Privacy Policy
We are committed to protecting your privacy and handling your data with transparency and care. This policy explains exactly how we collect, use, and protect your personal information.
Last updated: July 3, 2026
1. Introduction
Beedux is operated by الجذور الرقمية للحلول التكنولوجية (English reference: Digital Roots for Technology Solutions), a company registered in Jordan and trading as Beedux ("we", "our", or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our cloud-based approval management platform (the "Service").
By accessing or using the Service, you agree to this Privacy Policy. If you do not agree with the terms of this policy, please discontinue use of the Service.
This policy applies to our public websites and to the Beedux application. It should be read together with our Terms of Service and, for a plain-language summary of security practices, our Security page. If anything here is unclear, contact
[email protected] before relying on it.
2. Information We Collect
We collect information in the following ways:
2.1 Information You Provide Directly
- Account registration data: full name, email address, job title, company name
- Organization profile: company name, industry, size, billing email, timezone, preferred currency
- Documents and content: purchase orders, invoices, procurement requests, and attached files submitted through the Service
- Communications: messages, comments, and feedback you submit within the platform
2.2 Information Collected Automatically
- Usage data: pages visited, features used, workflow interactions, approval actions taken
- Device information: IP address, browser type, operating system, device identifiers
- Log data: server logs, error reports, timestamps of actions
- Cookies and similar technologies: session tokens, authentication cookies, preference cookies
2.3 Information from Third Parties
- Authentication providers: when you sign in with Google or other OAuth providers through Clerk, we receive your name, email address, and profile picture
- Payment processors: online checkout is being prepared and is not active yet. When online checkout is enabled, payment and billing information may be processed by Paddle as payment processor / Merchant of Record. Beedux does not store full payment-card details
3. Workspace and Approval Data
When your organization uses Beedux, the documents, requests, approvals, comments, and decision records submitted to a workspace ("Workspace Content") belong to the customer workspace that submitted them, as described in our Terms of Service. We process Workspace Content to provide the Service.
- Role-based visibility: members see documents, approvals, and workflow activity according to the roles your workspace assigns. Workspace administrators control who is invited and what each role can access.
- Audit trail: approval actions, comments, and decisions are recorded in an audit trail as part of the Service, and are retained as described in the Data Retention section.
- Our access: we access Workspace Content only as needed to operate and secure the Service, to resolve support requests you raise, or to meet legal obligations.
4. How We Use Your Information
We use the information we collect to:
- Provide the Service: process and route approval documents, notify approvers, maintain audit trails, and generate analytics
- Manage your account: authenticate your identity, manage your organization memberships and roles
- Manage workspace access: administer workspace plans and access tiers; billing is not active yet and no payment data is processed
- Send communications: service notifications (approval requests, rejections, comments), system alerts, and — with your consent — product updates and newsletters
- Improve the Service: analyze usage patterns, detect errors, and inform product development decisions
- Ensure security: detect and prevent fraud, abuse, and unauthorized access
- Meet legal obligations: comply with applicable laws, respond to lawful requests, and enforce our Terms of Service
Legal Bases for Processing (GDPR)
- Contract performance: processing necessary to deliver the Service you've contracted for
- Legitimate interests: security, fraud prevention, service improvement
- Legal obligation: regulatory compliance, audit record keeping
- Consent: marketing communications (where required by law)
5. Data Sharing and Disclosure
We do not sell your personal data. We share your information only in the following circumstances:
5.1 Service Providers (Data Processors)
We engage trusted third-party processors who act on our instructions:
- Clerk: identity and authentication management (clerk.com)
- Render: application hosting and managed PostgreSQL database hosting
- Cloudflare R2: storage of uploaded files and document attachments
- Resend: delivery of transactional and notification emails
Billing is not active yet (being prepared through Paddle). When paid plans are introduced, Paddle will act as the payment processor and this list will be updated before any billing begins.
5.2 Within Your Organization
Information about documents, approvals, and workflow actions is visible to other members of your organization with appropriate role-based access.
5.3 Legal Requirements
We may disclose your information if required by law, court order, or regulatory authority, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
5.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you before your data becomes subject to a different privacy policy.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. Specifically:
-
Active account data: retained for as long as your account is active, plus 90 days after closure (to allow recovery)
-
Audit trail records: retained for 7 years to support financial compliance and audit requirements
-
Document attachments: deleted within 30 days of account termination unless subject to a legal hold
-
Payment records: not applicable yet — billing is not active and no payment records are created
-
Anonymized usage analytics: may be retained indefinitely
You may request earlier deletion by contacting us at
[email protected].
7. Data Security
We apply reasonable technical and organizational safeguards to protect your data:
-
Encryption in transit and at rest: data is encrypted in transit, and encrypted at rest where supported by our infrastructure providers
-
Access controls: role-based access control (RBAC) with principle of least privilege
-
Authentication: multi-factor authentication support via Clerk
-
Audit logging: approval and account activity is recorded in the audit trail
-
Ongoing review: we continue to review and improve safeguards as the Service evolves
No system is completely secure. We encourage you to use a strong, unique password and to notify us at
[email protected] immediately of any suspected unauthorized access.
8. Customer Responsibilities
Beedux is a B2B service. Your workspace — acting through its Account Owner and administrators — decides what content to submit to the Service, who to invite, and which roles and permissions to assign. As a customer, you are responsible for:
- Lawful content: ensuring you have the right to submit any personal data contained in documents, requests, or comments your workspace uploads (for example, information about employees, vendors, or counterparties), and that your use of the Service is consistent with your own privacy notices and obligations.
- Access control: assigning roles and permissions carefully and reviewing them periodically; workspace members see data according to the access your workspace grants them.
- Requests about Workspace Content: directing requests about data inside documents your organization submitted (for example, correction or deletion of a record in a purchase request) to your workspace administrator first. We support customers in fulfilling such requests where our assistance is needed.
9. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data:
For EU/EEA Residents (GDPR)
-
Right of Access: request a copy of the personal data we hold about you
-
Right to Rectification: request correction of inaccurate or incomplete data
-
Right to Erasure: request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations
-
Right to Data Portability: receive your data in a structured, machine-readable format
-
Right to Restrict Processing: request that we limit how we process your data
-
Right to Object: object to processing based on legitimate interests or for direct marketing
-
Right to Withdraw Consent: where processing is based on consent, you may withdraw it at any time
For California Residents (CCPA)
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information
- Right to opt-out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising your privacy rights
To exercise any of these rights, contact us at
[email protected].
10. Cookies and Tracking Technologies
We use cookies and similar technologies to operate and improve the Service:
Essential Cookies
Required for the platform to function. These include authentication session cookies and security tokens. You cannot opt out of these without losing access to the Service.
Functional Cookies
Used to remember your preferences (organization selection, language, timezone). Stored in your browser's localStorage.
Analytics and Marketing Cookies
We do not currently use third-party advertising or marketing cookies. If we introduce analytics or marketing cookies in the future, we will do so with appropriate notice and controls.
Managing Cookies
You can control cookies through your browser settings. Blocking all cookies may impair certain features. For more information, visit www.allaboutcookies.org.
11. International Data Transfers
Beedux and the service providers listed in the Data Sharing section may process information in countries other than the country where you live or where your organization is established. Wherever information is processed, we take reasonable steps to ensure it receives protection consistent with this Privacy Policy, including choosing reputable providers and applying the safeguards described in the Data Security section.
If you have questions about where data relating to your workspace is processed, or about the transfer safeguards that apply to you, contact
[email protected] and we will provide current information for your review.
12. Children's Privacy
The Service is designed for business use by adults and is not directed at children under the age of 16. We do not knowingly collect personal information from children under 16. If you believe we have inadvertently collected such information, please contact us immediately and we will delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify you via email (for registered users) at least 30 days before the changes take effect
- Display a prominent notice within the Service
Your continued use of the Service after the effective date of the updated policy constitutes your acceptance of the changes.