This Privacy Policy explains how data is processed in the BiDesignLab service available at bidesignlab.com, in particular in connection with creating Business Intelligence report projects, analysing data schemas with artificial intelligence (AI), designing KPIs and dashboards, and generating Power BI projects.
BiDesignLab is a tool for designing a reporting solution before connecting it to live production data.
This document has been prepared with regard to Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”).
1. Data controller and contact
The controller of personal data processed in connection with the use of BiDesignLab is:
BiDesignLab web service available at bidesignlab.com
Contact for personal-data matters, account deletion, and exercising GDPR rights:
podkowa71@gmail.com
If a Data Protection Officer is appointed in the future, their contact details will be published in this Privacy Policy.
2. What BiDesignLab is
BiDesignLab is a web application that lets you design a Business Intelligence solution before connecting live data.
Among other things, you can:
- define the business goal of the report
- provide table and column structure
- indicate the planned data source
- use AI analysis
- agree KPIs
- design the data model
- define report page structure
- design dashboards and visuals
- define the look of the report
- generate a package containing a Power BI project
BiDesignLab is not a system for storing your production data or for pulling data directly from your production databases.
In particular, you should not submit actual sales, customer, transaction, employee, or other production records unless that is necessary for a given feature.
Designing a solution only requires structure information, such as table names, column names, and data types.
3. What data we may process
Depending on how you use BiDesignLab, we may process the following categories of data.
3.1. Account data
If you create an account, we may process:
- email address
- password as an irreversible cryptographic hash — BiDesignLab does not store passwords in plain text
- Google account data if you sign in with Google: account identifier, email address, name, and profile picture if Google provides them
- account creation date and last activity
- interface language
- information about projects assigned to the account
- email verification status
If you sign in with Google, BiDesignLab receives the data Google shares through OAuth (scopes: openid, email, profile). BiDesignLab does not receive your Google account password.
3.2. Use without an account
Some features are available without registration. In that case the application may create a temporary guest identity (an identifier in a cookie) so project progress can be saved on your device. A guest does not need to provide an email address. After you create an account, guest progress may be transferred to the registered account.
4. Data entered while creating a project
While using Studio you may enter information about the BI solution you are designing, in particular:
- project name
- business area
- industry
- description of the report goal
- information about report users
- questions and answers about the project
- table names
- column names
- data types
- information about relationships between tables
- schema or header screenshots, if you upload them
- planned data-source information (source type, server name, or file path — without passwords)
- KPI definitions and descriptions
- report page names
- dashboard configuration
- filter and navigation settings
- report look-and-feel information
- company logo and background, if you choose to upload them
This data is stored in a PostgreSQL database linked to the project so you can continue, edit, generate the solution, and download the package again.
5. Data schema versus actual business data
A core function of BiDesignLab is analysis of data structure, not analysis of actual records.
You may provide, for example:
Sales Products Customers Date quantity unit_price region category
BiDesignLab uses this information to understand the structure of the future reporting model.
BiDesignLab does not require production records
To use the wizard you do not need to send:
- customer lists
- transaction history
- employee data
- actual sales values
- financial data
- database passwords
- credentials for production systems
You should limit submitted information to what is necessary to design the solution.
If you voluntarily place personal data or other confidential information in project-description fields, or paste production rows instead of a schema, that information may be processed as described in this Policy — including being sent to the AI provider as needed to perform the requested function.
6. Analysis using artificial intelligence
BiDesignLab uses artificial intelligence to support the BI design process. The AI model provider is OpenAI (API, GPT-family models).
AI may be used, among other things, to:
- analyse a data schema
- recognise tables and their purpose from a screenshot or pasted schema
- identify potential relationships
- recognise business context
- propose KPIs
- create project summaries
- propose report structure, pages, and visuals
- help you refine the project
Information sent to AI models may include project data, in particular the business description, table and column schema, KPI definitions, schema screenshots, and other information needed to perform a specific task.
Data is sent to OpenAI only to the extent needed for the relevant function. OpenAI processes it under its own terms and privacy policy: https://openai.com/policies/privacy-policy
BiDesignLab does not use user data to identify the user or to take decisions about the user that produce legal effects or similarly significant effects.
7. Whether data is used to train AI models
Data you submit to BiDesignLab is used to provide application functions, in particular project analysis and preparation of a BI solution.
BiDesignLab does not use user data to train its own AI models. BiDesignLab does not own or train its own language models.
AI analysis runs through the OpenAI API. Under OpenAI’s current API data-use rules, data sent via the API is not used by OpenAI to train their models unless that use is expressly enabled. BiDesignLab does not enable that use of data.
If OpenAI’s use of data changes, BiDesignLab will update the information in this Policy.
8. Generating the Power BI project
After the design process, BiDesignLab may generate a package containing, among other things:
- a Power BI project (.pbip)
- model information
- a list of measures
- page and visual configuration
- an implementation guide
- solution sketches for Tableau and Qlik
The project is generated from information you entered and accepted. The ZIP package is assembled in your browser at download time and is not stored as a lasting file on BiDesignLab servers. Project configuration remains in the database so the package can be generated again.
After download you open the project in Power BI Desktop yourself and configure connections to your data sources.
BiDesignLab does not receive data-source passwords
Passwords, tokens, credentials, and other data needed to connect to a production database are configured by you in Power BI Desktop, not in BiDesignLab.
9. Data sources indicated in the project
You may indicate that the report will use, among others:
- Excel
- CSV
- SQL Server
- PostgreSQL
- MySQL
- Oracle
- an existing Power BI project
Information about the planned data source (type, server name, database name, or file path) may be stored as part of project configuration. You may also upload an existing Power BI project (.zip / .pbip) solely to read model structure — not to pull production data rows.
Indicating a data-source type does not mean BiDesignLab obtains access to that source. BiDesignLab does not automatically connect to your production database to retrieve its data.
10. Logo and graphic materials
After creating an account you may be able to upload materials used to personalise the report, such as:
- company logo
- report background
- other graphic materials supported by the application
These materials are stored with the project in the database so the solution can be generated and edited later.
You should have the appropriate rights to materials you upload to BiDesignLab.
11. Technical data and logs
To ensure security, correct operation, and diagnostics we may automatically process technical data such as:
- IP address
- date and time of the connection
- browser information
- device information
- operating-system information
- information about operations performed in the application
- technical error information
This data may be used in particular for security, abuse detection, error diagnosis, application maintenance, and service stability. BiDesignLab does not currently use advertising tools or third-party marketing analytics.
13. Purposes and legal bases of processing
Providing the service and operating the account
The legal basis may be Article 6(1)(b) GDPR — processing necessary to perform a contract or to take steps at the user’s request before entering into a contract.
This covers, among other things, creating and operating the account, saving projects, processing the project, generating the package, and enabling download.
Security and correct operation of the service
The basis may be Article 6(1)(f) GDPR — the controller’s legitimate interest. This covers, among other things, system security, preventing abuse, diagnostics, infrastructure maintenance, and protection against unauthorised access.
Legal obligations
In certain situations data may be processed on the basis of Article 6(1)(c) GDPR in order to comply with legal obligations.
Consent
If specific processing requires consent, the basis will be Article 6(1)(a) GDPR. Consent will be collected separately and you may withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing before withdrawal.
15. Transfers outside the European Economic Area
Some service providers used by BiDesignLab — in particular OpenAI, Google, and Resend — may process data outside the European Economic Area, including in the United States.
Where such a transfer occurs, the controller uses GDPR-required mechanisms that ensure an adequate level of protection, in particular — where applicable — standard contractual clauses or other legally permitted transfer mechanisms.
Detailed information about providers and processing locations may also follow from each provider’s terms of service.
16. Retention periods
We store data for as long as needed to fulfil the purpose for which it was collected.
- account data — for the life of the account, unless law requires longer storage
- projects of a signed-in user — until the user deletes the project or the account
- projects abandoned at an early wizard stage (draft / first steps, with no further activity) — deleted after 30 days without updates
- email confirmation tokens — 24 hours
- session and guest cookies — up to 180 days
- technical data and server logs — for as long as needed for security and diagnostics
- the ZIP package — not stored lastingly on the server; after download the user is responsible for it
- data required for accounting or legal purposes — for the period required by applicable law
After the retention period, data is deleted or anonymised unless further storage is required by law.
17. Deleting an account or project
You can delete an individual project yourself in the application (project list). Deleting a project removes the related project information stored in BiDesignLab.
You may also request deletion of your account or remaining data. Send the request to:
podkowa71@gmail.com
Deleting an account means you lose access to saved projects and other features available only to signed-in users.
Some data may be retained if storage is required by law or is necessary to establish, exercise, or defend legal claims.
18. Your rights
To the extent provided by the GDPR, you have the right to:
- access your data
- obtain a copy of your data
- rectify your data
- erase your data
- restrict processing
- object to processing
- data portability — where applicable
- withdraw consent — if processing is based on consent
- lodge a complaint with a supervisory authority
Requests concerning personal data can be sent to: podkowa71@gmail.com
The controller may ask for information that confirms the identity of the person making the request, if that is necessary to protect the data.
19. Right to lodge a complaint
If you believe your data is being processed in a way that does not comply with the GDPR, you have the right to lodge a complaint with the competent supervisory authority.
In Poland the competent authority is the President of the Personal Data Protection Office (UODO).
20. Data security
The controller applies appropriate technical and organisational measures to protect data against unauthorised access, loss, destruction, unauthorised alteration, and disclosure to unauthorised persons.
In particular, email-account passwords are not stored in plain text, the session is maintained with HttpOnly cookies, and access to projects is limited to the account owner.
No internet service can guarantee absolute security of data transmission and storage.
21. Data relating to other people
You should use BiDesignLab in a way that does not submit other people’s personal data unless that is necessary.
In particular, a data schema should mainly contain table names, column names, and data types — not actual records.
If you voluntarily submit other people’s personal data, you should have an appropriate legal basis for doing so and ensure that this complies with applicable law.
22. Third-party services
BiDesignLab uses external technology providers, in particular for:
- hosting and a PostgreSQL database
- Google authentication
- AI (OpenAI API)
- sending email (Resend)
Using some features may cause the relevant provider to process data according to the scope of that service. If you sign in with Google, part of the authentication process uses Google infrastructure.
23. Automated decision-making
BiDesignLab uses AI to support you in designing a BI solution. AI may generate proposals for KPIs, the data model, report pages, charts, report structure, and look and feel.
Final decisions about the project are made by you. Each key stage can be accepted, changed, or rejected by you.
BiDesignLab does not use this mechanism to take decisions about you that produce legal effects or similarly significant effects.
24. An account is not required at the start
Some BiDesignLab features may be used without creating an account.
An account may be required in particular to save a project, return to it later, generate the package, download the Power BI project, and use features available only to signed-in users (including uploading a logo and background).
The Retail example may be offered as a demonstration of the application without registration.
25. Data in the downloaded Power BI project
After the project is generated you download the package to your own device. From that moment you are responsible for further storage and use of the downloaded project and for the security of data on your device.
The Power BI project does not automatically contain your production data merely because you indicated a data source in BiDesignLab. The actual connection to the data source and credential configuration take place in Power BI Desktop.
26. Changes to this Privacy Policy
This Privacy Policy may be updated from time to time, in particular if BiDesignLab functionality develops, the way data is processed changes, technology providers change, the law changes, or new features requiring additional processing are introduced.
The current version of the Privacy Policy is published on the BiDesignLab website. In the event of material changes, the controller may inform users in a manner appropriate to the nature of the change.
27. Contact
For matters concerning BiDesignLab, personal-data protection, account deletion, or questions about data processing, you can contact:
podkowa71@gmail.com
© 2026 BiDesignLab