Beesiness Privacy Policy and Personal Data Protection Notice
Effective date: July 28, 2026
1. Introduction, Purpose and Scope
This Privacy Policy and Notice (the "Policy") has been prepared by Beesiness ("Beesiness" or the "Company") to explain the procedures and principles governing the processing of personal data in connection with the AI-powered meeting assistant service (the "Service") provided through the beesiness.com domain and the associated mobile, desktop, and Chrome applications, in order to fulfill the obligation to inform under Article 10 of the Turkish Personal Data Protection Law No. 6698 ("KVKK") and to satisfy the information obligations under Articles 13 and 14 of the European Union General Data Protection Regulation ("GDPR").
The Service comprises: the recording of meetings by a bot named "Beely · Recording" that joins Google Meet, Zoom, and Microsoft Teams meetings, as well as the capture of meeting audio recordings through local recording via the mobile, desktop, and Chrome applications without the use of the bot; the generation of transcripts, AI summaries, action items, and decision records from these recordings; the creation of a team knowledge base ("Ask"); and, optionally, the delivery of action items to CRM, Slack, and similar tools.
This Policy applies to account holders using the Service, users authorized by customer organizations, individuals participating in recorded meetings, and visitors to beesiness.com. Use of the Service signifies that this Policy has been read and understood; however, for processing activities requiring explicit consent, consent is obtained separately and in due form.
2. Data Controller, Data Processor and Roles
Beesiness ("Beesiness" or the "Company") acts in different capacities with respect to the data categories set out below. For details of the Company's legal entity and contact information, please contact info@beesiness.com.
- As data controller ("controller" within the meaning of KVKK Art. 3; GDPR Art. 4(7)): Beesiness is the data controller with respect to account and identity data, billing data, usage and log data, and beesiness.com website visitor data.
- As data processor ("processor" within the meaning of KVKK Art. 3; GDPR Art. 4(8)): with respect to meeting content (audio recordings, transcripts, AI outputs, participant metadata), the data controller is the customer organization or meeting host using the Service; Beesiness processes such data solely on the customer's instructions and for the purpose of providing the Service, in its capacity as data processor.
- The meeting host/customer organization is responsible for ensuring the lawfulness of meeting recording in its own jurisdiction (including informing participants and, where required, obtaining their consent); Beesiness provides the notification and consent tools described in Section 5 for this purpose.
3. Categories of Personal Data Processed
In connection with the provision of the Service, Beesiness processes the following categories of personal data. Beesiness does not intend to process special categories of personal data (KVKK Art. 6; GDPR Art. 9); however, information expressed by participants in meeting content may include data of this nature, and responsibility for such content is subject to the allocation of roles set out in Section 2.
- Account and identity data: full name, email address, and profile photo (obtained via sign-in with Google or Microsoft); organization name and role/title within the organization.
- Billing data: payment transactions are processed via Stripe; card numbers are under no circumstances stored by Beesiness. Beesiness has access only to subscription plan, invoice, and payment status information.
- Meeting data: meeting link (URL), date/time, and platform information; audio recording; transcript; AI-generated summary, action item, and decision outputs; participant names and email addresses derived from meeting metadata.
- Usage data: IP address, browser information, feature usage analytics containing no personal identifiers, and error logs scrubbed of personal data (PII-cleansed).
- Google Calendar data (where an optional connection has been established): upcoming meeting event information within the read-only (calendar.events.readonly) scope only (see Section 6).
4. Purposes of Processing and Legal Bases (KVKK Arts. 5-6 / GDPR Art. 6)
Your personal data is processed for the following purposes and on the legal bases indicated alongside each:
- Creation of the account, authentication, and provision of the Service: KVKK Art. 5/2(c) — processing directly related to the conclusion or performance of a contract; GDPR Art. 6(1)(b) — performance of a contract.
- Recording of meetings and generation of transcripts and AI outputs: performance of a contract pursuant to the instructions of the customer organization (the data controller) — KVKK Art. 5/2(c); GDPR Art. 6(1)(b); with respect to meeting participants, establishing the lawful basis is the responsibility of the customer organization in its capacity as data controller (depending on the relevant jurisdiction, explicit consent — KVKK Art. 5/1, GDPR Art. 6(1)(a) — or legitimate interest — GDPR Art. 6(1)(f)).
- Billing, collection, and fulfillment of financial obligations: KVKK Art. 5/2(a) — processing expressly provided for by law and Art. 5/2(ç) — compliance with a legal obligation; GDPR Art. 6(1)(c).
- Ensuring the security of the Service, preventing misuse, debugging, and improving service quality: KVKK Art. 5/2(f) — legitimate interest, provided that fundamental rights and freedoms are not harmed; GDPR Art. 6(1)(f).
- Responding to support requests and user communications: KVKK Art. 5/2(c); GDPR Art. 6(1)(b).
- Establishment, exercise, or defense of legal claims and responding to requests from competent authorities: KVKK Art. 5/2(a), (ç) and (e); GDPR Art. 6(1)(c) and (f).
- Displaying upcoming meetings via the Google Calendar connection and automatic joining: the data subject's explicit and separately granted authorization — KVKK Art. 5/1; GDPR Art. 6(1)(a); this permission may be withdrawn at any time.
For processing activities based on explicit consent, consent may be withdrawn at any time and without giving any reason; withdrawal of consent does not affect the lawfulness of processing carried out up to the moment of withdrawal.
5. Meeting Recordings and Consent Flow
Beesiness implements a multi-layered notification and consent flow to ensure that meeting participants are aware of the recording:
- The recording bot joins the meeting under the name "Beely · Recording", in a manner that clearly indicates it is recording, and announces itself within the meeting.
- For each meeting, a consent page is provided through which participants are informed about the recording and their preferences regarding the recording are collected.
- Participants who object to the recording may request that the meeting host remove the bot from the meeting; the meeting host may remove the bot from the meeting at any time.
- For local recordings made without the bot (mobile/desktop/Chrome), the user initiating the recording and the customer organization are responsible for informing the participants.
The lawfulness of meeting recording (including one-party/two-party consent rules) is governed by the law of the jurisdiction in which the meeting takes place. The customer (meeting host/workspace administrator), in its capacity as data controller, is obliged to establish a lawful basis for recording valid in its own jurisdiction. While Beesiness provides the notification and consent tools described above, it does not substitute for this obligation of the customer.
6. Google User Data: Access, Use, Sharing, Protection, and Retention (Google API Services User Data Policy)
This section describes, in a single consolidated place and in explicit terms, how Beesiness handles the Google user data it accesses through Google Sign-In and the Google Calendar API, in a manner that meets the requirements of the Google API Services User Data Policy. Both Google Sign-In and the Google Calendar connection are optional and may be removed by the user at any time.
(a) Google user data we access:
- Google Sign-In basic profile information: full name, email address, and profile photo (the openid, email, and profile scopes).
- Google Calendar event data — read-only "calendar.events.readonly" scope only: the title, date/time, meeting link (URL), and attendee information of upcoming meeting events. Beesiness never WRITES to the calendar and never creates, edits, or deletes calendar events.
(b) How we use Google user data:
- Profile information: to create your account, authenticate you, and identify you.
- Calendar event data: solely to (i) display your upcoming meetings to you and (ii) enable the recording bot to automatically join those meetings, subject to your preference. It is used for no other purpose.
(c) Sharing, transfer, and disclosure of Google user data:
- Google user data is never sold, rented, or transferred to any third party for that party's own purposes.
- Google user data may be processed only by the hosting, database, and storage sub-processors strictly necessary to operate this feature, under agreements compliant with KVKK and GDPR Art. 28 and on Beesiness' instructions; it is not shared for advertising or model-training purposes or with any other third party. The event title and meeting link imported from your calendar become part of that meeting's record; when the record is summarized or made searchable, the title may be included in the context sent to our AI sub-processors. Calendar data is never sent to speech-to-text sub-processors, and no sub-processor may use it for its own purposes.
- Disclosure occurs only where legally required (a competent-authority request or legal obligation) and only to the minimum extent necessary.
(d) Protection of Google user data (including sensitive data):
- Encryption in transit (TLS/HTTPS) and at rest.
- OAuth access/refresh tokens are stored in our access-restricted database, which is encrypted at rest; they are deleted immediately when you disconnect and can be revoked at any time from your Google account settings.
- Role-based access control and the principle of least privilege; access is limited to authorized personnel only.
(e) Retention and deletion of Google user data:
- Google user data is retained only for as long as the connection and the account remain active.
- When the user removes the Google connection or the Calendar connection, or deletes their account, the relevant Google user data and OAuth tokens are deleted/revoked within no more than 30 days.
- Users may revoke access at any time from the account settings or via their Google Account permissions (myaccount.google.com/permissions).
Beesiness' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Google user data is never sold under any circumstances.
- Google user data is not used or transferred for advertising purposes.
- Google user data is not used to train artificial intelligence/machine learning models.
- No human access to Google user data takes place; limited human access may occur only with the user's explicit consent for support purposes, for security purposes (including abuse investigations), or for compliance with legal obligations.
7. AI Processing and Model Training Commitment
Artificial intelligence technologies are used within the scope of the Service to generate transcripts from audio recordings and to produce summaries, action items, and decision outputs from transcripts. This processing is carried out solely for the purpose of providing the Service to the relevant customer and within the framework of the customer's instructions.
Beesiness does NOT use customer meeting content (including audio recordings, transcripts, and outputs generated from them) to train artificial intelligence models. Should any model improvement program be contemplated in the future, such program will (i) be based exclusively on express opt-in participation, (ii) use pseudonymized data, and (iii) be announced to users before being put into effect.
AI outputs are automatically generated assistive content; they may contain errors and must be verified by the user. No solely automated decision-making producing legal effects concerning data subjects or similarly significantly affecting them, within the meaning of GDPR Art. 22, is carried out within the scope of the Service.
8. Sub-processors (Sub Data Processors)
Beesiness engages a limited number of sub-processors to provide the Service. Data processing agreements compliant with KVKK and GDPR Art. 28 are concluded with sub-processors, and sub-processors process data only to the extent necessary for the provision of the Service and on Beesiness' instructions. The categories of sub-processors used are as follows:
- Hosting/infrastructure services
- Meeting recording bot services (the meeting link imported from your calendar is passed so the bot can join)
- Database services
- Speech-to-text transcription services
- AI summary generation services
- Object storage services
- Payment processing services (Stripe)
- Transactional email services
- Error monitoring services
A current, named list of sub-processors is provided upon request from info@beesiness.com. Customers are notified at least 30 days before a new sub-processor is engaged; customers may object on reasonable grounds within this period.
9. Retention Periods
Personal data is retained only for as long as required by the purposes of processing and within the maximum periods set out below; upon expiry of the period or where the purpose of processing ceases to exist, the data is deleted, destroyed, or anonymized in accordance with KVKK Art. 7 and GDPR Art. 5(1)(e):
- Audio recordings: 90 days by default; 12 months with the Storage Plus add-on or on Business Plus and above. Contact us for custom windows on enterprise plans.
- Transcripts and AI outputs: 2 years.
- Account and identity data: for as long as the account remains active; account deletion requests are fulfilled within no more than 30 days from receipt of the request.
- Billing and financial records: for the statutory retention periods prescribed by the applicable tax and commercial legislation.
- Usage data and error logs: for limited, reasonable periods for security and service improvement purposes; error logs are kept scrubbed of personal data.
- In the event of a dispute, the relevant data may be retained for the duration of the applicable limitation periods to the extent necessary for the establishment, exercise, or defense of legal claims.
10. International Data Transfers (KVKK Art. 9 / GDPR Chapter V)
The primary data hosting infrastructure is located within the borders of the European Union. Where the transfer of data to third countries is necessary for the provision of the Service, such transfers are carried out, for GDPR purposes, under the Standard Contractual Clauses (SCC) adopted by the European Commission together with any necessary supplementary safeguards, and, for KVKK purposes, in accordance with the international transfer provisions set out in KVKK Art. 9 (including adequacy decisions, appropriate safeguards, and the relevant procedures).
The same standard of protection is contractually ensured for transfers carried out through sub-processors. Detailed information on transfer mechanisms may be requested from info@beesiness.com.
11. Rights of the Data Subject (KVKK Art. 11 / GDPR Arts. 15-21)
Data subjects have the following rights under KVKK Art. 11 and GDPR Arts. 15-21:
- To learn whether their personal data is being processed and, if so, to request information regarding such processing (right of access — GDPR Art. 15).
- To learn the purpose of processing and whether the data is used in accordance with that purpose.
- To know the third parties, domestically or abroad, to whom the data has been transferred.
- To request the rectification of incomplete or inaccurately processed data (GDPR Art. 16).
- To request the deletion or destruction of the data within the framework of KVKK Art. 7 (right to erasure — GDPR Art. 17).
- To request that rectification, deletion, and destruction operations be notified to the third parties to whom the data has been transferred.
- To request restriction of processing (GDPR Art. 18) and data portability (GDPR Art. 20).
- To object to the occurrence of a result to their detriment through analysis carried out exclusively by automated systems (KVKK Art. 11/1(g); GDPR Arts. 21-22).
- To claim compensation for damage suffered as a result of unlawful processing.
- Under the GDPR, to withdraw consent at any time where processing is based on consent, and to lodge a complaint with the competent supervisory authority; under the KVKK, the right to lodge a complaint with the Personal Data Protection Board (KVKK Arts. 13-14).
Since Beesiness acts as data processor with respect to requests concerning meeting content, such requests may be redirected to the relevant customer organization (the data controller); Beesiness will reasonably assist the customer in responding to such requests.
12. Application Procedure and Response Time
Data subjects may submit their requests concerning the rights listed in Section 11 to info@beesiness.com, together with information and documents sufficient to verify their identity. Applications must be made in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller.
- Applications are concluded free of charge as soon as possible depending on the nature of the request and in any event within no more than 30 days (within one month pursuant to KVKK Art. 13; GDPR Art. 12(3)).
- Where, exceptionally, a request entails an additional cost, only the fee set out in the tariff permitted by the legislation may be charged.
- Applications for which identity cannot be verified, or which are manifestly unfounded or excessive, may be refused with reasons stated.
- In the event of refusal of the application, an inadequate response, or failure to respond within the time limit, the data subject may lodge a complaint with the Personal Data Protection Board pursuant to KVKK Art. 14; data subjects under the GDPR may lodge a complaint with the supervisory authority of the Member State in which they reside.
13. Children's Personal Data and Educational Institutions (K-12)
The Service is not intended for children to open accounts individually in their own name. The minimum age for opening an individual account is 16. Individual accounts found to belong to persons under the age of 16, and the data relating to them, are deleted within a reasonable period.
With respect to educational institution (K-12/school) customers: the data controller for student data is the relevant school/educational institution; Beesiness processes such data solely on the institution's instructions, in its capacity as data processor. Obtaining and managing parental/guardian consents is the responsibility of the relevant educational institution. Educational institutions may contact info@beesiness.com for specific requests concerning the processing of student data.
14. Data Security Measures and Breach Notification
Pursuant to KVKK Art. 12 and GDPR Art. 32, Beesiness implements appropriate technical and organizational measures to prevent the unlawful processing of and unlawful access to personal data and to ensure its safekeeping:
- Encryption in transit and at rest.
- Role-based access control and the principle of least privilege.
- Traceability of access and operations through audit logs.
- A self-hosted/on-premises deployment option for enterprise customers.
In the event of a personal data breach, Beesiness will inform the customers affected by the breach and, where required by the legislation, the Personal Data Protection Board and/or the competent supervisory authorities under GDPR Art. 33, within 72 hours of becoming aware of the breach. The address info@beesiness.com may be used for reporting security vulnerabilities and for communications on security matters.
15. Cookies
Two types of cookies are used on beesiness.com and within the Service interfaces: (i) strictly necessary cookies required for session management, authentication, and security; and (ii) analytics cookies, containing no personal identifiers, aimed at understanding how the Service is used. Strictly necessary cookies are required for the operation of the Service, and if disabled, the Service may not function properly. Analytics measurements are performed in a manner scrubbed of personal identifiers. Users may manage their cookie preferences through their browser settings.
16. Changes to the Policy
Beesiness may update this Policy in line with changes in legislation, developments within the scope of the Service, or changes in processing activities. Material (significant) changes are announced at least 15 days before they take effect, by email and/or via the in-app dashboard. The current version is published, together with its effective date, at beesiness.com. Although continued use of the Service after a change takes effect does not in itself constitute acceptance of the updated Policy, users are in any event separately informed of, and their consent is separately obtained for, any new processing activities requiring explicit consent.
17. Contact
The following channels may be used for any questions, requests, and notifications regarding this Policy and the processing of personal data:
- Privacy and data subject applications: info@beesiness.com
- Data Protection Officer (DPO): info@beesiness.com
- Legal matters and company information: info@beesiness.com
- Security notifications: info@beesiness.com
- General support: info@beesiness.com
This Privacy Policy and Notice entered into force on July 17, 2026 and was last updated on July 28, 2026.