Skip to content
Introducing The Council: the deliberation happens before you arrive. Learn more →
BGS
ProductCapabilitiesSystemTrust
ES|EN
Sign in to BGS Request my assessment
Product System Trust Sign in to BGS Request my assessment

Home · Privacy Policy

Privacy Policy

Last updated: September 2, 2026

This is an English translation of the original Spanish Política de Privacidad. In the event of any discrepancy between the two versions, the Spanish version shall prevail.

Contents

  1. Data controller
  2. What this policy applies to
  3. What BGS is
  4. Data we process on mibgs.com
  5. Purposes on mibgs.com
  6. Legal basis
  7. Commercial communications
  8. Data on the BGS platform
  9. Third-party services you connect
  10. Google: OAuth and Google Ads API
  11. What Google Ads information we process
  12. Tokens and credentials
  13. Isolation by organization
  14. Limited use of Google data
  15. Revocation and disconnection
  16. Retention periods
  17. Recipients and processors
  18. International transfers
  19. Your rights
  20. Security
  21. Automated analysis and decisions
  22. Changes to this policy

1. Data controller

The controller of the personal data collected through mibgs.com is the entity that currently operates the BGS platform and service:

Healthy Open Paths LLC (hereinafter, “HOP LLC”)

EIN: 30-1390773

Registered address: 1209 Mountain Rd Pl NE Ste N, Albuquerque, New Mexico 87110, United States

Contact address in Spain: Plaza del Duque de la Victoria, nº 1, Planta 2, Bloque 3, 41002 Sevilla, Spain

Email: admin@mibgs.com

BGS is a product, platform and service (a “Digital General Manager”) currently operated by HOP LLC until a separate BGS entity exists. When this policy refers to “BGS”, “we” or “the service”, it means HOP LLC in its capacity as operator.

The Seville address is provided solely as an operational and contact address in Spain. It is not HOP LLC’s registered office, nor does it, in itself, imply the appointment of a representative in the European Union for the purposes of Article 27 of the GDPR.

2. What this policy applies to

This policy covers two different things, with different roles. It is worth separating them from the outset, because your rights and whom you should contact depend on it.

  • The website mibgs.com. Here HOP LLC is the data controller: it decides what data is collected and for what purpose. This mainly concerns the assessment form and email communications. Sections 4 to 7 cover it in detail.
  • The platform app.mibgs.com. Here the client organization is the controller of the data it enters or connects, and HOP LLC acts as a data processor on its behalf, following its instructions and the data processing agreement signed. Sections 8 to 15 cover it in detail.

If you are an employee or collaborator of a client organization and wish to exercise your rights over the data that organization processes in BGS, please contact your organization first. We will assist it as appropriate.

Use of the website is also governed by the Legal notice; use of the platform, by the Terms of Service. The use of browser storage technologies is described on the Cookies page.

3. What BGS is

BGS is a multi-organization business management platform. It brings together in one place a company’s operational information — sales, financial, documentary and advertising — and, from it, produces reports, analyses and improvement recommendations for the people who run that company.

To gather that information, BGS allows an authorized user to connect services the company already uses (for example, its Google Ads account). BGS reads those services; it does not replace any of them.

One idea governs the entire product and explains much of this policy: BGS analyzes and proposes; people make the decisions. An analysis does not execute a change by itself.

4. Data we process on mibgs.com

On this site we process the data you provide when submitting the form on the assessment page (/en/diagnostic) or when writing to us by email, and, in aggregate form and without cookies, the site’s visit statistics:

  • Mandatory form data: name, company and email address.
  • Optional form data: website, how you heard about BGS and a free-text message in which you can describe your company or the question you wish to raise.
  • Origin of the visit: together with your request, we attach where your visit comes from (for example “Google”, “ChatGPT” or the name of a campaign), the page from which you reached the form and whether you were browsing on a mobile device or a computer. This information is not stored on your device — we do not use cookies or browser storage to obtain it — it is read at the time of submission from what your own browser already exposes and contains no identifiers that would allow you to be tracked across websites. It is kept together with your request and helps us know which contact channels work.
  • Communications data: if you write to us at admin@mibgs.com, we process your email address and the content of the message.
  • Site visit statistics: we use Netlify Analytics, an analytics tool that works on the server side: it compiles statistics from the logs of the server that handles your request, without installing cookies or writing anything to your device and without running any tracking code in your browser. To count distinct visitors, Netlify processes the IP address from which the request is made. We do not access individual IP addresses: we only see aggregate figures — page views, unique visitors, most visited pages, traffic sources, countries, resources not found and bandwidth — without any data that would allow you to be identified or tracked across websites. This data is kept for 7 days under the plan contracted, after which it is no longer available.

We do not request, and do not wish to receive, special categories of data (health, beliefs, etc.). Please do not include that type of information in the free-text message field.

The form’s hidden “anti-spam” field exists solely to detect automated submissions by bots and does not collect personal data from people.

5. Purposes on mibgs.com

We process your data to:

  • Manage and respond to the request you send us.
  • Contact you in relation to that request.
  • Carry out an initial study of your company based on the information you provide and available public sources.
  • Assess whether BGS can add value to your organization.
  • Prepare, where appropriate, a personalized assessment or proposal.
  • Manage communications related to your request.

That initial study is carried out by our team. We do not apply an artificial intelligence system to the assessment form that automatically analyzes your data to make decisions about your request.

6. Legal basis

For website data, the main legal basis is the performance of pre-contractual measures taken at the request of the data subject (Article 6(1)(b) GDPR): it is you who initiates contact by requesting an assessment with a view to a possible relationship with BGS, and we process your data to handle that request and, where appropriate, prepare a proposal.

Additionally, the handling of and response to enquiries that do not result in a pre-contractual relationship may be based on our legitimate interest in responding to the communications you send us (Article 6(1)(f) GDPR).

For aggregate visit statistics (Netlify Analytics), the legal basis is our legitimate interest in knowing the site’s reach and maintaining and improving it (Article 6(1)(f) GDPR). As they are compiled on the server side, without cookies or access to your device, they do not require consent under Article 22.2 of the LSSI (Spanish Information Society Services Act); and because this is data we only see in aggregate, the impact on your privacy is minimal. You may object to this processing under the terms of the rights section.

We do not use consent as the basis for this processing. The “I have read the Privacy Policy” checkbox on the form confirms that you were informed before submitting your data; it is not consent to processing and does not affect the legal basis above.

For data processed within the platform, the legal basis is determined by the client organization in its capacity as controller. Our processing as processor is based on the data processing agreement signed with it (Article 28 GDPR).

7. Commercial communications

We do not currently use the assessment form as a sign-up for newsletters or mass commercial campaigns. Submitting an assessment request does not mean agreeing to receive advertising.

If in the future we offer a newsletter or commercial communications, your consent will be requested separately and specifically, and you may withdraw it at any time.

8. Data on the BGS platform

Within app.mibgs.com, BGS processes the information the client organization enters or connects. In general:

  • User data: name, email address, BGS access credentials (always stored in non-reversible form), assigned role and the activity log needed for security and traceability.
  • The organization’s business data: the information the organization itself enters into the platform or that comes from the services it has connected.

This data is processed solely to provide the contracted service: gathering the information, presenting it, analyzing it and producing reports and recommendations for that organization.

9. Third-party services you connect

BGS can connect to services your organization already uses. The connection is always initiated by an authorized person and is made through each provider’s official authorization mechanisms.

  • BGS never asks you for the password of the third-party service. Authorization is granted on the provider’s own screen.
  • BGS only accesses what that authorization grants, and only the account that the authorized person has selected and linked to their organization.
  • When connecting a service, BGS receives information about the identity that authorized it (for example, their email address), in order to show who made the connection.
  • The connection can be withdrawn at any time (section 15).

10. Google: OAuth and Google Ads API

When an organization connects its Google Ads account to BGS:

  • Authorization is granted on Google’s official consent screen, using OAuth 2.0. BGS neither sees nor manages the Google account credentials.
  • BGS requests the Google Ads scope https://www.googleapis.com/auth/adwords. Google does not publish a read-only variant of this scope: it is granted in full. That BGS limits itself to reading is guaranteed by its own controls, described in this section and in section 21, and not by the nature of the scope.
  • BGS also requests the basic scopes openid, email and profile, used solely to identify which Google user granted the authorization.
  • Access is limited to the Google Ads accounts that authorization grants. BGS discovers on the server which ones they are, and the authorized person chooses one, which is linked to their organization.

Why we access it. To provide that organization with the functions it sees in the application itself: reports on its advertising activity, performance analysis, detection of problems and opportunities, improvement recommendations and, where applicable, the advertising management the organization expressly authorizes.

Current phase. BGS does not make changes to Google Ads accounts: it does not create, pause, enable or modify campaigns, budgets, bids or keywords. Write operations are disabled while the observation phase is being validated. Any change to the account is currently made by a person in Google Ads.

11. What Google Ads information we process

The general categories of information BGS obtains from the Google Ads API are:

  • Account settings: identifier, descriptive name, currency, time zone and status.
  • Advertising structure: campaigns, ad groups, ads, keywords, search terms, budgets and audience criteria.
  • Conversion actions and their measurement and attribution settings.
  • Performance metrics: impressions, clicks, cost, conversions, conversion value and impression share, together with the indicators we derive from them (CTR, CPC, conversion rate, cost per conversion and return on ad spend).

We do not request or receive identifying data about the people who see or click on the ads. The advertising information we process relates to the account’s settings and aggregate performance.

12. Tokens and credentials

When the connection is authorized, Google gives BGS technical credentials (access and refresh tokens) that allow the account to be queried without asking for permission each time. We handle them as follows:

  • They are stored encrypted, with a different key for each organization.
  • They are never displayed: not in the interface, reports, exports or activity logs, and they are never sent to the browser.
  • They are used only on our servers, at the time of querying the Google API, and are renewed automatically when they expire.
  • They are not shared with other client organizations or with third parties unrelated to the provision of the service.
  • They are deleted when the organization disconnects the service.

13. Isolation by organization

Each client organization operates in a separate data space. Its information, its credentials and the account it has linked belong to that space and that space only.

An organization cannot query, link or operate another organization’s Google Ads account. Access is always resolved on the server based on the session’s organization, never based on an identifier sent from the browser.

14. Limited use of Google data

BGS’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements (Limited Use).

In practice, and in relation to the data obtained from Google:

  • We use it solely to provide and improve the visible features of BGS for the organization that granted the authorization: reports, analyses, recommendations and, when expressly authorized, advertising management.
  • We do not sell it or transfer it to data brokers, advertising platforms or information resellers.
  • We do not use it for advertising purposes: not to serve ads, for remarketing, or for personalized or interest-based advertising outside the service itself.
  • We do not use it to determine creditworthiness or for lending purposes.
  • No person reads that data, except: when the organization has agreed to it with us (for example, authorized BGS staff providing analysis or support services on its behalf); when necessary for security reasons, such as investigating a bug or abuse; when required by law; or in aggregate form for internal operations in accordance with applicable regulations.
  • We only transfer data to providers when necessary to provide the service, under a data processing agreement, and we require the same compliance from our staff, collaborators and providers.

Artificial intelligence–assisted analysis. When an organization enables the AI-assisted analysis features, BGS may send a language model provider an aggregate extract of its information — for example, campaign names and performance figures — for the sole purpose of drafting the analysis text that organization will see in the application. Tokens and credentials are never sent. Those providers act as data processors and may only process the information to provide that service to us. An organization can operate BGS without enabling these features.

15. Revocation and disconnection

The authorization granted to BGS can be withdrawn at any time, through two independent routes:

  • From BGS. The “Disconnect” option for the connected service deletes the stored credentials and the link to the account. From that moment on, BGS no longer accesses the service.
  • From your Google account. You can withdraw the permission granted to BGS in your Google account’s security settings, at myaccount.google.com/permissions. You control this route directly and it does not depend on us.

Disconnecting a service does not, by itself, delete reports already generated within the platform. The organization may request their deletion in accordance with the following section.

16. Retention periods

On the website. We keep the data from requests that do not lead to a contractual relationship for a maximum of 12 months from the last interaction, unless there is a legal obligation or need that justifies a different period. If the request leads to a contractual relationship, we will keep the data for the duration of that relationship and, thereafter, for the periods required by the applicable contractual, tax and accounting obligations, after which it will be deleted or blocked in accordance with the regulations.

Visit statistics. Aggregate Netlify Analytics data is kept for 7 days, under the plan contracted; after that period it is no longer available. It does not generate any record associated with an identified person.

On the platform. We keep the data for as long as the relationship with the client organization lasts and in accordance with its instructions. The credentials for a connected service are deleted when it is disconnected. Once the relationship ends, we delete or return the data as agreed in the data processing agreement, unless there is a legal obligation to retain it.

17. Recipients and data processors

We do not sell your data or transfer it to third parties for commercial purposes. To provide the service we use providers that act as data processors, under a data processing agreement and with appropriate safeguards:

  • Netlify, Inc. — website hosting, handling of form submissions (Netlify Forms) and site visit statistics (Netlify Analytics). Netlify stores the requests submitted through the form and compiles aggregate visit statistics from its server logs, without cookies.
  • Microsoft (Microsoft 365 / Outlook) — email service for communications through admin@mibgs.com.
  • Infrastructure provider — hosting of the servers on which the app.mibgs.com platform runs.
  • Language model providers — only when the organization enables the AI-assisted analysis features described in section 14.
  • Payment provider — when the service is to be invoiced.

The complete, up-to-date list of processors involved in providing the service to each client organization forms part of its data processing agreement and is available on request at admin@mibgs.com.

We may disclose data to authorities or third parties when required by a legal obligation.

18. International transfers

Since HOP LLC is a United States entity and some of our providers are established in, or process data in, the United States, processing may involve international data transfers outside the European Economic Area.

These transfers are carried out with the safeguards provided for in the GDPR:

  • Netlify, Inc. (United States) is certified under the EU-U.S. Data Privacy Framework and, failing that, bases transfers on the European Commission’s Standard Contractual Clauses (Implementing Decision 2021/914), in accordance with its current Data Processing Agreement (DPA).
  • Microsoft likewise offers appropriate safeguards through its participation in the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses.
  • The other processors located outside the European Economic Area base transfers on Standard Contractual Clauses and/or their participation in the EU-U.S. Data Privacy Framework, as applicable to each.
  • The transfer of your data to HOP LLC, in its capacity as controller in the United States, is necessary to handle the request you yourself initiate and, where appropriate, prepare a proposal (Article 49(1)(b) GDPR), without prejudice to the additional safeguards that apply.

You can ask us for more information about these safeguards by writing to admin@mibgs.com.

19. Your rights

You may exercise the following rights over your data at any time:

  • Access to your personal data.
  • Rectification of inaccurate data.
  • Erasure of your data.
  • Objection to processing.
  • Restriction of processing.
  • Portability of data, where applicable.
  • Withdrawal of consent, where processing is based on it.

To exercise them, write to us at admin@mibgs.com stating the right you wish to exercise. We may ask you to verify your identity.

If your data is processed by a client organization within the platform, contact that organization first: it decides on that processing. If you write to us, we will guide you and forward the request to the appropriate party.

If you believe we have not properly handled your rights, you have the right to lodge a complaint with the competent supervisory authority. In Spain, the Spanish Data Protection Agency (AEPD) — www.aepd.es.

20. Security

We apply appropriate technical and organizational measures to protect data against loss, misuse or unauthorized access, taking into account the state of the art, costs and the nature of the data. Among others:

  • All traffic, for both the site and the platform, travels encrypted (HTTPS).
  • Credentials for connected services are stored encrypted, with a different key per organization, and are never displayed (section 12).
  • Each organization’s data spaces are separated from one another (section 13).
  • Access to the platform requires identification, and relevant actions are logged for traceability. Those logs contain no credentials.
  • Our staff’s access to an organization’s data is limited to what is necessary to provide the agreed service.

No system can guarantee absolute security, so we offer no unconditional guarantees in this respect.

21. Automated analysis and decisions

BGS automatically analyzes the information gathered and produces reports, signals and recommendations. It is worth being precise about what this means and what it does not.

  • That analysis does not make decisions that produce legal or similarly significant effects on people, nor does it build profiles or scores about them. It concerns the organization’s business, not its people.
  • A recommendation is not an action. For a change with an external effect to be executed, the approval of an authorized person is required, and it is recorded.
  • With regard to Google Ads, and as stated in section 10, BGS does not currently execute any change on the accounts: write operations are disabled.

If in the future we introduce automated processing that produces legal or similarly significant effects on people, we will update this policy and provide information on the logic involved and the related rights before applying it.

22. Changes to this policy

We may update this Privacy Policy to reflect legal changes or changes in how the service works. We will always publish the current version on this same page, with its last updated date. If a change substantially affects the processing of a client organization’s data, we will notify it through the channels set out in its contract.

BGS

The Digital General Manager. An Executive Management System that works under your supervision.

Product
The RadarThe CouncilThe Sign-offIntegrationsSign in to BGS
Learn more
What is a Digital General ManagerSecurity and controlBGS and ChatGPTAssessment
Legal
PrivacyTermsLegal noticeCookies
© 2026 BGS · Operated by Healthy Open Paths LLCYou decide · you sign off · nothing sensitive runs on its own