Data Processing Agreement

An Integral Part of Beeward's General Terms and Conditions

Data processor: Beeward Limited Liability Company

Headquarters: 7621 Pécs, 2 Kazinczy Street.

Company Registration Number: 02-09-088628

Tax ID Number: 32663871-2-02

Contact: hello@beeward.buzz

Effective Date: From the date of electronic acceptance.

 

In short: The Customer is the data controller for its own users’ personal data. Beeward Kft. processes this data as a data processor in accordance with the Customer’s instructions. BeePT Admin may only transmit data to the OpenAI API after the electronic acceptance of this agreement and the current General Terms and Conditions.

1. Subject Matter and Place of Performance of the Agreement as Specified in the Contract

1.1. This Data Processing Agreement is an integral part of the contract entered into for the use of the Beeward service and the General Terms and Conditions. This agreement governs the rights and obligations between the Customer and Beeward Kft. regarding the processing of personal data.

1.2. This agreement constitutes a written data processing agreement pursuant to the applicable laws governing the processing of personal data of natural persons, in particular Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council.

1.3. In the event of any conflict between this Agreement and the provisions of the General Terms and Conditions regarding data processing, the provisions of this Agreement shall prevail.

2. Parties and Roles

2.1. The Data Controller is the business entity, other organization, or natural person that orders the Beeward service and whose information is included in the registration, the customized offer, the billing information, or other contractual documents. Hereinafter: Customer.

2.2. The data processor is Beeward Limited Liability Company. Hereinafter referred to as: Beeward or the Service Provider.

2.3. The Client shall determine the purpose and legal basis for the processing of data concerning its employees, members, guests, and administrators. Beeward processes personal data exclusively in accordance with the Client’s documented instructions, the service agreement, and this agreement.

2.4. Beeward, in its capacity as a data controller, may process the data of its own contractual contacts, billing data, data necessary for legal claims, as well as its own system security and fraud prevention data. These are subject to Beeward’s Data Processing Notice, as amended from time to time.

3. Documented Instructions

3.1. Documented instructions include, in particular, the service agreement, the General Terms and Conditions, this agreement, settings made in the system by the Customer’s administrators, requests to activate or deactivate a feature, and written requests received from the Customer’s identifiable contact person.

3.2. Beeward shall immediately notify the Client if, in its opinion, any instruction violates applicable data protection laws. Beeward may suspend the execution of such an instruction until the situation is clarified.

3.3. If Beeward is required by law to process data in a manner that differs from the Client’s instructions, Beeward shall inform the Client of this prior to such data processing, unless prohibited by law for an important public interest.

4. Electronic Acceptance and Activation of BeePT Admin

4.1. This agreement may be accepted electronically by any active company administrator of the hive on behalf of the Customer. Acceptance applies to the entire hive and all of its current and future administrators.

4.2. The accepting administrator declares that he or she is acting on behalf of the Customer. To provide evidence of acceptance, Beeward records the hive ID, the accepting administrator’s internal ID, the date and time of acceptance, and the version of the accepted documents.

4.3. For existing hives, Beeward’s basic functions may continue to be used if acceptance is not granted, but BeePT Admin cannot make OpenAI API calls or generate automatic AI summaries. The backend must check for acceptance before every OpenAI API call and background process.

4.4. For new hives, BeePT Admin can be activated without a separate pop-up window, based on the current Terms and Conditions accepted during registration and this agreement. The paid, user-based BeePT is a separate feature that Beeward activates only upon the Customer’s specific request and after the related subscription has been established.

4.5. The employees’ separate consent is not part of this contractual acceptance. It is the Client’s responsibility to ensure that the processing of employee data has an appropriate legal basis and that the data subjects receive clear information about the data processing.

5. The subject matter, purpose, nature, and duration of the processing

5.1. The purpose of the processing is to provide, operate, support, and ensure the secure functioning of Beeward’s workplace recognition, community, rewards, and related AI features.

5.2. The main purposes of the processing are as follows:

  • Managing user accounts, permissions, administrator roles, and hive membership.

  • Management of acknowledgments, point awards, point balances, point transactions, rewards, redemptions, posts, comments, reactions, polls, and related content.

  • Delivery of transactional emails, system messages, and push notifications.

  • Generating statistics, team performance reports, and administrator summaries.

  • Operating BeePT Admin and, if separately activated, the user version of BeePT.

  • Customer support, troubleshooting, backup, incident management, and fraud prevention.

5.3. Processing continues from the effective date of the contract until its termination, and then until the end of the return and deletion period specified in Section 13. Backups will continue for a maximum of an additional 30 days.

6. The Customer’s Obligations

  • It specifies the purpose, legal basis, and necessary duration of the processing of personal data.

  • It will provide employees and other affected parties with appropriate information regarding data processing related to the Beeward and BeePT features.

  • It records, or permits the recording of, only personal data whose processing is lawful, necessary, and proportionate.

  • Ensures that administrator privileges are granted only to appropriately authorized individuals and that any privileges that are no longer needed are revoked immediately.

  • Administrators are required to keep login credentials confidential and to manually review AI responses.

  • As the data controller, it handles requests, objections, and requests for correction and deletion from data subjects, enlisting the assistance of Beeward as needed.

  • It conducts a balancing of interests, a data protection impact assessment, or a prior consultation if the specific use requires it.

6.2. The Client may not instruct Beeward to engage in unlawful data processing, nor may it use BeePT Admin’s response as the sole basis for an employee’s termination, promotion, discrimination, disciplinary action, or any other significant employment-related decision.

7. Beeward's Obligations

  • Personal data is processed solely in accordance with documented instructions and to the extent necessary to provide the service.

  • It ensures that individuals who have access to personal data are subject to appropriate confidentiality obligations.

  • It implements technical and organizational measures commensurate with the risks.

  • The Contractor shall assist the Client, to a reasonable extent, in handling requests from data subjects, data protection incidents, impact assessments, and inquiries from regulatory authorities.

  • It documents the data processing and the chain of subprocessors under this agreement.

  • Upon termination of the service, personal data will be returned or deleted in accordance with Section 13.

  • The Customer shall provide the information reasonably necessary to verify compliance with this agreement.

8. BeePT Admin and BeePT Users

8.1. Purpose and Access to BeePT Admin

BeePT Admin is a dedicated AI agent available to company administrators. It generates summaries of team performance and activity, helps interpret Beeward data, and can make recommendations for recognition and rewards. BeePT Admin does not perform any actions, award points, redeem rewards, modify data, or make automatic decisions. It provides only text-based responses or images generated from text prompts.

BeePT Admin has access to the text and structured Beeward data that hive users can normally view, as well as to the administrative data that the administrator can otherwise access via the Beeward admin interface. This may include reward redemptions and the associated administrative data.

BeePT Admin can analyze scores, point allocations, justifications, acknowledgments, posts, comments, reactions, votes, rewards, redemptions, and activity patterns across the entire available historical time period. Direct searches for users who have left the platform or are in "soft delete" status are prohibited, but their previous content may be included in aggregated or content-based analyses.

8.2. Data Transmitted to OpenAI

During the operation of BeePT Admin, administrator prompts, conversation context, system commands, tool definitions, the results of tool calls, business and activity statistics, and the text content required to generate the AI response may be transmitted to the OpenAI API.

Beeward replaces known names, usernames, email addresses, and internal user IDs in the text input of the Responses API with tenant-level, permanent, non-transparent tokens whenever possible. This is pseudonymization, not anonymization. Technical metadata transmitted to OpenAI may include the tenant domain, internal user ID, and agent type.

When generating images, the prompt provided by the user may contain personal data, such as a name, if this is necessary to create the requested image. Beeward does not permanently store the generated image, but the image generation prompt may be retained for up to 30 days as part of the administrator chat.

8.3. Administrator Chats and Monthly Summary

Administrator BeePT conversations in the Beeward system can be viewed for 30 days, after which the conversation content is permanently deleted. An administrator can view only the conversations they have initiated themselves. The deletion background process must continue to run even after BeePT Admin is subsequently shut down.

After activating BeePT Admin, a monthly, team-level summary can be generated automatically. All company administrators who are active at that time will receive the summary via email. The content of the email cannot be viewed in the Beeward app. The content may be retained in the recipients’ inboxes according to the Customer’s own retention policies, and in the Postmark system according to the service provider’s current retention settings. With the default Postmark retention setting, this period is 45 days.

8.4. Isolation of the User BeePT

The user BeePT is an AI agent separate from BeePT Admin. It has access only to data related to that specific user and to the knowledge base documents provided by the Client for that function. It cannot view company-wide statistics, other users’ personal data, or other users’ BeePT conversations.

Company administrators and other users cannot access users’ BeePT conversations. The content of raw conversation messages is deleted after 30 days. A summary may be generated from the chats after direct identifiers have been redacted. Since the summary may still be indirectly linked to a person or hive, Beeward treats it as personal data and deletes it no later than when the tenant is deleted.

Documents in the knowledge base may be uploaded in their entirety to the OpenAI Files and Vector Stores services. There is no guaranteed automatic filtering of personal data prior to uploading the documents. Therefore, the Customer may only submit documents for which it has a valid legal basis for processing for this purpose. Independent activation of BeePT Admin does not result in the upload of documents from the company’s knowledge base.

8.5. AI Preservation and Security Principles

  • In Responses API calls, the `store` value must be explicitly set to `false`. Enabling this is a prerequisite for activating BeePT Admin in production.

  • Under its current terms of service, the OpenAI API may retain logs related to the detection of provider abuse for up to 30 days by default, unless longer retention is required by law or for security reasons.

  • OpenAI may not use customer data sent to the OpenAI API to train its models, unless Beeward provides separate, express consent to do so. Beeward may not grant such consent for customer data.

  • Items in OpenAI Files and Vector Stores may remain accessible for as long as they are necessary for the active operation of the user's BeePT. Beeward initiates their deletion when the feature is discontinued or when the tenant is deleted.

  • Beeward does not claim that pseudonymized data is anonymous data. It applies the confidentiality provisions of this agreement to pseudonymized employee statistics in the same manner.

9. Restrictions on Automated Decision-Making and Profiling

9.1. BeePT Admin may draw conclusions regarding a specific individual or team based on activity patterns. This may constitute profiling; therefore, the Customer must ensure the appropriate legal basis, transparency, necessity, and proportionality.

9.2. The response from BeePT Admin is a decision-support recommendation. The system may not make any decision that is based solely on automated processing and that produces legal effects or similarly significant effects on the data subject. Any conclusion concerning an individual must be reviewed by a person with the appropriate authorization.

9.3. BeePT Admin may not be used for covert employee surveillance, for ranking employees, or for drawing conclusions about their health, union membership, political views, religious beliefs, sexual orientation, or other sensitive personal information.

10. Sub-data processors

10.1. The Customer grants general written authorization to use the subprocessors listed in Annex 2. Beeward shall ensure that the subprocessor undertakes, in a written contract, data protection obligations that are at least equivalent to those set forth in this agreement.

10.2. Beeward shall notify the Customer of any material change in its circle of data processors at least 15 days in advance via email or by posting a notice on the Service. During this period, the Customer may raise an objection for specific and reasonable data protection reasons. The parties shall consult on measures to mitigate the risk. If this is not possible, the Customer may disable the affected supplementary service or terminate the contract.

10.3. Beeward is liable to the Customer for the subcontractor’s performance as if Beeward had performed the work itself.

11. International Data Transfers

11.1. Rackforest and YCO Digital process data in Hungary. In the case of services provided by OpenAI, Postmark, and Google, personal data may also be processed outside the European Economic Area.

11.2. Beeward will only transfer personal data to a third country if the transfer complies with Chapter V of the GDPR. This may be based on an adequacy decision, an applicable data protection framework, standard contractual clauses adopted by the European Commission, or other lawful safeguards for data transfer.

11.3. Based on the information available to it, Beeward shall assist the Customer in preparing the required data transfer risk assessment.

12. Requests from Data Subjects, Inquiries from Regulatory Authorities, and Audits

12.1. If Beeward receives a request directly from a data subject regarding data processed by the Client, it shall direct the requester to the Client and forward the request, unless the law prescribes a different procedure.

12.2. Beeward shall provide reasonable technical and organizational assistance, taking into account the nature of the processing, to fulfill requests for access, rectification, erasure, restriction, objection, and data portability. Complete erasure may currently require a manual database operation.

12.3. The Client may request information regarding the performance of this agreement once a year, and on additional occasions in the event of a data breach or a well-founded compliance concern. On-site or technical audits may only be conducted by prior arrangement and must ensure the protection of other customers’ data, Beeward’s trade secrets, and system security.

13. Termination of the Contract, Return of Data, and Deletion

13.1. Upon termination of the service agreement, the Customer may request the return of personal data and its own content in a reasonable, generally usable format up to the date of termination. Beeward will provide the export functionality that is technically available.

13.2. Upon termination of the contract, the tenant’s user access will be terminated. Beeward will delete or irreversibly anonymize the active tenant’s database within 30 days of termination, except for data that must be retained by law.

13.3. Deletion applies to the active database, related personal content, AI conversations, summaries, uploaded OpenAI files, vector store items, as well as delivery and device identifiers managed by Beeward. Data will be deleted from backups within a maximum of 30 additional days.

13.4. During normal business operations, no retroactive individual deletions are made to backups. If a backup must be restored for disaster recovery purposes, Beeward will ensure that any previously deleted data is deleted again.

13.5. Beeward shall confirm in writing, at the Customer’s request, that the data has been deleted. Data that must be retained in accordance with the law may be processed solely for the required purpose and for the required period.

14. Data Breach

14.1. Beeward shall notify the Customer’s contact person without undue delay—and, if possible, within 48 hours—of any data breach involving the Customer’s personal data that comes to its attention.

14.2. The notification shall include, to the extent available, the nature of the incident, the categories of data and individuals affected, the likely consequences, the measures taken or planned, and contact information for further communication. Beeward will provide additional information without delay as it becomes available.

14.3. As the data controller, the Client shall decide whether to report the matter to the authorities or to the data subject. Beeward shall reasonably provide the information at its disposal for this purpose.

15. Confidentiality, Liability, and Final Provisions

15.1. Beeward and its affiliates with access to the data shall treat any personal data, business information, and customer data that comes to their knowledge as confidential. The obligation of confidentiality shall remain in effect even after the termination of the contract.

15.2. The parties shall be liable for any breach of their data protection obligations in accordance with applicable law and the service agreement. The limitation of liability in the service agreement shall not be interpreted as limiting the rights of data subjects under the GDPR or the powers of the supervisory authority.

15.3. This agreement shall be governed by Hungarian law. The parties shall settle their disputes primarily through mutual agreement. The provisions of the General Terms and Conditions shall apply with respect to jurisdiction.

15.4. This Agreement is entered into through electronic acceptance. Beeward shall retain the accepted version and the log data regarding the acceptance and shall make them available to the Customer upon request.

Appendix 1. Detailed Description of Data Processing

Element

Description

Purpose of Data Processing

Beeward SaaS, BeePT Admin, and—if separately activated—the user's BeePT account.

Duration

The term of the service agreement, followed by a 30-day active database deletion period. Backups expire within a maximum of an additional 30 days.

Operations

Collection, recording, organization, storage, retrieval, display, transmission, interconnection, statistical analysis, pseudonymization, summarization, generative AI processing, restriction, export, deletion, and anonymization.

Stakeholders

The Client’s employees, members, administrators, invited and registered users, contacts, and former users listed in the historical data.

Geography Circle

Primary processing and storage in Hungary. Some subcontractors may also carry out processing outside the EEA.

 

Categories of Personal Data

  • Identification and contact information: name, email address, username, profile information, internal user ID, tenant domain, and hive membership.

  • Authorization data: user role, administrator status, team membership, activation and acceptance log data.

  • Recognition and activity data: points, point awards, justifications, recognitions, posts, comments, reactions, votes, rewards, reward redemptions, purchases, timestamps, and statistics.

  • AI data: prompts, responses, conversation context, AI inferences, conversation summaries, image-generation prompts, anonymized activity logs, and technical metadata.

  • Knowledge Base data: the full text of documents uploaded by the Customer, which may contain personal information.

  • Technical and security data: login and access logs, device and browser data, push registration tokens, Firebase installation IDs, and IP addresses, if they appear in the app's security logs.

  • Communication data: recipient, subject, content, delivery, and open events for transactional emails, as specified in the service provider's settings.

Special Data

Beeward’s features do not require the provision of any specific personal data. However, such data may appear in free-text content or uploaded documents. It is the Customer’s responsibility to ensure that such data is entered into the system only on an appropriate legal basis, to the extent necessary, and with appropriate safeguards. BeePT Admin cannot be instructed to infer special categories of personal data.

Appendix 2. Authorized Subcontractors

Service Provider

Location

Task

Rackforest Ltd.

Hungary

Server infrastructure, application and database hosting, backups.

YCO Digital, Ltd.

Hungary

Development, bug fixes, technical operations, and limited support access.

OpenAI

EEA and third countries, as specified in the applicable agreement

Responses API, image generation, and—for the BeePT user—Files and Vector Stores.

AC PM, LLC, Postmark

The United States and its subcontractor locations

Delivery of transactional emails and monthly BeePT Admin summaries.

Google Firebase Cloud Messaging

The applicable Google agreement and the locations of its subprocessors

Managing push notifications, registration tokens, and Firebase installation IDs.

 

The current terms and conditions and privacy policies of data processors are available on the service providers’ respective websites. Beeward will send a notification regarding any material changes to the list in accordance with Section 10.2.

Appendix 3. Technical and Organizational Measures

Area

Action

Data Transfer

The Beeward app and external API connections operate over HTTPS and TLS-secured connections.

Tenant Isolation

The data for each hive is logically separated. Users can access only the data associated with their own hive and within the scope of their permissions.

Access

Email and password-based authentication, role-based user and administrator access, and individual developer access.

Logging

The system can technically log logins, administrator approvals, and privileged access. Access to the logs is permitted only when justified.

Confidentiality

Employees of Beeward and YCO Digital who have access to this information are bound by a confidentiality agreement. The public agreement does not include a list of individuals by name.

Data Minimization

In OpenAI's text input, known direct identifiers should be redacted and tenant-level pseudonymization should be applied, provided that this does not interfere with the purpose of the feature.

AI Storage

Responses API calls are made with the `store:false` setting. Beeward does not allow the sharing of customer data for model development purposes in the OpenAI account.

Backup

Database backups are retained for up to 30 days.

Delete

The active tenant database must be deleted or irreversibly anonymized within 30 days of the contract’s termination. The associated backups will expire within a maximum of 30 additional days.

Availability

Regular backups, recovery options, bug fixes, and the installation of critical security updates within a reasonable timeframe.

Review

Beeward regularly reviews access rights, data processors, and AI data transfers based on risks and changes to the service.

 

Appendix 4. Preservation Summary

Data Set

Duration

Comment

BeePT Admin Chat

30 days

The administrator in question can review their own chat, after which the content is deleted.

Image Generation Prompt

Up to 30 days at Beeward

Beeward does not permanently store the generated image.

User BeePT raw message

30 days

The content is being cleared. Other users and administrators cannot access it.

BeePT User Summary

Until the tenant is deleted

Direct identifiers must continue to be treated as personal data even after they have been redacted.

Monthly BeePT Admin Email

There are no past issues available for viewing in the Beeward app

In the recipient's mailbox, in accordance with the Customer's rules. By default, Postmark can store the content and delivery data for 45 days.

OpenAI Responses API

When `Store:false`, there is no persistent application state

By default, the abuse audit log is retained for up to 30 days.

OpenAI Files and Vector Stores

Until the user actively uses BeePT

When a tenant is deactivated or deleted, Beeward initiates a deletion request. The current service provider's deletion times apply.

Postmark Email Content and Activity

45 days by default

The current Postmark retention setting for the Beeward account takes precedence.

Firebase installation ID

According to Google's current Terms of Service,

Beeward deletes tokens in its own system by deleting the tenant. Deletion on the Google side occurs in accordance with the available API and the tool's lifecycle.

Active Tenant Database After Termination

30 days

Deletion or irreversible anonymization.

Backup

Up to an additional 30 days

It is deleted when the backup cycle ends.

 

Armsing condition: According to the document, the system must operate under the following conditions: the backend must verify tenant-level acceptance before every OpenAI call; Responses API calls must be made with an explicit `store:false` value; and the 30-day conversation deletion policy must continue even after the feature is disabled.