// PRIVACY_NOTICE
What we collect, and why.
This site has one form and one purpose for the information it collects: reading and replying to project enquiries. This notice explains exactly what that involves.
Last updated:
1. Who we are
Beenwise Solutions ("we", "us", "our") is an independent software and automation practice operating from Bangladesh, and it runs beenwise.org. We are the data controller for the personal information described in this notice, which means we decide why and how it is processed.
For anything in this notice, including any request under section 10, write toprivacy@beenwise.org. A person reads that address; there is no ticketing system in between.
2. What we collect
We collect three things, and nothing else.
Information you give us through the enquiry form
The form on our contact page asks for your name, email address, project type, and a description of your project. You may also choose to add a company name, website, estimated budget, and preferred timeline. Those four are optional, and leaving them blank does not change how we read your enquiry.
You must tick a box confirming you have read this notice before the form will submit. Anything else you send us afterwards, such as a reply to our email, is held on the same basis.
Information collected automatically
- Server logs. Our host records the IP address, timestamp, requested page, referrer, and browser user agent for each request. These exist to keep the site available and secure.
- Anti-spam checks. The enquiry form is protected by Cloudflare Turnstile, which examines your IP address and browser characteristics to decide whether a submission is automated. Turnstile is designed to do this without profiling you or tracking you across sites.
Information stored on your device
If you switch between the light and dark theme, your choice is saved in your browser's local storage so the site remembers it next time. That value never leaves your device and is never sent to us. See cookies and local storage for the full list.
We do not run analytics, advertising, or social media tracking. We do not buy personal data, and we do not build profiles of visitors.
3. Why we process it
- To read your enquiry, reply to it, and have the conversation that follows.
- To send you an automatic confirmation that your enquiry arrived.
- To keep a record of what was discussed and agreed.
- To keep the site available, and to block spam and abuse.
We do not use your details for marketing. We will not add you to a mailing list, and we will not send you anything you did not ask for.
4. Legal bases
Where the UK GDPR, the EU GDPR, or a comparable law applies to you, we rely on the following bases:
- Steps taken at your request before entering a contract. Reading and answering an enquiry about possible work.
- Legitimate interests. Keeping the site secure, preventing spam, and keeping records of business correspondence. We have weighed these against your interests and consider them proportionate given how little we collect.
- Legal obligation. Retaining records where tax or accounting law requires it, once work is contracted.
We do not rely on consent for the enquiry form, and we do not ask for marketing consent, because we do no marketing.
5. Who we share it with
We do not sell, rent, or trade personal information, and we do not share it with third parties for their own purposes.
Running the site does involve a small number of service providers who process information strictly on our behalf, under contract and on our instructions:
- Hosting and content delivery. Serves these pages to your browser and keeps the server logs described above.
- Email delivery. Sends the notification to us and the confirmation to you, so the contents of your enquiry pass through it.
- DNS, inbound mail routing, and anti-spam. Routes messages sent to our published addresses, and runs the check that keeps automated submissions out of the enquiry form.
Each provider is bound by a data processing agreement, acts only on our instructions, and may not use your information for its own purposes. We add no provider that would change what this notice says without updating this page first.
We may also disclose information where the law requires it, or where it is necessary to establish or defend a legal claim.
6. International transfers
We operate from Bangladesh, and our providers run global infrastructure, so your information is processed outside the country you live in, including in the United States. Where that involves a transfer out of the UK or the European Economic Area, our providers rely on transfer mechanisms recognised under those laws, such as Standard Contractual Clauses and the EU-US Data Privacy Framework.
7. Cookies and local storage
We set no cookies. We store the light or dark theme you choose in local storage on your device. Cloudflare Turnstile returns a short-lived, one-time token when it verifies the enquiry form and is configured not to issue a clearance cookie. We do not use any of these mechanisms for analytics, advertising, or tracking.
Our cookies and local storage notice lists each item, what it is for, and how long it lasts.
8. How long we keep it
- Enquiries that do not become work. Deleted 24 months after our last exchange with you.
- Client correspondence. Where work is contracted, retained for the duration of the engagement and for as long afterwards as tax and accounting law requires.
- Server logs. Retained by our host for a short period under its own policy, then rotated out.
- Email delivery logs. Held by our email provider under its own retention policy.
If you want your enquiry deleted sooner, ask us and we will do it unless we are required to keep it.
9. How we protect it
The site is served over HTTPS with a strict Content Security Policy. Enquiry data is validated on the server, escaped before it enters any email, and never written to a database, because there is not one. Access to the inbox that receives enquiries is limited to people who need it. Our API credentials are held as server-side environment variables and are never exposed to the browser.
No system is perfectly secure, and we cannot guarantee that transmission over the internet is free of risk. If a breach affects your rights and freedoms, we will notify you and the relevant supervisory authority as the law requires.
10. Your rights
Depending on where you live, you may have the right to:
- ask what personal information we hold about you, and get a copy of it;
- have inaccurate information corrected;
- have your information deleted;
- restrict or object to how we use it, including objecting to legitimate interests;
- receive it in a portable, machine-readable format;
- withdraw consent, where we relied on it;
- not be subject to a decision made solely by automated means. We do not make any such decisions.
If you are in California, you also have the right to know what is collected, to request deletion or correction, and not to be treated differently for exercising those rights. We do not sell or share personal information as the CCPA defines those terms, so there is nothing for you to opt out of.
To exercise any of these, emailprivacy@beenwise.org. We respond within 30 days and we do not charge for it. We may need to confirm your identity first, so that we do not hand your information to someone else. We honour these requests wherever you live, whether or not your local law compels us to.
11. Children's privacy
This is a business-to-business site. It is not directed at children, and we do not knowingly collect information from anyone under 16. If you believe a child has sent us personal information, contact us and we will delete it.
12. Changes to this notice
If what the site does changes, this notice changes with it, and the date at the top of the page is updated in the same edit. Where a change materially affects how we use information you have already given us, we email you about it rather than relying on you to notice.
13. Contact and complaints
For any privacy matter, write toprivacy@beenwise.org. For anything else,hello@beenwise.org reaches us just as well.
If our answer does not satisfy you and you live somewhere with a data protection authority, you may complain to it. We would rather you came to us first and gave us the chance to put it right.