Privacy Policy
Last updated:
This Privacy Policy explains how Generation Beta Digital Limited (trading as BetaOffice — “we”, “us”, “our”) collects, uses, discloses and protects personal data when you use our products and services at betaoffice.uk (the “Services”), including optional integrations with supported third-party services.
1) Who we are (Data Controller)
The data controller is Generation Beta Digital Limited (trading as BetaOffice).
- Registered office: 3rd Floor, 86–90 Paul Street, London EC2A 4NE, UK
- Company No: 16274319 • ICO Registration: ZB883806
- Email: privacy@betaoffice.uk
2) Data we collect
We may collect the following categories of data, depending on how you use the Services:
- Identity & Contact: name, email, phone, date of birth, address and identity/KYC information or documents.
- Company: company name, registration number, address, directors and beneficial owners.
- Service Data: virtual office preferences, forwarding options, scanned mail metadata, referral codes, custom slugs and wallet transactions.
- Subscription & Cancellation Data: subscription status, service and billing dates, renewal cut-off, cancellation request date, cancellation reason, optional cancellation notes, expected final-payment date and cancellation-effective date.
- Scanned Mail Metadata: information used to organise, search and display your business mail, which may include sender, document title, dates, categories, summaries, extracted key information, processing status, envelope images and secure document references or links.
- Payments: payments are processed through our payment provider. We do not store full payment card details.
- Technical: IP address, device/browser information, timestamps, event logs and site/app interactions.
- Marketing & Communications: communication preferences and referral or campaign attribution.
- Integration Data: where you choose to connect BetaOffice to a supported third-party service, we may process authorisation information, granted permissions, connection status and technical information required to establish, secure and maintain that connection.
- Optional partner services: information required to facilitate an optional partner service that you actively choose, such as an eligible business account referral.
- Physical mail (unforwarded): physical mail may be securely held for up to 30 days after receipt and then confidentially destroyed in accordance with the applicable service policy. Once destroyed, it cannot be recovered or forwarded.
We collect data directly from you, from service providers and integrations used to deliver the Services, and from public sources such as Companies House where relevant.
3) How we use data & lawful bases
We process personal data for the following purposes and lawful bases, as applicable:
- Provide & manage the Services — including account setup, virtual office services, mail handling and the customer dashboard. Basis: contract necessity.
- KYC/AML & compliance — including identity verification, fraud prevention and regulatory compliance. Basis: legal obligation and, where applicable, legitimate interests.
- Payments, billing & cancellations — including subscriptions, renewal timing, final payments, cancellation scheduling, top-ups and withdrawals. Basis: contract necessity, legal obligation and legitimate interests in maintaining accurate records and resolving disputes.
- Scanned Mail processing — including display, search, organisation, summaries and AI-assisted metadata extraction. Basis: contract necessity and legitimate interests in providing an efficient digital mail service.
- User-authorised integrations — to establish and operate optional connections between your BetaOffice account and supported third-party services at your request. Basis: contract necessity where required to provide the feature you request and legitimate interests in providing interoperable account features.
- Referral Program — including click tracking, verified signups, rewards and wallet ledger administration. Basis: contract necessity and legitimate interests, including fraud prevention.
- Support & service communications — including support requests, incidents and service updates. Basis: contract necessity and legitimate interests.
- Product improvement & security — including analytics, logs, abuse prevention and anti-bot controls. Basis: legitimate interests.
- Marketing (optional) — newsletters and promotions where permitted. Basis: consent or another lawful basis where applicable. You may opt out at any time.
5) AI & third-party integrations
BetaOffice may allow you to connect your account to supported third-party services, including AI assistants such as ChatGPT. These integrations are optional and are not enabled automatically. You must explicitly choose to connect and authorise your BetaOffice account.
- Information made accessible: depending on the permissions you authorise and the features you use, the third-party service may access information such as your authorised companies and digital mail information, including senders, document titles, dates, categories, summaries and extracted key information.
- Access controls: BetaOffice integrations are designed to restrict access to companies and mail that the authenticated BetaOffice account is authorised to access.
- Read-only integrations: where an integration is described as read-only, the integration does not provide tools to forward or delete physical mail, cancel subscriptions, make payments, change billing information or perform other account-changing actions.
- Authorisation: supported integrations may use secure authorisation mechanisms such as OAuth. BetaOffice does not provide your BetaOffice login credentials to the connected third-party service.
- Third-party processing: once information is requested by and disclosed to a third-party service that you have chosen to connect, that service may process the information under its own privacy policy, terms and account settings. You should review the third party's policies before connecting.
- Your choice: third-party integrations are optional. You may continue using BetaOffice without connecting an external AI or third-party service.
- Permissions: the permissions requested by an integration will be limited to the capabilities made available by BetaOffice and, where applicable, presented during the connection or authorisation process.
We may add, modify or discontinue supported integrations over time. An integration does not gain broader access to your BetaOffice account merely because it has been connected; access is subject to the permissions and access controls applicable to that integration.
6) International transfers
Where personal data is transferred outside the UK or EEA, we use appropriate safeguards where required by applicable data protection law. These may include adequacy regulations, the UK International Data Transfer Agreement or Addendum, EU Standard Contractual Clauses, and appropriate technical and organisational measures.
If you choose to connect BetaOffice to a third-party service, that provider may process information in other countries in accordance with its own privacy policy and applicable data-transfer safeguards.
7) Data retention
- Account & KYC records: retained for the life of the account and for any additional period required by applicable legal, regulatory, fraud-prevention or compliance obligations.
- Physical mail: retained by our trusted mail handling provider for up to 30 days from receipt unless collected or forwarded, after which it may be securely and confidentially destroyed in accordance with the applicable operational policy.
- Digital mail metadata: retained for as long as reasonably necessary to provide the Services, support your account and comply with applicable legal obligations.
- Digital mail documents: BetaOffice does not permanently store scanned mail documents on its own systems. Digital mail scans may remain with our trusted mail handling provider in accordance with the provider's applicable retention arrangements.
- Integration authorisation records: connection, permission and security records may be retained for as long as reasonably necessary to operate the integration, protect accounts, investigate abuse and meet legal obligations.
- Wallet & referral ledger: typically 6 years where required for tax, accounting or legal purposes.
- Billing and cancellation records: typically 6 years after the relevant transaction or end of the customer relationship where required for accounting, contractual, fraud-prevention or legal-claims purposes.
- Support & communications: typically up to 3 years after ticket closure unless a longer period is reasonably necessary or legally required.
- Marketing data: until you withdraw consent, unsubscribe or object, subject to any limited suppression record we may need to retain to honour your preference.
8) Security
We use technical and organisational measures designed to protect personal data, including encryption in transit, access controls, authentication, role-based permissions, logging and other security measures appropriate to the Services.
Access to personal data is restricted to authorised users, personnel and service providers where access is necessary for their role or service. No internet-based service can guarantee absolute security, but we regularly review and improve our security controls.
9) Your rights
Subject to applicable conditions and exemptions under UK or EU data protection law, you may have the right to:
- Access personal data we hold about you
- Correct inaccurate or incomplete personal data
- Request erasure of personal data in applicable circumstances
- Restrict or object to certain processing
- Request data portability where applicable
- Withdraw consent where processing is based on consent
- Lodge a complaint with a competent supervisory authority, including the ICO in the UK
To exercise your rights, email privacy@betaoffice.uk. We aim to respond within the period required by applicable law.
UK Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint/
11) Special categories of personal data
We do not intentionally collect special category personal data unless it is necessary for a particular lawful purpose, such as identity verification, or you provide it voluntarily in circumstances where its processing is lawful. Where required, we apply an appropriate legal condition and additional safeguards.
12) Automated decision-making
BetaOffice does not ordinarily make decisions that produce legal or similarly significant effects on customers solely by automated means. We may use automated systems to assist with security, fraud detection, abuse prevention, document understanding, categorisation and other service features.
AI-generated summaries, classifications and extracted information are provided to assist with organisation and understanding of business mail and may contain errors. Where a document is important, you should refer to the original correspondence and, where appropriate, obtain professional advice.
13) Children’s data
Our Services are not intended for children. We do not knowingly collect personal data from users under the age required to use the Services under applicable law. If you believe personal data about a child has been provided to us improperly, please contact us.
14) Changes to this Policy
We may update this Privacy Policy to reflect legal, regulatory, technical or business changes, including changes to supported integrations. We will publish the current version on this page and update the “Last updated” date. Where appropriate, material changes may also be communicated by email or through the Services.
15) Contact us
Generation Beta Digital Limited3rd Floor, 86–90 Paul Street, London EC2A 4NE, UK
Email: privacy@betaoffice.uk