By5 Privacy Documentation
Privacy Policy
This Privacy Policy sets out how By5 collects, uses, stores, discloses and protects personal data in connection with the operation of the By5 platform, including account data, customer enquiry data, lead data, job-related information, support records, media, attachments, usage data, security logs and telemetry data.
The By5 platform is operated by By5 Ltd ("By5"). By5 Ltd is the data controller identified in this Privacy Policy and can be contacted at hello@by5.ai.
This Privacy Policy is intended to support transparency and compliance with applicable data protection legislation, including the UK GDPR and, where applicable, the EU GDPR. It should be read together with the By5 Commercial Licence & Platform Terms, Data Processing Addendum, Cookies & Telemetry Notice and any applicable order form, proposal or service agreement.
1. Scope of this Privacy Policy
This Privacy Policy applies to personal data processed through or in connection with the By5 platform, including personal data relating to Customers, authorised users, administrators, business contacts, leads, customer enquiries, job records, support interactions, media files, attachments, platform usage, security records and operational telemetry.
For the purposes of this Privacy Policy, "Customer" means the business, organisation or account holder that has been granted access to the By5 platform. "Authorised User" means any individual permitted by the Customer to access or use the platform.
2. Controller and Processor Roles
By5 may act as a data controller in respect of personal data processed for its own business purposes, including account administration, billing, customer onboarding, support communications, platform account identity, administrator access records, security monitoring, legal compliance, service management and product improvement.
By5 may act as a data processor where it processes personal data on behalf of a Customer through the platform, including customer enquiry data, lead data, job-related information, uploaded media, attachments, workflow records and communication data handled in accordance with the Customer's instructions.
The Customer remains responsible for determining the lawful basis, purposes and means of processing personal data relating to its own customers, leads, enquiries, communications, job records and business operations. The Customer is also responsible for providing any required privacy notices, obtaining any required consents, and ensuring that its use of By5 complies with applicable data protection laws.
Further controller and processor obligations are set out in the By5 Data Processing Addendum.
3. Categories of Personal Data
By5 may process the following categories of personal data, depending on the Customer's package, configuration, integrations, workflows and use of the platform:
- Account and administrator identity data, including names, email addresses, phone numbers, login details, authentication status, user roles, support access records and acceptance records.
- Customer business data, including organisation profile, package information, platform configuration, branding, communication channels, operational settings, workflow preferences and account administration information.
- Lead, customer and enquiry data, including names, phone numbers, email addresses, property or site addresses, job descriptions, enquiry details, message history, notes, attachments, media files and linked customer records.
- Job and workflow data, including estimates, quote history, booking details, scheduling information, deposit or payment workflow records, site-survey notes, operational status updates and aftercare records.
- Support and communication data, including support requests, service communications, onboarding records, issue reports, feedback, correspondence and customer success interactions.
- Telemetry, usage and security data, including messaging events, AI usage records, upload sizes, platform usage information, system logs, security logs, diagnostic data, error reports and operational monitoring data.
4. Purposes of Processing
By5 may process personal data for the following purposes:
- to provide, operate, maintain, secure and improve the By5 platform;
- to route enquiries, manage authentication, administer Customer accounts, deliver messages, classify and summarise enquiries, store attachments and support Customer workflows;
- to support lead capture, enquiry management, estimating workflows, quote preparation, booking, scheduling, job management, customer communication and follow-up processes;
- to monitor platform usage, service performance, reliability, security, misuse, error events, operational diagnostics and fair-use thresholds;
- to provide onboarding, technical support, troubleshooting, customer success assistance and service communications;
- to investigate suspected abuse, misuse, security incidents, unlawful activity or breach of applicable terms;
- to administer billing, package entitlements, commercial records, contractual obligations and operational reporting;
- to comply with applicable legal, regulatory, accounting, audit, security and record-keeping obligations.
By5 does not use identifiable or pseudonymised Customer-controlled personal data to train shared AI models. AI providers may process Customer-controlled data only to deliver the requested platform function under the applicable provider and subprocessor terms.
5. Data Subject Rights and Customer Cooperation
Where By5 acts as a data controller, By5 shall handle applicable data subject rights requests in accordance with applicable data protection laws. Such rights may include, where applicable, rights of access, rectification, erasure, restriction, portability and objection.
Where By5 acts as a data processor on behalf of a Customer, By5 shall provide reasonable assistance to the Customer in responding to data subject requests relating to personal data processed through the platform, subject to applicable law, technical feasibility and the Customer's cooperation.
The Customer remains responsible for handling data subject requests relating to its own customers, leads, enquiries, communications, job records and business operations where the Customer determines the purposes and means of processing.
The Customer shall cooperate promptly with By5 where a data subject request, regulatory enquiry, complaint, correction request, deletion request, export request or objection relates to Customer-controlled data processed through the platform.
By5 may refuse, restrict or delay action on a request where permitted by applicable law, where the request cannot be verified, where the request relates to data controlled by the Customer, or where retention is required for legal, security, contractual, accounting, dispute-resolution or legitimate business purposes.
6. International Transfers and Subprocessors
By5 may use third-party service providers, subprocessors and infrastructure providers to support the delivery, security, hosting, communication, authentication, billing, analytics, AI-assisted functionality and operation of the By5 platform.
Such third-party providers may process or store personal data in the United Kingdom, the European Economic Area, the United States or other jurisdictions, depending on the relevant provider, service configuration, infrastructure location and operational requirements.
Where personal data is transferred outside the United Kingdom or European Economic Area, By5 shall take reasonable steps to ensure that such transfer is carried out in accordance with applicable data protection laws and, where required, is supported by appropriate safeguards such as adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, EU Standard Contractual Clauses, transfer risk assessments or equivalent lawful transfer mechanisms.
By5 shall remain responsible for appointing subprocessors that are reasonably appropriate for the provision of the platform and shall require subprocessors to process personal data only in accordance with applicable contractual, confidentiality, security and data protection obligations.
The Customer acknowledges that certain platform functions may depend on third-party services, including authentication providers, messaging providers, email providers, hosting providers, AI model providers, analytics providers, payment or billing providers and support tools.
A current list of material subprocessors may be made available through the By5 legal documentation, platform notice, onboarding materials, service agreement or other written notice.
7. Security and Personal Data Incidents
By5 shall apply appropriate technical and organisational measures designed to protect personal data against unauthorised access, accidental or unlawful destruction, loss, alteration, disclosure, misuse or unlawful processing.
Such measures may include, where appropriate, access controls, authentication controls, role-based permissions, system monitoring, security logging, data backup controls, provider security controls, operational procedures and staff or contractor confidentiality obligations.
By5 shall take reasonable steps to investigate any suspected or actual personal data breach affecting the platform and shall notify affected Customers where required by applicable law, contract or data processing terms.
Where By5 acts as a data processor, By5 shall notify the relevant Customer without undue delay after becoming aware of a personal data breach affecting Customer-controlled personal data, to enable the Customer to assess and comply with any applicable notification obligations.
Where By5 acts as a data controller, By5 shall assess whether any personal data breach is notifiable to the relevant supervisory authority and/or affected individuals in accordance with applicable data protection laws.
8. Retention and Deletion
By5 shall retain personal data only for as long as reasonably necessary for the purposes for which it was collected or processed, including service delivery, account administration, security, support, billing, legal compliance, audit, dispute resolution, fraud prevention and legitimate business operations.
Retention periods may vary depending on the type of personal data, the Customer's package, platform configuration, legal requirements, contractual obligations, operational needs, backup processes and the nature of the relevant records.
Where By5 acts as a processor, normal application access ends with the applicable trial or paid service period. The Customer may request an operator-assisted return of Customer-controlled personal data during the following 30 days. That return window does not preserve normal login or self-service application access.
Subject to narrow legal, tax, security, fraud-prevention, audit or dispute-resolution holds, active application copies of Customer-controlled personal data are deleted or anonymised by day 60 after normal access ends. Backup copies expire through the normal backup cycle within 90 days and are not restored for ordinary service use after deletion from active systems.
By5 may retain certain records where necessary to comply with legal, accounting, tax, regulatory, security, audit, contractual, dispute-resolution or legitimate business requirements.
Following account closure, termination or expiry of the applicable service, By5 may retain limited controller records required for billing, legal compliance, tax, security, fraud prevention, audit or dispute resolution. Those exceptions do not extend ordinary access to Customer-controlled operational data.