Privacy Policy

Last updated: June 2025

This policy describes how BeeKeeper collects, uses, and protects your personal information when you use our website portfolio management platform.

1. Introduction

BeeKeeper ("we", "us", or "our") is a website portfolio management platform built by Hive IT Ltd. We are committed to protecting your privacy and handling your data responsibly. This Privacy Policy explains what information we collect, why we collect it, and how we safeguard it.

2. Data We Collect

We collect only the data necessary to provide and improve BeeKeeper:

  • Account Information: When you sign in via Google, we receive your name, email address, and profile picture from the authentication provider.
  • Website Data: URLs, technology stack details, security configuration status (headers, SSL, email authentication), dependency information, and domain records for the websites you manage.
  • Integration Data: If you connect integrations (e.g. Slack, Jira, GitHub, or GitLab), we store the necessary credentials (encrypted) and configuration to deliver notifications and sync data.
  • Client & Project Data: Names, contact details, and organisational structure you enter to manage your client portfolio within BeeKeeper.

3. How We Use Your Data

We use your data for the following purposes:

  • To provide, maintain, and improve the BeeKeeper platform.

  • To scan repositories for dependencies and known vulnerabilities.

  • To monitor the security posture and technology lifecycle of your registered websites.

  • To run accessibility audits and track compliance over time.

  • To send automated alerts via Slack and other configured channels.

  • To generate reports, health scores, and actions for your hosting portfolio.

  • To authenticate your identity and secure your account.

  • To sync actions and issues with connected project management tools (Jira).

4. Third-Party Services

We use select third-party services to operate BeeKeeper. These providers process data only as necessary to provide their services to us:

  • Google: Authentication and account management via OAuth 2.0.

  • GitHub / GitLab: Read-only repository access for dependency scanning.

  • Slack: Delivery of notifications and alerts to your workspace.

  • Jira (Atlassian): Issue synchronisation when you enable the integration.

  • OSV.dev: Vulnerability database queries for known CVEs.

  • endoflife.date: Technology version and end-of-life status data.

We do not sell, rent, or share your personal data with third parties for marketing purposes.

5. Data Security

We implement industry-standard security measures to protect your data, including encryption in transit (TLS) and at rest, encrypted credential storage, secure authentication flows, and regular security assessments. Access to production data is restricted to authorised personnel only. All integration tokens are stored using AES-256-GCM encryption.

6. Data Retention

We retain your account data for as long as your account is active. Website monitoring data is retained for the duration of your subscription. If you delete your account or request data removal, we will remove your personal data within 30 days, except where we are required by law to retain it.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • The right to access the personal data we hold about you.

  • The right to correct inaccurate or incomplete data.

  • The right to request deletion of your data.

  • The right to data portability.

  • The right to object to or restrict processing.

To exercise any of these rights, contact us using the details below.

8. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact the Hive IT team at [email protected] or through our internal support channels.

This policy may be updated from time to time. We will notify you of significant changes through the platform or via email.