Privacy Policy
Service: BeBrand Suite (bebrandsuite.com) - SaaS product
Scope: this policy applies to the BeBrand Suite SaaS product. It does NOT cover the human marketing-agency services of BeBrand Agency Kft. (a separate line of business with its own policy).
Version: v1.1 · Language: EN (HU: /adatvedelem) · Effective date: 2026-07-03
1. Identity and contact details of the data controller
The data controller is:
- Company name: BeBrand Agency Kft.
- Registered seat: 6320 Solt, Vendéglő u. 11., Hungary
- Tax number: 28726975-2-3 · EU VAT number: HU28726975
- Data protection contact: Dániel Hoss
- Contact: hoss.daniel@bebrand.hu
2. Categories of data processed and the two controller/processor roles
Using BeBrand Suite gives rise to two categories of data with different GDPR roles:
(a) Account, billing and usage data - here BeBrand Agency Kft. is the CONTROLLER.
This includes: the name, email address, phone number, billing and company details of the registering business and its contact person, payment identifiers (payments are processed by Stripe), and login and usage logs.
(b) Your end-user / customer-contact data that you upload to or connect with the Suite - here BeBrand Agency Kft. is the PROCESSOR, and you (the subscribing business) are the CONTROLLER.
This includes: the lead and customer data you upload or integrate, the performance data retrieved from your advertising accounts (Meta, Google Ads, GA4, TikTok), and the content processed by the modules (e.g. chatbot conversations, call transcripts, data of generated proposals/contracts). The processing of this data is governed by the Data Processing Agreement (DPA).
3. Purposes and legal bases of processing
| Purpose | Legal basis (GDPR Article 6) |
|---|---|
| Providing the service, operating the account | Performance of a contract (6(1)(b)) |
| Invoicing, accounting obligations | Legal obligation (6(1)(c)) |
| Service improvement, security, fraud prevention | Legitimate interest (6(1)(f)) |
| Marketing communication (newsletter) | Consent (6(1)(a)) |
| Processing of tenant data under 2.(b) | On the controller's (subscriber's) instructions, under the DPA |
4. Sub-processors
We use the following sub-processors to provide the service. The AI and Voice providers are engaged only when the relevant module is actually used (modular dependency).
| Sub-processor | Function | Data concerned | Location / mechanism |
|---|---|---|---|
| Supabase | database / hosting / auth | all tenant data | EU region; DPA |
| Vercel | frontend / edge hosting | request data | US/global edge; SCC |
| Stripe | payment processing | billing/payment data (here BeBrand = controller) | US/IE; PCI-DSS |
| Meta (Facebook/Instagram) API | advertising data and social publishing | ad account data, page/account IDs, publishing tokens | US; SCC |
| Google Ads / GA4 API | advertising / analytics | advertising/analytics data | US; SCC |
| TikTok Ads API | advertising data | ad account data | US/international; SCC |
| Google reCAPTCHA | bot protection | IP / usage data | US; SCC |
| Anthropic (Claude) | AI text generation (proposal/contract/chatbot) | prompt content (may contain personal data) | US; SCC; only in the relevant module |
| AI image-generation provider | AI social image generation | prompt data | only in the image module; SCC |
| ElevenLabs | Voice TTS | call text/audio | only in the Voice module; US/EU; SCC |
| Speech-to-text (STT) provider | Voice transcription | call audio | only in the Voice module; SCC |
| Retell (BYOK) | Voice-agent orchestration | call data | only in the Voice module; US; SCC |
| Transactional email provider | transactional/marketing email | email/contact data | SPF/DKIM; SCC where outside the EEA |
We keep the current list of sub-processors up to date and notify the affected controllers of material changes in accordance with the DPA.
5. Transfers to third countries
Some sub-processors operate outside the EEA (typically in the United States). We safeguard such transfers with appropriate measures under the GDPR: typically the Standard Contractual Clauses (SCC) adopted by the European Commission, or, where the provider holds it, certification under the EU-US Data Privacy Framework.
6. Retention periods
- Billing / accounting data: for the period required by the Hungarian Accounting Act (typically 8 years).
- Account and usage data: for the duration of the contract, and after the purpose ceases, deletion or anonymization following a reasonable grace period.
- Tenant-uploaded data: as set out in the DPA, returned or deleted upon termination of the contract.
- Voice call recordings/transcripts (only when the Voice module is used): for the short period necessary to achieve the processing purpose, then deleted.
7. Rights of the data subject
The data subject may request access to, rectification or erasure of their personal data, restriction of processing, may exercise the right to data portability, may object to processing based on legitimate interest, and may withdraw any consent previously given.
Important: for tenant data under 2.(b), the data subject should primarily contact the business (controller) that uploaded the data into the Suite; BeBrand, as processor, assists in accordance with the controller's instructions.
Complaints: the data subject may lodge a complaint with the supervisory authority - the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) - and may also seek a judicial remedy.
8. Security (technical and organizational) measures
- Encryption of data in transit and at rest.
- Role-based access control.
- Separation of platform admin and tenant admin: the platform operator does not have unrestricted access to tenant data.
- Logged, time-limited support access: support can access customer data only in a logged manner and for a limited time.
9. Cookies and reCAPTCHA
The website uses cookies necessary for operation and the Google reCAPTCHA service for bot protection. For details on cookies, see the Cookie Notice.
10. Processing and deletion of data obtained from the Meta (Facebook / Instagram) platform
If you use the Meta integration of BeBrand Suite, we process the following data related to the Meta platform (Facebook, Instagram):
- the performance and campaign data of your Meta advertising account, which we access via the Meta Ads API for reporting and ad management;
- where you connect the publishing function, the ID of the selected Facebook Page or Instagram Business account and the access tokens required to publish on your behalf, which we store encrypted and use solely to publish the content you create and approve in the dashboard, and to read the result of publishing (status, basic engagement).
We use data obtained from the Meta platform solely to provide the function you use, we do not sell it to third parties, and we handle it in accordance with the Meta Platform Terms and this policy.
Data deletion: you may request deletion of data obtained through the Meta integration at any time by: (a) disconnecting the connection in the Suite; (b) submitting a request via the contact in Section 1; or (c) a data deletion request initiated by Meta, which is processed automatically by our dedicated data deletion endpoint (https://iuqubqauwikrgyodxrji.supabase.co/functions/v1/meta-data-deletion). Following a deletion request, we delete the data attributable to you that originates from the Meta integration.
11. California consumers (CCPA / CPRA)
If you are a consumer subject to the CCPA/CPRA (for example, a California resident), you may be entitled under the applicable law to request information about the categories and use of personal data collected about you, to request its deletion, and to opt out of the "sale" or "sharing" of personal data. BeBrand does NOT sell personal data. You may exercise these rights via the contact in Section 1.
12. Changes to this policy
We may update this policy from time to time. We will notify you of material changes within the service or by email. The current version is available at bebrandsuite.com/privacy.