Privacy policy

What we collect, why, who else touches it, and how to get it back or deleted. Short, because we collect little — and clear about the part we deliberately cannot see, which is everything inside your workspace.

In effect from 31 Jul 2026

1. Who is responsible

The data controller for everything described here is the Individual Entrepreneur trading as Bee Workspace, identification number 306502594. That is a person rather than a company, and they are named, with the registered address, in section 11.

Data protection questions and requests go to [email protected]. We have not appointed a Data Protection Officer: we are small enough that the law does not require one, and claiming an office we do not have would be worse than saying so. That address reaches the person who makes these decisions.

2. What we collect

  • Your account. An email address, and a display name if you set one. There is no password, because sign-in is by emailed link.
  • Your orders. Which size and zone you picked, which term, what was charged, and — if you gave one — your company name and tax number. Also the record of what you were told before you bought, which we keep because it is the evidence that we told you.
  • What your workspace reports about itself. A running workspace posts a short technical status — its address, software versions, CPU, memory and disk use, and how long it has been up. This is telemetry about the machine, not about you: it never includes your files, your keystrokes, or your commands.
  • Support correspondence and server logs. What you write to us, and the request logs and IP addresses our own servers keep in the ordinary course of running a website securely.
  • Bug reports and feature requests. What you write in the feedback form, the page you sent it from, and — if you gave one — an email address to reply to. You do not need an account to send one, and if you send one without an account and without an address, the only personal data in it is whatever you chose to type. We keep the most recent of these and delete the rest.

We do not collect payment card details. They go to the payment provider and never reach our systems. We run no advertising and no advertising trackers on this site, and we do not sell or share what we hold.

We do measure how the site is used, and only if you agree to it. PostHog is the tool, its European servers process it, and it loads from our own domain — so no third party sets a cookie here and none receives anything from a visitor who has not opted in. If you are signed in it is told your account id and nothing else: not your name, not your email, not your address. Section 9 says what it stores in your browser and how to change your mind.

3. Why we are allowed to hold it

WhatWhy we may hold it
Account, orders, and consent recordsPerforming the contract, and complying with tax and consumer law that requires us to keep proof of what was sold and what was disclosed.
Workspace self-reports and server logsOur legitimate interest in keeping the service running, keeping abuse off it, and being able to show you what is on your own machine.
Service email about your own workspacesPerforming the contract. You cannot opt out of being told that your machine is about to be deleted.
Bug reports and feature requestsOur legitimate interest in knowing what is broken and what people want built. Sending one is your choice, an address is optional, and we hold only the most recent of them.
Marketing email, and any non-essential cookieYour consent, asked for separately, and withdrawable at any time.

4. What is on your workspace

Whatever you put there. We do not index it, scan it, read it, or use it to train anything. We can technically reach the machine — provisioning and support require it — and we look at its contents only to fix a fault you have reported, to keep the service running, where the acceptable use policy requires us to act on a complaint, or where the law compels us.

If you put other people’s personal data on your workspace, you are the controller of it and we are your processor. That is a real legal relationship with obligations on both sides. Business customers who need it can ask [email protected] for our data processing addendum, which sets out the terms and names our sub-processors; we do not publish it, we supply it.

5. Who else processes it

CategoryWhat forWhat they see
Payment processingPaddle.com Market LtdSells the subscription as merchant of record, invoices, and handles sales taxName, email, billing address, company and tax number if given, payment details
Customer database and sign-inHolds your account, your orders, and what your machine reports about itselfEmail address, display name, order and machine records
InfrastructureRuns the virtual machines themselvesMachine metadata, network addresses, and whatever you put on your machine
Email deliverySends sign-in links and service notices about your own machinesEmail address and the contents of that message
Product analyticsPostHog, EU regionCounts visits and records how the site is used, only for visitors who agree to itPages viewed, clicks, approximate location from IP, and your account id if you are signed in

Workspace infrastructure is provided by third-party infrastructure providers operating data centres in the European Union, the United States, and Singapore.

We do not sell personal data and we do not share it with anyone outside these categories, except where the law compels us. Adding a service that touches customer data means adding it to this table in the same change.

6. Where it is held, and transfers

Account and order records are held in the European Union. A workspace runs in the zone you chose when you ordered, which may be outside the EU — the zones are named on the pricing page, and choosing one outside the EU is a choice you make knowing that.

We are established in Georgia, which is outside the European Economic Area, so running the service means transferring data there, and to processors in the United States and Singapore. Those transfers are covered by the European Commission’s standard contractual clauses.

7. How long we keep it

  • Account records: until you ask us to delete the account.
  • Order, payment, consent, and provisioning records: seven years after the order, because tax and consumer law require us to be able to show what was sold and what was disclosed.
  • Workspace self-reports: ninety days, then discarded — they are a live view, not a history.
  • Support correspondence: three years.
  • Server logs: ninety days.
  • The workspace disk: destroyed when the term ends.

A failed payment has its own timetable, and it ends in the disk being wiped: straight away, payment fails; grace, the machine keeps running; end of grace, the term ends. How long the middle stage lasts depends on how long the account has been with us. It is set out in full in the refund policy.

8. Your rights

You can ask for a copy of what we hold, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, object to processing based on legitimate interest, or ask for it in a portable form. Write to [email protected] and we will answer within one month.

Deleting your account does not delete the order records that tax law requires us to keep, but those are stripped back to what the law actually requires. If you think we have handled your data badly you can complain to the data protection authority where you live — and we would rather you told us first, so we can fix it.

9. Cookies

CookieWhat forHow longType
sb-*-auth-tokenKeeps you signed in between pages. Set only after you sign in.Until you sign out, or one yearStrictly necessary
bw-cookie-consentRemembers your answer to the cookie banner, so it is not asked twice.One yearStrictly necessary
ph_*_posthogRecognises this browser between visits, so a returning reader is not counted as a new one. Set only if you accept.One yearNeeds your consent

The cookies marked as needing consent are not set until you agree to them, and the code that would set them is not even downloaded until then.

10. Changes

If this policy changes materially — a new processor category, a new purpose — we will tell you by email before it takes effect. The date at the top says which version you are reading.

11. The controller, in full

Data protection law asks for the controller’s identity and contact details, so here they are. Requests go to [email protected] rather than to the postal address — they reach the same person, faster.

Individual Entrepreneur Artem MelnikovIdentification number: 306502594Registered by the LEPL National Agency of Public Registry, GeorgiaPolice Lane I N5, Floor 2, N4aTbilisiGeorgia[email protected]