Privacy Policy
Introduction
At My-Beacon, we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains what data we collect, how we use it, and your rights under GDPR.
What Data We Collect
- Contact Information (email, mobile number) - Encrypted or Hashed for security - even we cannot access them.
- Beacon Access Data - Only stored in encrypted form.
- Usage Data - Basic analytics to improve the service (no personal tracking).
How We Use Your Data
- To provide secure access to your Beacon.
- To notify authorised users when access to a Beacon is requested.
- To notify authorised users when access to a Beacon is granted.
- To notify users when they have been added to a Beacon.
- To improve the service and troubleshoot issues.
Data Security
- All stored contact details are encrypted or hashed, so even we cannot access them.
- No third-party data sharing - We never sell or share your data with third parties.
- Data is processed securely and the Beacon is only displayed over a secure connection.
- Data is never transferred outside our infrastructure boundary, which includes all servers, cloud environments, and hosting providers under our direct control, except for secure backup purposes. Any such backups are encrypted at rest and in transit in accordance with industry standards to ensure data protection and regulatory compliance.
GDPR Compliance
Under GDPR, users in the UK and EU have specific rights regarding their personal data:
GDPR Right What It Means
- Right to Access - Request a copy of the personal data we store about you.
- Right to Rectification - Request corrections to incorrect or incomplete data.
- Right to Erasure (“Right to be Forgotten”) - Request deletion of your personal data.
- Right to Restrict Processing - Request limited processing of your data.
- Right to Data Portability - Request your data in a machine-readable format.
- Right to Object - Opt out of processing for direct marketing or legitimate interest.
To exercise these rights, contact us with the subject line "GDPR Data Request".
Data Retention Policy
- Encrypted contact details are retained for as long as the Beacon is enabled + a 4 week reactivation window.
- Disabled Beacons will be automatically deleted after 4 weeks.
- You can request a Beacon deletion at any time.
Emergency Service Access Disclaimer
- Emergency service access is a convenience feature and does not guarantee entry.
- We are not responsible for delays, failures, or miscommunications related to emergency access.
Third-Party Services & Data Transfers
- Our servers are located in the EU.
- We do not transfer data outside of the UK/EU.
- If we use external services, they are GDPR-compliant and listed here: Stripe, AWS, IONOS.
Changes to This Privacy Policy
We may update this Privacy Policy. If significant changes occur, we will notify users.
Contact Us
For GDPR-related requests or privacy concerns, please contact us.