Request access

Legal

Privacy Policy

This policy explains how Becpt handles personal data and keeps its email program direct, consent-based, and limited to legitimate service needs.

Effective and last updated: August 15, 2026

1. Scope and roles

This Privacy Policy applies to the Becpt website, account registration, support interactions, and the Becpt business collaboration service (collectively, the “Services”). “Becpt,” “we,” “us,” and “our” refer to Becpt, located at the address in Section 15.

Becpt is the controller of personal data used to operate accounts, our website, billing, security, and customer support. When a business customer submits or connects messages, contacts, or other workspace content to the Services, the customer generally determines the purposes and means of that processing. For that customer content, Becpt acts as a processor or service provider under the customer’s instructions and applicable agreement.

2. Data we collect directly

We collect personal data directly from you, your authorized organization, and your use of the Services. The data depends on how you interact with Becpt and may include:

  • Registration data: name, business email address, organization name, role, authentication information, and the choices you make while creating or administering an account.
  • Contact data: information you provide in a contact, access, demo, or support form and the content of your request and our response.
  • Usage and device data: sign-in events, feature interactions, workspace settings, IP address, browser and device type, timestamps, diagnostic logs, and security events.
  • Billing data: subscription level, billing contact, transaction status, invoice details, and receipt history. Payment card data is handled by our payment processor; Becpt does not need to store complete card numbers.
  • Customer content: messages, attachments, comments, assignments, and contact information that authorized users choose to process in a workspace.

We do not seek sensitive personal data through our public forms. Customers are responsible for deciding what customer content they submit and for providing notices or obtaining permissions required for that content.

3. How we obtain email addresses

Becpt obtains an account or contact email address only when a person enters it directly while registering, requests contact or support, accepts an authorized invitation, or performs another clear account action. Where a checkbox is used, it is unchecked by default and the person must affirmatively select it. We keep appropriate evidence of the request or account event.

We never buy, scrape, harvest, append, or acquire email addresses from data brokers or third-party marketing lists. We do not use purchased lists, scraped lists, harvested lists, appended lists, or lists supplied for unrelated marketing. We never sell or rent personal data, and we do not send cold email or unsolicited outreach.

4. How we use personal data

We use personal data to:

  • Create, authenticate, administer, and support accounts and workspaces.
  • Provide shared inbox, collaboration, assignment, and workflow features.
  • Process subscriptions, produce invoices, and deliver billing receipts.
  • Respond to direct questions, access requests, and support cases.
  • Detect abuse, investigate security events, maintain service availability, and protect users and the Services.
  • Diagnose errors and understand aggregate feature performance so we can maintain and improve the Services.
  • Meet legal obligations and enforce our agreements.

We do not use customer content or account email addresses to build third-party advertising profiles or for cross-context behavioral advertising.

5. Transactional email practices

Becpt’s service email program is limited to messages caused by a user or account event: one-time passwords (OTP), email verification, password reset, billing receipts, security alerts, and necessary account or system notifications. We send these messages to complete the requested action, protect the account, fulfill the service contract, or meet a legal duty.

We do not use the transactional stream for promotions, cold email, lead generation, or list-based outreach. We do not currently use registered addresses for marketing. If Becpt later offers an optional non-transactional update, it will require separate affirmative consent where required, will clearly identify Becpt, include our postal address, and provide a working one-click Unsubscribe control. Opt-out requests will be honored as required by CAN-SPAM and other applicable laws.

Unsubscribing from an optional update does not stop essential transactional messages that are necessary to complete a user request, secure an account, deliver a receipt, communicate a material system event, or provide the Services. A user can stop most account messages by closing the account, subject to retention and legal requirements.

6. Lawful bases and consent records

For individuals in the European Economic Area, United Kingdom, and other places that require a lawful basis, we process personal data as follows:

  • Contract: to create and service an account, provide requested features, authenticate users, and process billing.
  • Legitimate interests: to secure, maintain, troubleshoot, and responsibly improve a B2B service, after considering the effect on individuals.
  • Legal obligation: to keep required financial records, respond to lawful process, and meet applicable compliance duties.
  • Consent: when you make an optional choice that the law requires us to base on consent. Consent may be withdrawn at any time without affecting earlier lawful processing.

When consent is the basis for processing, we maintain reasonable consent records, which may include the person or account identifier, date and time, form or interface used, the notice and checkbox wording shown, the action taken, and any later withdrawal. We use these records to demonstrate that an affirmative choice occurred, not to expand the scope of that choice.

7. Processors and limited disclosures

We disclose personal data only as needed to operate Becpt, comply with law, or complete a transaction directed by a customer. Recipients may include vetted providers for cloud hosting, email delivery, payment processing, customer support, error monitoring, security, and professional advice. These providers may process data only for contracted purposes, must protect it, and may not sell it or use it for their own advertising.

We may disclose information when we reasonably believe it is necessary to comply with valid legal process, protect rights or safety, investigate fraud or abuse, or complete a merger, financing, acquisition, or sale of assets. In a business transaction, the recipient must continue to handle personal data consistently with this policy or provide legally required notice before using it differently. We do not sell or rent personal data.

8. International data transfers

Becpt and its processors may handle personal data in the United States and other countries where they operate. Privacy laws in those countries may differ from those where you live. When applicable law requires a transfer mechanism, we use appropriate safeguards such as contractual protections, including standard contractual clauses, and supplementary technical or organizational measures where appropriate. You may request information about applicable safeguards by contacting us.

9. Data retention and deletion

We keep personal data only for as long as reasonably necessary for the purpose collected. Account and workspace data is generally retained while the account is active and for a limited period afterward to support recovery, deletion processing, dispute resolution, and security. Support records are kept while a case is open and for a reasonable period afterward. Billing and transaction records are retained for legally required accounting and tax periods. Security logs are retained for a limited period proportionate to investigation and prevention needs.

At the end of the applicable period, we delete or de-identify data unless a longer period is required by law, a litigation hold, fraud prevention, or the establishment or defense of legal claims. Deletion from encrypted backups occurs through the normal backup lifecycle; restored data remains subject to the deletion request.

10. Security

We use technical and organizational safeguards designed to protect personal data, including access controls, authentication controls, encryption in transit, logging, restricted administrative access, provider review, backup procedures, and incident response practices. Access is limited according to role and business need.

No internet service can guarantee absolute security. You are responsible for protecting account credentials, using appropriate workspace permissions, and promptly reporting suspected unauthorized access to support@becpt.com.

11. Cookies and similar technology

Becpt uses only strictly necessary cookies or local storage by default. These technologies support authentication, session continuity, security, load balancing, saved privacy choices, and other functions required to provide a request. They are not used for third-party behavioral advertising.

We will not place optional analytics, advertising, or other non-essential cookies unless we first provide the notice and obtain the consent required in your location. If optional cookies are introduced, a consent control will let you refuse or withdraw that choice as easily as you gave it.

12. Privacy rights

GDPR and similar laws

Depending on your location and subject to legal limits, you may ask to access, correct, delete, restrict, or object to processing of your personal data; ask for portable data; withdraw consent; and object to processing based on legitimate interests. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Becpt does not make such solely automated decisions about website visitors or account users.

California and other U.S. state privacy rights

Subject to applicable thresholds, exceptions, and verification, residents may have rights to know or access categories and specific pieces of personal data, correct inaccuracies, delete data, obtain a portable copy, opt out of sale, sharing for cross-context behavioral advertising, or qualifying targeted advertising and profiling, and appeal a denied request. Becpt does not sell personal data and does not share it for cross-context behavioral advertising. We do not discriminate against anyone for exercising a privacy right.

California residents may request the categories of personal information collected, sources, business purposes, and categories of recipients described in this policy. An authorized agent may submit a request when permitted by law, but we may require proof of authority and identity verification. We use request data only to verify and fulfill the request.

How to exercise a right

Email privacy@becpt.com or support@becpt.com with the subject “Privacy Request” and describe the right you wish to exercise. We may ask for information reasonably necessary to verify that the requester is the account holder or authorized agent. We will respond within the period required by applicable law. If we deny a request, our response will explain the reason and any available appeal process.

13. Children

Becpt is a business service and is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided personal data to Becpt, contact privacy@becpt.com so we can investigate and delete it as appropriate.

14. Changes to this policy

We may update this policy to reflect changes in the Services, law, or our practices. We will post the revised policy here and update the effective date. If a change materially affects how we use personal data, we will provide additional notice through the Services or an account notification when required. We will obtain consent before applying a new use where the law requires consent.

15. Privacy contact and complaints

Questions, complaints, data protection inquiries, and requests for our Data Protection Officer or privacy lead may be directed to:

Becpt Privacy Team

548 Market Street, Suite 404

San Francisco, CA 94104, United States

Email: privacy@becpt.com

Support: support@becpt.com

Phone: +1 (415) 890-2340

If you are in the EEA or United Kingdom, you may also complain to the data protection authority in the place where you live or work. We encourage you to contact us first so we can address the concern promptly, but doing so does not limit your right to contact a regulator.