Back to Beonflow

Privacy Notice

How Beonflow processes personal data about limited partners (LPs), the ultimate beneficial owners behind entity LPs, and the fund-administrator users who run a Beonflow tenant. Last reviewed: 4 June 2026.

Who we are

Beonflow is the platform a fund administrator (the “GP”) uses to run their fund operations. If you are reading this as an LP, your relationship is with your GP; Beonflow processes your personal data on the GP’s behalf. Under GDPR that makes the GP the controller and Beonflow the processor. For one specific purpose — keeping an audit trail of every action taken on our platform — Beonflow acts as a separate controller, because we maintain that trail for our own defensibility regardless of any particular GP’s instructions.

What we process and why

The fields below come from the full processing record in our internal docs/compliance/ropa.md §1. We summarise them here so you can read them in plain language.

Lawful basis

We process your data on three lawful bases under Article 6 of the GDPR:

Who sees your data

Inside your GP’s Beonflow tenant: only the GP staff with the role to do so. Database row-level security enforces tenant isolation as the floor.

Outside Beonflow, we engage the following sub-processors:

International transfers

Some of our sub-processors may process your data outside the European Economic Area. Where they do, we rely on the European Commission’s Standard Contractual Clauses (or equivalent adequacy mechanism) to keep the transfer lawful. The Standard Contractual Clauses are an instrument held with the sub-processor; we can identify which clause applies to your data on written request.

AI verdicts

When you upload a KYC document or a bank letter, an AI model analyses it and produces a verdict (verified, flagged as a mismatch, or unknown). The verdict is not the decision: a human reviewer on your GP’s team approves or rejects every gated action before your KYC status changes or your bank account on file is updated. This means GDPR Article 22 (no solely-automated decisions producing legal effects) does not require a separate opt-out for our AI verdicts.

You will see an in-product disclosure (a small banner with a “reviewed by a human” sentence) on every screen where AI input is collected or output is shown.

How long we keep your data

Retention follows your GP’s licence requirements, typically 5 to 10 years after your investor relationship ends, because the regulator expects the GP to be able to reproduce KYC evidence for that period. The audit log is retained for 7 years.

Erasure on request is something we are still building — see “Your rights” below. Today, requests are routed through your GP, who can act on the underlying records.

Your rights

Under GDPR you have the right to:

You exercise these rights by contacting your GP. Your GP can act on the underlying records, and where they need Beonflow to act on their behalf we will. We do not act on LP requests unilaterally because doing so would risk violating the GP’s instructions to us as their processor.

If something goes wrong

If a personal data breach affects you, your GP will notify you under their own Article 33 / 34 obligations as controller. Our breach procedure is at docs/runbooks/data-breach-response.md; the summary is that we notify your GP within hours of confirming a breach so their 72-hour clock to their supervisory authority can start.

You also have the right to lodge a complaint with a supervisory authority. In the EU, the relevant authority is typically the one in your country of residence.

Changes to this notice

We update this notice whenever the underlying processing changes — a new sub-processor, a new data field, a new AI surface, or a retention change. The “last reviewed” date at the top of this page is the authoritative timestamp.

This notice is a summary written for clarity. The controlling legal documents are your investment agreement with your GP and (where Beonflow is a separate controller) the agreement covering your use of the Beonflow platform.