Last updated: 2 September 2026
This policy covers the personal data BeeSensible is responsible for: the data of website visitors, customers, and users of our services. We follow the GDPR.
It does not cover the text you or your organisation process through the Application. Your organisation is responsible for that, with us as the processor; that is set out in the Data Processing Agreement (DPA).
Article 1: Who are we?
BeeSensible is a service of Venturo Media B.V., Spijksedijk 1a, 6917 AD Spijk, the Netherlands. Chamber of Commerce 72127198, VAT NL858996492B01. For privacy questions, email trust@beesensible.eu.
Article 2: What data do we process, and why?
What we collect depends on how you reach us. Per situation, here is which data it is, what for, on what legal basis, and how long we keep it.
2.1 You visit our website
Data: technical data such as your IP address (anonymised), browser, operating system, and the pages you view.
Purpose: keeping the website working and secure, and measuring visits. We measure visits without cookies.
Legal basis: legitimate interest.
Retention: technical logs for up to 30 days.
2.2 You create an account (free or paid)
Data: your name, email address, language and time zone, the details of the account you sign in with (Google, Microsoft, or your organisation's identity provider), and technical details about your installation of the extension and the desktop app (version, last seen, whether the installation is managed by your organisation).
Purpose: creating and managing your account, giving you access, and supporting you.
Legal basis: performance of the agreement.
Retention: as long as your account exists. If you delete it, your data is gone within 30 days.
You sign in through our own login environment with Google, Microsoft, or your organisation's identity provider. If you set a password of your own there, we keep only a hash of it.
2.3 Your organisation takes out a paid subscription
Data: company name, address, Chamber of Commerce number, the contact's name and email, and payment details (those last ones are held by our payment provider).
Purpose: running the subscription, invoicing, and keeping the administration.
Legal basis: performance of the agreement and a legal obligation (our duty to the Tax Administration).
Retention: invoice and payment data for 7 years, as the law requires. Account data for the contract term plus 7 years.
2.4 You contact us or send feedback
Data: your name, email, and your message.
Purpose: answering your question, helping you, and improving the product. Your message arrives in our mailbox at Proton. If you use the contact form on the website, we also get a notice with those details in our internal Slack channel.
Legal basis: performance of the agreement, your consent, or legitimate interest.
Retention: up to 2 years after the last contact, unless the law requires longer.
2.5 You start a trial or sign up for updates
Data: your email address and your first name.
Purpose: getting you started with BeeSensible and keeping you posted. If you start a trial, we put your email address on our list for product emails; if your organisation moves to a paid subscription or you delete your account, we take you off that list.
Legal basis: your consent. You can unsubscribe through the link in each email.
Retention: as long as you are subscribed.
2.6 The Application processes text (us as processor)
While you type in a supported web application, or in a supported desktop application if your organisation uses the desktop app, BeeSensible analyses the text for sensitive data. Where that happens depends on the mode your organisation has set:
- On your own device (local). Detection runs entirely on your device, through the desktop app. The text does not leave your machine.
- In our EU cloud. The text goes to our own servers in the EU, is processed there in working memory, and is discarded right away. We do not store it.
In both cases we never pass your text to an outside AI service, and we never use it to train models.
What we do keep is a set of figures about the detection: the type of sensitive data, the level, the app or website, the detection engine used, the time, what you did with it (mask, replace, remove, or nothing), and whether the message was sent anyway afterwards. Full prompts, emails, or chats are not in there, and neither is a user id: the database has no column for it. If your organisation has switched on department insights, the server stamps the reporter's department on the figures; who it was is not stored, and departments are shown only above a minimum group size. We keep these figures for up to 24 months, then delete them.
So we do not count the same detection twice within an hour, a technical key goes with those figures. How that key is produced differs per mode:
- Local: your device mints a random reference unrelated to the detected value. Only that random reference is sent. The value itself, and any cryptographic derivative of it, never leaves your device.
- Cloud: since the text is already with us for detection, our servers compute the key as a cryptographic derivative (SHA-256) of the type and the detected value. We store that derivative alongside the detection figures, under the same retention of up to 24 months. We do not store the value itself. For short, predictable values such as a national identification number, such a derivative is in theory reversible, so we treat it as personal data rather than as anonymous data. If your organisation would rather avoid this altogether, local mode is the answer.
When you anonymise a PDF, we process the document temporarily and keep only the number of items removed.
This processing is there for one thing: spotting sensitive data in time and offering you a suggestion. We do not use it to monitor performance or assess people.
2.7 Overview of AI tools (only if your organisation turns this on)
If your organisation enables the AI tool overview module, the extension recognises on your own device whether a page you visit is an AI tool. It does so from the page title, the meta description, and whether a chat field is present; those signals stay on your device.
Data: the domain of the visited page plus a signal that it looks like an AI tool, added up per organisation per day; per tool and use-case category the number of prompts sent per day; and for every notice BeeSensible shows on an AI tool, that it was shown and how it ended (alternative opened, or continued anyway). No user ID, no URL path, no page content, and no stored prompt content. How often you personally use AI tools is summarised on your own device into a single category per month, such as "weekly"; the underlying daily data stays on your device.
To sort a prompt into a use-case category, such as "summarising", in cloud mode the first prompt of a conversation goes to our own servers in the EU, is sorted there, and is discarded at once; only the category is counted. In local mode the desktop app does that sorting on your own device.
Purpose: giving your organisation a picture of which AI tools are in use, and setting policy on that. Not to track individual employees.
Retention: for as long as the licence runs.
Article 3: Which services do we use?
We bring in a few outside services to run BeeSensible, each under a processor agreement. We do not sell your data.
In the detection itself:
| Service | What for | Location |
|---|---|---|
| Scaleway | Hosting, database, object storage, and the service that redacts PDFs | EU (France, Netherlands, Poland) |
| Hetzner | Server for cloud detection (not used in local mode) | EU (Germany) |
In local mode no outside service is involved in detection at all. The processing happens entirely on the device.
Around the service:
| Service | What for | Location |
|---|---|---|
| Cloudflare | CDN, security, and cookieless analytics for our website | US |
| Google / Microsoft | Sign-in (SSO) | US |
| Slack | Internal notifications about how the service is running, and messages from our contact form | US |
| Paddle | Billing and subscriptions (Merchant of Record) | UK |
| Brevo | Invitations, welcome emails, reminders, and product emails to free users | EU (France) |
| Proton | Our email and customer correspondence | Switzerland (adequacy decision) |
| GitHub Container Registry | Hosting of our software images (no personal data) | US |
Keycloak, which you sign in through, runs in our own environment at Scaleway and is not an outside party.
Three things go to Slack. First, internal notices about how our service is running; those hold only counts and technical status. Second, a notice when a new organisation is created, with its name, email domain, number of seats, and plan. Third, the messages you send us through our contact form, with the details you fill in there. The extension and the desktop app send nothing to Slack themselves, and no data about our customers' users ever goes there.
Article 4: Does your data go outside the EU?
We process your data within the EU as much as we can. Detection and storage run in the EU.
A few services sit outside it. Paddle is in the United Kingdom and Proton is in Switzerland; both have an adequacy decision from the European Commission. Cloudflare (CDN and analytics), Google, Microsoft, and Slack (sign-in and feedback) are in the US; that transfer relies on the EU-US Data Privacy Framework or on the standard contractual clauses. GitHub only hosts our software images and processes no personal data.
Article 5: How do we secure your data?
Traffic between your device and our servers, and between our servers and the detection environment, is encrypted with TLS. Our stored data is encrypted. Traffic between our own components runs inside a shielded cluster that is not reachable from the internet; one internal leg, between our API and the service that redacts PDFs, does not yet carry additional encryption. That is on our improvement list.
Access goes only to those who need it for their work, through role-based rights. Our hosting partners Scaleway and Hetzner hold ISO 27001 certification; BeeSensible itself does not. We carry out periodic security reviews.
Logs hold technical details of a request: the address, the method, the path with any parameters, the status, and the duration. Message content or typed text is not in them.
Article 6: What are your rights?
You have the right to access, correct, delete, restrict, object to, and port your data, and to withdraw consent you gave.
This does not apply to the text you type: we do not keep it, so there is no stored version to access or delete.
Send a request to trust@beesensible.eu. We respond within a month and may ask you to confirm your identity. If something does not sit right, you can also turn to the Dutch Data Protection Authority.
Article 7: Automated decisions
BeeSensible makes no automated decisions that affect you. You get a highlight with a suggestion; you decide what to do.
Article 8: Cookies
We use only functional cookies needed to run the site, plus the security cookies set by Cloudflare, our CDN. Our visitor statistics are cookieless: we measure visits without cookies and without tracking you. We do not use tracking or marketing cookies, so there is no consent banner.
Article 9: For organisations deploying BeeSensible
BeeSensible is not built to monitor employees. A product DPIA is available on request at trust@beesensible.eu; your own DPIA stays your responsibility.
Article 10: Changes
We may update this policy. The date at the top shows when we last did. We let you know about material changes.