Privacy Policy

besideU Ltd Last updated: May 2026 UK GDPR compliant

Plain English summary: besideU collects only what it needs to provide the platform. We never sell your data, never use it to train external AI models, and always treat bereavement-related information with the highest level of sensitivity. This policy explains exactly what we collect, why, and what your rights are.

1. Who we are

besideU Ltd is a company registered in England and Wales. We operate the besideU platform — an AI-powered workplace bereavement platform that helps organisations support employees through bereavement and loss.

Company name: besideU Ltd

Registered in: England and Wales

Email: [email protected]

Website: besideu.ai

ICO Registration Number: ZC137733

For all data protection queries, please contact us at [email protected] with the subject line "Data Protection Enquiry".

2. What data we collect and why

We collect different types of data depending on who you are and how you use besideU.

2.1 Data collected from organisations (our clients)

Data typeWhy we collect itLawful basis
Organisation name and contact detailsTo set up and manage your accountContract performance
HR lead name and email addressTo provide platform access and supportContract performance
Bereavement policy documentsTo configure Maeve with your organisation's specific policyContract performance
Billing informationTo process your subscription paymentContract performance

2.2 Data collected from platform users (managers, HR, employees)

Data typeWhy we collect itLawful basis
Name and work email addressTo create and manage platform accountsLegitimate interests / contract
Job title and reporting structureTo assign correct platform access levelLegitimate interests
Bereavement case information (relationship to deceased, dates, leave taken)To enable case tracking, touchpoint scheduling, and appropriate guidanceLegitimate interests of the organisation with employee consent where required
Maeve conversation contentTo provide AI guidance and, where enabled, to improve response quality within your organisation onlyLegitimate interests / consent
Touchpoint logs and completion recordsTo enable HR oversight and ensure no employee is overlookedLegitimate interests
Platform usage dataTo improve the platform and provide reportingLegitimate interests

2.3 Data collected from website visitors

Data typeWhy we collect itLawful basis
IP address and browser informationSecurity, analytics, and fraud preventionLegitimate interests
Pages visited and time on siteTo understand how people use our websiteLegitimate interests / consent
Contact form submissionsTo respond to enquiriesConsent

3. Sensitive data

Bereavement information — including the nature of a loss, relationship to the deceased, and the emotional state of an employee — is treated by besideU as sensitive personal data, even where it does not technically fall under the UK GDPR special categories.

Our commitment: We apply the highest level of care to any data connected to bereavement. We do not share it beyond what is necessary to deliver the platform service, we do not use it for marketing, and we do not use it to train external AI models.

Where data does fall under UK GDPR special categories — for example health information relating to grief-related illness — we rely on explicit consent or substantial public interest as our lawful basis for processing.

4. How we use AI (Maeve)

Maeve is besideU's AI guidance assistant. She processes information shared during platform interactions to generate contextual guidance for managers, HR teams, and employees.

For full details of how we use AI responsibly, please see our AI Ethics Policy.

5. Who we share data with

We do not sell personal data. We share data only where necessary to deliver the platform, and only with parties who are contractually bound to protect it.

RecipientPurposeLocation
Cloud hosting providerTo host and run the besideU platformUK / EEA
AI infrastructure providerTo power Maeve's guidance capabilitiesUK / EEA (contractually restricted)
Payment processorTo process subscription paymentsUK / EEA
Email service providerTo send platform notifications and system emailsUK / EEA

All third-party processors are subject to data processing agreements that meet UK GDPR requirements. No data is transferred outside the UK or EEA without appropriate safeguards in place.

6. How long we keep your data

Data typeRetention period
Active platform user dataFor the duration of your organisation's subscription
Bereavement case recordsUp to 3 years after case closure, unless your organisation requests earlier deletion
Maeve conversation logs (where retained)90 days by default, unless otherwise agreed
Billing records7 years (UK legal requirement)
Website enquiry data12 months from last contact

On termination of a subscription, we will delete or anonymise all personal data within 30 days unless legally required to retain it, or unless you request a data export first.

7. Your rights under UK GDPR

Under UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data:

To exercise any of these rights, please email [email protected] with the subject line "Data Rights Request". We will respond within one calendar month.

If you are unsatisfied with how we handle your request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

8. Cookies

The besideU website uses a small number of cookies to ensure it functions correctly and to understand how visitors use the site.

Cookie typePurposeConsent required?
Essential cookiesRequired for the website and platform to functionNo
Analytics cookiesTo understand how visitors use the site so we can improve itYes

You can manage cookie preferences at any time through your browser settings. Refusing analytics cookies will not affect your ability to use the site.

9. Security

besideU takes the security of personal data seriously. We implement appropriate technical and organisational measures to protect data against unauthorised access, loss, or disclosure. These include:

In the event of a personal data breach that is likely to result in risk to individuals, we will notify the ICO within 72 hours and affected individuals without undue delay, in accordance with UK GDPR Article 33.

10. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to our platform, legal requirements, or how we operate. When we make significant changes, we will notify active platform users by email and update the "last updated" date at the top of this page.

We encourage you to review this policy periodically.

11. Contact us

If you have any questions about this Privacy Policy or how we handle your personal data, please get in touch.

Email: [email protected]

Subject line: Data Protection Enquiry

ICO Registration: ZC137733

besideU Ltd · Registered in England and Wales