Privacy Policy
Effective date: 1 September 2026
1. Who We Are
BeaverFlow ("we", "our", "us") operates the BeaverFlow Platform platform and related services. This Privacy Policy explains how we collect, use, and protect personal data when you use our website or Service.
Data controller contact: [email protected]
2. Data We Collect
We may collect the following categories of personal data:
- Account data: name, business email address, company name, phone number.
- Usage data: pages visited, features used, session duration, IP address, browser type.
- Support data: messages and files you send when contacting our support team.
- Transaction data: subscription plan, billing period, payment status (we do not store card numbers — payments are processed by our PCI-compliant payment processor).
3. How We Use Your Data
We use personal data to:
- Provision, operate, and improve the Service.
- Process orders and manage your subscription.
- Send transactional emails (order confirmations, invoices, service notifications).
- Respond to support requests.
- Send marketing communications (only with your consent, which you may withdraw at any time).
- Comply with legal obligations.
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area and the UK, we process personal data on the following legal bases:
- Contract: processing necessary to perform our contract with you.
- Legitimate interests: service improvement, fraud prevention, security.
- Consent: marketing communications and optional analytics cookies.
- Legal obligation: compliance with applicable laws.
6. Data Retention
We retain personal data for as long as necessary to provide the Service and comply with legal obligations. Account data is deleted within 90 days of subscription termination upon request. Anonymised analytics data may be retained indefinitely.
7. International Transfers
Your data may be transferred to and processed in countries outside your country of residence. Where data is transferred outside the EEA, we use appropriate safeguards such as Standard Contractual Clauses approved by the European Commission.
8. Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request erasure of your data.
- Object to or restrict processing.
- Request portability of your data in a structured, machine-readable format.
- Withdraw consent at any time (where processing is based on consent).
- Lodge a complaint with your local data protection authority.
To exercise your rights, contact us at [email protected]. We will respond within 30 days.
10. Security
We implement industry-standard security measures including TLS encryption in transit, AES-256 encryption at rest, access controls, and regular security audits. However, no method of transmission over the internet is 100% secure.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a prominent notice in the Service. The updated policy will be effective on the date indicated at the top of this page.
12. Contact Us
If you have questions about this Privacy Policy, contact our Data Protection Officer at [email protected].