Privacy Policy
Last updated: September 27, 2026
This Privacy Policy explains how BevoraX LLC ("BevoraX", "we", "us") processes personal data through our website and the BevoraX application (together, the "Service").
1. Who we are
BevoraX LLC, a New Mexico limited liability company 1209 Mountain Road Pl NE, Ste H, Albuquerque, NM 87110, USA Email: privacy@bevorax.im
For personal data we process about our customers' account users and website visitors, BevoraX is the controller. For personal data our customers put into the Service about their own staff and contacts, BevoraX acts as a processor on the customer's instructions; see section 9 and the DPA.
2. Scope
This policy covers the public marketing website and the authenticated application. It does not cover third-party sites we link to.
3. Personal data we collect
You provide it:
- Account data - name, email address, company name, encrypted password or authentication token, and your company/role assignment.
- Contact and support messages - the name, email, subject and message you send us, plus the interface language.
- Beta waitlist - the email address and language you submit to be reminded once when the beta opens.
- Billing data (after the beta) - the information needed to charge for a paid plan, handled by our payment processor.
Collected automatically:
- Server log data - IP address, date and time, requested URL, referrer, browser type and version, and operating system, recorded by our hosting provider to deliver the site, keep it stable and secure, and defend against attacks.
- Cookies and local storage - see the Cookie Policy.
Entered through the application:
- Service data - the operational records you and your team enter (products, stock, recipes, sales, purchases, suppliers, activity). We process this on your instructions to run the Service.
4. How we use personal data
- Provide, operate, maintain and support the Service.
- Keep the Service and its users secure and prevent abuse (including rate limiting).
- Communicate with you about your account, support requests, and the beta waitlist reminder.
- Bill for paid plans and keep the records the law requires.
- Improve the Service using aggregated, non-identifying usage information.
5. Legal bases (GDPR)
Where the GDPR applies we rely on:
- Performance of a contract - creating and running your account, providing the Service, responding to support requests.
- Legitimate interests - securing the Service, keeping short-lived server logs, error monitoring, and product analytics where you have opted in; our interest is a functioning, safe, improvable service.
- Consent - analytics and marketing cookies, and the beta waitlist. You can withdraw consent at any time.
- Legal obligation - tax and accounting retention.
6. Cookies and analytics
We use strictly necessary and functional storage without consent, and - only
with your consent - cookieless reach and performance measurement (Vercel Web
Analytics and Speed Insights) and Google Analytics 4 (which sets the _ga
cookies and transfers data to Google, including in the USA, under the EU-US Data
Privacy Framework). Cloudflare Turnstile is loaded on our forms to tell humans
from bots and is strictly necessary for those forms. Full detail and controls
are in the Cookie Policy.
7. The contact form
When you contact us through the form we store your name, email, subject, message and language, and - to prevent abuse - your user-agent string and a secret-keyed hash of your IP address. The IP address itself is not stored; the hash only lets us limit how many messages come from one source per hour and cannot be traced back to you. Your message is also delivered to our mailbox by our email provider.
8. Beta waitlist (double opt-in)
If you join the waitlist we send a confirmation email; your address is only stored as confirmed once you click the link in it. Unconfirmed entries are deleted automatically after 48 hours. We store your email address, language, the times of sign-up and confirmation, your user-agent string, and a secret-keyed IP hash (as above) as proof of consent and for rate limiting. Confirmed addresses are kept until the beta launch plus a short grace period for the reminder, then deleted. You can withdraw at any time via the unsubscribe link in every email or by contacting us.
9. Service data processed for customers
Personal data that a customer enters into the Service about its own staff and contacts is processed by us only to provide the Service, on the customer's documented instructions, under the DPA. The customer is the controller of that data; individuals should direct requests to the customer.
10. AI document scanning
When you use the AI scan, the photo or PDF you upload (for example a delivery note, invoice or sales report) is sent to Anthropic, PBC (USA) to extract its line items. Such documents may contain personal data, such as the name of a supplier's contact person or of the employee who signed for a delivery. Anthropic processes the data as our subprocessor only to return the result, does not use it to train its models, and deletes it after a short period under its commercial terms. The uploaded file is kept in our EU storage for 12 months (see section 13). The AI only suggests values; nothing is booked until a user confirms it, so no decisions with legal or similarly significant effect are made solely by automated means.
Mail inbox for supplier documents. Customers can set up their own receiving address to which suppliers send order confirmations and other documents. These mails are received for us by Postmark (ActiveCampaign, LLC, USA) and passed on to the Service. We store the sender address, the subject and the PDF or image attachments; we do not store the rest of the message. The attachments are read by the AI scan like an uploaded document (see above). The customer is the controller of this data; we process it as a processor (see section 9).
11. How we share personal data
- Subprocessors - infrastructure and service providers that process personal data on our behalf under contract. The current list, with purpose and location, is at Subprocessors.
- Legal and safety - where required by law or to protect rights, safety or the integrity of the Service.
- Business transfers - in connection with a merger, acquisition or sale of assets, subject to this policy.
We do not sell personal data, and we do not "share" it for cross-context behavioural advertising as those terms are defined under California law.
12. International transfers
The application database is hosted in the European Union (Supabase,
eu-central-1). Some providers are located in the USA. Where personal data is
transferred outside the EEA/UK we rely on the European Commission's Standard
Contractual Clauses and, where a provider is certified, the EU-US Data Privacy
Framework. BevoraX LLC itself is based in the USA and is not certified under the
EU-US Data Privacy Framework; transfers to us are therefore also covered by the
Standard Contractual Clauses (for customers, as part of the DPA). The UK
Addendum and the Swiss adaptations apply to transfers from the UK and
Switzerland.
13. Retention
- Account data - for the term of the contract, then deleted once no legal retention period (e.g. tax and commercial-law retention) still applies.
- Company data after a company account is deleted - archived for 180 days (can be restored during that time), then deleted permanently.
- Server logs - a short period (days), then deleted or anonymised.
- Error reports (Sentry, data centre in Germany) - 90 days, then deleted automatically by the provider. They contain the error message, stack trace, the route requested and the browser type, but no IP address, no cookies and no form contents; they set no cookies either, so no consent is required.
- Contact messages - until the request is resolved and no retention duty applies.
- Documents uploaded for the AI scan (photos and PDFs of delivery notes, invoices and sales reports) - 12 months from the upload, then deleted automatically. The data read from them, and any purchase order or delivery created from them, is business data and is kept under the first bullet.
- Mail inbox - sender and subject of received mails for 90 days, then deleted automatically. Mails that did not become a document (for example rejected, or without a usable attachment) are deleted with their attachments after 90 days; attachments that became a document follow the 12-month period for AI scan documents.
- Waitlist - as described in section 8.
14. Security
We use TLS in transit, database row-level security, least-privilege access, and mandatory two-factor authentication for administrative access, and we review these measures on an ongoing basis.
15. Your rights
If the GDPR applies to you, you have the rights to access, rectification, erasure, restriction of processing, data portability, and objection, the right to withdraw consent with effect for the future, and the right to lodge a complaint with a data protection supervisory authority.
If a US state privacy law applies to you (for example the California Consumer Privacy Act as amended, and comparable laws in other states), you have the rights to know about and access the personal data we hold, to have it deleted, to correct it, and to not be discriminated against for exercising these rights. We do not sell or "share" personal data, so there is nothing to opt out of. You may use an authorised agent to make a request. We honour Global Privacy Control (GPC) signals as an opt-out of any sale or sharing.
To exercise any right, email privacy@bevorax.im. We may need to verify your identity, and we will respond within the period the applicable law requires.
16. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal data from children.
17. Third-party links
Our site may link to third-party websites we do not control and are not responsible for. Their privacy practices are their own.
18. Changes to this policy
We may update this policy. We will post the new version here with an updated date and, for material changes, give notice by email or in the Service.
19. Contact
BevoraX LLC, 1209 Mountain Road Pl NE, Ste H, Albuquerque, NM 87110, USA · privacy@bevorax.im

