Data processing terms
Last updated: 19 September 2026
Draft, subject to contract. These terms are still in review and the wording may change. They show what we intend to offer, and they are not a binding offer: the plan, service levels, hosting and recovery arrangements that apply to you are the ones in your signed agreement.
These terms apply where we process personal data on your behalf and form part of the terms of service. They are designed to meet Article 28 of the UK GDPR. You are the controller, and we are the processor.
1. Subject matter and duration
We process personal data to provide the BeeGrow AI platform, for as long as your agreement is in force plus the retention periods set out below.
2. Nature and purpose
Hosting, storage, transmission, display, backup and support of personal data you enter into the platform, and provision of the associated web, mobile and API interfaces.
3. Categories of data subject and personal data
| Data subjects | Personal data |
|---|---|
| Your employees and contractors | Name, work email, role, authentication data, activity records, shifts and hours worked, certifications |
| Your business contacts | Name, business contact details, correspondence, where you record them against orders |
The platform is not designed for special category data and you should not enter any.
4. Our obligations
- Process personal data only on your documented instructions, unless required otherwise by law, in which case we will tell you before processing unless the law prohibits it
- Ensure personnel with access are under a duty of confidentiality
- Implement appropriate technical and organisational measures, described in clause 6
- Not engage a sub-processor without the general authorisation in clause 7
- Assist you in responding to data subject requests, taking account of the nature of the processing
- Assist you with data protection impact assessments and consultations with the ICO, where relevant
- Notify you without undue delay, and in any event within 24 hours, on becoming aware of a personal data breach
- Delete or return personal data at the end of the agreement, per clause 8
- Make available the information needed to demonstrate compliance and allow audits, per clause 9
5. Your obligations
You warrant that you have a lawful basis for the personal data you put into the platform, that you have provided any required privacy information to your staff, and that your instructions to us will not put us in breach of applicable data protection law.
6. Security measures required before production
- Encryption in transit and at rest, including backups, evidenced for the selected hosting environment
- Tenant-isolation and server-side permission coverage verified by release tests
- Audit coverage for state-changing actions verified with actor, timestamp and reason
- Least-privilege production access, managed secrets and reviewed access logs
- Automated off-host backups with defined retention and successful restore tests
- Centralised monitoring, alerting and a tested incident response procedure
7. Sub-processors
You give general authorisation for us to use sub-processors, subject to us imposing equivalent obligations on them by contract and remaining liable for their performance.
| Category | Purpose | Processing location |
|---|---|---|
| Public cloud hosting | Running the platform services and databases | United Kingdom |
| Object storage and backup | Encrypted off-host backups and their retention | United Kingdom |
| Transactional email delivery | Account, alert and notification email | United Kingdom or European Economic Area |
| Error and performance monitoring | Diagnosing faults and performance problems | United Kingdom or European Economic Area |
The current named provider in each category, with its legal entity and processing location, is given on request to hello@beegrow.ai, and is listed in the signed sub-processor schedule for your deployment.
We will give at least 30 days' notice before adding or replacing a sub-processor. To be notified, email hello@beegrow.ai. If you reasonably object on data protection grounds, we will work with you to find an alternative, and if we cannot, you may terminate the affected service and receive a pro-rated refund of prepaid fees.
8. Return and deletion
On termination we make a complete export available for 30 days. After that we delete personal data from live systems within 30 days, and from backups as they age out of the backup cycle, within 12 months. We will certify deletion in writing on request.
9. Audit
We will make available the information reasonably necessary to demonstrate compliance with these terms. You may audit no more than once in any 12-month period, on 30 days' notice, at your cost, during business hours, subject to confidentiality, and in a manner that does not disrupt our operations or compromise other customers' data. Where available, a current third-party report or completed security questionnaire will be provided in the first instance.
10. International transfers
The signed terms name each processing location and the UK transfer mechanism used for any provider outside the UK.
11. Liability
Liability under these terms is subject to the limitations in clause 11 of the terms of service.
12. Contact
Data protection enquiries: hello@beegrow.ai.