Privacy Policy

As of: 11 July 2026

This is a convenience translation. The legally binding version is the German one.

1. Controller

The controller responsible for the data processing in connection with the service "BeeFlow" (hereinafter the "Service") is:

LOUMITECH UNIPESSOAL LDA
Praça Duque de Saldanha 1, 2, 1050-094 Lisboa, Portugal
NIF/NIPC: 519203640
Email: support@bee-flow.io

The appointment of a data protection officer is not legally mandatory; for all data protection matters you can reach us at the email address stated above.

2. Role of the Provider (Controller / Processor)

For the data arising within the provider's own website and account administration (e.g. registration, billing), the provider acts as controller. For the content that customers, as businesses, process within their workspaces (e.g. project, meeting and personal data of their employees and contacts), the provider acts as a processor on behalf of the respective customer on the basis of a data processing agreement (DPA) pursuant to Art. 28 GDPR. In this respect, the customer is the controller.

3. What Data We Process

4. Purposes and Legal Bases

5. Hosting and Infrastructure

The Service is operated on Google Cloud / Firebase in the region europe-west1 (Belgium). Application data (authentication, database, file storage, server-side functions, server logs) is processed there within the EU.

6. Recipients / Processors

To provide the Service, we use carefully selected processors that are bound to a level of data protection and security corresponding to the state of the art. Where processing takes place outside the EU/EEA, we base the transfer on appropriate safeguards within the meaning of Art. 44 et seq. GDPR (in particular the EU Standard Contractual Clauses).

ProviderPurposeRegion
Google Cloud / FirebaseHosting, authentication, database, storage, functions, logsEU (europe-west1)
DeepgramAudio transcriptionEU endpoint (api.eu.deepgram.com)
Microsoft Azure OpenAISummaries, drafts, review/analysis steps (AI)EU (Sweden — processing within the EU)
OpenAIAI fallback if the EU service is unavailableUSA (on the basis of the EU Standard Contractual Clauses; zero data retention targeted)
ResendTransactional emails (e.g. invitations, notifications)EU (Dublin)
StripeSubscription billing, payment processingEU (Ireland)
Microsoft (Graph) / Google (Calendar) (opt-in)Calendar/mailbox synchronization after OAuth authorizationEU
Sentry (optional)Error diagnosticsEU instance

The processors used at any given time are set out in the sub-processor list within the DPA.

7. AI-Assisted Functions and Recordings

The Service offers optional AI functions (e.g. speech-to-text transcription, summaries, drafts, extraction from screenshots/emails). These do not happen automatically: in particular, recording and transcription are triggered exclusively by a deliberate user action; without such action, no audio content is transmitted to an AI service. Consent is obtained before a recording starts. Audio files are automatically deleted after transcription; the transcript remains in the EU database. Results of AI-assisted functions may be incomplete or erroneous and must be reviewed under your own responsibility before use.

8. Payments

The processing of paid subscriptions is handled via Stripe. Payment method data (e.g. card details) is processed exclusively by Stripe and is not transmitted to us in plain text. The privacy notices of Stripe additionally apply.

9. Retention Period and Deletion

We store personal data only for as long as is necessary for the stated purposes or as long as statutory retention obligations exist. Audio files are deleted immediately after transcription. After the end of the contractual relationship, we provide an export option for a limited period and then delete the data in accordance with the statutory requirements.

10. Cookies and Local Storage

We use exclusively technically necessary cookies or local storage that are required for logging in and operating the Service (Art. 6(1)(f) GDPR and Section 25(2) TDDDG, respectively — the German Telecommunications Digital Services Data Protection Act). We do not use tracking or advertising cookies.

11. Your Rights

Under the GDPR, you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You may withdraw a consent you have given at any time with effect for the future (Art. 7(3)).

You can exercise access and erasure directly in the application (Settings → Privacy → "Export data" or "Delete my account & all data") or by email to support@bee-flow.io.

You also have the right to lodge a complaint with a supervisory authority. The provider's competent supervisory authority is the Portuguese data protection authority CNPD (Comissão Nacional de Proteção de Dados), www.cnpd.pt. You may also contact the supervisory authority of your habitual place of residence.

12. Necessity of Provision

The provision of account and billing data is required for the use of the Service. Without this data, no contract can be concluded and the Service cannot be provided. The use of optional functions (e.g. AI transcription, integrations) is voluntary.

13. Changes to This Privacy Policy

We adapt this privacy policy where changes to the Service or the legal situation require it. The version published on this page at any given time applies.