Legal
Privacy Policy
This Privacy Policy explains how HEOSSI (Pte.) Ltd. ("HEOSSI") collects, uses, shares, and protects personal data when you use Bee or visit bee.heossi.com. We act as the controller for data of website visitors and account holders and as the processor for personal data inside Customer Data submitted via the API or workspace (governed by the DPA).
1. Who we are
- HEOSSI (Pte.) Ltd. is a private limited company incorporated in Singapore. We are the data controller for personal data described as "controller" data below, including for EEA, UK, and Singapore data subjects. Our Data Protection Officer can be reached at bee-privacy@heossi.com; this is also our public channel for access, correction, withdrawal, complaints, and other data-protection matters.
- We do not currently have an establishment or appointed Article 27 representative in the EEA or UK. That is an acknowledged compliance gap, not a claim that Singapore incorporation displaces EEA or UK law. Until representatives are appointed, contact the DPO directly at the address above.
2. Personal data we collect
- Account data — email, display name, organisation, password hash, OAuth provider id, subscription tier.
- Billing data — Stripe customer id, last-4 of payment method, billing address (we never see full card numbers).
- Product telemetry — request volume, latency, error rates, feature usage. Aggregated and minimised where possible.
- Communications — emails to support / sales / security inboxes; chat with the in-product assistant; contact-form submissions and attachments.
- Inputs and outputs — prompts you submit, files you upload, and responses Bee generates for you. These are Customer Data; we are processor for these under the DPA.
- Sensitive data — Bee is not intended for special-category, highly sensitive, health, biometric, government-identifier, or payment-card data on shared public tiers. Submit such data only under an approved enterprise or Enclave deployment with appropriate contractual and technical safeguards.
- Server logs — IP address, user-agent, request method and path; retained 30 days for security investigation.
- Android notification data — when you opt in, an encrypted FCM registration token, Firebase installation identifier, app/device metadata, delivery state, and notification interaction routing. Notification bodies are minimised and do not contain prompt or response content.
3. Sources
Most personal data comes directly from you. Some comes from third parties: Stripe (billing metadata), Supabase (authentication), OAuth providers (Google / GitHub / Microsoft, when you choose to use them), Google Firebase Cloud Messaging (optional Android installation and delivery metadata), and in limited cases public sources for sales contact research.
4. Why we use it
- Operate the service — serve responses, route traffic, scale, render the workspace.
- Bill you — invoicing, payment, dispute handling.
- Secure the platform — anomaly detection, abuse prevention, incident response.
- Comply with law — tax, regulatory, legal-process compliance.
- Improve operational reliability — fix bugs, debug latency, plan capacity. We do not use Customer Data to pre-train a foundation/base model.
- Governed model improvement — Improve Bee is enabled by default for accounts and service surfaces. Prompts, outputs, feedback and other submitted content may be used to improve Bee unless the account holder or customer turns Improve Bee off. The opt-out applies to future collection and does not reduce access to Bee.
- Communicate — service updates, billing notices, security bulletins, and (where permitted) marketing you opt into.
5. Legal bases (GDPR / UK GDPR)
- Performance of the contract — operating the service for paid customers.
- Legitimate interests — security, fraud prevention, product analytics and model improvement; balanced against your rights.
- Consent — optional analytics and marketing cookies; product marketing communications; and processing where applicable law requires consent.
- Legal obligation — tax, accounting, court orders.
- For Singapore (PDPA) processing, equivalent grounds (consent, legitimate interests assessment, deemed consent) apply.
6. Sharing and sub-processors
- We do not sell personal data, do not show third-party advertising, and do not share Customer Data with anyone except sub-processors used to run the service.
- Sub-processors are listed in the Data Processing Addendum and updated via the changelog. Customers can subscribe to sub-processor change notifications.
7. International transfers
- We are headquartered in Singapore and use sub-processors in the EU/EEA, UK, and US. Personal data may be transferred to countries outside the country of collection.
- EEA / UK transfers rely on the EU Standard Contractual Clauses (Decision 2021/914) plus the UK Addendum where applicable. APAC transfers comply with the Singapore PDPA's data-transfer provisions.
- Hive-plan and above customers can request EU-only or US-only processing for Customer Data.
8. Retention
- Account data — retained while your account is active and for up to 24 months after closure (for billing/audit/dispute).
- For free individual accounts, we may begin an inactivity-notice process after 12 months without meaningful authenticated activity. If the account remains inactive after the stated notice period, we may delete or irreversibly anonymize account data, except for records retained for legal, security, fraud-prevention, billing, or contractual purposes. No automated inactivity deletion is currently in operation.
- Conversation history — retained per workspace policy (default 90 days; configurable up to 7 years on Enclave).
- Audit logs (Hive+) — 1 year by default, configurable up to 7 years.
- Server logs — 30 days.
- Model-improvement copies and safety research captures — retained until opt-out/deletion or for up to 24 months, whichever occurs first; derived aggregate statistics that no longer identify a person may be retained longer.
- Media-generation job prompts, status, and result links — 90 days unless deleted sooner; provider-side copies follow the applicable sub-processor schedule.
- Scheduled tasks and results — while active and for 90 days after deletion or completion, unless the user deletes them sooner.
- Android push registrations — while enabled; revoked registrations are deleted within 30 days and inactive registrations within 180 days.
- Backups — encrypted backups expire on a 35-day rolling window.
9. Your rights
- EEA / UK / similar regimes: access, rectification, erasure, restriction, portability, and objection.
- California (CCPA / CPRA): the right to know, delete, correct, and limit use of sensitive personal information; the right not to be discriminated against for exercising those rights. We do not 'sell' personal information as defined by the CCPA.
- Singapore (PDPA): access, correction, withdrawal of consent, and complaint to the PDPC.
- Other jurisdictions (e.g. Brazil LGPD, India DPDPA, Japan APPI, Australia Privacy Act): we extend the core rights above — access, correction, deletion, and consent withdrawal — to all users on request, and honour additional local rights where the law of your jurisdiction requires them.
- Exercise rights by emailing the privacy address. Identity verification is required. We respond within 30 days.
- Account holders can also export data, delete the account, disable model improvement, disable history, and use incognito chats from Account > Privacy. Turning model improvement off stops future training capture; contact the privacy address to request removal of prior identifiable training copies.
10. Children
Bee is not directed at children under 16. We do not knowingly collect personal data from children under 16 absent verifiable parental consent.
11. Automated decision-making
Bee generates content and may automatically route requests, detect abuse, and apply safety restrictions. We do not use controller personal data to make solely automated decisions that produce legal or similarly significant effects about individuals. Customers must not deploy Bee for such decisions without a lawful basis, required notices, meaningful human review, and any assessment or safeguards required by applicable law.
12. Security
We use industry-standard administrative, technical, and physical safeguards. Data in transit is protected with TLS 1.3; post-quantum transport (FIPS 203/204/205) is the default for Bee Enclave Sovereign deployments. See the Security Practices document for details.
13. Complaints and regulatory authorities
- Please contact our Data Protection Officer first at bee-privacy@heossi.com so we can investigate.
- Singapore individuals may complain to the Personal Data Protection Commission. EEA and UK individuals may complain to the supervisory authority where they live or work. California and other US residents may contact the regulator or attorney general empowered by applicable state law. Contacting us first is welcome but does not limit a right to approach a regulator.
14. Updates
Material changes to this Policy are announced via the changelog and (for account holders) by email at least 30 days before they take effect.
Questions about this document? Contact bee-privacy@heossi.com. Service of process: bee-legal@heossi.com (HEOSSI (Pte.) Ltd., Singapore).
Counter-signed copies on request. The text on this page is the canonical published version. For procurement teams that need a counter-signed copy of the Terms, DPA, or Order Form, email bee-legal@heossi.com. Where there is conflict between this page and an executed counter-signed agreement, the counter-signed agreement controls.