Beevi legal
Privacy Policy
Last updated 23 September 2026
This policy explains what personal data the Beevi platform holds, who it is shared with and why, and what you can do about it. It covers both the businesses that subscribe to Beevi and the people those businesses keep records about.
1.Who we are
Beevi is a multi tenant business management platform (an ERP) sold to gyms, clinics, salons, retail shops and agencies. It is operated by [LEGAL ENTITY NAME], registered under company number [COMPANY REGISTRATION NUMBER] at [REGISTERED ADDRESS]. In this policy, Beevi, we and us all mean that company.
The service is delivered at www.beevi.co. For any question about this policy or about personal data, write to [PRIVACY CONTACT EMAIL].
2.Our two roles: processor and controller
Beevi handles personal data in two different capacities, and it matters which one applies to you.
As a processor. Every business that subscribes to Beevi gets its own tenant. The records that business keeps about its own members, patients, clients, leads and customers belong to that business. It decides what to collect, why, how long to keep it and who on its staff may see it. Beevi only stores and processes that data on its instructions, in order to provide the service. If you are a customer, patient or member of a business that uses Beevi, that business is your data controller and it is the right first point of contact for any request about your data.
As a controller. Beevi is the controller for the data it needs to run its own business: the accounts of the staff who sign in to the platform, subscription and billing records, support correspondence, demo requests submitted from the marketing site, and the technical logs and error reports the platform produces.
3.Data our customers store about their end users
The fields below are the ones the platform actually provides. Which of them are filled in is entirely up to the business using Beevi, and which modules it has switched on.
Leads and CRM contacts
First and last name, email address, phone number, company name, industry, date of birth, gender, source and source detail, interests, tags, deal size, pipeline stage and status, free text notes, a do not contact flag, any custom fields the business defines, and a history of interactions, meetings and follow ups.
Members (gym and fitness)
Name, email address, phone number, street address, city and country, date of birth, gender, profile photo, member number, emergency contact name, phone and relationship, health notes, a medical clearance flag, join date, visit counts, check in history, class and personal training bookings, membership plans and freezes.
Patients (clinic)
Everything listed for members, plus blood type, allergies, chronic conditions, current medications, height and weight, insurance provider, policy number and expiry date, and clinical notes. See the section on health data below.
Salon and spa clients
Contact details, plus service preferences such as hair type and colour, skin type, preferred products, style notes, a preferred stylist, allergy notes, and before and after photographs where the business uploads them.
Money and commerce
Invoices and line items, payment records (amount, currency, method, date, status, gateway transaction reference, gateway response, receipt link, refund amount and reason), point of sale receipts and returns, store credit, gift cards, loyalty points, tiers and redemptions, promo code redemptions, subscriptions and payment plans. Beevi does not store full card numbers. See the section on payments below.
Scheduling and operations
Appointments, class bookings, court reservations, personal training sessions, calendar events, waiting lists, tasks and task comments.
Messages
Conversations and messages exchanged over WhatsApp and Instagram, and campaign or notification sends over email, SMS, push and in app channels. See the messaging section below.
4.Health and clinical data
The clinic modules are designed to hold data about health, which in most legal systems is a special or sensitive category and carries stricter obligations. A business using those modules can record:
- Consultations: chief complaint, history of the present illness, examination findings, diagnosis and diagnosis codes, procedures performed, treatment plan, follow up instructions, and the clinician who signed the record.
- Prescriptions and dispensing: prescribed items, issue and expiry dates, prescription status, and a dispensing log.
- Treatment plans and their individual sessions, including cost and progress.
- Vital signs history: blood pressure, heart rate, respiratory rate, oxygen saturation, temperature, blood sugar, height, weight and BMI.
- Lab orders, the tests requested, result notes and result files.
- Patient documents uploaded by the clinic, which can be marked confidential, and before and after photographs.
- Insurance claims: provider, policy number, claim number, amounts claimed, approved and paid, and any rejection reason.
- Gym members can also carry health notes and a medical clearance flag, and salon clients can carry allergy notes.
The clinic or business that enters this data is its controller. It is responsible for having a lawful basis to collect it, for obtaining any consent its own regulator requires, and for deciding which of its staff may open a patient record. Beevi provides the per tenant isolation, the role and page level access controls and the audit trail that make those decisions enforceable, but it does not decide what is recorded.
Beevi is not a certified electronic health record system and has not been certified under any national health data programme. If you are bound by a regime such as HIPAA, ask us before you record regulated health data in the platform, because a signed agreement may be required first.
5.Data about people who sign in to Beevi
For the owners, managers and staff who use the platform we hold: email address, a securely hashed password, full name, phone number, profile photo, organisation and branch, role and any per page access grants, notification preferences, browser push subscription details, shift and commission records where the HR module is used, and the assistant conversations described below.
We also keep an audit log of changes to records, which stores the user who acted, the table and record affected, the fields that changed, the values before and after, the IP address and the browser user agent. The audit log exists so that a business can answer the question of who changed what, and it is visible to that business only.
6.Website visitors and prospective customers
If you request a demo from the Beevi website we store the name, business name, email address, phone number, vertical and message you submit, so that we can reply.
The site uses Vercel Analytics and Vercel Speed Insights, which measure page views and loading performance in aggregate and do not use advertising cookies or build a cross site profile of you.
We use Sentry to capture application errors. Sentry receives the error itself, the page it happened on, browser and device information and the IP address of the request. On the server side we have disabled Sentry's default collection of personally identifying request data. In the browser we also run Sentry Session Replay, which reconstructs a recording of the page for a sample of sessions and for sessions where an error occurs, so that we can reproduce faults. Replay is configured with Sentry's text masking so recorded page text is obscured rather than captured verbatim, and we use it only to diagnose problems.
7.WhatsApp and Instagram messaging
A business using Beevi can connect its own WhatsApp Business account and its own Instagram professional account, through Meta's embedded signup. Beevi never connects an account on a business's behalf without it going through that flow.
Once a channel is connected:
- Messages sent to that business's WhatsApp number or Instagram inbox are delivered to Beevi by Meta over a webhook, and stored against that business's tenant. We store the message body, the message type, attachment references and any media file where the business chooses to keep a copy, the delivery and read status, the timestamps, the contact's phone number for WhatsApp, the contact's app scoped sender id for Instagram, and the profile name that Meta reports.
- Outbound messages sent by the business's staff, and template messages sent outside WhatsApp's twenty four hour service window, are stored the same way.
- The raw webhook payload Meta delivers is written to a diagnostic log before it is interpreted, so that undelivered or malformed messages can be investigated. Those payloads contain the message content and the sender's phone number or sender id.
- The access token for the connected channel is encrypted before it is written to the database.
Meta Platforms is the provider of WhatsApp and Instagram and processes the message in transit under its own terms and privacy policy. A conversation over these channels is subject to Meta's rules as well as this policy, including its rules on who may be messaged and when.
8.Artificial intelligence features
Beevi includes an in app assistant (Copilot) and a number of automated analysis features. These send data to a third party model provider. This section says exactly what leaves the platform, because it is the part most people want a straight answer on.
Who the provider is
Our model provider is OpenAI. Text features use the gpt-4o-mini model and voice input uses the gpt-4o-mini-transcribe model, both over OpenAI's API. Requests are sent from our servers, not from your browser.
Copilot
Copilot answers questions about a business's own data and can create or update records on request. To do that it queries the business's tenant and the results of those queries are sent back to the model as part of the conversation. That means the assistant's context can include real customer records: names, phone numbers, email addresses, bookings, invoices and amounts, and, for a business on a clinic plan, patient records, consultations and prescriptions. Your prompts and the assistant's replies are stored in the platform as chat history, and the assistant can keep short notes about your preferences to make later answers more useful. Copilot cannot delete records, and actions that change data require approval in the interface.
Voice input
If you dictate to the assistant rather than typing, the audio recording is uploaded to OpenAI and transcribed there. The recording may contain anything you said, including names and other details.
Spreadsheet import
When you import a spreadsheet, Beevi asks the model to match your column headings to the right fields. To make that reliable it sends the column headings together with up to three example values taken from your file for each column. Those examples are real data from your spreadsheet, so they can include real names, email addresses and phone numbers. If no model is configured, or the call fails, the import falls back to a purely local matching rule and nothing is sent.
Automated analysis
Other features send a summary of the relevant records to the model: churn and retention risk, lead scoring, customer lifetime value, the daily briefing, revenue forecasting, pricing suggestions, schedule and staffing suggestions, anomaly detection, inventory forecasting, staff performance analytics, message drafting and automated follow ups. Most of these send counts, dates and scores rather than identities, but some are personal by nature. Workout plan generation, for example, sends the member's name, age, gender and health notes.
What we do with it
We use these calls only to produce the output you asked for. We do not train any model on your data and we do not sell it. We record the number of tokens each call used and its estimated cost, for billing and capacity planning, but not the content of the call. The model provider's own API terms govern how it handles the data we send; you can read those terms on its website.
Turning it off
AI features are delivered as modules. A business that does not want data sent to a model provider should ask us to disable the Copilot and AI modules for its tenant. Contact [PRIVACY CONTACT EMAIL].
9.Subprocessors
These are the third parties that receive personal data in order for Beevi to work. Each is listed with what it actually does in the platform. Some are optional and receive nothing unless the relevant feature is configured for a tenant.
| Provider | What it does | Data it receives |
|---|---|---|
| Supabase | Database, authentication and file storage | All platform data, including everything described in this policy |
| Vercel | Hosting, Analytics and Speed Insights | Every request to the platform, plus aggregate page view and performance measurements |
| OpenAI | Assistant, AI analysis, import mapping and transcription | The prompts, records and audio described in section 8 |
| Meta Platforms | WhatsApp Business and Instagram messaging | Message content and the contact identifiers for connected channels |
| Stripe | Card payments | Card details entered by the payer, the amount, and the organisation, branch and user references attached to the payment |
| Resend | Transactional email | Recipient address and the content of the email |
| Sentry | Error monitoring and session replay | Error details, device and browser data, IP address |
| Twilio (optional) | SMS notifications, only where a tenant is configured for it | Recipient phone number and the message text |
| Upstash (optional) | Rate limiting | Request identifiers used to count requests |
| Apple, Google and Mozilla push services | Delivery of browser and mobile push notifications | The push subscription endpoint and the notification payload |
We will keep this list current. If you want to be told before we add a subprocessor, ask at [PRIVACY CONTACT EMAIL].
10.Payments
Card payments are processed by Stripe. Card details are entered into Stripe's own hosted fields and go to Stripe directly. Beevi never receives or stores a full card number, expiry date or security code. What we keep is the outcome: the amount, the currency, the method, the date, the status, Stripe's transaction reference, the response summary Stripe returns, and any refund.
11.How we use personal data
- To provide the platform and the modules a business has enabled.
- To authenticate users, enforce role and page level permissions, and keep tenants separate from one another.
- To send transactional messages: sign in and password reset emails, invitations, booking and payment reminders, and notifications a business has configured.
- To produce the analyses, summaries and suggestions the AI features offer, when they are enabled.
- To take payment and to keep accurate financial records.
- To keep the service secure and available: rate limiting, abuse prevention, error monitoring and audit logging.
- To provide support when someone asks for it.
- To meet legal, tax and accounting obligations.
We do not sell personal data. We do not use it for advertising, and we do not share it with advertising networks or data brokers.
12.Our legal basis
Where Beevi acts as a processor, the lawful basis for handling an end user's data is established by the business that collected it, not by us. We act on that business's documented instructions.
Where Beevi acts as a controller, we rely on the performance of our contract with the subscribing business (providing the service, supporting it and billing for it), our legitimate interests (keeping the platform secure, preventing abuse, and improving reliability), consent where we ask for it (for example a demo request or a marketing email), and legal obligation where the law requires us to keep records.
The governing law and the data protection regime that applies to this policy are those of [GOVERNING LAW JURISDICTION].
14.Where data is stored and transferred
The platform database and file storage are hosted with Supabase in [PRIMARY HOSTING REGION]. The application itself runs on Vercel's global edge and serverless infrastructure. Our other subprocessors operate internationally, so personal data handled by Beevi is transferred across borders, including to the United States and the European Union.
Where such a transfer needs a safeguard, we rely on the transfer terms in our agreements with those providers, including standard contractual clauses where they apply.
15.Security
The measures actually in place include:
- Every tenant's rows are separated by an organisation identifier and enforced at the database with row level security policies, so one business cannot read another's records.
- Role based access, plus a per user page grant that lets an administrator narrow a staff member to specific screens. Both are enforced on the server, not only hidden in the interface.
- Passwords are hashed by our authentication provider. We never see or store them in plain text.
- Traffic to and from the platform is encrypted in transit.
- Messaging provider access tokens are encrypted before they are stored, so a stolen database copy does not yield a usable token.
- Inbound provider webhooks are signature verified before they are processed.
- An audit log records who changed which record, and what the values were before and after.
- Rate limiting on sensitive endpoints.
No system is perfectly secure. If you believe you have found a vulnerability, report it to [PRIVACY CONTACT EMAIL] rather than disclosing it publicly, and we will work with you on it.
16.How long we keep data
While a business's subscription is active, its records are kept until that business deletes them. A business can delete an individual record itself from within the platform. Where a record is referenced by financial history, such as a member attached to paid invoices, the platform deactivates it instead of deleting it, so that the accounts stay correct.
Public API request logs are automatically pruned after ninety days.
When a subscription ends, the tenant's data is retained for [ACCOUNT CLOSURE RETENTION WINDOW] so that the business can export it, and is then deleted. Backups are rotated and purged within [BACKUP RETENTION PERIOD], so a deleted record can persist in a backup for that long before it disappears entirely.
We keep invoices, payment records and other accounting documents for as long as tax and company law requires, even after an account closes.
17.Your rights
Depending on where you live you may have the right to ask for a copy of your personal data, to have it corrected, to have it deleted, to restrict or object to how it is used, to receive it in a portable format, and to withdraw consent you previously gave.
If you are a customer, member, patient or client of a business that uses Beevi, contact that business first. It controls your record and it can action your request directly inside the platform. If you do not know who to contact, or the business does not respond, write to us at [PRIVACY CONTACT EMAIL] and we will help you reach them, or act on their instruction.
If you hold a Beevi account yourself, write to the same address. We will respond within thirty days. We may need to verify your identity before acting, and we will only ask for what is necessary to do that.
To request deletion, see the data deletion instructions.
19.Children
Beevi is a tool for businesses. We do not knowingly create accounts for children, and nobody under sixteen should sign in to the platform.
A business using Beevi may legitimately keep records about a minor, for example a child enrolled in a swimming class or seen at a clinic. That business is the controller of those records and is responsible for obtaining parental consent where its own law requires it.
20.Changes to this policy
We update this policy when the product changes. The date at the top shows when it was last revised. For a change that materially affects how personal data is handled, we will notify the businesses that subscribe to Beevi before it takes effect.
21.Contact us
Questions, requests and complaints about this policy go to [PRIVACY CONTACT EMAIL], or by post to [LEGAL ENTITY NAME], [REGISTERED ADDRESS].
If you are not satisfied with our response, you may be able to complain to the data protection authority in your country.