Privacy Policy
Last updated: 30 June 2026
1. Who we are
Beecause.AI is a service operated by Wisely, Lda., a company incorporated in Portugal with registered office at Rua de S. Pedro n.º 12A, 4720-092 Amares, Portugal (referred to as "Beecause.AI", "we", "us" or "our"). Wisely, Lda. is the data controller for the personal data described in this policy.
For privacy-related queries or to exercise your rights, contact: privacy@beecause.ai. For data-protection enquiries, you may also contact our data-protection team at: dpo@beecause.ai.
Our infrastructure is hosted on Google Cloud Platform, europe-west1 (EU), fronted by Cloudflare for CDN and edge security.
2. Controller vs processor
Beecause.AI acts in two distinct capacities depending on the data involved:
- Controller — for data about you as an individual: your account information (name, work email, organisation, authentication credentials managed via Google Identity Platform), billing data (processed by Stripe — we never store your card details), product usage/activity, and marketing-site analytics (collected only with your consent).
- Processor — for customer data: the incident/conversation content, telemetry (logs, metrics, traces) we query from your connected observability tools, repository metadata from connected code platforms, and the encrypted credentials you provide to connect those tools. We process this data solely on your organisation's documented instructions to operate the service, and we may pass it to AI model sub-processors for analysis. Your organisation's own privacy obligations govern this data; see our Data Processing Agreement.
3. Data we collect, purposes, and lawful bases
| Category | Examples | Purpose | Lawful basis (GDPR Art. 6) |
|---|---|---|---|
| Account data | Name, work email, organisation name, hashed password | Providing and securing your account | Contract (6(1)(b)) |
| Billing data | Email, billing name, invoice history (Stripe manages card data) | Processing payments and issuing invoices | Contract (6(1)(b)); Legal obligation (6(1)(c)) |
| Product usage | Features used, team configuration, AI interactions, API calls | Delivering and improving the service | Contract (6(1)(b)); Legitimate interests (6(1)(f)) |
| Server/security logs | IP address, request path, timestamp, error details | Security, fraud prevention, debugging | Legitimate interests (6(1)(f)) |
| Analytics (marketing site) | Anonymised page views, referrers (via Google Analytics) | Understanding how visitors find and use beecause.ai | Consent (6(1)(a)) — only after opt-in |
| Marketing email | Email address, communication preferences | Sending product news and updates (where opted in) | Consent (6(1)(a)) |
4. Sub-processors
We share personal data with the following categories of third-party service providers (sub-processors). A full, up-to-date list is maintained at beecause.ai/subprocessors.
- Google Cloud Platform (hosting via Cloud Run, Firestore, Pub/Sub, Identity Platform, Vertex AI for Gemini models and embeddings, Cloud Trace) — EU (europe-west1) primary — covered by Google's DPA, EU-US Data Privacy Framework, and Standard Contractual Clauses where applicable.
- Cloudflare (CDN, edge security, bot protection) — global — covered by Cloudflare's DPA and SCCs.
- Stripe (billing and payment processing) — EU/US — covered by Stripe's DPA and EU-US DPF/SCCs.
- Resend (transactional email delivery) — US — covered by Resend's DPA and SCCs.
- Anthropic (Claude AI model, used for RCA analysis where configured) — US — covered by Anthropic's DPA and SCCs.
- OpenAI (AI model, used for RCA analysis where configured) — US — covered by OpenAI's DPA and SCCs.
- Google (Vertex AI / Gemini) (AI models and embeddings) — EU and global — covered by Google's DPA.
- Google Analytics (marketing-site analytics, consent-gated only) — US — covered by the EU-US Data Privacy Framework.
The AI model provider active for a given RCA depends on the models configured for your organisation. Customer-connected tools (such as GitHub, Slack, Datadog, or other observability platforms) are systems you own and operate; Beecause.AI accesses them on your instructions and they are not Beecause.AI sub-processors.
5. International data transfers
Our primary processing is within the European Union (Google Cloud, europe-west1). Some sub-processors are located in the United States. Where data is transferred outside the EU/EEA, we rely on one or more of the following safeguards:
- The EU-US Data Privacy Framework (DPF), where the recipient is certified.
- Standard Contractual Clauses (SCCs) adopted by the European Commission, incorporated into our data processing agreements.
You can request a copy of the applicable transfer safeguards by contacting privacy@beecause.ai.
6. Retention
- Account data: held for the lifetime of your account and for a limited period afterwards (typically up to 90 days) to allow recovery or resolve disputes, then deleted. Billing records are retained for the period required by applicable accounting and tax laws.
- Server and security logs: retained for a short period (typically 30–90 days) for security and debugging purposes.
- Analytics data: Google Analytics retains data for up to 14 months.
- Customer (processor) data: retained only as long as necessary to provide the service. On account closure, data is deleted in line with our DPA retention schedule, subject to backup cycles (up to 30 days).
7. Your rights
Under GDPR, you have the following rights in relation to your personal data. To exercise any of them, contact us at privacy@beecause.ai. We will respond within 30 days.
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — request deletion of your data where there is no overriding legal basis to retain it.
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on your consent (e.g. analytics cookies, marketing emails), you may withdraw at any time without affecting the lawfulness of prior processing.
- Lodge a complaint — you have the right to complain to a supervisory authority. Our lead supervisory authority is the CNPD — Comissão Nacional de Proteção de Dados (Portugal). You may also lodge a complaint with the supervisory authority in your own EU/EEA member state.
8. Cookies and tracking
We use cookies and similar technologies on beecause.ai. Analytics cookies are only placed after you give explicit consent via our cookie banner. You can change your preferences at any time using the "Cookie settings" link in the footer. For a full description of every cookie we use, see our Cookie Policy.
9. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure, including:
- Hosting within the EU (Google Cloud, europe-west1).
- Encryption at rest and in transit (TLS 1.2+).
- Tenant isolation — each customer's data is logically separated.
- Minimal privilege access controls; credentials for connected tools are stored encrypted.
- Regular dependency updates and security patching.
No system is 100% secure. If you become aware of a security issue, please contact privacy@beecause.ai.
10. Children
Beecause.AI is a B2B service intended for use by professionals aged 18 and over. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting a notice on beecause.ai or by email. The "Last updated" date at the top of this page will always reflect the most recent version.
12. Contact
For any privacy-related queries or to exercise your rights, contact: privacy@beecause.ai.
For data-protection enquiries, contact our data-protection team at: dpo@beecause.ai.
Wisely, Lda.
Rua de S. Pedro n.º 12A, 4720-092 Amares, Portugal