Privacy Policy
Last updated: June 30, 2026
1. Data controller
BICODE SAS, a commercial company identified with NIT 901081283 and domiciled in Colombia, is the data controller for personal data collected and processed through SODANA, the SaaS platform for social media analytics and artificial intelligence-assisted content generation.
For requests, inquiries, or claims related to personal data, you may contact us at info@bicode.co or through the channels made available by the Platform at any given time.
2. Scope of this policy
This Privacy Policy explains how BICODE collects, uses, stores, shares, transmits, protects, and retains personal data when the User accesses, registers for, connects accounts to, contracts, or uses SODANA.
Personal data processing is carried out in accordance with applicable Colombian personal data protection law, including Law 1581 of 2012, its regulatory decrees, and any rules that amend or replace them.
BICODE will process personal data in accordance with Colombian law and, when applicable by territoriality, international offering, digital behavior, or distribution channel, will endeavor to align its practices with complementary standards of privacy, transparency, security, and rights management of other jurisdictions. Colombian law requires prior, express, and informed authorization for the processing of personal data and recognizes rights of consultation, rectification, update, deletion, and revocation where applicable.
3. Personal data processed
BICODE may collect and process the following categories of data, depending on how the User uses the Platform:
- Identification and contact data, such as name, email address, user identifiers, and avatar.
- Billing, subscription, contracted plan, payment status, and commercial relationship records.
- Browsing, usage, security, technical logs, IP address, authentication events, audit, and diagnostic data.
- Data from social media accounts authorized by the User, including identifiers, public profile, posts, videos, channels, metrics, comments, statistics, granted permissions, and OAuth tokens.
- Inputs provided by the User, such as briefs, URLs, PDFs, brand information, calendars, preferences, settings, and files.
- Generated Content produced by the Platform, including analyses, ideas, recommendations, classifications, scripts, storyboards, reports, summaries, and artificial intelligence-assisted results.
- Workspace data, members, roles, permissions, notification preferences, and operational settings.
BICODE does not request or store passwords for Instagram, Facebook, TikTok, Google/YouTube, or other connected social networks. Connections with those platforms are made through OAuth authorization mechanisms or other official mechanisms from integrated third parties.
4. Purposes of processing
Personal data may be processed for the following purposes:
- Create, administer, authenticate, and protect User accounts and workspaces.
- Connect authorized social media accounts and process the information necessary to provide the service.
- Display analytics, metrics, reports, dashboards, comparisons, trends, and performance results.
- Generate, organize, and present ideas, recommendations, scripts, storyboards, analyses, and other Generated Content.
- Execute artificial intelligence-assisted features, semantic search, content analysis, comment analysis, and brand intelligence.
- Manage plans, payments, billing, support, operational communications, notifications, and request handling.
- Prevent fraud, unauthorized access, security incidents, Platform abuse, or contractual breaches.
- Audit events, diagnose errors, monitor availability, and improve security, performance, and user experience.
- Comply with legal, contractual, accounting, tax, regulatory obligations, or requests from competent authorities.
- Defend the rights of BICODE, Users, third parties, or the Platform in disputes, claims, or incidents.
5. Bases that enable processing
Processing is based, as applicable, on:
- The data subject's prior, express, and informed authorization.
- The performance of the contractual or pre-contractual relationship with the User or Client.
- Compliance with legal obligations applicable to BICODE.
- BICODE's legitimate interest in operating, securing, improving, and protecting the Platform, when appropriate under applicable law.
Authorization must be obtained before processing when required, and BICODE may retain evidence of the consent granted, including the accepted text version, date, time, user, channel, IP, and other reasonable technical identifiers.
6. Third parties, transmission, and transfer
BICODE may share personal data with processors, technology providers, operating partners, and integrated third parties when necessary to operate the Platform or fulfill the informed purposes.
These third parties may include providers of authentication, cloud infrastructure, databases, storage, analytics, monitoring, payments, transactional email, artificial intelligence, and social networks connected by the User.
Where national or international transmission or transfer of data occurs, BICODE will adopt reasonable security, confidentiality, and contractual control measures according to each third party's role and applicable regulations.
BICODE does not sell personal data.
7. Artificial intelligence and Generated Content
The Platform includes artificial intelligence-assisted features to generate ideas, recommendations, classifications, drafts, summaries, and other creative or analytical inputs.
To provide these features, BICODE may process inputs provided by the User, connected account data, brand information, metrics, comments, files, URLs, and Generated Content.
AI-generated results may be incomplete, inaccurate, biased, approximate, outdated, or inappropriate for certain contexts. The User must review and validate Generated Content before using it.
8. Cookies and similar technologies
The Platform may use cookies, pixels, SDKs, local storage, and similar technologies for authentication, security, measurement, personalization, analytics, and service improvement.
Necessary cookies are essential for the basic operation of the Platform. Functional, analytics, or marketing cookies will be used only to the extent permitted by law and, when required, with the User's consent.
Where applicable, the Platform may include a banner or preference center to accept, reject, or configure non-essential cookies. The User may also modify preferences through the available settings or through their browser.
9. Data retention
Personal data will be retained for the time necessary to fulfill the informed purposes, while the contractual relationship remains in effect, while there is a legal obligation, or while necessary to defend rights.
When processing is no longer necessary, BICODE may delete, anonymize, block, or retain data only to the extent required or permitted by applicable law.
Some data may remain for limited periods in backups, logs, audit records, accounting support, consent evidence, fraud prevention, or dispute handling.
10. Security
BICODE will implement reasonable technical, administrative, and organizational measures to protect information against unauthorized access, loss, misuse, alteration, disclosure, or destruction.
These measures may include authentication controls, workspace segregation, permission control, security validations, event monitoring, encryption or equivalent mechanisms where appropriate, and provider management.
No security measure implies an absolute guarantee of invulnerability.
11. Data subject rights
The personal data subject may exercise the rights of access, update, rectification, deletion, revocation of authorization, consultation, and claim, in the cases and under the conditions provided by applicable law.
To exercise these rights, the data subject may submit a request to info@bicode.co or through the channel made available by the Platform at any given time. The request must allow identification of the data subject, clearly describe the petition, and provide the information necessary to handle it.
BICODE will respond to inquiries and claims within the terms provided by applicable Colombian regulations.
12. Minors
The Platform is not directed to minors, unless expressly indicated otherwise. If BICODE identifies that it has collected data from a minor without valid authorization when required, it will adopt reasonable measures for deletion or handling in accordance with the law.
13. Changes to this policy
BICODE may modify this Privacy Policy at any time. The current version will be the one published on the Platform or the one expressly indicated as applicable.
Continued use of the Platform after changes are published will constitute acceptance of the new version, unless the law requires an additional mechanism.
14. Contact
For questions, inquiries, claims, or requests related to this Privacy Policy or personal data processing, you may contact:
BICODE SAS
NIT: 901081283
Email: info@bicode.co
Website: https://app.sodana.ai