Legal · draft

Privacy notice

Last updated: 19 September 2026

Draft notice. We are still reviewing this notice and the wording may change. It describes how we handle personal data today. If anything here is unclear, email hello@beegrow.ai. Hosting and service-provider details for the platform are confirmed in each customer’s data processing terms.

1. Who we are

Beestech Ltd (“BeeGrow AI”, “we”, “us”) is a company registered in England and Wales under company number 12490303, with its registered office at 10 Maplin Close, London, N21 1NB, United Kingdom.

We are the data controller for personal data collected through this website and for the personal data of our direct contacts. Where we process personal data inside the BeeGrow AI platform on behalf of a customer, that customer is the controller and we act as processor under the data processing terms.

For any data protection question, contact hello@beegrow.ai.

2. What personal data we collect

2.1 When you contact us

  • Your name, work email address and organisation
  • Your growing area and area of interest, where you tell us
  • The content of your message and our correspondence with you

2.2 When you use the platform

If your employer has an account, we process, on their instructions:

  • Your name, work email address and role
  • Authentication data, including a hashed password and session records
  • Records of actions you take, such as observations recorded, shifts worked and hours logged, with their timestamps
  • Certifications and training records where your employer records them

2.3 Technical data

Our servers keep standard access logs, which include IP address, browser type, pages requested and timestamps. These are used for security and diagnostics.

2.4 What we do not collect

We do not collect special category data. We do not use tracking cookies, advertising pixels or third-party analytics on this website. We do not buy personal data from data brokers, and we do not enrich your details from third-party sources.

3. Why we use it

Purposes for processing personal data
PurposeData used
Responding to your enquiryContact details and message content
Providing the platform to your employerAccount, role and activity data
Securing the service and investigating incidentsAuthentication and access logs
Meeting our legal and accounting obligationsContract and billing records
Improving the productAggregated, non-identifying usage patterns

We do not use your personal data to train machine learning models that serve other customers. Models that operate on your farm data do so within your tenant only.

4. Lawful basis

  • Legitimate interests: responding to business enquiries you send us, securing our service, and improving the product using aggregated data. Our interest is in operating and improving a business service; we have considered the impact on you and consider it minimal, as the data involved is business-context and limited in scope.
  • Contract: providing the platform under an agreement with your employer, and administering that agreement.
  • Legal obligation: retaining accounting records and responding to lawful requests.

5. Who we share it with

We do not sell personal data. We share it only with:

  • Sub-processors who help us run the service, listed in the data processing terms, each under a written contract that limits them to our instructions
  • Service providers who host this website and our email, such as our content delivery network and email provider, which process your IP address, requests and messages only to provide those services
  • Professional advisers such as accountants and solicitors, where necessary and under a duty of confidentiality
  • Authorities, where we are legally required to do so
  • A successor entity, if the business is sold or reorganised, in which case we will tell you before your data becomes subject to a different privacy notice

6. International transfers

The platform and its backups are hosted in the United Kingdom. Two supporting categories of sub-processor, email delivery and error monitoring, may process data in the United Kingdom or the European Economic Area. The categories, their purposes and their locations are set out in the data processing terms.

Where a transfer outside the United Kingdom is involved, we rely on UK adequacy regulations where they apply, and otherwise on the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, supported by a transfer risk assessment. We will not move the hosting region outside the United Kingdom without giving you at least 30 days’ notice under the sub-processor change process.

7. How long we keep it

Retention periods
DataRetention
Enquiry correspondence where no relationship follows24 months from last contact
Customer account and activity dataDuration of the agreement, then a 30-day export window, deleted from live systems within 30 days of that window closing
Farm and operational dataAs instructed by the customer; exported on request before deletion
Server access logs90 days
Security incident records3 years
Accounting and contract records7 years, to meet our tax, accounting and limitation obligations

Deletion removes data from the live platform on the timescales above. Encrypted backups are retained on a rolling cycle, so a deleted record can persist in backup media for up to 12 months before it ages out. Backups are not used to restore individual records once deleted, only to recover the service after an incident.

8. Your rights

Under UK GDPR you have the right to:

  • Be told what personal data we hold about you, and get a copy of it
  • Have inaccurate data corrected
  • Have data erased, where we have no overriding lawful reason to keep it
  • Restrict how we process it while a concern is resolved
  • Receive data you gave us in a portable, machine-readable format
  • Object to processing carried out on the basis of legitimate interests
  • Object at any time to the use of your personal data for direct marketing, which we stop when you ask
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects for you, and to ask for human review where such a decision is made
  • Withdraw consent where consent is the basis we rely on

To exercise any of these, email hello@beegrow.ai. We respond within one month, and will tell you if we need to extend that, which we may do by up to two further months for complex requests. There is no charge unless a request is manifestly unfounded or excessive.

If your employer holds the account, requests about your platform data may need to go to them as controller. We will tell you if that is the case and forward your request.

9. Security

Personal data is protected by TLS encryption on all connections, server-side access control enforced at the API gateway, tenant isolation between customers, least-privilege production access, secrets held outside source control, centrally monitored operational logs, and an audit trail recording actor, timestamp and context for critical state-changing workflows. More detail is on the security page.

If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware, and will tell you directly where the risk is high.

10. Cookies

This website sets no cookies and runs no third-party analytics. The platform application sets a small number of strictly necessary cookies for authentication and security. See the cookie policy.

11. Children

Our services are for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we have, contact us and we will delete it.

12. Changes to this notice

We may update this notice. Material changes will be notified to account holders by email and the “last updated” date above will change. Previous versions are available on request.

13. Complaints

If you are unhappy with how we have handled your data, please tell us first at hello@beegrow.ai so we can put it right.

You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk/make-a-complaint or on 0303 123 1113.