Legal · draft

Data processing terms

Last updated: 19 September 2026

Draft, subject to contract. These terms are still in review and the wording may change. They show what we intend to offer, and they are not a binding offer: the plan, service levels, hosting and recovery arrangements that apply to you are the ones in your signed agreement.

These terms apply where we process personal data on your behalf and form part of the terms of service. They are designed to meet Article 28 of the UK GDPR. You are the controller, and we are the processor.

1. Subject matter and duration

We process personal data to provide the BeeGrow AI platform, for as long as your agreement is in force plus the retention periods set out below.

2. Nature and purpose

Hosting, storage, transmission, display, backup and support of personal data you enter into the platform, and provision of the associated web, mobile and API interfaces.

3. Categories of data subject and personal data

Data subjects and personal data categories
Data subjectsPersonal data
Your employees and contractorsName, work email, role, authentication data, activity records, shifts and hours worked, certifications
Your business contactsName, business contact details, correspondence, where you record them against orders

The platform is not designed for special category data and you should not enter any.

4. Our obligations

  • Process personal data only on your documented instructions, unless required otherwise by law, in which case we will tell you before processing unless the law prohibits it
  • Ensure personnel with access are under a duty of confidentiality
  • Implement appropriate technical and organisational measures, described in clause 6
  • Not engage a sub-processor without the general authorisation in clause 7
  • Assist you in responding to data subject requests, taking account of the nature of the processing
  • Assist you with data protection impact assessments and consultations with the ICO, where relevant
  • Notify you without undue delay, and in any event within 24 hours, on becoming aware of a personal data breach
  • Delete or return personal data at the end of the agreement, per clause 8
  • Make available the information needed to demonstrate compliance and allow audits, per clause 9

5. Your obligations

You warrant that you have a lawful basis for the personal data you put into the platform, that you have provided any required privacy information to your staff, and that your instructions to us will not put us in breach of applicable data protection law.

6. Security measures required before production

  • Encryption in transit and at rest, including backups, evidenced for the selected hosting environment
  • Tenant-isolation and server-side permission coverage verified by release tests
  • Audit coverage for state-changing actions verified with actor, timestamp and reason
  • Least-privilege production access, managed secrets and reviewed access logs
  • Automated off-host backups with defined retention and successful restore tests
  • Centralised monitoring, alerting and a tested incident response procedure

7. Sub-processors

You give general authorisation for us to use sub-processors, subject to us imposing equivalent obligations on them by contract and remaining liable for their performance.

Categories of sub-processor used in production
CategoryPurposeProcessing location
Public cloud hostingRunning the platform services and databasesUnited Kingdom
Object storage and backupEncrypted off-host backups and their retentionUnited Kingdom
Transactional email deliveryAccount, alert and notification emailUnited Kingdom or European Economic Area
Error and performance monitoringDiagnosing faults and performance problemsUnited Kingdom or European Economic Area

The current named provider in each category, with its legal entity and processing location, is given on request to hello@beegrow.ai, and is listed in the signed sub-processor schedule for your deployment.

We will give at least 30 days' notice before adding or replacing a sub-processor. To be notified, email hello@beegrow.ai. If you reasonably object on data protection grounds, we will work with you to find an alternative, and if we cannot, you may terminate the affected service and receive a pro-rated refund of prepaid fees.

8. Return and deletion

On termination we make a complete export available for 30 days. After that we delete personal data from live systems within 30 days, and from backups as they age out of the backup cycle, within 12 months. We will certify deletion in writing on request.

9. Audit

We will make available the information reasonably necessary to demonstrate compliance with these terms. You may audit no more than once in any 12-month period, on 30 days' notice, at your cost, during business hours, subject to confidentiality, and in a manner that does not disrupt our operations or compromise other customers' data. Where available, a current third-party report or completed security questionnaire will be provided in the first instance.

10. International transfers

The signed terms name each processing location and the UK transfer mechanism used for any provider outside the UK.

11. Liability

Liability under these terms is subject to the limitations in clause 11 of the terms of service.

12. Contact

Data protection enquiries: hello@beegrow.ai.