there are isolated from company connections. The selected Page token is kept in an encrypted, short-lived browser cookie and is read only by our server. Demo save and dismiss choices are temporary; optional AI assessments send the selected public post to Gemini. Security and rate-limit events are logged without the access token or post text.

Who receives data and where it is processed

Company users receive access according to their role and assigned page permissions. Service providers support hosting, processing and delivery: DigitalOcean hosts the dashboard and database; Google Gemini API processes material submitted for AI analysis; Microsoft Exchange Online sends dashboard emails. Connected platform providers receive the authentication and API requests needed for their integration. Relevant company staff and advisers may also receive data necessary for their work or a legal obligation.

The dashboard is hosted in Frankfurt, Germany. Providers can also process personal data outside the European Economic Area, including through remote support and security operations.

For international transfers, DigitalOcean’s Data Processing Agreement provides Data Privacy Framework protection and Standard Contractual Clauses as a fallback in the circumstances specified in that agreement. The paid Gemini API terms incorporate Google’s Data Processing Addendum: transfers to certified Google entities in the United States use the EU–US Data Privacy Framework, while Standard Contractual Clauses apply where an applicable transfer solution is unavailable. Microsoft’s terms for Exchange Online provide the European Commission’s Standard Contractual Clauses for transfers outside the EEA.

The agreements are linked above. Contact admin@iprobio.sk for information about recipients, processing locations and the safeguards applicable to your data, including how to obtain a copy.

How long records remain

Business, customer, employment and accounting records are retained according to the purpose of the record, the continuing relationship, applicable retention duties and any need to establish or defend a claim. These records do not all have an automatic deletion date in the dashboard.

The active scanner removes unsaved posts and their metric snapshots outside its 30-day window during cleanup. Pausing the scanner can delay cleanup. Saved findings, daily scan archives, source-change history, feedback and delivery records do not currently have an automatic age cutoff. They require a specific deletion or retention review. Routine scan and application logs are generally cleaned after 90 days; some business audit records are retained with the underlying activity. Login history is generally cleaned after 180 days, with the latest successful login retained for an existing user.

Server backup cleanup is configured to remove daily copies older than approximately 14 days and monthly copies older than approximately 95 days, and to keep the five most recent pre-deployment copies. Pre-deployment and separately held backup copies can last longer. A deletion request therefore needs to address backups and exports as well as the live database; it is not completed merely by disconnecting an integration.

Cookies and access

The dashboard uses necessary cookies for login sessions, device verification, connection flows and reviewer access. These public information pages do not add an advertising tracker. Access to company records requires authentication and the appropriate permissions.

Your choices and rights

You can ask for access, correction, erasure or restriction of your personal data, object to processing based on legitimate interests, and request portability where it applies. You can withdraw consent for processing based on consent. These rights depend on the applicable legal conditions; retaining a record may still be necessary for a legal duty or claim.

Send a request to admin@iprobio.sk. We may request proportionate information to verify that the data relates to you. We will respond within one month; if a lawful extension is needed, we will explain it within that month. See data-deletion instructions for the information that helps us locate a record.

You may complain to the Office for Personal Data Protection of the Slovak Republic or the relevant supervisory authority in your country.