Privacy Policy

Last updated: 5 April 2026  ·  Voov Digital Limited T/A BeansSuite  ·  Company No. 08871876

Privacy Policy · Data Processing Agreement · Sub-processors · ← Sign in

This Privacy Policy explains how Voov Digital Limited, trading as BeansSuite (company number 08871876, registered in England & Wales) ("we", "us", "our"), collects, uses, stores and shares personal data when you use the BeansSuite platform ("Service").

We act as a data processor on behalf of companies that subscribe to BeansSuite (the "Controllers"). This policy also explains your rights as an individual whose data may be processed through the Service.

We process personal data in accordance with the UK GDPR, the UK Data Protection Act 2018, and the EU GDPR (Regulation 2016/679) where applicable.

1. Who we are

Voov Digital Limited T/A BeansSuite
Registered in England & Wales — Company No. 08871876
Privacy contact: privacy@beanssuite.com

For queries about how your data is used within the BeansSuite platform by one of our customers, please contact that organisation directly. They are the data controller for your personal information.

2. What personal data we collect

2.1 Platform users (subscribers and their team members)

  • Name, email address, password (hashed, never stored in plain text)
  • Login activity, session records, 2FA status
  • Role and permission assignments
  • Audit trail entries generated by user actions

2.2 CRM data entered by subscribers

Subscribers enter personal data about their own contacts and leads into the platform. This may include:

  • Names, email addresses, phone numbers, postal addresses
  • Organisation affiliations and job titles
  • Deal and quote information
  • Notes, activity logs, and documents
  • Geographic location data (latitude/longitude, What3Words)
  • E-signature records (name, IP address, timestamp, OTP confirmation)

We process this data only on the documented instructions of the subscribing company (the controller).

2.3 Technical and usage data

  • IP addresses, browser type, device type
  • Log data for security and debugging purposes
  • Cookies necessary for session management

3. Lawful basis for processing

PurposeLawful basis
Providing the Service under a subscription contractContract performance (Art. 6(1)(b))
Processing CRM data on behalf of subscribersLegitimate interests of the controller (Art. 6(1)(f)) or as directed by the controller
Security, fraud prevention, audit loggingLegitimate interests (Art. 6(1)(f))
Legal compliance (e.g. tax records)Legal obligation (Art. 6(1)(c))
E-signature recordsContract performance and legal obligation

4. How we use personal data

  • To provide, maintain and secure the BeansSuite platform
  • To authenticate users and prevent unauthorised access
  • To send transactional emails (e-signature OTPs, quote delivery, notifications)
  • To generate PDF documents including quotes, estimates and signed contracts
  • To store files in the subscriber's configured Google Drive
  • To support subscribers with technical queries
  • To comply with legal and regulatory obligations

We do not use your data for advertising, profiling, or sale to third parties.

5. Data retention

  • Active accounts: retained for the duration of the subscription
  • Deleted records (soft delete): retained for up to 30 days in the Trash, then permanently deleted unless subject to a legal hold
  • GDPR erasure requests: processed within 30 days; audit trail entries referencing the erased individual are anonymised, not deleted, to preserve record integrity
  • Signed documents: retained for the longer of the subscriber's configured retention period or 7 years (standard UK contract limitation period)
  • Account data on cancellation: deleted within 90 days of subscription end, unless a data export has been requested

6. International data transfers

Some of our sub-processors are based outside the UK and EU. Where personal data is transferred to the United States or other third countries, we ensure appropriate safeguards are in place:

  • UK transfers: International Data Transfer Agreements (IDTAs) or UK Addendum to EU SCCs
  • EU transfers: Standard Contractual Clauses (SCCs) approved under EU GDPR

A full list of our sub-processors, their locations and the safeguards applied is available at beanssuite.com/legal/sub-processors.

7. Your rights

Under UK GDPR and EU GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — correct inaccurate or incomplete data
  • Erasure — request deletion of your personal data ("right to be forgotten")
  • Restriction — ask us to restrict processing in certain circumstances
  • Portability — receive your data in a structured, machine-readable format
  • Object — object to processing based on legitimate interests
  • Withdraw consent — where processing is based on consent, withdraw it at any time

To exercise any of these rights, contact us at privacy@beanssuite.com. We will respond within 30 days. If you are unsatisfied with our response:

  • UK residents: complain to the Information Commissioner's Office (ICO)
  • EU residents: complain to your local supervisory authority

8. Security

We implement appropriate technical and organisational measures to protect personal data, including:

  • Passwords stored as bcrypt hashes (never plain text)
  • TLS encryption in transit; encrypted storage at rest
  • Two-factor authentication (2FA) available for all users
  • Role-based access controls with per-module permissions
  • Full audit trail of all data access and modification events
  • Session management with concurrent session limits
  • SHA-256 document hashing for signed contracts

9. Cookies

We use only strictly necessary cookies for session management and user preference storage (theme, brand colour). We do not use advertising or analytics cookies. No cookie consent banner is required.

10. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of the Service after changes constitutes acceptance of the revised policy. Subscribers will be notified of material changes by email.

11. Contact

Voov Digital Limited T/A BeansSuite
Registered in England & Wales — Company No. 08871876
Email: privacy@beanssuite.com

Voov Digital Limited T/A BeansSuite  ·  Company No. 08871876  ·  Registered in England & Wales  ·  privacy@beanssuite.com

Data Processing Agreement  ·  Sub-processors