BeyondCore Master Data Quality
PrivacyCookies & storageTermsSecuritySub-processors

Privacy Policy

Last updated: 10 September 2026

This policy explains what personal data BeyondCore handles, why, and what you can do about it. It is written to be read, not to be survived.

BeyondCore is operated by BeyondCore, Org.nr 559155-2129, Sweden ("BeyondCore", "we"). Questions or requests: the contact form.


1. Two different roles — and why it matters

Almost everything below turns on which of these two situations you are in.

Who decides what happens to the dataWho we areGoverned by
Your account — signing up, signing in, being emailed, contacting usBeyondCoreControllerThis policy
The master data you assess — your supplier, customer or material extractYour organisationProcessor, acting on your instructionsOur DPA

So: we decide how your account works, and this policy covers that. We do not decide anything about the master data you upload — your organisation does, and we only act on its instructions under a data processing agreement.

2. The master data you assess

This is the part most people care about, so it comes first.

finding per problem — each holding the record identifier from your own system and a short evidence snippet that justifies the finding.

is structure, not content — your naming convention, not your records.

and no AI provider is involved — only the deterministic rule checks run.

Where the AI engine is used, only a fixed allowlist of non-identifying fields is sent to the AI provider. VAT and tax numbers, email addresses, phone numbers, bank and IBAN details, credit limits and payment terms are deliberately withheld. See Security for the full list.

3. Account and website data we hold as controller

WhatWhyLegal basis (GDPR Art. 6)How long
Name of your organisation, your email address, password hash, roleTo create and run your accountArt. 6(1)(b) — performance of a contractWhile the account exists, then deleted within 90 days
Sign-in timestampsSecurity, and so an owner can see who is activeArt. 6(1)(f) — legitimate interest in securing the service12 months
Emails we send you (confirmation, password reset, invitations) and their delivery statusTo operate the account and to support you when something does not arriveArt. 6(1)(b) and 6(1)(f)24 months
Messages you send through the contact formTo answer youArt. 6(1)(f) — legitimate interest in responding to enquiries24 months
Assessment history (scores, findings, decisions)The product itself — tracking quality over timeArt. 6(1)(b)While the account exists, or until you delete it
Server logs (IP address, request path, timestamp)Security, abuse prevention, debuggingArt. 6(1)(f)Short-lived, retained by our hosting provider

We do not use your data to train AI models, sell it, share it for advertising, or profile you. There is no automated decision-making with legal effects under Art. 22.

4. Cookies and browser storage

We set no cookies at all, and there are no analytics, advertising or third-party scripts on any page. The application stores a few items in your browser's local storage, all strictly necessary or a plain preference. See the Cookies & storage page — it lists each item, shows what is in your browser right now, and lets you clear it.

5. Who else processes data for us

Our sub-processors are published and kept current at /legal/subprocessors. In short: hosting and the database run on Fly.io in the EU (Frankfurt); transactional email goes through Resend; the optional AI engine uses Anthropic, receiving only the allowlisted non-identifying fields described above, configured for no training and no retention.

International transfers. Everything is processed in the EU by default. Where a sub-processor processes data outside the EEA (today: the AI provider), the transfer is covered by the EU Standard Contractual Clauses and is limited to the allowlisted fields. Customers who need no non-EEA processing at all can run BeyondCore in their own cloud or on-premise with their own AI provider.

6. Security

Encryption in transit; access controls and per-organisation isolation, so one customer can never reach another's data; passwords stored only as PBKDF2 hashes; optional single sign-on; and the data minimisation described in section 2, which is the strongest protection of all — data we never keep cannot be breached. Details on the Security page.

7. Your rights

Under the GDPR you may request access, rectification, erasure, restriction, portability, and you may object to processing based on legitimate interest. You can also withdraw consent where processing rests on consent, without affecting what happened before.

Contact us through the contact form and we will respond within one month. If you are an employee of a customer and your request concerns the master data your employer uploaded, we will refer you to that employer — they are the controller for it, and we may only act on their instructions.

If you believe we have handled your data wrongly you may complain to the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY), imy.se, or to the authority in your own country.

8. Children

BeyondCore is a business tool and is not directed at children. We do not knowingly collect data about anyone under 16.

9. Changes

We will update this page when the service changes, and update the date at the top. If a change materially affects how we handle your personal data, we will tell account owners by email before it takes effect.


This policy describes the service as built. It is not legal advice; if you are a customer relying on it for your own compliance work, read it alongside our DPA and sub-processor list.