Privacy Policy
As of: 11 July 2026
This is a convenience translation. The legally binding version is the German one.
1. Controller
The controller responsible for the data processing in connection with the service "BeeFlow" (hereinafter the "Service") is:
LOUMITECH UNIPESSOAL LDA
Praça Duque de Saldanha 1, 2, 1050-094 Lisboa, Portugal
NIF/NIPC: 519203640
Email: support@bee-flow.io
The appointment of a data protection officer is not legally mandatory; for all data protection matters you can reach us at the email address stated above.
2. Role of the Provider (Controller / Processor)
For the data arising within the provider's own website and account administration (e.g. registration, billing), the provider acts as controller. For the content that customers, as businesses, process within their workspaces (e.g. project, meeting and personal data of their employees and contacts), the provider acts as a processor on behalf of the respective customer on the basis of a data processing agreement (DPA) pursuant to Art. 28 GDPR. In this respect, the customer is the controller.
3. What Data We Process
- Account and master data: name, email address, company name, password (encrypted), role within the workspace.
- Usage and content data: projects, tasks, notes, files, calendar/meeting data and other content you enter into the Service.
- Meeting/audio data (optional): when the dictation/transcription function is actively used, audio content and the transcripts/summaries generated from it (see Section 6).
- Integration data (opt-in): when connecting a calendar/mailbox, the appointment/message data released via OAuth.
- Billing data: plan, number of seats, payment status; payment methods are processed exclusively by the payment service provider (Stripe).
- Technical data: server logs, IP address, timestamps, browser/device information for the provision and safeguarding of the Service.
4. Purposes and Legal Bases
- Provision of the Service, performance of the contract (Art. 6(1)(b) GDPR) — account, core functions, support.
- Billing (Art. 6(1)(b) and (c) GDPR) — contractual and retention obligations.
- IT security, abuse prevention, error analysis (Art. 6(1)(f) GDPR) — legitimate interest in a stable, secure Service.
- AI transcription/recording (Art. 6(1)(a) GDPR) — only on the basis of your consent, which is obtained before the start (see Section 6).
- Integrations (Art. 6(1)(a)/(b) GDPR) — only after you have explicitly established the connection.
5. Hosting and Infrastructure
The Service is operated on Google Cloud / Firebase in the region europe-west1 (Belgium). Application data (authentication, database, file storage, server-side functions, server logs) is processed there within the EU.
6. Recipients / Processors
To provide the Service, we use carefully selected processors that are bound to a level of data protection and security corresponding to the state of the art. Where processing takes place outside the EU/EEA, we base the transfer on appropriate safeguards within the meaning of Art. 44 et seq. GDPR (in particular the EU Standard Contractual Clauses).
| Provider | Purpose | Region |
|---|---|---|
| Google Cloud / Firebase | Hosting, authentication, database, storage, functions, logs | EU (europe-west1) |
| Deepgram | Audio transcription | EU endpoint (api.eu.deepgram.com) |
| Microsoft Azure OpenAI | Summaries, drafts, review/analysis steps (AI) | EU (Sweden — processing within the EU) |
| OpenAI | AI fallback if the EU service is unavailable | USA (on the basis of the EU Standard Contractual Clauses; zero data retention targeted) |
| Resend | Transactional emails (e.g. invitations, notifications) | EU (Dublin) |
| Stripe | Subscription billing, payment processing | EU (Ireland) |
| Microsoft (Graph) / Google (Calendar) (opt-in) | Calendar/mailbox synchronization after OAuth authorization | EU |
| Sentry (optional) | Error diagnostics | EU instance |
The processors used at any given time are set out in the sub-processor list within the DPA.
7. AI-Assisted Functions and Recordings
The Service offers optional AI functions (e.g. speech-to-text transcription, summaries, drafts, extraction from screenshots/emails). These do not happen automatically: in particular, recording and transcription are triggered exclusively by a deliberate user action; without such action, no audio content is transmitted to an AI service. Consent is obtained before a recording starts. Audio files are automatically deleted after transcription; the transcript remains in the EU database. Results of AI-assisted functions may be incomplete or erroneous and must be reviewed under your own responsibility before use.
8. Payments
The processing of paid subscriptions is handled via Stripe. Payment method data (e.g. card details) is processed exclusively by Stripe and is not transmitted to us in plain text. The privacy notices of Stripe additionally apply.
9. Retention Period and Deletion
We store personal data only for as long as is necessary for the stated purposes or as long as statutory retention obligations exist. Audio files are deleted immediately after transcription. After the end of the contractual relationship, we provide an export option for a limited period and then delete the data in accordance with the statutory requirements.
10. Cookies and Local Storage
We use exclusively technically necessary cookies or local storage that are required for logging in and operating the Service (Art. 6(1)(f) GDPR and Section 25(2) TDDDG, respectively — the German Telecommunications Digital Services Data Protection Act). We do not use tracking or advertising cookies.
11. Your Rights
Under the GDPR, you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You may withdraw a consent you have given at any time with effect for the future (Art. 7(3)).
You can exercise access and erasure directly in the application (Settings → Privacy → "Export data" or "Delete my account & all data") or by email to support@bee-flow.io.
You also have the right to lodge a complaint with a supervisory authority. The provider's competent supervisory authority is the Portuguese data protection authority CNPD (Comissão Nacional de Proteção de Dados), www.cnpd.pt. You may also contact the supervisory authority of your habitual place of residence.
12. Necessity of Provision
The provision of account and billing data is required for the use of the Service. Without this data, no contract can be concluded and the Service cannot be provided. The use of optional functions (e.g. AI transcription, integrations) is voluntary.
13. Changes to This Privacy Policy
We adapt this privacy policy where changes to the Service or the legal situation require it. The version published on this page at any given time applies.