Privacy Policy
Last updated: 13 July 2026
1. Who we are
Beedero is a platform connecting startups and investors, operated by Beedero, headquartered at Lisbon, Portugal, tax number (NIF) Available upon request to privacy@beedero.com, registered with the Commercial Registry of Conservatória do Registo Comercial de Lisboa ("Beedero", "we", "us").
We are the data controller for the personal data described in this policy, under the General Data Protection Regulation (GDPR).
Privacy contact: privacy@beedero.com
2. What data we process, why, and on what legal basis
2.1 Account data
What: name, email, password (stored as a hash), email verification status.
Why: creating and managing your account, authentication, essential service communications.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Retention: for as long as the account exists; see §6 for deletion.
2.2 Profile data (person and organisation)
What: the information you choose to publish on your personal profile or your organisation's profile — description, team, products, market, milestones, financial and fundraising data, data room documents.
Why: making the profile available to other users according to the visibility levels you set (public / restricted / private). Restricted content is only accessible to those you grant access to; private content only to members of your organisation.
Legal basis: performance of a contract (Art. 6(1)(b)).
Note: you control the visibility of each field. Information marked as public is accessible to anyone on the internet, including search engines.
2.3 Credibility verification data
What: when you request verification of your organisation — tax number (NIF), permanent commercial registry certificate access code, tax and social security clearance certificates, financial statements, identification of the Certified Accountant (name and OCC registration number), and traction data obtained through integrations you authorise (e.g. Stripe, in read-only mode).
Why: verifying the identity, compliance and financial information of the organisation and awarding the corresponding credibility badges.
Legal basis: performance of a contract (Art. 6(1)(b)) as regards the organisation's data; as regards the Certified Accountant's data (a third party), legitimate interest (Art. 6(1)(f)) in verifying the authenticity of the accounts.
Retention: verification documents are kept for 24 months after verification or account deletion, whichever comes first; badges and metadata (type, date, outcome) for as long as the profile exists.
Storage: documents are held in private storage, accessible only via temporary, logged links.
2.4 Activity and interest records ("who viewed what")
What: we record profile views (who viewed, when), access to restricted content and data room documents (including IP address), and interest signals (saving a startup, expressing interest, following).
Why: (a) security and auditing — on a platform where you share confidential information with investors, a record of who accessed what protects you; (b) insight features — showing an organisation's managers who has shown interest in their profile (we show your profile name, never your email address).
Legal basis: legitimate interest (Art. 6(1)(f)) — ours and our users' interest in the security and transparency of interactions on the platform.
Retention: profile views — 12 months; audit records of access to restricted content — 24 months, given their security purpose.
2.5 Technical data
What: IP address, session data (authentication cookies), technical error and performance logs.
Why: authentication, security (login attempt limits, abuse prevention), troubleshooting.
Legal basis: legitimate interest (Art. 6(1)(f)) in the security and operation of the service.
2.6 Communications
What: transactional emails (account verification, password recovery, verification expiry warnings, service notifications).
Legal basis: performance of a contract. Marketing communications, if any, only with consent (Art. 6(1)(a)) and with an opt-out in every message.
3. Cookies
We use strictly necessary cookies only: session cookies for authentication (httpOnly). We do not use advertising cookies or third-party tracking cookies.
4. Who we share data with
We do not sell personal data. We share only with:
Other users — according to the visibility you set on your profiles and content, and as described in §2.4 (interest insight).
Sub-processors (providers processing data on our behalf under data processing agreements — Art. 28 GDPR):
| Sub-processor | Service | Location |
|---|---|---|
| Microsoft Azure | Hosting, database, file storage, email delivery | region — e.g. European Union (West Europe) |
| Stripe | Traction verification (read-only access authorised by you) | EU/US |
| Sentry | Error monitoring | Conservatória do Registo Comercial de Lisboa |
| Managed Redis, if applicable | Cache | Conservatória do Registo Comercial de Lisboa |
Authorities — where legally required.
5. International transfers
Data is hosted in Azure region in the EU. Where a sub-processor involves a transfer outside the European Economic Area, it relies on adequacy decision / standard contractual clauses.
6. Your rights
You have the right to access, rectify, erase, restrict and object to the processing of your data, as well as the right to data portability, under Articles 15 to 22 GDPR. To exercise these rights, contact hello@beedero.com. We respond within one month.
Account deletion: you can delete your account at your account settings or by email to privacy@beedero.com. Deletion removes your personal data, with the following exceptions: (a) audit records of access to restricted content, which we keep for 24 months for security and evidentiary reasons ; (b) content belonging to organisations with other members, which belongs to the organisation; (c) whatever the law requires us to keep.
[PRODUCT DECISION PENDING: what happens to an organisation whose sole owner deletes their account — delete the organisation, or orphan it with a recovery period? Decide before publishing.]
You also have the right to lodge a complaint with the CNPD (Portuguese Data Protection Authority — www.cnpd.pt) or your local supervisory authority.
7. Security
We apply appropriate technical and organisational measures, including: field-level access control enforced server-side and at the database level (Row-Level Security), encryption in transit (TLS), private document storage with access via temporary links, audit logging of access to restricted content, password hashing, and abuse limits.
8. Minors
Beedero is intended for people aged 18 or over. We do not knowingly collect data from minors.
9. Changes to this policy
We will publish changes on this page and, where material, notify you by email or on the platform with reasonable notice.