Privacy policy

This policy describes which data is processed when you use befame.io and which rights you have.

1. Controller

The provider named in the legal notice is responsible for data processing. Contact for privacy requests: support@befame.io.

2. Data when visiting the website

When you visit the site, technically necessary data is processed: IP address, time of the request, page requested, browser type and operating system. This processing serves secure operation and is based on legitimate interest.

3. Account and learning progress

For the member area we store your email address, an encrypted password hash and optionally a display name.

We also store which lessons, checklist items and steps you have marked as done. This data is used only for the progress display and is visible only to you.

The legal basis is performance of the user contract.

4. Processors

For hosting, authentication and the database we use service providers who process data only on our instructions. Data processing agreements are in place with them.

Any transfer to third countries takes place only on the basis of appropriate safeguards.

5. Payments

Payments are handled by external payment providers. Payment data is collected and processed by them; we receive only status information to assign your access.

6. Cookies

We use technically necessary cookies or local storage objects for signing in. Logging in is not possible without them.

Non-essential cookies are only set after explicit consent.

7. Retention

Account data is stored until the account is deleted. After that it is removed unless statutory retention duties apply. Server log data is deleted after 30 days at the latest.

8. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interests.

You can withdraw consent at any time with effect for the future. You also have the right to lodge a complaint with a data protection authority.

9. Data security

Transmission is encrypted via TLS. Access to user data is technically limited to each user's own records.

Last updated: August 2026. This document is a template and does not replace legal advice.