Stevan Nesovic PR Maistery ("we", "us", "our", or "BeaSmart") operates the BeaSmart platform (the "Service"), an AI Agent and Brand Ambassador for Beauty Professionals. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at beasmart.io, use our mobile applications (iOS and Android), or interact with our Service in any way.
We are committed to protecting your privacy and the privacy of your clients. Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
Data Controller:
Stevan Nesovic PR Maistery
Daniciceva 104, 34000 Kragujevac, Republic of Serbia
Email:
[email protected] 1. Definitions
- "Service" means the BeaSmart platform, including the website, web application, iOS application, Android application, APIs, and all related services.
- "User" (or "you") means a beauty professional or business owner who creates an account and uses the Service to manage their bookings and client communications.
- "End Client" means an individual who interacts with the AI Agent through Instagram Direct Messages to inquire about or book services with a User.
- "AI Agent" means the automated artificial intelligence system that communicates with End Clients on behalf of Users via Instagram Direct Messages.
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data, whether automated or not, such as collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, erasure, or destruction.
- "Platform" means the BeaSmart software, infrastructure, and all associated technologies.
2. Data We Collect
We collect and process the following categories of Personal Data:
2.1 Account Data
- Full name
- Email address
- Password (encrypted)
- Instagram Business or Creator account information (username, profile data, account tokens)
- Profile picture (if provided)
2.2 Waitlist Data
- Name
- Email address
- Instagram handle (optional)
2.3 Business Profile Data
- Business name and description
- Services offered (names, descriptions, prices, durations)
- Working hours and break schedules
- Staff/worker information (names, assigned services, schedules)
- Business address or location
- AI personality configuration and custom responses
2.4 Instagram Integration Data
- Instagram Direct Message content (messages sent and received)
- Instagram profile data (username, display name, profile picture, account type)
- Conversation metadata (timestamps, message status, read receipts)
- Instagram API access tokens
2.5 End Client Data
The following data is collected from End Clients during interactions with the AI Agent, on behalf of the User:
- Names
- Phone numbers
- Appointment preferences and requests
- Booking history
- Conversation transcripts (DM messages exchanged with the AI Agent)
- Any other information voluntarily provided in DM conversations
2.6 AI Interaction Data
- AI-generated responses and messages
- Conversation logs and flow data
- Booking confirmations and reminder messages
- AI performance metrics (response times, conversation outcomes)
2.7 Financial Data
- Subscription plan and billing cycle
- Payment method details (processed and stored by our third-party payment processor; we do not store full credit card numbers)
- Billing history and invoices
- Refund records
2.8 Technical Data
- IP address
- Device type, model, and operating system
- Browser type and version
- App version
- Crash logs and error reports
- Session duration and timestamps
2.9 Analytics Data
- Feature usage patterns
- Booking trends and patterns
- Conversion rates
- Peak messaging times
- User engagement metrics
3. How We Use Your Data
We process your Personal Data for the following purposes:
- Service Delivery: To provide, maintain, and operate the AI Agent service, including processing Instagram DM conversations and managing bookings on your behalf.
- Appointment Management: To process, schedule, confirm, and manage appointments and bookings between Users and their End Clients.
- AI Responses: To generate intelligent, contextual AI responses to End Client inquiries based on User-provided business information.
- Payment Processing: To process subscription payments, billing, refunds, and related financial transactions.
- Service Communications: To send service-related notifications, updates, booking confirmations, and reminders.
- AI Improvement: To improve the accuracy, quality, and effectiveness of AI responses and the overall Service (using aggregated and anonymized data).
- Analytics: To generate business analytics and insights for Users, including booking trends, revenue tracking, and client patterns.
- Fraud Prevention: To detect, prevent, and address fraud, abuse, security incidents, and technical issues.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, and governmental requests.
- Product Updates: To communicate product updates, new features, and promotional offers (with opt-out available at any time).
4. Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation (GDPR) and applicable Serbian data protection laws, we process your Personal Data on the following legal bases:
- Performance of a Contract (Art. 6(1)(b) GDPR): Processing necessary for the performance of our contract with you, including account creation, service delivery, payment processing, and appointment management.
- Consent (Art. 6(1)(a) GDPR): Where you have given clear consent for us to process your Personal Data for specific purposes, such as joining the waitlist, receiving marketing communications, and the use of non-essential cookies.
- Legitimate Interest (Art. 6(1)(f) GDPR): Processing necessary for our legitimate interests, including service improvement, security measures, fraud prevention, and aggregated analytics, provided these interests are not overridden by your rights.
- Legal Obligation (Art. 6(1)(c) GDPR): Processing necessary to comply with legal obligations, such as tax record keeping, responding to lawful requests from law enforcement, and regulatory compliance.
5. BeaSmart as Data Processor
With respect to End Client data, the relationship between BeaSmart and the User is as follows:
The User (beauty professional) is the Data Controller for their End Client data. The User determines the purposes and means of processing End Client personal data.
BeaSmart acts as a Data Processor, processing End Client data solely on the User's behalf and in accordance with the User's instructions through the Service configuration.
As Data Processor, BeaSmart commits to:
- Process End Client data only as necessary to provide the Service and as instructed by the User.
- Implement appropriate technical and organizational security measures.
- Not engage sub-processors without the User's knowledge (sub-processors are listed in Section 6).
- Assist the User in responding to End Client data subject requests.
- Delete or return End Client data upon termination of the Service, subject to legal retention obligations.
- Make available all information necessary to demonstrate compliance with data processing obligations.
User Responsibilities as Data Controller: Users are responsible for ensuring they have a lawful basis to collect and process their End Clients' personal data, for providing appropriate privacy notices to their End Clients, and for responding to End Client data subject access requests.
6. Data Sharing and Third Parties
We may share your Personal Data with the following categories of recipients:
- Meta Platforms / Instagram: Your Instagram account data and DM content are processed through Meta's Instagram Graph API. This integration is essential for the Service to function. Meta's own privacy policy governs their processing of your data.
- Payment Processors: Financial data is shared with our third-party payment processor for subscription billing and payment processing. They process payment data in accordance with PCI-DSS standards.
- Cloud Hosting Providers: Your data is stored on secure cloud infrastructure. All data is encrypted at rest and in transit.
- Analytics Providers: We may share aggregated, anonymized data with analytics tools to improve our Service. This data cannot be used to identify any individual.
- Legal Authorities: We may disclose your data if required by law, regulation, legal process, or governmental request, or to protect our rights, privacy, safety, or property.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will provide notice before your Personal Data becomes subject to a different privacy policy.
We NEVER sell your Personal Data or your End Clients' Personal Data to third parties for advertising, marketing, or any other purpose. This is an absolute commitment.
7. AI-Specific Privacy Provisions
7.1 How the AI Processes Data
The AI Agent processes Instagram DM conversations in real-time to understand End Client inquiries and generate appropriate responses. The AI uses the business information you provide (services, prices, availability, personality settings) to craft responses that accurately represent your business.
7.2 AI Training Data
We may use aggregated, anonymized, and de-identified conversation patterns to improve the overall quality and accuracy of the AI Agent. Individual conversations are never used to train models in a way that could expose your personal data or your End Clients' personal data.
7.3 Automated Decision-Making (GDPR Article 22)
The AI Agent engages in automated processing of conversations and booking decisions. End Clients and Users have the right to:
- Request human intervention in any conversation at any time.
- Express their point of view regarding any AI-managed interaction.
- Contest any decision made by the AI Agent.
Users may override, modify, or cancel any booking or communication made by the AI Agent at any time through the BeaSmart application.
7.4 AI Accuracy
While we strive for high accuracy, AI-generated responses may occasionally contain errors or imprecise information. We recommend that Users regularly review AI conversations and bookings to ensure accuracy.
8. International Data Transfers
Your Personal Data may be transferred to, and processed in, countries other than the Republic of Serbia and/or the European Economic Area (EEA), including locations where our cloud hosting providers, Meta Platforms, and other service providers operate.
When we transfer Personal Data outside Serbia/EEA, we ensure that appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy decisions where the destination country provides an adequate level of data protection.
- Other legally recognized transfer mechanisms under applicable data protection laws.
You may request a copy of the safeguards we use for international transfers by contacting us at [email protected].
9. Data Retention
We retain your Personal Data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law. Specific retention periods:
- Account Data: Duration of your active account plus 30 days after account deletion request.
- Conversation and Booking Data: Duration of your active account plus 30 days after account deletion.
- Financial and Billing Data: 5 years from the date of the transaction, as required by Serbian tax legislation.
- Waitlist Data: Until the waitlist purpose is fulfilled (product launch) or until you withdraw your consent, whichever is earlier.
- Technical and Crash Logs: 12 months from the date of collection.
- Anonymized Analytics Data: May be retained indefinitely as it does not constitute Personal Data.
You may request early deletion of your data at any time, subject to any legal retention obligations that may apply.
10. Your Rights
Under GDPR and applicable Serbian data protection law (Law on Personal Data Protection), you have the following rights:
- Right of Access (Art. 15 GDPR): You have the right to obtain confirmation of whether we process your Personal Data and, if so, to access that data along with information about how it is processed.
- Right to Rectification (Art. 16 GDPR): You have the right to have inaccurate Personal Data corrected and incomplete data completed.
- Right to Erasure (Art. 17 GDPR): You have the right to request the deletion of your Personal Data ("right to be forgotten") where certain conditions apply.
- Right to Restriction of Processing (Art. 18 GDPR): You have the right to request that we restrict the processing of your Personal Data under certain circumstances.
- Right to Data Portability (Art. 20 GDPR): You have the right to receive your Personal Data in a structured, commonly used, machine-readable format and to transmit it to another controller.
- Right to Object (Art. 21 GDPR): You have the right to object to processing of your Personal Data based on legitimate interests, including profiling.
- Right Related to Automated Decision-Making (Art. 22 GDPR): You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia (Poverenik za informacije od javnog znacaja i zastitu podataka o licnosti), or with any competent supervisory authority in your country of residence.
How to exercise your rights: Send your request to [email protected]. We will respond within 30 days of receiving your request. We may request verification of your identity before processing your request.
11. Data Security
We implement appropriate technical and organizational measures to protect your Personal Data, including:
- Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher.
- Encryption at Rest: All stored data is encrypted using AES-256 encryption standards.
- Access Controls: Strict access controls and authentication mechanisms limit access to Personal Data to authorized personnel only.
- Regular Security Assessments: We conduct periodic security reviews and vulnerability assessments.
- Incident Response: We maintain incident response procedures to address data breaches promptly.
- Breach Notification: In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, in accordance with GDPR Article 33 and 34.
12. Cookies and Tracking Technologies
Our website currently uses minimal cookies and tracking technologies:
- Strictly Necessary Cookies: Essential for the website to function properly (e.g., language preference, session management).
- Third-Party Resources: We load fonts from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). Google may set cookies and collect limited technical data through this service.
We do not currently use third-party analytics, advertising, or social media tracking cookies. If we introduce additional cookies or tracking technologies in the future, we will update this section and, where required, obtain your consent.
Managing Cookies: You can manage or disable cookies through your browser settings. Please note that disabling essential cookies may affect website functionality.
13. Children's Privacy
The Service is not intended for individuals under the age of 16. We do not knowingly collect Personal Data from anyone under 16. If we become aware that we have collected Personal Data from a child under 16, we will take steps to delete that information promptly. If you believe we have inadvertently collected data from a minor, please contact us immediately at [email protected].
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Sending a notification to your registered email address at least 30 days before the changes take effect.
- Displaying a prominent notice within the Service.
- Updating the "Last updated" date at the top of this page.
Your continued use of the Service after the effective date of the revised Privacy Policy constitutes your acceptance of the changes. If you do not agree with the updated policy, you should discontinue use of the Service before the changes take effect.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Stevan Nesovic PR Maistery
Daniciceva 104, 34000 Kragujevac, Republic of Serbia
Email:
[email protected]
For privacy-specific inquiries, please include "Privacy Request" in your email subject line.