Legal Documents
BeSync Legal

Privacy Policy

Effective 02.03.2026

Overview and Scope

This Privacy Policy explains how BeSync ("BeSync", "we", "us", "our") collects, uses, shares, and protects Personal Data when you visit our website, use our web dashboard, or use our AI-powered assistant inside collaboration platforms such as Slack.

Important: B2B / workplace service. BeSync is provided to organisations ("Customers"). Most end users use BeSync under their employer's Workspace and instructions. In most cases, your employer is the controller of employee data processed through BeSync, and BeSync processes that data as a processor/service provider.

Contracting & Operations Model

  • Contracting entity (UK): InfraSync Tech Ltd, 17047718, 71-75, Shelton Street, Covent Garden, London, WC2H 9JQ, UNITED KINGDOM
  • Operating entity (Turkey): InfraSync Teknoloji Tic. Ltd. Şti, Pınarbaşı, Hürriyet Cd., 07070 Konyaaltı/Antalya-Türkiye
  • Privacy contact: [email protected]

Where this policy applies

  • Marketing website(s) that link to this policy
  • Web dashboard (reports, Kanban board, admin settings, logs)
  • In-product experiences within collaboration platforms where BeSync is installed
  • Support communications (emails, tickets, onboarding calls)

Controller vs Processor Roles

BeSync as a processor/service provider (most Workspace content). When processing Customer Content inside a Customer Workspace — collecting standups, generating reports, extracting project signals, syncing tasks, and providing the "Ask BeSync" assistant — we generally act as processor on behalf of the Customer (the controller).

BeSync as a controller (limited contexts). We act as a controller for:

  • Website analytics and cookie preferences
  • Billing and account administration data for Customer administrators/billing contacts
  • Our own security logs, fraud prevention, and service improvement telemetry

Definitions

Personal Data

Information relating to an identified or identifiable individual (e.g., name, work email, user identifier, IP address, or message content where it relates to a person).

Customer

The organisation that subscribes to BeSync and controls the Workspace configuration.

Workspace

The environment connected to the Customer's collaboration platform instance and associated BeSync settings, users, integrations, and data.

User

An individual authorised by a Customer to use BeSync (e.g., employees, contractors).

Customer Content

Data that the Customer or its Users submit to, store in, send through, or otherwise make available to BeSync in the context of using the Service.

Sub-processor

A third party we engage to process Personal Data on our behalf (e.g., cloud hosting, monitoring, email delivery, payment processing).

What Data We Collect

Account, Admin & Billing Data (Controller)

  • Name, work email, job title, and role (Owner/Admin/PM/Viewer)
  • Authentication and account metadata (login timestamps, SSO configuration metadata)
  • Workspace administration settings and preferences
  • Billing contact details, invoice history, plan level

Workspace & Collaboration Platform Metadata (Processor)

  • Workspace/tenant identifiers, channel identifiers and names
  • User identifiers, display name, profile fields made available by platform scopes
  • Message metadata (timestamps, channel IDs, thread IDs) and message content only from sources the Customer authorises

Standup Data (Processor)

  • Free-text responses from direct message flows (yesterday / today / blockers)
  • Optional structured selections (project, tags, blockers)
  • Timestamps and completion state

Message Processing for Project Signals (Processor)

  • Blockers, risks, dependencies
  • Deadlines and due dates mentioned in text
  • Requests and task updates
  • Links and references contained in messages

Usage Data, Device Data & Logs

  • IP address, device/browser type, app version
  • Event logs (features used, settings changes, integration sync events)
  • Audit logs of admin actions
  • Error and performance telemetry (crash logs, latencies)

How We Share Data and International Transfers

Sharing within BeSync entities. InfraSync Tech LTD UK may share Personal Data with InfraSync Teknoloji TR to deliver engineering, operations, support, and related services, under contractual controls and confidentiality obligations.

Sub-processors

We may share Personal Data with vetted sub-processors for cloud hosting, monitoring and error tracking, email delivery, customer support, payment processing, AI infrastructure/model providers, and website analytics.

International Transfers

Personal Data may be processed in multiple countries, including the United Kingdom and Turkey. Under UK GDPR, transfers may require appropriate safeguards such as the UK IDTA or the UK Addendum to EU Standard Contractual Clauses. Under Turkey's KVKK, cross-border transfers are permitted under conditions such as explicit consent or where adequate protection applies.

Data Retention, Security & Customer Controls

We retain Personal Data only as long as necessary to provide the Service, meet contractual obligations, comply with legal obligations, resolve disputes, and enforce agreements.

Security Measures

  • Access controls and least-privilege principles
  • Encryption in transit and, where applicable, at rest
  • Logging and monitoring
  • Secure development and vulnerability management practices
  • Incident response procedures

Customer Controls (Admins)

  • Which channels/conversations are monitored
  • Enabled features (e.g., date extraction, persona insights)
  • Approval policies for task creation/sync and due date writes
  • Access roles (RBAC) for dashboards and reports
  • Integrations and their permissions/tokens

Your Rights

If BeSync is acting as a controller for your Personal Data, you may have rights such as access, rectification, erasure, restriction, objection, data portability, withdrawing consent, and lodging a complaint with a supervisory authority.

Employees/end users in a Customer Workspace: For most Customer Content and workplace data, BeSync acts as a processor and your employer is the controller. You should usually direct requests to your employer/workspace admin first.

To contact us regarding privacy: [email protected] — Subject line: "Privacy Request – BeSync"

Supervisory Authorities

  • In the UK: the Information Commissioner's Office (ICO)
  • In Turkey: the Personal Data Protection Authority (KVKK)

For questions about this document, contact [email protected]. © 2026 InfraSync Tech Ltd. All rights reserved.