Privacy notice
Legal-review draft — updated 29 July 2026. This notice describes Beekeeper’s current founder-beta processing and must be confirmed against the final production providers and operating procedures before general sale.
Who is responsible for your information?
Taglab Limited is the controller responsible for the personal information described in this notice. Taglab Limited is registered in England and Wales under company number 14711186. Its registered office is Synergy House, Lawson Street, North Shields, United Kingdom, NE29 6TG.
Where a business customer instructs us to process personal information contained in its systems or assessment evidence solely on its behalf, Taglab Limited may instead act as that customer’s processor. The customer remains the controller for that information, and the applicable contract, scope and any data-processing terms govern that processing.
Privacy questions, rights requests and data protection complaints can be sent to help@in-flow.co.uk.
Information we collect
Depending on how you use Beekeeper, we may collect:
- your name, work email address, employer, role and contact details;
- the public domains and exact hostnames you submit, selected service, currency and enquiry details;
- account, authentication, consent and communication records;
- Stripe customer, subscription, invoice, payment-status and billing references, but not full payment-card details;
- ownership proofs, authority confirmations, assessment scope, exclusions, testing windows, emergency contacts and audit records;
- technical evidence, screenshots, findings, reports and remediation activity generated during an authorised assessment;
- a one-way network-address hash, limited browser information, security events and access logs used to prevent abuse and protect the service; and
- marketing preferences and the minimum information needed to honour an unsubscribe or suppression request.
Submitting an enquiry, creating an account or paying for a service does not itself authorise security testing.
Why we use information and our lawful bases
| Purpose and information | Lawful basis |
|---|---|
| Responding to enquiries, preparing proposals and taking requested steps before a contract | Legitimate interests in operating and developing our business; contract where you ask us to take steps before entering one |
| Creating and administering customer accounts, subscriptions, assessments, reports, support and service communications | Contract; legitimate interests where the contact acts for a corporate customer rather than contracting personally |
| Processing billing records, invoices, tax records, refunds and disputes | Contract; legal obligation; legitimate interests in establishing and defending legal claims |
| Verifying ownership and authority, agreeing scope, performing authorised testing and retaining evidence of instructions | Contract; legitimate interests in delivering security services safely and demonstrating lawful authority |
| Protecting accounts, detecting abuse, rate limiting, investigating incidents and maintaining audit logs | Legitimate interests in protecting Beekeeper, its customers and third parties; legal obligation where applicable |
| Sending optional marketing or limited, relevant business-to-business outreach | Consent where required; otherwise legitimate interests, subject to applicable electronic-marketing law and your right to object |
| Keeping a minimal suppression record after an opt-out | Legitimate interests and compliance with applicable electronic-marketing law |
Where we rely on legitimate interests, those interests include responding to business enquiries, providing and improving a secure service, preventing misuse, protecting systems and evidence, and establishing or defending legal claims. We consider whether those interests are necessary and balanced against the rights and freedoms of the people concerned.
Authenticated assessments and credentials
Authenticated-assessment requests record the verified application host, operator and authority contacts, proposed roles, environment, data classification, scope restrictions and an audit trail. Dedicated temporary test credentials are accepted only after scope approval. They are encrypted in a separate private vault, expire within 24 hours, may be revealed once by an authorised Beekeeper administrator using re-authentication and a time-limited verification code, and are then permanently removed. Credential values are not placed in ordinary account records, audit events or email.
Do not submit real customer passwords, production administrator credentials, MFA seeds, recovery codes or unnecessary personal information.
AI-assisted analysis
Certain public-surface evidence and technical context may be analysed using AI models, including services provided by OpenAI, to help identify potential vulnerabilities, organise evidence and draft remediation guidance. We minimise the information submitted and do not intentionally send temporary credentials, payment-card details, special-category information or unnecessary personal information to an AI provider.
AI-generated output is reviewed where appropriate. It is assistance, not a guarantee that a vulnerability exists, that every vulnerability has been found, or that remediation is complete.
Service providers and international transfers
We use service providers to operate Beekeeper. They act under their own terms and, where applicable, data-processing agreements:
- hosting and infrastructure providers to host the application, private data and backups;
- Stripe for Checkout, subscriptions, invoices, refunds and payment administration;
- Resend for account, report, security and other service email;
- Google Fonts on the current development site, which may receive a visitor’s IP address, requested URL and browser headers when a font is fetched; and
- OpenAI, where AI-assisted analysis is used as described above.
Some providers process information in the United States or other countries outside the UK. A country may not provide the same legal protections as the UK. Where a restricted transfer occurs, we use an applicable UK adequacy regulation, including the UK Extension to the EU-US Data Privacy Framework where available, or appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. We assess the transfer and apply additional technical or organisational protections where required.
You can ask us for more information about the relevant provider, destination and transfer safeguard.
How long we keep information
We keep information only for as long as it is needed for the stated purpose, security, legal claims or a legal obligation. Our standard periods are:
| Record | Standard retention period |
|---|---|
| Enquiries that do not become customers | 12 months after the last meaningful contact |
| Customer accounts, contracts, authority, approved scope and core service records | For the customer relationship and 6 years after it ends |
| Invoices, payments, refunds and accounting records | 6 years from the end of the financial year to which they relate, or longer where law requires |
| Assessment reports and supporting evidence | 24 months after delivery, unless a contract, dispute, legal obligation or agreed remediation period requires longer |
| Security, access and abuse-prevention logs | 12 months, unless needed for an active investigation or legal claim |
| Dedicated temporary assessment credentials | No more than 24 hours; earlier on reveal, revocation or completion where applicable |
| Marketing suppression records | For as long as reasonably needed to honour the opt-out, using the minimum information necessary |
Short-lived verification and password-reset tokens expire automatically. Encrypted backups may retain a deleted record for a limited backup cycle before it is overwritten, during which the record remains protected and is not restored except for disaster recovery.
Client reports
A client report may be shared through a long, unguessable keyed link. Anyone holding that link can view the report summary, so recipients should treat it as confidential. Detailed remediation requires the intended recipient’s portal account and an active subscription.
Your rights
Depending on the circumstances and lawful basis, you may ask us to:
- provide access to your personal information and a copy of it;
- correct inaccurate or incomplete information;
- delete information;
- restrict how information is used;
- provide information in a portable format where the right applies; or
- stop processing based on legitimate interests, including an absolute right to object to direct marketing.
You can withdraw consent at any time without affecting processing that was lawful before withdrawal. These rights are not absolute, and an exemption or overriding legal requirement may apply. We may need to verify your identity before acting on a request.
Send a request or complaint to help@in-flow.co.uk. We will acknowledge a data protection complaint within 30 days and respond without undue delay in accordance with applicable law. If you remain dissatisfied, you may complain to the Information Commissioner’s Office.
Cookies and analytics
The public development site does not intentionally set analytics or advertising cookies. The administration and client portals use strictly necessary session cookies for authentication, security and continuity. Stripe may set cookies when you use its Checkout or billing pages.
Changes to this notice
We may update this notice when the service, providers or law changes. We will publish the revised notice and effective date here and provide additional notice where required.
Contact
Taglab Limited
Synergy House, Lawson Street
North Shields, United Kingdom, NE29 6TG
help@in-flow.co.uk