Privacy Policy
1. Who is the data controller?
BeepSweep is a service offered by Basinc B.V., incorporated in the Netherlands and registered with the Dutch Chamber of Commerce (KvK) under number 72055197. The data controller within the meaning of the General Data Protection Regulation (GDPR) is Basinc B.V., reachable at support@beepsweep.app.
2. What data do we process?
Account data: email address, password (hashed), company name, name and preferences you enter yourself.
Call data: caller's phone number, date and duration of the call, audio recording of the call, automatically generated transcript and summary, and any notes or tasks you add.
Technical data: IP addresses, browser type, session information and logs required for the security and operation of the service.
Push notifications: if you enable push notifications, we store a push subscription key linked to your account.
WhatsApp messages: if WhatsApp is enabled, we process the content of WhatsApp messages to and from callers, the WhatsApp phone number and the name as provided by WhatsApp.
Contacts (address book): if you link your phone contacts, we store name and phone number to recognise known callers.
3. Why do we process your data?
Performance of a contract (GDPR Art. 6(1)(b)): processing and transcribing incoming calls, displaying the inbox, sending notifications and providing access to the app.
Legitimate interests (GDPR Art. 6(1)(f)): security, fraud prevention, troubleshooting and improving the service on the basis of anonymised statistics.
Consent (GDPR Art. 6(1)(a)): for push notifications and the processing of special call data outside the core functionality, where consent is required.
4. Third parties and AI processors
OpenAI (Realtime API): BeepSweep sends call audio and conversation content to OpenAI's Realtime API to generate transcripts and summaries. OpenAI acts as a processor and may not use the data to train models. Processing takes place on OpenAI's servers outside the EEA. We have concluded a data processing agreement with OpenAI on the basis of the European Commission's Standard Contractual Clauses.
Telnyx: for handling telephone traffic (PSTN gateway), storing call recordings, and sending and receiving WhatsApp and SMS messages. Telnyx acts as a processor; recordings may be stored on servers outside the EEA, under the Standard Contractual Clauses.
WhatsApp / Meta: if WhatsApp is enabled, messages are sent and received via Meta's WhatsApp Business platform.
Hostinger (VPS): the application server and database run on a VPS at Hostinger in the EU.
Email service (Resend / SMTP): for sending notification and system emails (e.g. new-call alerts and password resets) we use an email processor; it receives the delivery address and message content, solely for delivery.
Push services (Apple, Google, Mozilla): push notifications are technically delivered through your platform's push infrastructure. The payload contains no caller data (no name, number or call content) — only a generic notification with a link to the app.
Cloudflare (Turnstile): forms with bot protection load a Cloudflare Turnstile check; Cloudflare processes the IP address and technical browser characteristics for bot detection.
Fonts are served from our own servers; no requests are made to Google Fonts or other external CDNs.
We never sell your data to third parties and do not share it with advertising networks.
5. International transfers
Call audio is processed by OpenAI, whose servers are located outside the European Economic Area (EEA). The transfer takes place on the basis of Standard Contractual Clauses (SCCs) as approved by the European Commission.
6. Retention periods
Calls (telephone and WhatsApp), audio recordings, transcripts and associated metadata are retained for a maximum of 12 months from the date of the call, after which they are automatically deleted. Account data is retained for as long as your account is active. After account deletion, or following an erasure request for a specific caller, the data concerned will be erased within 30 days, except for data we are required to retain longer by law.
7. Your rights (GDPR)
You have the right to:
- Access the personal data we process about you;
- Rectification if data is inaccurate or incomplete;
- Erasure ("right to be forgotten");
- Restriction of processing;
- Object to processing based on legitimate interests;
- Data portability;
- Withdraw consent previously given.
You can delete your own account (or, as an administrator, the entire company) via Settings → Account → Danger zone or via beepsweep.app/account/delete. For other requests, email support@beepsweep.app. We will respond within 30 days. You also have the right to lodge a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl) or the supervisory authority in your country of residence.
8. Security
We take appropriate technical and organisational measures to protect your data, including encryption of data at rest and in transit, access controls and regular backups.
9. Cookies
We use a functional session cookie for authentication only. No tracking or advertising cookies are placed. See our cookie policy for details.
10. Changes
We may update this privacy policy. The date at the top indicates the latest version. For material changes we will notify you by email or via an in-app notification.
11. Contact
Questions about this privacy policy or submitting a GDPR request? Email support@beepsweep.app.