Privacy
Privacy policy
What we process on our own account, for what purpose, on what basis and for how long.
Last updated:
First, two different things
Content created by your organisation — messages, files, calendars and documents — belongs to your organisation. We process it on your behalf and on your instructions, as a processor. That processing is governed by the Data Processing Agreement.
Data arising from our commercial relationship — account, billing, security logs and support correspondence — is processed on our own account, as a controller. This policy concerns that processing.
Contents
Who processes the data
Open Solutions, established at Wawrzyńca Engeströma 10, 60-571 Poznań, Poland. NIP PL7773457857.
For any data protection matter, including the exercise of your rights: privacy@beskos.com. No data protection officer has been appointed, the scale of the processing not requiring one under Article 37 of the GDPR.
What we hold, and why
Account and organisation: name, email address, domain, role and permissions. To provide access to the service and to determine each user's permissions. Basis: performance of the contract.
Billing: address, tax identification number, the finance contact's address and invoice history. To charge, and to meet tax obligations. Basis: performance of the contract and legal obligation.
Access and security logs: IP address, date and time, device, and the outcome of authentication attempts. To detect improper access and to notify you of new sign-ins. Basis: legitimate interest in the security of the service and of customer data.
Support: correspondence exchanged with our support service. To resolve the matter and to retain a record of it. Basis: performance of the contract.
Website visits: a single cookie holding your chosen currency, and technical server logs. See the cookie policy.
Audience measurement: the page visited, the referring source, the approximate country and the type of device, recorded in aggregate by software we run ourselves, without cookies and without identifying individual visitors. Basis: legitimate interest.
What we do not do
We do not sell personal data, to anyone, under any circumstances.
We do not use customer content for advertising, nor to train artificial intelligence models, whether our own or those of third parties.
We do not carry out profiling or automated decision-making with legal effects on anyone.
This site carries no behavioural analytics.
Who else touches it
The providers engaged in the provision of the service are listed individually, with purpose, location and safeguard, on the sub-processors page. The list is published in full and kept current.
Otherwise, data is disclosed to public authorities only where required by law. In such cases the customer is notified, unless the law prohibits notification.
In the event of a transfer of the business to another entity, the data follows the service and customers are notified with sufficient time to terminate.
Where it is
The application, database and mail servers are in the European Union. Files are held in storage under European jurisdiction. Artificial intelligence processing takes place in European data centres.
Some providers are United States companies, notwithstanding that they process the data within the European Union. In those cases the EU Standard Contractual Clauses apply, and the sub-processors page identifies which.
For how long
Account data: for the duration of the contract, and 30 days after it ends.
Invoices and accounting records: five years from the end of the year in which the tax became due, because Polish tax law requires it. This period cannot be shortened on request.
Security and administration logs: 90 days.
Support correspondence: two years.
Your rights
You have the right to access your data, to have inaccurate data corrected, to request erasure, to request restriction of processing, to object to processing based on legitimate interest, and to portability of the data you provided to us.
Most of these can be exercised directly: the administration console allows you to view, correct, export and delete the data of your organisation and its users.
Other requests may be addressed to privacy@beskos.com. We respond within one month; where a request is complex, we notify you of the extension and its grounds.
Where you are a user of a customer organisation and the request concerns that organisation's content, such as your mailbox or files, we refer you to its administrator, who is the controller.
Complaining
You have the right to lodge a complaint with a supervisory authority. The authority competent for us is the Polish one — Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw — and you may equally address the authority of your country of residence or place of work.
We ask that you contact us first, which is generally the faster route.
Changes
Material changes to this policy are notified by email to the administration and billing addresses, and the revised text is published with a new date. Minor changes are reflected in the date alone.