Privacy Policy

At beUplifter, privacy and security are a core part of how we design and operate our website and SaaS platform. We do not sell personal data, and we do not use the website for cross-site behavioral advertising. This policy explains how we process personal data in connection with our website, business communications, and the beUplifter platform, with a focus on individuals in the EU and EEA.

Last Updated: April 21, 2026

1. Controller and Processor Roles

This policy covers two different processing contexts:

  • Website and business contact data: beUplifter processes this data for its own business purposes, such as operating the website, handling contact requests, managing supplier and customer communications, and protecting the service. For this data, beUplifter acts as the data controller.
  • Customer account and employee data: beUplifter processes this data through the platform on behalf of customer organizations. For this data, the customer organization acts as the data controller and beUplifter acts as the data processor under a data processing agreement or other applicable contract.

If you use beUplifter through your employer or another organization, that organization is usually the first point of contact for privacy requests relating to your platform data. We assist customer controllers where required.

2. Website and Business Contact Data

When you visit our website, use our contact channels, or otherwise interact with us directly, we may process:

  • Contact and inquiry data: name, work email address, company name, message contents, meeting request details, and related correspondence
  • Website analytics data: pages viewed, approximate location, browser and device information, timestamps, referrer information, and related analytics identifiers
  • Technical and security data: IP address, request metadata, status codes, diagnostic logs, and anti-abuse or fraud-prevention signals
  • Preference data: consent choices, language, time zone, and similar website preferences

We use this data to operate the website, respond to requests, maintain business relationships, improve the website, measure performance, and protect the security and integrity of our services.

3. Customer Account and Employee Data

Depending on how a customer configures beUplifter, we may process the following categories of personal data on that customer's behalf:

  • Account data: names, work contact details, roles, organization details, user identifiers, and authentication-related metadata
  • Profile and organization data: reporting lines, team structures, job information, and similar workplace profile data
  • Collaboration and workspace data: goals, meeting information, and other content entered by users or administrators
  • Survey and feedback data: survey responses, comments, and aggregated or threshold-based reporting outputs
  • Uploads and integration data: files, images, calendar information, and related synchronization metadata where customers enable those features
  • Technical and audit data: timestamps, access logs, audit records, and support or administration records associated with use of the platform

The exact categories of data processed depend on the customer's configuration, enabled features, integrations, and user activity.

Customers are responsible for deciding what data they collect through the platform and for identifying an appropriate legal basis where required. We ask customers and users not to include special category data or other highly sensitive data in free-text fields or uploaded documents unless they have assessed the need and put suitable safeguards in place.

4. AI Features and Automated Processing

beUplifter may offer optional AI-assisted features to help users draft, summarize, classify, or analyze work-related content.

  • User-initiated features: AI features are intended to run when a user requests the feature or otherwise triggers the relevant workflow.
  • Inputs: depending on the feature, inputs may include customer-provided workspace content relevant to the requested task.
  • Data minimization: where practical, we aim to limit the amount of personal data sent to AI providers and reduce direct identifiers, but some features may require contextual information to produce useful results.
  • Provider commitments: where our provider terms or contracts state that customer data is not used to train general models, we rely on those commitments.
  • Human oversight: AI outputs are intended to support users and are not, by themselves, used to make solely automated decisions with legal or similarly significant effects about individuals.
  • Providers: our current AI providers and other subprocessors are listed on our subprocessors page.

6. Data Sharing and Subprocessors

We share personal data only where necessary, including with:

  • service providers that support hosting, authentication, analytics, email delivery, security, integrations, and AI functionality
  • customer-selected or user-connected providers, such as calendar or conferencing services
  • legal authorities, regulators, courts, or other third parties where required by law or where necessary to establish, exercise, or defend legal claims, protect safety, or protect the service

We permit limited internal access to personal data on a need-to-know basis for activities such as customer support, technical troubleshooting, security investigations, and platform administration.

We publish a current list of subprocessors and their locations on our subprocessors page.

7. International Data Transfers

Some subprocessors may process personal data outside the EEA, including in the United States. Where required, we use appropriate transfer safeguards, such as Standard Contractual Clauses, Data Privacy Framework participation where applicable, or another lawful transfer mechanism under GDPR.

8. Data Retention

We retain personal data for different periods depending on the context:

  • Customer platform data: generally for the duration of the customer relationship and thereafter as instructed by the customer or required by law
  • Website inquiries and business correspondence: for as long as needed to respond to the request, manage the relationship, and maintain appropriate business records
  • Operational and security records: for as long as reasonably necessary for troubleshooting, security investigations, audit, or compliance purposes
  • Backups and disaster recovery copies: for limited periods consistent with our backup and recovery processes

We may retain data for longer where required by law or where necessary to resolve disputes, enforce agreements, or protect legal claims.

9. Security Measures

We use technical and organizational measures designed to protect personal data, including:

  • role-based access controls and authentication controls
  • encryption in transit
  • encryption at rest for sensitive data and protected storage layers
  • logging, monitoring, and security investigation processes
  • backup and recovery procedures

10. Cookies, Local Storage, and ePrivacy

We use cookies and similar technologies for the following purposes:

  • Essential authentication and security: cookies required for sign-in, session handling, and secure operation of the platform
  • Preferences: first-party cookies or browser local storage to remember settings such as consent choices, language, and time zone
  • Analytics: analytics technologies on our website to understand traffic and usage, improve the website, and measure performance

Where required, we rely on consent before enabling non-essential analytics technologies. You can manage cookie preferences through our consent tools where available, and you can also control cookies through your browser settings.

11. Minors

The platform is intended for workplace use and is not directed to children. We do not knowingly collect personal data from children through the website.

12. Your GDPR Rights and How to Exercise Them

If GDPR applies to our processing of your personal data, you may have the following rights, subject to applicable conditions and exceptions:

  • Access (Art. 15): ask whether we process your personal data and request a copy of it
  • Rectification (Art. 16): ask us to correct inaccurate or incomplete personal data
  • Erasure (Art. 17): ask us to delete personal data in certain circumstances
  • Restriction (Art. 18): ask us to limit processing in certain circumstances
  • Data Portability (Art. 20): receive personal data you provided to us in a structured, commonly used, and machine-readable format, and ask us to transmit it to another controller where technically feasible
  • Objection (Art. 21): object to processing based on legitimate interests and, at any time, object to direct marketing
  • Automated Decision-Making (Art. 22): not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where applicable
  • Withdraw Consent (Art. 7(3)): withdraw consent at any time where processing is based on consent
  • Lodge a Complaint (Art. 77): lodge a complaint with a competent supervisory authority

If your request relates to website or business contact data for which beUplifter acts as controller, you can contact us at ask@beuplifter.com.

If your request relates to platform data processed for your employer or another customer organization, that organization is usually the first point of contact because it is typically the controller. We assist customer controllers in responding to rights requests as required by applicable law.

13. Contact Information

For privacy questions or requests relating to this policy, contact ask@beuplifter.com.

14. Changes and Updates

We may update this policy from time to time to reflect legal, technical, operational, or product changes. The "Last Updated" date shows when the current version took effect.