Privacy Policy
Last updated: 10 September 2026
This policy explains what personal data BeyondCore handles, why, and what you can do about it. It is written to be read, not to be survived.
BeyondCore is operated by BeyondCore, Org.nr 559155-2129, Sweden ("BeyondCore", "we"). Questions or requests: the contact form.
1. Two different roles — and why it matters
Almost everything below turns on which of these two situations you are in.
| Who decides what happens to the data | Who we are | Governed by | |
|---|---|---|---|
| Your account — signing up, signing in, being emailed, contacting us | BeyondCore | Controller | This policy |
| The master data you assess — your supplier, customer or material extract | Your organisation | Processor, acting on your instructions | Our DPA |
So: we decide how your account works, and this policy covers that. We do not decide anything about the master data you upload — your organisation does, and we only act on its instructions under a data processing agreement.
2. The master data you assess
This is the part most people care about, so it comes first.
- Your extract is processed in memory and discarded when the request ends. We do not store it.
- What we keep is the assessment result: scores, counts, a plain-language summary, and one
finding per problem — each holding the record identifier from your own system and a short evidence snippet that justifies the finding.
- We also keep the column mapping (which of your column names corresponds to which field). That
is structure, not content — your naming convention, not your records.
- We never keep a record that had no finding. A clean record leaves no trace at all.
- If you use the free Sandbox on the public page without signing in, nothing is stored at all,
and no AI provider is involved — only the deterministic rule checks run.
Where the AI engine is used, only a fixed allowlist of non-identifying fields is sent to the AI provider. VAT and tax numbers, email addresses, phone numbers, bank and IBAN details, credit limits and payment terms are deliberately withheld. See Security for the full list.
3. Account and website data we hold as controller
| What | Why | Legal basis (GDPR Art. 6) | How long |
|---|---|---|---|
| Name of your organisation, your email address, password hash, role | To create and run your account | Art. 6(1)(b) — performance of a contract | While the account exists, then deleted within 90 days |
| Sign-in timestamps | Security, and so an owner can see who is active | Art. 6(1)(f) — legitimate interest in securing the service | 12 months |
| Emails we send you (confirmation, password reset, invitations) and their delivery status | To operate the account and to support you when something does not arrive | Art. 6(1)(b) and 6(1)(f) | 24 months |
| Messages you send through the contact form | To answer you | Art. 6(1)(f) — legitimate interest in responding to enquiries | 24 months |
| Assessment history (scores, findings, decisions) | The product itself — tracking quality over time | Art. 6(1)(b) | While the account exists, or until you delete it |
| Server logs (IP address, request path, timestamp) | Security, abuse prevention, debugging | Art. 6(1)(f) | Short-lived, retained by our hosting provider |
We do not use your data to train AI models, sell it, share it for advertising, or profile you. There is no automated decision-making with legal effects under Art. 22.
4. Cookies and browser storage
We set no cookies at all, and there are no analytics, advertising or third-party scripts on any page. The application stores a few items in your browser's local storage, all strictly necessary or a plain preference. See the Cookies & storage page — it lists each item, shows what is in your browser right now, and lets you clear it.
5. Who else processes data for us
Our sub-processors are published and kept current at /legal/subprocessors. In short: hosting and the database run on Fly.io in the EU (Frankfurt); transactional email goes through Resend; the optional AI engine uses Anthropic, receiving only the allowlisted non-identifying fields described above, configured for no training and no retention.
International transfers. Everything is processed in the EU by default. Where a sub-processor processes data outside the EEA (today: the AI provider), the transfer is covered by the EU Standard Contractual Clauses and is limited to the allowlisted fields. Customers who need no non-EEA processing at all can run BeyondCore in their own cloud or on-premise with their own AI provider.
6. Security
Encryption in transit; access controls and per-organisation isolation, so one customer can never reach another's data; passwords stored only as PBKDF2 hashes; optional single sign-on; and the data minimisation described in section 2, which is the strongest protection of all — data we never keep cannot be breached. Details on the Security page.
7. Your rights
Under the GDPR you may request access, rectification, erasure, restriction, portability, and you may object to processing based on legitimate interest. You can also withdraw consent where processing rests on consent, without affecting what happened before.
Contact us through the contact form and we will respond within one month. If you are an employee of a customer and your request concerns the master data your employer uploaded, we will refer you to that employer — they are the controller for it, and we may only act on their instructions.
If you believe we have handled your data wrongly you may complain to the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY), imy.se, or to the authority in your own country.
8. Children
BeyondCore is a business tool and is not directed at children. We do not knowingly collect data about anyone under 16.
9. Changes
We will update this page when the service changes, and update the date at the top. If a change materially affects how we handle your personal data, we will tell account owners by email before it takes effect.
This policy describes the service as built. It is not legal advice; if you are a customer relying on it for your own compliance work, read it alongside our DPA and sub-processor list.