LEGAL / PRIVACY POLICY

Privacy Policy

Version 2026-09-14 · Effective September 14, 2026

The short version: we do not sell your data, we store the evidence you bring so the platform can work and stay auditable, and everything is scoped by your written authorization. The details follow.

Clause 01

What this policy covers

This Privacy Policy explains how BeeraSafe ("we," "us," or "our") handles personal information when you use the BeeraSafe platform, including the Bolt security workspace, Rampart organization workspaces, our website, and our managed services (together, "the platform"). It is incorporated into and read alongside our Terms of Service. Engaging with us on behalf of an organization means that organization's rules and the scope of our written agreement also apply.

Clause 02

What we collect

Account data. The email address and a hashed password you provide when you register, your display name where you set one, and the products you may access. We do not store plaintext passwords. Session data. A signed, HttpOnly session token valid up to 30 days, a limited set of active devices, and a log of sign-in events used for abuse review and to support sign-out on suspension. Content. The evidence, prompts, case files, and repository scan inputs you bring to the platform, plus the analysis output generated for you. Billing data. Payment details go directly to Nylon Pay; we record the reference, amount, and token balance credit only. We do not store your card details. Correspondence. The content of support conversations you choose to have with us.

Clause 03

How we use it

We use the information above to operate and secure the products, to deliver scans, analysis, and scoped engagements you request, to meter token usage and bill accurately, to respond to support requests, and to investigate abuse, fraud, or unauthorized access. For audit, billing, abuse-prevention, and service improvement we keep prompts, their token usage, and related metadata. Aggregated and de-identified data (which cannot be linked back to you or your organization) may be used for analytics and product development. We do not sell personal information.

Clause 04

Subprocessors and sharing

We share the minimum necessary to run the platform with a small set of subprocessors: an inference infrastructure provider (receiving prompts and evidence only where a workflow is AI-assisted), our payment processor, our application host, and our transactional email provider. Each is bound by obligations consistent with this policy. We do not provide personal information to advertisers or brokers. We may disclose information where required by law, regulation, or a valid legal process, and in emergencies to protect the safety of people or systems.

Clause 05

Retention and deletion

We retain account and usage data while your account is active and for a reasonable period afterward to satisfy audit, billing, and abuse-prevention obligations. Your evidence, findings, and case files are yours; you may export or request their deletion, and we will action verified deletion requests within a reasonable time, subject to records we are legally required to keep. On account closure we will sign out active sessions and honour applicable retention commitments.

Clause 06

Security of your data

Passwords are stored hashed and are never logged. Sessions use signed HttpOnly cookies with limited lifetime and device counts, and are revoked on sign-out or suspension. Sign-in, password, and product-access events are recorded for our own abuse review. Access to your content is limited to staff engaged in delivering the service or resolving support requests, under the same authorization discipline we apply to engagements.

Clause 07

Your choices and rights

You can update your account details, sign out of individual sessions, and request a copy or deletion of your personal data by contacting support. Where applicable law grants you rights to access, correct, or erase personal data, we will honour verified requests promptly and without prejudice to your use of the platform. You may also withdraw a consent you previously gave where consent is the legal basis we rely on.

Clause 08

Children's data

The platform is intended for use by people who are at least 18 years old under our Terms of Service. We do not knowingly collect personal information from children. If you believe a child's information has been provided to us, contact support and we will delete it promptly.

Clause 09

Contact

Questions about this policy or privacy practices may be directed to support@beerasafe.com. We will respond within a reasonable time, and will not treat a privacy question as a reason to lower your level of service.