Effective date: 17 September 2026
BeeLiked Media Ltd is a company registered in England and Wales under company number 06795071, with registered office at Unit 6 Third Avenue, Team Valley Trading Estate, Gateshead, Tyne and Wear, NE11 0BU, United Kingdom. Our ICO registration number is Z3249632.
In this notice, BeeLiked, we, us and our mean BeeLiked Media Ltd. You can contact us about privacy or make a data-protection complaint at privacy@beeliked.com.
This notice covers personal data for which BeeLiked decides the purposes and means of processing and therefore acts as controller. This includes our public website, sales and customer administration, business contacts, users of the BeeLiked customer platform, our own security and legal-compliance records, and any BeeLiked-operated Promotion that expressly links to this notice.
For a Customer-Operated Promotion, the customer or its disclosed client normally determines why participant data is collected and used. BeeLiked acts as processor or subprocessor and follows the controller’s instructions. The controller’s Promotion privacy notice explains that processing; BeeLiked’s Data Processing Addendum governs our processor obligations.
This notice does not govern use of RunnyHoney. RunnyHoney has a separate RunnyHoney Privacy Policy, together with any Promotion-specific notice or official rules that apply there.
If a Promotion-specific notice conflicts with this general notice, the more specific notice applies to that Promotion, but it cannot change the parties’ legal roles merely by applying a label.
Depending on how you interact with us, we may use:
Please do not provide special-category or criminal-offence data unless the relevant form, Promotion rules or notice expressly requests it and explains why it is needed.
We receive personal data directly from you; from your employer, agency or other organisation; from customers and partners; from your use of our websites and services; from service providers; from professional networks and publicly available business sources; and, for a Promotion, from the applicable entry, verification, reward or fulfilment process.
If we obtain your data indirectly, we provide privacy information within the period required by law unless an exception applies.
| Purpose | Typical data | Lawful basis |
|---|---|---|
| Respond to enquiries, provide demonstrations and take steps towards a contract | Identity, contact, organisation, communications and technical data | Contract steps; legitimate interests in responding to and developing relevant business opportunities |
| Set up and administer customer accounts, subscriptions, billing and support | Identity, contact, account, commercial, billing, communications and security data | Contract; legitimate interests in administering business-customer relationships; legal obligation |
| Secure our services, prevent fraud and misuse, investigate incidents and maintain audit records | Account, technical, usage, security and communications data | Legitimate interests in protecting users, services and business information; legal obligation |
| Operate BeeLiked-operated Promotions where this notice applies, verify eligibility or activity, and administer rewards | Identity, contact, account, entry, activity, eligibility and reward data | Contract where applicable; legitimate interests in operating secure and fair services; consent where required for a particular use; legal obligation |
| Measure and improve our websites, products, communications and customer experience | Technical, usage, account, communications and feedback data | Legitimate interests; consent where required for tracking technologies |
| Send and measure business marketing and manage preferences | Identity, business contact, organisation, interests, communications and engagement data | Legitimate interests for proportionate business marketing; consent where required; legal obligation to honour opt-outs |
| Comply with law, exercise or defend legal rights, handle rights requests and complaints, and support corporate transactions | Relevant data from the categories above | Legal obligation; legitimate interests in compliance, governance and protecting legal rights |
Where we rely on legitimate interests, we consider necessity, proportionality and the impact on individuals. You can object as explained below. We do not treat consent as the default basis for all marketing processing; the applicable basis depends on the purpose and legal context.
Where a field is marked as required, the information is needed to enter into or administer a contract, comply with law, protect an account or service, or determine eligibility for the applicable BeeLiked-operated Promotion. If you do not provide required information, we may be unable to respond to your request, provide the relevant service, create or secure the account, or process the relevant entry or Reward. Other information is optional unless we explain otherwise when it is requested.
When we process personal data solely for a customer-controlled Promotion, the customer or its disclosed client is responsible for the lawful basis, notices, collection choices, participant rights and retention instructions. We use that data only to provide, secure, support and maintain the services, to follow documented instructions, or as law requires. Questions about that Promotion should normally be directed to the controller named in its privacy notice.
Limited account-security, fraud-prevention or legal-compliance records may be controlled separately by BeeLiked only where we genuinely determine that separate purpose and use the data consistently with law. Calling data “telemetry” or changing this notice does not itself reclassify customer-controlled data.
We share personal data only where necessary with:
We do not sell personal data. We do not share identifiable BeeLiked-operated Promotion data with a customer for its independent marketing merely because it sponsored or funded a Promotion; any such sharing must have a valid basis and be clearly explained at collection.
The following table identifies the principal providers currently used for BeeLiked’s own website, customer-platform, sales, support, billing, analytics and business-administration activities. It does not list suppliers that receive no personal data. Processing of customer-controlled Promotion data is governed separately by the customer agreement and DPA.
| Provider | How BeeLiked uses it | Personal data that may be involved | Relevant activity |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, storage, databases, backups, delivery and infrastructure security. | Account, platform, technical, security and, where applicable, customer-controlled data. | Hosting and infrastructure |
| WordPress | Public-website content management and administration. | Website-administrator details and technical or visitor information processed through the public website and its configured integrations. | Website operation |
| GoDaddy | Domain registration and related domain administration. | Business and administrative contact details and domain-account records. | Domain administration |
| Google Workspace | Business email, documents, calendars, meetings and internal collaboration. | Business contact details, communications, meeting information and documents. | Business administration |
| Dropbox | Business file storage, sharing and collaboration. | Business records, documents, account details and personal data contained in files stored or shared for authorised work. | Document management |
| Linear, GitHub and Figma | Product, engineering, source-code, issue-management and design collaboration. | User and collaborator details, technical records and limited customer, support or example content where needed for authorised product work. | Product development |
| LastPass | Workforce password and credential management. | Authorised-user details, account metadata and encrypted credential records. | Access security |
| Sprinto | Security and compliance management, evidence collection and vendor oversight. | Workforce and vendor contact details, device or account compliance information, control evidence and security records. | Security and compliance |
| HubSpot | CRM, sales and customer communications, website forms or chat, and marketing measurement. | Business identity and contact details, organisation, enquiries, communications, preferences and engagement data. | Sales, support and marketing |
| Fillout | Contact, enquiry and demonstration-request forms. | Name, business contact details, organisation, requested information and form responses. | Website enquiries |
| Mandrill by Mailchimp | Sending transactional and service emails. | Recipient name and email address, delivery and engagement metadata and the content of the applicable service message. | Service communications |
| PostHog | Website and product analytics, feature-use measurement, diagnostics and, where enabled, session replay. | Device, browser, IP-derived location, identifiers, page or feature usage, events and account-linked usage where configured. | Analytics and product improvement |
| Google Analytics, Google Ads and Google Tag Manager | Website measurement, tag management, conversion measurement and advertising. | Device, browser, identifiers, pages, interactions, referrals and campaign or conversion data. | Analytics and marketing |
| LinkedIn, LinkedIn Sales Navigator and Meta | B2B prospecting and outreach, audience and advertising measurement, subject to applicable consent controls. | Business profile or contact information, device and browser data, interactions, campaign and conversion data. | Sales and advertising |
| Clearbit (HubSpot) | Business-visitor identification or enrichment where the relevant tag is operational and permitted. | Business-domain, organisation, device, browser, visit and enrichment data. | B2B sales intelligence |
| FirstPromoter | Referral and affiliate attribution. | Referral identifiers, device or browser information, visits, sign-ups and attributable conversion data. | Referral management |
| Zapier | Automating configured workflows between business systems. | The contact, account, enquiry, support or operational information required by the particular authorised workflow. | Workflow automation |
| OneTrust | Cookie notices, preference management and consent records on the public website. | Consent choices, timestamps, device or browser information and consent identifiers. | Consent management |
| Crisp | Customer-platform support messaging. | Account or contact details, support conversations and related technical information. | Customer support |
| Sentry and Pingdom | Error, availability and performance monitoring. | Technical logs, IP address, device or browser information, page or feature context and diagnostic events. | Reliability and security |
| Wistia | Hosting and measuring videos embedded in BeeLiked websites or services. | Device, browser, viewing, interaction and referral information. | Embedded media and analytics |
| Tremendous or another selected reward provider | Reward delivery or redemption where an applicable service or Promotion is configured to use that provider. | Recipient identity and contact details, reward allocation, delivery and redemption information required for fulfilment. | Conditional reward fulfilment |
| Stripe | Payment collection, payment-method tokenisation, invoices and transaction administration. | Billing contact information, billing address, payment status, transaction and Stripe customer references. BeeLiked does not receive complete card details. | Payments and billing |
| DocuSign | Electronic execution and administration of contracts and related documents. | Signatory identity and contact details, signature, document content and execution audit records. | Contract administration |
| Xero | Accounting, invoicing and financial records. | Customer or supplier identity, business contact, invoice, payment and transaction information. | Accounting |
| Slack | Internal operational communication and collaboration. | Business communications and limited customer, support or incident information where needed for the relevant work. | Internal operations |
Some providers act only on BeeLiked’s instructions. Others, such as payment, advertising or professional-service providers, may also act as independent controllers for specified activities. Their own privacy information explains that separate processing. We review this table when a provider or its purpose changes materially.
Some recipients may process personal data outside the United Kingdom or European Economic Area. Where required, we use an applicable adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, EU Standard Contractual Clauses or another lawful safeguard, together with supplementary measures where appropriate.
The customer DPA governs restricted transfers of customer-controlled personal data. For BeeLiked’s controller processing, contact us for information about the applicable safeguard.
We keep personal data only for as long as reasonably necessary for the purpose collected, including service delivery, security, fraud prevention, complaint handling, legal claims, accounting and regulatory requirements. We consider the data’s nature and sensitivity, risk, the relationship or Promotion lifecycle, applicable limitation periods and whether the purpose can be achieved with less or anonymised data.
We use technical and organisational measures designed to protect personal data against accidental or unlawful loss, alteration, disclosure, access or destruction. Measures are selected according to risk and include appropriate access control, authentication, encryption, monitoring, incident response, personnel confidentiality, vendor oversight and continuity arrangements. No internet or storage system is completely secure.
The security measures contractually applicable to customer-controlled personal data are described in Annex B of the DPA.
Our Cookie Policy explains the tracking technologies used on the BeeLiked public website and how to change your choices. Tracking within the signed-in BeeLiked customer platform is addressed separately through this notice, applicable customer documentation and any in-product information or controls.
You can opt out of marketing emails at any time using the unsubscribe link or by contacting us. We may retain a minimal suppression record so that we continue to honour the request. Opting out of marketing does not stop necessary service, security, billing or legal communications.
We do not currently make decisions about you based solely on automated processing that produce legal or similarly significant effects, unless a specific notice explains the decision, lawful basis and safeguards. We may use automated signals to support security, fraud review or service personalisation, with human review where appropriate.
Depending on the circumstances, you may have rights to access, rectify, erase or restrict personal data; receive portable data; withdraw consent; and obtain safeguards relating to significant automated decisions. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal. Rights are not absolute and may be subject to legal exceptions.
Your right to object. You have an absolute right to object to our use of your personal data for direct marketing. Where we rely on legitimate interests for another purpose, you may object on grounds relating to your particular situation; we will stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims.
Contact privacy@beeliked.com. We may ask for information needed to verify identity and authority. If your request concerns a customer-controlled Promotion, we may refer it to the relevant controller and assist that controller under the DPA.
You may complain to us if you believe we have infringed data-protection law in relation to your personal data. Email privacy@beeliked.com with enough detail for us to understand the issue and how you would like it resolved.
We will facilitate complaints, acknowledge receipt within 30 days, make appropriate enquiries, keep you informed about progress where appropriate and communicate the outcome without undue delay. This complaints process is separate from, and does not reduce, the statutory time limits for an individual-rights request.
You may also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint. We would appreciate the opportunity to address the issue first, but you do not have to contact us before contacting the ICO.
Our business website and customer platform are not directed at children. A Promotion may be open to younger participants only where its official rules, age-appropriate privacy information, lawful basis and safeguards permit this. The applicable controller is responsible for those requirements for a Customer-Operated Promotion; BeeLiked is responsible where it operates the Promotion as controller.
We review this notice when our processing or the law changes. We will publish the current version and effective date and will bring material new uses of personal data to the attention of affected individuals where required.