Politique de confidentialité
1. Data controller
The controller of personal data collected via beemmvision.com is BeeMM, a SAS (Société par actions simplifiée), whose registered office is located in Paris, France [TO FILL — full street address + ZIP], registered under SIREN 989 030 879 / SIRET 989 030 879 00013.
2. Data collected
We collect the following categories of data:
- Account data: email, display name, profile photo (if provided), Firebase user ID.
- Billing data: last name, first name, address, VAT number, transaction history (processed by Stripe — we do not store card numbers).
- Usage data: projects, boards, workflows, prompts, uploaded files and AI-generated content.
- Technical data: IP address, session identifier, browser type, operating system, pages visited (collected via PostHog in pseudonymized mode).
- Masked session recordings: when you consent to analytics cookies, we may record a masked replay of your screen and interactions (session replay) via PostHog. Recording uses masking: all input fields (passwords, emails), AI prompts and any free text are masked and are not recorded; network request bodies are not recorded. Recording is primarily triggered when an error occurs, for debugging and product improvement.
- Communications: content of emails you send us for support purposes.
3. Processing purposes
- Provision of the service (account creation, access to Studio / Scale / App features).
- Prompt execution and storage of generated content.
- Billing and subscription management.
- Service security (fraud detection, abuse prevention).
- Pseudonymized audience measurement, continuous product improvement and error debugging (including masked session replay, where you have consented to analytics cookies).
- Transactional communications (confirmations, quota alerts, invoices).
4. Legal bases
The processing of your data relies on one of the following legal bases (GDPR art. 6):
- Contract performance — for account creation, access to the service and billing.
- Legitimate interest — for service security and product improvement.
- Consent — for non-essential analytics cookies and any optional marketing communications.
- Legal obligation — for the retention of invoices (10 years).
5. Retention period
| Category | Duration |
|---|---|
| Account data (active account) | As long as the account is active |
| Account data (inactive account) | 3 years after last sign-in, then deletion / anonymization |
| Generated content (boards, workflows, generations) | At your discretion — you can delete it at any time from the dashboard |
| Invoices and accounting data | 10 years (legal obligation) |
| Technical logs | 12 months |
| Analytics cookies | 13 months maximum (cf. Cookie Policy) |
6. Subprocessors
We rely on the following subprocessors to deliver the service:
| Subprocessor | Role | Location |
|---|---|---|
| Google Cloud / Firebase | Hosting, authentication, database | EU (Belgium) — Standard Contractual Clauses |
| Stripe Payments Europe Ltd. | Payment processing | Ireland (EU) |
| PostHog (EU Cloud) | Product analytics (pseudonymized) and masked session replay | EU Cloud — data hosted in the EU; processor PostHog Inc. is US-incorporated, with EU data residency. Any residual access by the US parent is framed by DPF + SCCs. |
| AI model providers | User prompt execution (Google, OpenAI, Black Forest Labs, Runway, Luma, etc.) | USA / EU depending on provider — SCCs |
Important: prompts sent to an AI model provider are transmitted to that provider solely for the execution of the request. No provider is authorized to use your prompts or generations to train its models under our integration.
7. Transfers outside the European Union
Certain processing operations involve transfers outside the EU (notably to the United States for some AI model providers). These transfers are governed by the Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by additional technical and organizational measures (encryption in transit, pseudonymization where possible). Our analytics data (PostHog) is hosted in the EU on PostHog EU Cloud; any residual access by its US parent (PostHog Inc.) is likewise framed by the EU–US Data Privacy Framework (DPF) and SCCs.
8. Your rights
Under the GDPR, you have the following rights:
- Right of access — obtain confirmation that your data is being processed and receive a copy.
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — request the deletion of your data.
- Right to portability — retrieve your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interest.
- Right to restriction — request the freezing of a contested processing.
- Right to withdraw consent at any time, for processing that depends on it.
- Right to lodge a complaint with the CNIL (cnil.fr) if you believe your rights are not respected.
To exercise these rights, contact our Data Protection Officer — see section 12.
10. Security
We implement appropriate technical and organizational measures to protect your data: encryption in transit (TLS 1.3), encryption at rest on Firebase, strict access controls, regular audits, team training. In the event of a breach likely to result in a risk to your rights and freedoms, you will be notified as soon as possible in accordance with article 34 of the GDPR.
11. Changes
This policy may be modified to reflect changes to the service, the legal framework, or our subprocessors. The date of last update is shown at the top of the page. Any substantial change will be notified to you by email.
12. Contact / DPO
For any question relating to your data or to exercise your rights, you can contact our Data Protection Officer (DPO):
- Email: [email protected]
- Mail: for the attention of the DPO, at the registered office address.