Sign in

Legal & policies

How FundyBee works, what we do with your data, and the terms you agree to when you use the service.

TermsPrivacyCookiesData processingRefundsWithdraw

Privacy Notice

Effective date: 31 August 2026 · Version 2026-08-31

Contents

  1. 1. Controller and scope
  2. 2. Personal data we process
  3. 3. Where data comes from
  4. 4. Purposes and lawful bases
  5. 5. AI processing and public-source research
  6. 6. Recipients and service providers
  7. 7. International transfers
  8. 8. Retention
  9. 9. Your rights and choices
  10. 10. Required and optional data
  11. 11. Children and sensitive information
  12. 12. Security
  13. 13. Automated decisions and AI transparency
  14. 14. Cookies and device storage
  15. 15. Changes
  16. 16. Contact and complaints

1. Controller and scope

Innovation Bee P.C., registered as INNOVATION BEE ΙΔΙΩΤΙΚΗ ΚΕΦΑΛΑΙΟΥΧΙΚΗ ΕΤΑΙΡΕΙΑ, is the controller for account administration, billing, platform security, service communications, product operations and our own partner-directory and business-contact activities. Registered office: Palaeokastro 0, 50300 Voio, Kozani, Greece; G.E.MI. 164094236000; VAT EL801827709. Our privacy contact is info@innovationbee.gr. We have not appointed a data protection officer; this mailbox is monitored by the privacy lead.

A customer organisation is normally the controller for personal data it chooses to put in proposals, partner records, uploaded files and collaboration spaces. For that data we act as its processor under our Data Processing Addendum. Other consortium organisations can be separate or joint controllers depending on their own arrangements. This notice covers our controller processing; the customer must provide any additional notice required for its processing.

2. Personal data we process

CategoryExamples
Account and profileName, email, password handled by Supabase Auth, phone, profession, avatar URL, role in Erasmus+ proposal work and approximate writing volume, account identifiers, accepted legal version/time, purchase-contract confirmation and authentication/session records.
Organisation and teamOrganisation name, address, country, OID/PIC, VAT/tax details, legal representative and contacts, workspace membership, role, invitations and collaborator presence.
Ideas, proposals and AI interactionsIdeas, concept notes, chats, prompts, instructions, proposal text, research queries and results, sources, budgets, evidence, reviews, scores, edits, versions and AI tool-operation inputs and results.
Files and signaturesPIFs, images, PDFs, Word, Excel and other supported uploads; file names, types, sizes, hashes and uploader; signer name, email, statement, method and timestamps.
Partner and public professional contactsOrganisation, role, professional name/email/phone, public source URL, evidence snippet, provenance, verification status, suppression status and records of directory exposure.
Sharing and activityRecipient email, invitation message, role, share token, inviter, views, timestamps, notifications and collaboration events.
BillingStripe customer/subscription/payment identifiers, plan, seats, purchase amount, tax/invoice information, status and payment-event payloads. We do not receive or store a full card number.
Support and communicationsName, email, subject and message; delivery/bounce/complaint events; campaign, consent, unsubscribe, objection and suppression records.
Technical and securityIP address, route, browser/device request data, cookie/session identifiers, rate-limit keys, error message, account/user identifiers, timestamps and model/token/cost metadata.

3. Where data comes from

  • From you when you register, pay, contact us, enter content, upload a file or use an AI feature.
  • From your organisation and collaborators when an administrator invites you, a teammate edits shared content, or a partner supplies a PIF or signature.
  • From service providers, including authentication, payment, email, hosting and error-delivery records.
  • From public professional sources, including the Erasmus+ Project Results Platform and related European Commission datasets, organisation websites and professional directories. We record the source and do not intentionally collect private contact data through this process.
  • Created through use, such as AI output, review results, activity events, inferred partner relevance and security signals.

If we obtain professional contact data from a public source rather than from you, we provide this notice within one month and, at the latest, when we first contact you or disclose the data, unless a documented GDPR Article 14 exception applies. Every enabled outreach flow includes a link to this notice and records the first provider-confirmed delivery. You may object or request suppression at any time. Customer-facing partner results and marketing imports are limited to verified generic organisational inboxes; named-person candidates are not published or imported through those paths.

4. Purposes and lawful bases

PurposeLawful basis under GDPR Article 6
Create accounts, provide workspaces, collaboration, AI tools, exports and support.Contract, Article 6(1)(b); legitimate interests for organisation users where the contract is with their employer, Article 6(1)(f).
Take payment, administer subscriptions, prevent billing fraud and keep invoices/accounting records.Contract, legitimate interests and legal obligation, Articles 6(1)(b), (f) and (c).
Authenticate users, isolate tenants, rate-limit, monitor errors, investigate abuse and defend legal claims.Legitimate interests in a secure and reliable service, Article 6(1)(f); legal obligation where applicable.
Generate, retrieve and review content with AI at your request.Contract, Article 6(1)(b), or the customer’s documented instruction where we are processor.
Build and maintain a professional partner directory from public sources and show relevant organisations/contacts.Legitimate interests in enabling Erasmus+ professional collaboration, Article 6(1)(f), balanced against professional contacts’ rights; objection and suppression are always available.
Send requested service messages, invitations, signature requests and support replies.Contract and legitimate interests, Articles 6(1)(b) and (f).
Send optional marketing or permitted business outreach.Consent where required, Article 6(1)(a), or documented legitimate interests for proportionate B2B outreach, Article 6(1)(f), subject to national ePrivacy/direct-marketing rules.
Measure service use and improve reliability using operational metadata rather than advertising profiles.Legitimate interests, Article 6(1)(f).
Optional Google Analytics on fundybee.com, only after you accept the cookie banner, to see which public and in-app pages are used.Consent, Article 6(1)(a). You may withdraw it from the cookie banner or cookie policy without affecting access to the Service.

Our legitimate interests are limited by necessity, data minimisation, access controls and your rights. We do not sell personal data or use it for third-party behavioural advertising.

5. AI processing and public-source research

When you request AI drafting, review, extraction, matching or chat, the Service selects relevant Customer Content and sends it through our self-hosted routing and drafting infrastructure to an authorised model provider. This can include proposal context, prompts, chat history, extracted file text and—in supported cases—file bytes. Do not include personal data that is unnecessary for the result.

Production AI processing is fail-closed unless an explicit, approved commercial API model route is configured; unbounded “auto” routing and consumer/subscription routes are not authorised for Customer Content. For the authorised Anthropic commercial API route, Anthropic states that customer API content is not used to train shared models and publishes a standard retention period of up to 30 days for API inputs and outputs, subject to stated safety, legal and contractual exceptions. A different upstream provider cannot be enabled until its identity, role, terms, location, retention, transfer safeguards and subprocessor notice have been completed and this notice/DPA are updated where required.

Research and contact discovery may send a query, organisation name, country and website to an AI web-search service and retrieve public pages. A public email or role is not proof of consent to marketing. We retain source provenance, honour objections and suppress a contact from further use where required.

6. Recipients and service providers

Authorised staff and workspace users receive data only as needed for their role and the sharing choices made by the workspace. Current provider categories and named suppliers are:

Authorised users of customer workspaces may receive verified generic professional directory/contact records when they use partner-search or matching features. The receiving customer is responsible for any later use or outreach.

RecipientFunction and dataProcessing scope
Hetzner Online GmbHOrigin, web, worker and internal-service hosting through our Coolify deployment.European data-centre infrastructure used by the current production origin.
Cloudflare, Inc.DNS, content delivery, traffic security, connection/security metadata and proxied request/response traffic.Global edge network; provider data terms and the applicable adequacy decision or EU Standard Contractual Clauses apply to restricted transfers.
Supabase, Inc.Authentication, Postgres database, private/public storage and realtime collaboration.This notice does not claim a specific project region: the active project region and data-residency configuration are not evidenced in this repository and must be verified from current dashboard or contract records before Customer Content processing is released. Provider support and listed subprocessors may process elsewhere under the documented transfer mechanism.
Anthropic Ireland, Limited / Anthropic, PBCApproved commercial-API model inference and hosted web search for prompts, relevant context and supported files.EEA, United States and provider subprocessor locations under its commercial terms, DPA and applicable transfer safeguards.
Stripe Payments Europe, Limited and affiliatesCheckout, recurring billing, tax/payment status and fraud prevention.EEA and global Stripe infrastructure under Stripe’s data terms.
Resend, Inc.Registration/contract confirmations, transactional/service email, support replies and authorised campaigns, including message content and delivery events.Provider and subprocessor locations under its DPA and applicable transfer safeguards.
DocuSeal (when e-signature is enabled)Signature requests, signer details and signed documents.Enabled only after the selected endpoint, role, location, retention, processor terms and transfer mechanism are recorded.
Functional Software, Inc. (Sentry, when enabled)Error monitoring: error message, route, account identifier and limited diagnostic context.Configured Sentry region and subprocessors under its DPA.
Google LLC (Google Analytics 4, after consent)Website and app-page measurement: page path with project/invite identifiers removed, client identifier, device/browser data and IP address received at collection time. Not used for advertising in our configuration, and not a destination for proposal text.United States and Google processing locations under Google’s Analytics terms and the applicable Chapter V transfer mechanism. Loaded only after analytics consent on fundybee.com.
jsDelivr (public demo only)Delivers the GSAP animation script used by an embedded landing-page demonstration and receives ordinary connection data such as IP address and user agent.Global content-delivery network; fonts/icons are self-hosted and no account or proposal content is intentionally sent.

Professional advisers, auditors, insurers, courts or authorities may receive limited data where necessary to comply with law or establish, exercise or defend claims. We do not disclose Customer Content to another customer unless you share it or authorise collaboration.

7. International transfers

Not every supplier or network request is confined to the EEA. Before personal data is transferred to a country without an EU adequacy decision, we require an applicable GDPR Chapter V mechanism—normally the European Commission’s Standard Contractual Clauses in the supplier’s DPA—plus supplementary measures where the assessment requires them. A provider may also rely on an adequacy framework for the covered entity and processing. Contact us for the mechanism relevant to a particular provider and a copy of available safeguards (commercial terms may be redacted).

8. Retention

DataRetention rule
Account, organisation, proposal, partner, chat and project filesWhile needed to provide the account or workspace. A support-assisted workspace closure disables ordinary access but does not itself erase these records. A separate verified return or erasure request follows the documented deletion process, subject to another workspace member’s rights, a recorded legal hold and verified provider or backup constraints.
Chat-upload working objectsObjects become eligible for cleanup 24 hours after upload. Cleanup is periodic and can occur later; a verified erasure request provides an additional deletion path.
Share links and collaboration recordsLinks expire after 30 days unless renewed or revoked sooner. Share/activity records remain while needed for the workspace, security and accountability, then follow the verified workspace deletion process.
Public professional contactsPublished contact freshness is reviewed after 120 days. Source, verification, exposure and suppression records are kept while needed to operate the directory, document lawful use and honour objections.
AI provider copiesDirect Anthropic API inputs/outputs are normally retained up to 30 days under its published commercial policy, unless a shorter contractual setting or stated exception applies. Copies saved in FundyBee follow the workspace rule above.
Billing and accountingAt least five years from the end of the relevant accounting period, or longer where Greek tax/accounting law, an audit or a legal claim requires it.
Legal acceptance and contract evidenceThe accepted version/time, attached-document hashes, order or withdrawal confirmation and a pseudonymous email hash are retained only while reasonably needed to prove the contract, notice or request, meet a legal duty, or manage an active dispute. They are deleted or anonymised when no such purpose remains under the approved production retention schedule.
Support and direct communicationsUntil the request is resolved, then reviewed and deleted or anonymised when no longer needed; retained longer only where necessary for a contract, complaint, security incident or legal claim.
Marketing and suppressionUntil consent is withdrawn, you object, or the contact becomes inactive/outdated. A minimal suppression record can be kept longer so we do not contact you again.
Security, rate-limit, error and AI-usage metadataWhile needed to protect, debug and account for the Service, then deleted or aggregated under periodic review; longer only for an incident, abuse investigation or legal claim.
Google Analytics measurement events (after consent)Held in our Google Analytics property according to that property’s retention setting, and until you withdraw consent or request erasure of the client identifier we can reasonably locate.

This table records intended rules and currently identified application-level triggers; it is not a promise that every database, object, log, queue, backup or processor copy is deleted on a fixed timetable. A complete technical retention schedule and end-to-end deletion evidence remain release gates. We will not represent an erasure as complete until the affected live systems and processor instructions have been checked. Provider backup cycles and legally required records can outlast removal from the live Service; retained copies must remain isolated from ordinary use until expiry or lawful deletion.

9. Your rights and choices

Depending on the processing, you may request access, rectification, erasure, restriction, portability, or object to processing. You may withdraw consent at any time without affecting earlier lawful processing. You have an unconditional right to object to direct marketing; use the unsubscribe control or contact us and we will suppress further marketing.

Email info@innovationbee.gr. We may verify identity and authority before acting. We normally respond within one month, with any lawful extension explained. Some account and workspace controls are available at Account & privacy; they do not replace a rights request. A workspace export is restricted to authorised workspace management because it can contain other people’s data. A member seeking only their own data should contact us.

Leaving a workspace removes the member’s access only. Support-assisted workspace closure disables the organisation account without deleting its records or authentication users. Neither action is represented as completion of an Article 17 erasure request.

If we process data solely for a customer organisation, we will normally forward the request to that controller and assist it under the DPA.

10. Required and optional data

Email, authentication data, legal acceptance and basic workspace information are contractually required to create and secure an account. Payment and billing information is required only for a purchase. Proposal fields, partner contacts, files, profile details beyond the required fields and marketing consent are optional, although a feature may not work without the information it needs. Refusing optional marketing has no effect on Service access.

11. Children and sensitive information

FundyBee accounts are for adults aged 18 or over and the Service is not directed to children. Erasmus+ materials can nevertheless refer to child participants. Use aggregated or pseudonymised information wherever possible and do not put a child’s identity into prompts or uploads unless your organisation has a documented necessity, lawful basis, safeguards and appropriate notice.

The Service does not require health, disability, ethnicity, religion, political opinion, sexual-orientation or other special-category data. Free text and files can contain it, so customers must avoid it unless strictly necessary and lawful. Contact us to restrict or remove material entered by mistake.

12. Security

Measures include TLS in transit, provider encryption at rest where supported, server-side secret handling, individual authentication, role-based access, Postgres row-level security, private storage for customer files, tenant-scoped application queries, controlled administrative access, logging, rate limiting and incident response. Shared links and public avatars are accessible as designed, so customers must choose sharing settings carefully. No system is risk-free.

13. Automated decisions and AI transparency

FundyBee produces suggestions, matching scores, proposal reviews and AI drafts, but does not make a solely automated decision that has legal or similarly significant effects on an account holder or participant. A human decides what to accept, submit or act on. The interface identifies the AI assistant before interaction and warns that output requires verification. Contact us if you believe an automated result has been used incorrectly.

14. Cookies and device storage

We use authentication and short-lived operational cookies plus local/session storage for settings and requested workflow continuity. Optional Google Analytics cookies are used only after you accept them. We do not use advertising or other cross-site tracking cookies. The exact keys, purposes and durations are in the Cookie Policy.

15. Changes

We will update this notice when purposes, providers or legal requirements change. Material changes will be communicated by email or an in-app notice before they take effect where practicable. The date and version above identify the current notice.

16. Contact and complaints

Privacy requests: info@innovationbee.gr. General support: support page. Postal contact: Innovation Bee P.C., Palaeokastro 0, 50300 Voio, Kozani, Greece.

You may complain to the Hellenic Data Protection Authority or, where applicable, the supervisory authority in your habitual residence, workplace or place of the alleged infringement. We would appreciate the chance to address the concern first, but you are not required to contact us before using that right.