NoteBeeZField intelligence for better beekeeping

NoteBeeZ Privacy Policy

Effective date: 4 September 2026
Version: 2026-09-04

This Privacy Policy explains how personal data is handled when you use the NoteBeeZ Android application, its Cloudflare-hosted backend, and the related public pages at https://notebeez.badluckstudios.com (together, the Service).

1. Controller and contact

For account administration, security, subscription verification, support, and operation of the Service, the controller is:

Bad Luck Studios e.U.
Feßtgasse 10/24
1160 Wien
Austria
Commercial register number: FN 683233f
Commercial register court: Handelsgericht Wien
Email: notebeez@badluckstudios.com

Privacy requests may be sent to the email address above.

An organization using NoteBeeZ for its business may determine why and how its beekeeping, personnel, and operational data is used. For that organization-controlled content, the organization may be a separate controller and Bad Luck Studios e.U. may act as its processor. Members should first address workplace-data questions to their organization owner or employer. Bad Luck Studios e.U. remains responsible for its own controller activities described above.

2. Scope and important distinction between device and cloud data

NoteBeeZ is free to download and may show its interface as a read-only preview, but ordinary additive diary use requires a registered account, an active organization membership, and an active server-confirmed organization entitlement. The entitlement is required to create or make non-deletion edits, import or restore, upload or synchronize new/non-deletion-updated content, change organization settings, expand team/assignment access, use AI or analytics, create or rotate QR access, or connect/select/synchronize Google Calendar. Subject to authentication, role, scope, and safety checks, existing supported records remain readable and exportable after entitlement ends. The controls that remain available are safety reporting/moderation; deletion of an authorized photo or voice draft; confirmed deletion of local-diary data, an account, or an organization; moderation removal; pending-invitation revocation, member suspension/removal/permission reduction, and assignment revocation; QR-request denial/read resolution; Calendar disconnect/task unsync; and acceptance of the server version when discarding a sync conflict. Historical records remain correction-first rather than generally deletable from the app.

"Local-first" describes how an authorized diary operation may be stored on the Android device first, remain usable during a temporary loss of network connectivity, and synchronize through the Cloudflare backend later. It does not describe a free, accountless, device-only diary. Legacy device records from an earlier app state or data that has already been synchronized may remain locally until the device user migrates or deletes it, clears app storage, or uninstalls the app.

The Android app disables Android system backup for its private application data. Device-cached data nevertheless remains under the control of the device user and may exist in user-created export or backup files. Deleting a cloud account does not remotely erase local copies, exported files, another member's device, Google Calendar events, or backups held outside the Service.

3. Data we process

Depending on the features you choose, we process the following categories:

Please do not enter personal data about another person unless you are authorized to do so. NoteBeeZ is not intended for human medical records or special-category personal data. Beekeeping observations about animal health are not a substitute for professional veterinary records or legally required registers.

4. Sources of data

We receive data directly from you, from authorized members of your organization, from your Android device during synchronization or an explicitly confirmed AI or private-workspace safety report, from Google when you use Google Sign-In, Calendar, or Play Billing, and from OpenAI only as the response to an AI request that you initiated through our Cloudflare Worker.

5. Purposes and legal bases

We process personal data only where a legal basis applies:

If your employer or organization is the controller of organization content, it is responsible for selecting and communicating its legal basis, including any workplace monitoring or employment-law requirements. Because consent is often not freely given in an employment relationship, an organization should not rely on employee consent without legal review.

6. Optional permissions and connected services

7. Recipients and processors

We do not sell or rent personal data. We do not use diary content for advertising and the app contains no advertising SDK or third-party analytics SDK by default. Data is disclosed only as needed to operate requested features, comply with law, protect rights and security, or complete a business transfer subject to appropriate safeguards.

The principal service providers are:

Each provider processes data under its own terms and data-protection commitments. Their current policies should be reviewed as part of production release and vendor management. We may also disclose the minimum necessary information to professional advisers, courts, authorities, or law enforcement when legally required or necessary to establish, exercise, or defend legal claims.

8. International transfers

Cloudflare, Google, or OpenAI may process data outside Austria or the European Economic Area. Where Chapter V GDPR applies, transfers are to be covered by an applicable adequacy decision, the EU Standard Contractual Clauses with supplementary measures where required, or another lawful transfer mechanism. Provider infrastructure and legal terms can change, so the production controller must keep transfer assessments and processing agreements current.

9. Retention

Our production retention periods are:

Scheduled deletion is not instantaneous in distributed systems. Short backup, cache, provider, or disaster-recovery remnants may persist until overwritten under the relevant provider cycle, isolated from ordinary use. Data may be held longer only where necessary to comply with law, preserve evidence of a security incident, resolve a payment or deletion failure, or establish, exercise, or defend legal claims. Access is restricted during such a hold.

10. Security

We use HTTPS, tenant and role checks, assignment-scoped authorization, rotating and revocable sessions, hashed one-time and QR tokens, a deployment-secret verifier and rate limits for the narrowly assigned reviewer or support password, Android Keystore protection for app credentials, server-side encryption for Google and Play tokens, private R2 buckets, request-size limits, idempotency and report rate-limit controls, immutable core report evidence, reviewer conflict checks, and logs designed to exclude request bodies, diary content, credentials, email addresses, transcripts, safety-report bodies, reporter identities, and raw provider responses.

No service is perfectly secure. Users must protect their device and email or Google account, and an authorized reviewer or support recipient must also protect any assigned credential. Keep the app updated, use only intended invitation recipients, and report suspected unauthorized access promptly.

11. Organization members and workplace transparency

An organization owner controls invitations, roles, scope assignments, subscription, organization-wide export, and organization deletion. Authorized owners or managers may see activity history and work content within their scope. NoteBeeZ is not designed for covert employee surveillance, continuous location tracking, contact-book collection, or background microphone recording.

An AI safety report is not placed in the organization's ordinary activity feed or owner export, because exposing the reporter through those operational tools could discourage safety reporting or create workplace retaliation risk. The report remains available to appropriately authorized Bad Luck Studios personnel for safety review and to the reporting person through an authenticated data-subject request where legally required. An organization export still contains the underlying organization AI job/output under the ordinary content rules, but not the separate report row.

A private-workspace safety report is likewise excluded from ordinary activity and organization export. An owner or administrator reviewing it in the app sees the existing target, reason, status, and age, but not reporter identity. The reviewer must not try to identify or retaliate against a reporter. Core submission evidence cannot be rewritten; only bounded review status and outcome fields can change, and a terminal outcome cannot be reopened. The report remains available to appropriately authorized Bad Luck Studios personnel for abuse prevention, exceptional conflict review, security, legal obligations, and authenticated rights requests. The underlying organization content remains independently visible or exportable under its ordinary authorization and retention rules until it is deleted.

An employer or organization using NoteBeeZ must provide members with its own privacy information, use proportionate permissions, establish a lawful basis, honor labor and works-council rules, avoid entering unnecessary personal information, and respond to requests concerning organization-controlled data. Bad Luck Studios e.U. cannot determine those purposes for the organization.

12. Automated processing

NoteBeeZ produces heuristic risk flags, operational indices, summaries, and AI suggestions. These may be inaccurate and do not create legal or similarly significant decisions about a person. The Service does not use personal data for solely automated employment decisions, credit decisions, insurance decisions, biometric identification, or advertising profiles. Users must review AI drafts before saving them and must apply professional judgment before acting.

13. Your GDPR rights

Subject to the conditions and exceptions in applicable law, you may request:

You may access, correct, export, or delete much of your data directly in the app. AI and private-workspace safety reports are deliberately excluded from an organization owner's operational export; a reporting person can request access to their report through the address below. A report subject may also ask about applicable processing, but access may be limited where disclosure would adversely affect another person's rights, confidentiality, security, or abuse-prevention measures. Send requests to notebeez@badluckstudios.com. We may request proportionate identity verification. We generally respond within one month; that period may be extended by up to two further months for complex or numerous requests as permitted by Article 12 GDPR.

Organization-controlled data may require coordination with the organization that acts as controller. A request does not override another person's rights, legal retention, ownership of organization records, or the need to preserve evidence of a valid transaction or security event.

You also have the right to complain to a supervisory authority, in particular in the EEA state of your habitual residence, workplace, or alleged infringement. In Austria:

Österreichische Datenschutzbehörde
Barichgasse 40-42
1030 Wien
Austria
https://www.dsb.gv.at

14. Children

The Service is intended for adults carrying out personal or professional beekeeping operations and is not directed to children. You must be at least 18 years old to create a cloud account or purchase a subscription. Do not submit a child's personal data through diary notes or media.

15. Changes

We may update this Policy when the Service, providers, law, or retention practices change. A new effective date and version will be shown. Material changes will be presented in the app or otherwise communicated where required. If acceptance is legally or contractually required, cloud use will pause until the current documents are reviewed.

16. Official legal references

This Policy is designed around the information duties in Articles 12 to 14 and the rights in Articles 15 to 22 of the EU General Data Protection Regulation. Information about Austrian data-subject rights and complaints is available from the Austrian Data Protection Authority.

This document is a product-specific disclosure, not legal advice. Bad Luck Studios e.U. should have qualified Austrian/EU counsel confirm the final production configuration, controller/processor allocation, international-transfer safeguards, employment use, and translations before launch.