Data protection statement

Data Processing for the Beeward Website, the Beeward Platform, and BeePT Features

Data Controller: Beeward Limited Liability Company

Headquarters: 7621 Pécs, 2 Kazinczy Street.

Company Registration Number: 02-09-088628

Tax ID Number: 32663871-2-02

Contact: hello@beeward.buzz, +36 30 480 0513

Version: 2.0

Effective: From the date of publication on the website.

 

In short: Beeward acts as a data controller with respect to its own website, business relationships, billing, and service security. As a general rule, the client’s organization is the data controller for employee and community data generated within the company’s hive, while Beeward acts as the data processor. BeePT Admin may draw conclusions from activity data linked to specific individuals, but it does not make automated decisions regarding employment law.

1. Purpose and Scope of This Prospectus

1.1. This privacy notice explains what personal data Beeward Kft. processes, for what purposes, on what legal basis, and for how long, in connection with the operation of the beeward.buzz website, the Beeward app, BeePT Admin, and the separately activatable user version of BeePT.

1.2. This privacy notice applies to website visitors, interested parties, business contacts, customer administrators, invited and registered users, as well as other individuals appearing in the Beeward system.

1.3. With regard to user data in the corporate hive, the client’s organization’s own employee or member privacy notice also applies. This document does not replace it.

2. Roles of Data Controllers and Data Processors 2.1. When Beeward acts as the data controller

Beeward processes, for its own purposes and at its own risk, in particular website visit data, data on prospective clients and business contacts, contract, billing, and payment data, customer support communications, log data necessary to prove acceptance, as well as data necessary for the security of its own services and to meet its legal obligations.

2.2. When Beeward acts as a data processor

As a general rule, the purpose of processing user profiles, recognitions, points, posts, comments, rewards, activity data, BeePT content, and related employee data managed in the corporate hive is determined by the organization that orders Beeward. In this context, the client organization is the data controller, and Beeward is the data processor acting in accordance with the client’s documented instructions.

The legal basis, necessity, and proportionality of data processing are determined by the client’s organization. Employee consent is not a general requirement for using Beeward or BeePT Admin. In a workplace setting, consent is often not considered truly voluntary; therefore, the client must select another appropriate legal basis and, if necessary, conduct a balancing of interests or a data protection impact assessment.

Important: The adoption of a privacy notice does not, in and of itself, establish a legal basis for data processing. The client’s organization must define a legitimate purpose and legal basis and provide its employees with appropriate information.

3. Information about the Data Controller

Data

Contact Information

Full name

Beeward Limited Liability Company

Headquarters

7621 Pécs, 2 Kazinczy Street.

Company registration number

02-09-088628

Tax number

32663871-2-02

Representative

Máté Lovas, Managing Director

E-mail

hello@beeward.buzz

Phone

+36 30 480 0513

Website

beeward.buzz

Data protection inquiries or requests may be submitted to hello@beeward.buzz.

4. Principles, Data Sources, and Required Data

  • Beeward processes personal data only for specific, clear, and lawful purposes.

  • The scope of the data processed is limited to what is necessary for the purpose.

  • It restricts access based on role, tenant, and task.

  • You may obtain the data from the data subject, the client organization, through the use of the system, and from technical service providers associated with the service.

  • If providing a piece of information is required to create an account or to fulfill the contract, the relevant feature cannot be provided without it.

  • Beeward's features do not require the provision of sensitive personal data. Such data may appear in free text, prompts, or uploaded documents only if it is lawful and absolutely necessary.

5. Beeward’s Own Data Processing Activities

Goal

Data

Legal Basis

Preservation

Website Operation and Security

IP address, browser and device information, date and time, log data, necessary cookies

Article 6(1)(f) of the GDPR: legitimate interest in ensuring secure operations

In accordance with technical requirements and log rotation, until the incident is resolved.

Contact Us, Demo, and Quote

Name, work email, phone number, company, job title, message

GDPR Article 6(1)(b), pre-contractual measures, and (f), maintaining a business relationship

Two years following the last substantive relationship; in the case of a contract, for the duration of the contract.

Registration and Administrator Account

Name, email, password hash, role, tenant, acceptance log

GDPR Article 6(1)(b), performance of a contract, and (f), customer relationship and audit trail

During the term of the contract and thereafter until the statute of limitations for civil claims expires—generally 5 years.

Contract, Billing, and Payment

Contact, billing, and transaction information; contractual documents

Article 6(1)(b) and (c) of the GDPR: contract and legal obligation

Accounting documents must be retained for at least 8 years.

Customer Support and Troubleshooting

Contact information, message, error description, screenshot, related log

GDPR Article 6(1)(b) and (f): performance of a contract and service development

Until the matter is resolved, and for as long as necessary to pursue legal claims.

Newsletter and Marketing Emails

Name, email address, subscription and unsubscription data, page views and clicks

GDPR Article 6(1)(a), consent, or (f) in the case of a lawful B2B inquiry

Until you unsubscribe or object. Proof of consent may be retained until the end of the statute of limitations.

Analytics and Remarketing

Cookie ID, device and browser data, site usage, campaign event

GDPR Article 6(1)(a), consent

For the duration specified in the cookie settings or until consent is withdrawn.

6. Data Managed in the Company's Database

6.1. Categories of Data

  • Identification and profile data: name, email address, username, profile picture, job title, team, internal ID, tenant, and role.

  • Recognition and Point Data: point issuance, point balance, point transaction, recognition, justification, and date and time.

  • Social media content: posts, comments, reactions, votes, images, events, and other user-generated content.

  • Reward data: rewards, recommendations, voting, redemption, purchases, and related administrative information.

  • Activity and statistical data: logins, feature usage, timestamps, activity patterns, and team-level reports.

  • Communication and delivery data: transactional emails, push notifications, device tokens, Firebase installation IDs, and delivery events.

  • AI data: prompt, response, conversation context, summary, AI-generated conclusion, image-generation prompt, and technical metadata.

  • Knowledge Base data: the full content of company documents provided to separately activated BeePT users.

6.2. Access Points Inside the Hive

Users can view profiles, recognitions, posts, comments, and other community content published in the hive based on their permissions. Company administrators can access additional management and statistical data—including point transactions and reward redemptions—on the Beeward admin interface.

BeePT Admin conversations are not shared. An administrator can only view the conversations they have initiated themselves. However, the monthly BeePT Admin summary is available to all company administrators who are active at the time it is generated.

6.3. Users Who Have Left or Been Deleted

Terminating a user’s access does not, in and of itself, result in the immediate deletion of all historical company data associated with that user. Point transactions, acknowledgments, posts, comments, and other community activity may remain until the tenant is deleted, provided that the customer’s data processing purpose and legal basis permit this. BeePT Admin cannot perform a direct search for a user who has left the platform, but the user’s previous content may appear in aggregated or content-based analyses.

In the event of a data subject’s request for erasure, the client, as the data controller, decides on the request. Based on the client’s documented request, Beeward will also manually delete or anonymize data that can no longer be processed without a legal basis.

7. BeePT Admin Data Management

7.1. Purpose and Operation

BeePT Admin is an AI agent available exclusively to company administrators. It generates team-level activity and performance summaries, helps interpret Beeward data, and can make recommendations for recognition or rewards. This feature can analyze structured and text-based data from the Beeward tenant database across the entire available historical time range.

BeePT Admin can use data that is generally visible to hive users, as well as administrative data that the admin can otherwise access on the Beeward interface. The system can identify a specific employee by name on the Beeward interface and draw conclusions about that individual based on activity patterns.

7.2. Data Transmitted to OpenAI

BeePT Admin operates using the OpenAI Responses API. The following can be sent to OpenAI: administrator queries, conversation context, system instructions, tool definitions and tool results, text content required for analysis, business statistics, and activity data.

Beeward replaces known names, usernames, email addresses, and internal identifiers that directly identify individuals in the text input of the Responses API with tenant-level, permanent, non-transparent tokens whenever possible. This is pseudonymization, not anonymization. The technical metadata transmitted to OpenAI may include the tenant domain, internal user ID, and agent type.

When generating images, the text prompt may contain personal information, such as a name, if this is necessary to create the requested image. Users cannot upload images; they can only request generated images using a text prompt. Beeward does not store the generated images permanently.

7.3. Storage and Automated Processes

  • Administrator BeePT chats on Beeward can be viewed for 30 days, after which the chat history is permanently deleted.

  • The 30-day deletion process must continue even after BeePT Admin is turned off.

  • The monthly team-level BeePT Admin summary can be generated automatically, and the current company administrators can receive it via email.

  • The monthly summary cannot be viewed in the Beeward app. In the recipient's mailbox, it remains available for 45 days by default in the Postmark system, in accordance with the recipient's organizational policies.

  • The Responses API sends requests with the "store:false" setting. Regardless, OpenAI may retain abuse monitoring logs for up to 30 days by default.

  • OpenAI does not use customer data transmitted to the OpenAI API to train its models, except when data sharing has been specifically enabled. Beeward does not enable such data sharing for customer data.

8. The separately activatable user BeePT

The user BeePT is an AI agent separate from BeePT Admin. It has access only to data associated with that specific user and to the knowledge base documents provided by the client for that feature. It cannot view company-wide statistics, other users’ personal data, or other users’ BeePT conversations.

Company administrators and other users do not have access to users’ BeePT chats. The content of raw messages is deleted after 30 days. A summary may be created from the chat after direct identifiers have been redacted. Beeward treats this summary as personal data and deletes it no later than when the tenant is deleted. Only anonymized, topic-based summaries from BeePT conversations may be provided to BeePT Admin.

Documents from the knowledge base can be uploaded in their entirety to the OpenAI Files service and linked to an OpenAI vector store item. There is no guaranteed automatic filtering of personal data before documents are uploaded. This feature can only be activated upon a specific customer request and with a subscription. Activating BeePT Admin on its own does not upload company documents.

9. Profiling and Automated Decision-Making

BeePT Admin can draw conclusions from personal activity patterns; therefore, this method of use may be considered profiling. Beeward provides this feature solely as a decision-support and informational tool.

BeePT Admin does not make decisions that are solely automated and that result in legal effects or have a similarly significant impact. It cannot perform actions, award points, redeem rewards, modify data, or be the basis for dismissal, promotions, disciplinary actions, task assignments, discriminatory practices, or other significant employment-related decisions.

The AI’s response may be incorrect, incomplete, or misleading. Conclusions regarding an individual must be verified by a person with the appropriate authority, and the data subject must be given the opportunity to present their point of view. The system must not be used to infer special categories of personal data, such as health status, political opinions, religious beliefs, or trade union membership.

10. Recipients and Data Processors

Service Provider

Contact Information

Task

Location

Rackforest Ltd.

1132 Budapest, Victor Hugo Street 11, 5th Floor, B05001.

Server infrastructure, application and database hosting, and backups.

Hungary

YCO Digital, Ltd.

7622 Pécs, 3 Siklósi Street.

Development, bug fixes, technical operations, and authorized support access.

Hungary

OpenAI

In accordance with the OpenAI agreement governing the customer account.

Responses API, image generation, and—for the BeePT user—Files and Vector Stores.

EEA and third countries

AC PM, LLC, Postmark

According to the service provider's current contract information.

Delivery of transaction emails and the monthly BeePT Admin summary.

United States and its subcontractor locations

Google Firebase Cloud Messaging

According to Google's current contract information.

Push notifications, registration token, and Firebase installation ID.

EEA and third countries

 

Designated employees of Beeward and YCO Digital may access customer data only for legitimate development, bug-fixing, support, or security purposes. Individuals with access are bound by confidentiality obligations, and access is logged. A list of these individuals by name is not included in the public disclosure.

Additional provider information: OpenAI Data Management Settings, Postmark Data Processing Terms and Conditions, Firebase Privacy, Rackforest Data Management.

11. International Data Transfers

Personal data may be processed outside the European Economic Area in connection with the services provided by OpenAI, Postmark, and Google. Beeward will only carry out such transfers if safeguards are in place in accordance with Chapter V of the GDPR. Such safeguards may include an adequacy decision, an applicable data protection framework, standard contractual clauses adopted by the European Commission, or another lawful data transfer mechanism.

The data subject may request information at hello@beeward.buzz regarding the guarantee applied to the specific transfer and a copy of that guarantee.

12. Retention Periods

Data Set

Duration

Comment

Corporate Tenant Information During the Term of the Contract

For the duration of the service contract.

In accordance with the client's data processing instructions.

Tenant after the termination of the lease

30 days.

Deleting or irreversibly anonymizing the active database.

Backup

No more than an additional 30 days.

It is deleted when the backup cycle ends.

BeePT Admin Chat

30 days.

Only the admin who started the conversation can see it; the content is then deleted.

Image Generation Prompt

A maximum of 30 days at Beeward.

Beeward does not permanently store the generated image.

User BeePT raw message

30 days.

Other users and admins do not have access.

BeePT User Summary

Until the tenant is deleted, at the latest.

It must continue to be treated as personal data even after editing.

OpenAI Responses API

When "Store:false" is set, there is no 30-day application status.

By default, the fraud audit log is retained for a maximum of 30 days.

OpenAI Files and Vector Stores

Until the user actively uses BeePT.

A deletion request is initiated when the tenant is deactivated or deleted.

Postmark Email Content and Activity

The default is 45 days.

The current backup settings for the Beeward account apply.

Firebase installation ID

For the period specified in Google's Terms of Service.

Beeward's native token is deleted when the tenant is deleted. The Google ID may remain in place according to the service provider's lifecycle.

Invoices and Accounting Documents

At least 8 years.

Legal retention requirement.

Contract and Acceptance Log

For the duration of the contract, and generally for 5 years.

The contract and the provability of legal claims.

13. Data Security

  • The Beeward app and external API connections use HTTPS and TLS-secured connections.

  • Hive data is logically separated, and access is restricted by tenant, user role, and permissions.

  • Access is protected by an email address and password. The password is stored in an unreadable format.

  • Developer and support access are tied to individual permissions; they may be used and logged when warranted.

  • Redaction of known direct identifiers in OpenAI's text input and tenant-level pseudonymization should be applied, provided that this does not interfere with the purpose of the feature.

  • Beeward implements regular backups, bug fixes, access reviews, and an incident management process.

Internet data transmission and the use of generative AI carry risks even with all reasonable safeguards in place. Beeward implements measures commensurate with the risks, but does not promise complete risk-free operation.

14. Rights of the Data Subject

  • Information and Access: You can find out whether we are processing your personal data and request a copy of it.

  • Correction: You may request that inaccurate or incomplete information be corrected.

  • Deletion: You may request the deletion of your personal data if the legal conditions are met.

  • Restriction: In certain cases, you may request a temporary restriction on the processing of your data.

  • Data Portability: In cases of automated data processing based on consent or a contract, you may request the machine-readable transfer of the data you have provided.

  • Objection: You may object to data processing based on legitimate interests, particularly in the case of direct marketing.

  • Withdrawal of consent: Withdrawal does not affect the lawfulness of prior data processing.

  • Right to object to automated decisions: You may request that decisions based solely on automated processing that have a significant impact on you not be applied to you. Beeward does not make such decisions.

The request must be answered without undue delay, generally within one month. In the case of complex requests or multiple requests, the deadline may be extended by an additional two months, and the data subject must be notified of this within one month. As a general rule, there is no fee for the request. Proof of the applicant’s identity may be required.

15. Requests, Complaints, and Legal Remedies

15.1. Who should you contact?

If your question concerns employee, community, or BeePT data managed in the company hive, please first contact your client’s organization—typically your employer or the hive administrator. That party is the data controller. Beeward may forward such requests received directly by Beeward to the relevant client and, as a data processor, assist in fulfilling them.

You can send requests regarding Beeward's own data processing to hello@beeward.buzz.

15.2. Complaints to Regulatory Authorities and Court Proceedings

You can file a complaint with the National Authority for Data Protection and Freedom of Information, and you can also take the matter to court.

Data

Contact Information

Name

National Authority for Data Protection and Freedom of Information

Title

1055 Budapest, 9–11 Falk Miksa Street.

Mailing address

1363 Budapest, P.O. Box 9.

E-mail

ugyfelszolgalat@naih.hu

Phone

+36 1 391 1400

Website

naih.hu

16. Cookies and Similar Technologies

The beeward.buzz website may use necessary, analytics, and marketing cookies. Strictly necessary cookies ensure the website’s functionality, security, language settings, and privacy settings. Without them, certain parts of the website will not function properly.

Category

Goal

Legal Basis

Settings

Absolutely necessary

Session, security, language, and cookie preferences.

The legitimate interest in ensuring safe operation and the provision of the requested service.

It cannot be turned off on the consent screen.

Analytical

Measuring website usage, traffic, performance, and conversions, for example, using Google Analytics.

Consent.

It works only with prior consent.

Marketing

Campaign tracking, remarketing, and more relevant ads, such as those offered by Google and Meta.

Consent.

It works only with prior consent.

 

The names, providers, purposes, and current expiration dates of the cookies actually used on the website can be viewed on the Privacy Settings page. You can modify or withdraw your consent there at any time. Cookies can also be deleted in your browser settings, but this may affect the functioning of certain features.

17. Amendments to the Prospectus

Beeward may amend this notice due to changes in the service, data processing, legislation, or the group of data processors. The current version is available on the beeward.buzz website. Beeward may provide separate notice of any significant changes that substantially affect users or customers through the service or via email.

Acknowledging that you have read the privacy policy does not constitute general consent. For data processing based on consent, Beeward provides a separate, unambiguous option.

 

Appendix. Brief BeePT Data Management Summary

Question

Answer

Who can use BeePT Admin?

The tenant's active company administrators.

What do you see?

The structured and text-based data in the Beeward tenant database, including the entire historical time range and the data that is otherwise visible in the admin interface.

Can you draw your own conclusions?

Yes. You can identify a specific employee and draw conclusions based on their activity patterns.

What might be included in OpenAI?

Prompt, conversation context, anonymized activity data, business statistics, text content, technical metadata, and image generation prompt.

Will the name or email address be transferred?

In the text input for Responses, known direct identifiers must be redacted. A name may appear in an image-generation prompt. Tenant and internal identifiers may appear in technical metadata.

How long is the admin chat visible?

For 30 days, exclusively for the admin who started the conversation.

Can the admin see the BeePT user chat?

No. Only anonymized, topic-based summaries can be used to form a team-level picture.

Is an automatic summary being generated?

Yes, a monthly team-level summary can be generated and sent via email to the current administrators.

Can you make a decision regarding labor law?

No. The AI output is only information to aid decision-making, subject to human review.

When will OpenAI's data processing begin?

Only after contractual approval at the tenant level and the necessary backend verification.