← Back to Beekeeper

Privacy notice

Legal-review draft — updated 29 July 2026. This notice describes Beekeeper’s current founder-beta processing and must be confirmed against the final production providers and operating procedures before general sale.

Who is responsible for your information?

Taglab Limited is the controller responsible for the personal information described in this notice. Taglab Limited is registered in England and Wales under company number 14711186. Its registered office is Synergy House, Lawson Street, North Shields, United Kingdom, NE29 6TG.

Where a business customer instructs us to process personal information contained in its systems or assessment evidence solely on its behalf, Taglab Limited may instead act as that customer’s processor. The customer remains the controller for that information, and the applicable contract, scope and any data-processing terms govern that processing.

Privacy questions, rights requests and data protection complaints can be sent to help@in-flow.co.uk.

Information we collect

Depending on how you use Beekeeper, we may collect:

Submitting an enquiry, creating an account or paying for a service does not itself authorise security testing.

Why we use information and our lawful bases

Purpose and informationLawful basis
Responding to enquiries, preparing proposals and taking requested steps before a contractLegitimate interests in operating and developing our business; contract where you ask us to take steps before entering one
Creating and administering customer accounts, subscriptions, assessments, reports, support and service communicationsContract; legitimate interests where the contact acts for a corporate customer rather than contracting personally
Processing billing records, invoices, tax records, refunds and disputesContract; legal obligation; legitimate interests in establishing and defending legal claims
Verifying ownership and authority, agreeing scope, performing authorised testing and retaining evidence of instructionsContract; legitimate interests in delivering security services safely and demonstrating lawful authority
Protecting accounts, detecting abuse, rate limiting, investigating incidents and maintaining audit logsLegitimate interests in protecting Beekeeper, its customers and third parties; legal obligation where applicable
Sending optional marketing or limited, relevant business-to-business outreachConsent where required; otherwise legitimate interests, subject to applicable electronic-marketing law and your right to object
Keeping a minimal suppression record after an opt-outLegitimate interests and compliance with applicable electronic-marketing law

Where we rely on legitimate interests, those interests include responding to business enquiries, providing and improving a secure service, preventing misuse, protecting systems and evidence, and establishing or defending legal claims. We consider whether those interests are necessary and balanced against the rights and freedoms of the people concerned.

Authenticated assessments and credentials

Authenticated-assessment requests record the verified application host, operator and authority contacts, proposed roles, environment, data classification, scope restrictions and an audit trail. Dedicated temporary test credentials are accepted only after scope approval. They are encrypted in a separate private vault, expire within 24 hours, may be revealed once by an authorised Beekeeper administrator using re-authentication and a time-limited verification code, and are then permanently removed. Credential values are not placed in ordinary account records, audit events or email.

Do not submit real customer passwords, production administrator credentials, MFA seeds, recovery codes or unnecessary personal information.

AI-assisted analysis

Certain public-surface evidence and technical context may be analysed using AI models, including services provided by OpenAI, to help identify potential vulnerabilities, organise evidence and draft remediation guidance. We minimise the information submitted and do not intentionally send temporary credentials, payment-card details, special-category information or unnecessary personal information to an AI provider.

AI-generated output is reviewed where appropriate. It is assistance, not a guarantee that a vulnerability exists, that every vulnerability has been found, or that remediation is complete.

Service providers and international transfers

We use service providers to operate Beekeeper. They act under their own terms and, where applicable, data-processing agreements:

Some providers process information in the United States or other countries outside the UK. A country may not provide the same legal protections as the UK. Where a restricted transfer occurs, we use an applicable UK adequacy regulation, including the UK Extension to the EU-US Data Privacy Framework where available, or appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. We assess the transfer and apply additional technical or organisational protections where required.

You can ask us for more information about the relevant provider, destination and transfer safeguard.

How long we keep information

We keep information only for as long as it is needed for the stated purpose, security, legal claims or a legal obligation. Our standard periods are:

RecordStandard retention period
Enquiries that do not become customers12 months after the last meaningful contact
Customer accounts, contracts, authority, approved scope and core service recordsFor the customer relationship and 6 years after it ends
Invoices, payments, refunds and accounting records6 years from the end of the financial year to which they relate, or longer where law requires
Assessment reports and supporting evidence24 months after delivery, unless a contract, dispute, legal obligation or agreed remediation period requires longer
Security, access and abuse-prevention logs12 months, unless needed for an active investigation or legal claim
Dedicated temporary assessment credentialsNo more than 24 hours; earlier on reveal, revocation or completion where applicable
Marketing suppression recordsFor as long as reasonably needed to honour the opt-out, using the minimum information necessary

Short-lived verification and password-reset tokens expire automatically. Encrypted backups may retain a deleted record for a limited backup cycle before it is overwritten, during which the record remains protected and is not restored except for disaster recovery.

Client reports

A client report may be shared through a long, unguessable keyed link. Anyone holding that link can view the report summary, so recipients should treat it as confidential. Detailed remediation requires the intended recipient’s portal account and an active subscription.

Your rights

Depending on the circumstances and lawful basis, you may ask us to:

You can withdraw consent at any time without affecting processing that was lawful before withdrawal. These rights are not absolute, and an exemption or overriding legal requirement may apply. We may need to verify your identity before acting on a request.

Send a request or complaint to help@in-flow.co.uk. We will acknowledge a data protection complaint within 30 days and respond without undue delay in accordance with applicable law. If you remain dissatisfied, you may complain to the Information Commissioner’s Office.

Cookies and analytics

The public development site does not intentionally set analytics or advertising cookies. The administration and client portals use strictly necessary session cookies for authentication, security and continuity. Stripe may set cookies when you use its Checkout or billing pages.

Changes to this notice

We may update this notice when the service, providers or law changes. We will publish the revised notice and effective date here and provide additional notice where required.

Contact

Taglab Limited
Synergy House, Lawson Street
North Shields, United Kingdom, NE29 6TG
help@in-flow.co.uk