Privacy Policy
This Privacy Policy explains how Bleepy collects, uses, and protects your personal information when you use our platform, website, or related services.
1. Overview
This Privacy Policy explains how Bleepy ("we," "us," or "our") collects, uses, and protects your personal information when you use our platform, website, or related services.
This policy complies with the General Data Protection Regulation (GDPR), UK GDPR, and other applicable privacy laws. By using our service, you consent to the data practices described in this policy.
2. Data Controller and Contact
Bleepy acts as the Data Controller for individual user data and as a Data Processor for data uploaded by organisations.
Contact Information
Email: support@bleepy.co.uk
Subject Line: Privacy Policy Inquiry
We aim to acknowledge all requests within 2 working days and provide full responses within one month, as required by data protection law.
3. Information We Collect
3.1 Voluntarily Provided Information
We collect data you provide directly, including:
- Account registration details (name, email, profession, university/institution)
- Event participation and attendance information
- Educational or organisational affiliation
- Profile data (role, academic year, profile picture, bio)
- Event bookings, registrations, and attendance records
- Portfolio files and documents for IMT portfolio
- Feedback form responses, ratings, and comments
- Quiz challenge participation and leaderboard data
3.2 Automatically Collected Information
We collect certain information automatically when you use Bleepy, such as:
- Log and usage data (e.g., access times, pages viewed, device type)
- Browser details and technical information
- Performance and diagnostic data
- Training session transcripts, performance metrics, and scores
- Interaction data (station attempts, completion times, gamification progress)
- QR code scan data and attendance verification
We collect this data through cookies and similar technologies. For details, see our Cookie Policy.
3.3 Organisation Data
Event organisers and institutions may upload or generate:
- Participant lists, resources, and attendance records
- Certificates or survey responses created within the system
For this data, the organisation is the Data Controller and Bleepy acts as the Data Processor.
If you are a participant, contact your organisation directly to exercise your data rights.
3.4 Prohibited Data
Bleepy is not designed for clinical or patient data.
You must not upload:
- Patient-identifiable information
- Clinical data or medical records
- Any data subject to healthcare confidentiality
If such data is uploaded in error, immediately contact support@bleepy.co.uk with subject "Urgent: Data Breach".
4. How We Use Personal Information
We use your information to:
- Provide and improve the Bleepy platform
- Facilitate events, resources, and learning activities
- Manage subscriptions and payments
- Communicate important updates via email and push notifications
- Send event reminders, booking updates, certificate notifications, and feedback requests via push notifications
- Maintain platform security and integrity
- Comply with legal obligations
- Track progress, performance metrics, and gamification achievements
- Generate personalized feedback, reports, and certificates
- Process voice interactions in real-time for emotion recognition and training assessment
5. Legal Basis for Processing
We process your data under the following legal bases:
Contract
To provide services you request (e.g., account access, subscriptions)
Legitimate Interests
For service improvement, analytics, and security
Consent
For marketing communications and optional features
Legal Obligation
To meet regulatory, tax, or accounting requirements
6. Marketing Communications
We may send communications about Bleepy and relevant professional opportunities or products.
You can opt out at any time via email footer links or by contacting support@bleepy.co.uk.
6.1 Push Notifications
Bleepy offers push notifications to keep you informed about important events, bookings, certificates, and feedback requests. Push notifications are optional and require your explicit consent.
What We Send
- Event reminders (1 hour and 15 minutes before events)
- Event updates and cancellations
- Booking reminders (24 hours, 1 hour, and when events start)
- Waitlist promotion notifications
- Certificate availability alerts
- Feedback request reminders
- Announcements (if enabled)
Your Control
- You can enable or disable push notifications in your profile settings
- You can customize which types of notifications you receive (events, bookings, certificates, feedback, announcements)
- You can opt out completely at any time
- Browser-level notification permissions can be managed in your browser settings
Data Collection: To deliver push notifications, we store your browser's push subscription endpoint, encryption keys (p256dh and auth), and your notification preferences. This data is stored securely and is only used to send notifications you've requested.
Service Workers: Push notifications use browser service workers to deliver messages even when the Bleepy website is not open. The service worker code is stored locally in your browser and does not track your browsing activity.
To manage your push notification preferences, visit your profile settings page or contact support@bleepy.co.uk.
7. Data Portability
You may request a copy of your data by contacting support@bleepy.co.uk.
We will verify your identity and provide exports in commonly used, machine-readable formats (CSV or JSON) within 14 days of verification.
8. Data Retention
- Active accounts: Retained for as long as your account remains active.
- Deleted accounts: Profile, settings, and content deleted within 7 days.
- System and billing records: Retained for up to 7 years to comply with UK tax and accounting laws (HMRC requirements).
- Session data: Retained for 1 year for educational analysis.
- Event bookings: Retained for 2 years after event date for attendance records.
- Certificate data: Retained for 5 years for verification and compliance purposes.
- Chat transcripts (Hume EVI): Stored in our database for 1 year, then automatically deleted. Zero retention on Hume's platform.
- Organisation data: Retained up to 90 days after subscription cancellation for export or reactivation, unless deletion is requested earlier.
9. Data Storage and Transfers
Data is primarily stored in the UK and EEA.
Some sub-processors may process data in other jurisdictions with adequate safeguards, such as Standard Contractual Clauses (SCCs).
For a complete list of our sub-processors and their data processing locations, see our Sub-Processors page.
10. Sub-Processors
We use trusted third-party providers to operate our Services securely and reliably. These sub-processors process personal data on our behalf.
We only use sub-processors that meet security, privacy, and compliance standards consistent with UK GDPR and EU GDPR, operate under written data-processing terms, and provide appropriate technical and organisational safeguards.
A maintained list of sub-processors is available on our Sub-Processors page.
11. Data Security and User Responsibilities
We implement appropriate technical and organisational measures to protect your data.
Users are responsible for:
- Maintaining secure passwords
- Avoiding account sharing
- Not uploading prohibited or sensitive data
- Reporting unauthorised access via support@bleepy.co.uk ("Security Incident")
12. Data Breach Notification
If a data breach occurs that poses a risk to individuals, Bleepy will:
- Notify the ICO within 72 hours (where legally required)
- Notify affected users without undue delay
- Provide details of the breach and mitigation steps
13. Children and Minors
Bleepy is intended for users aged 16 and above.
We do not knowingly collect data from children under 13.
Age Verification
- We rely on users and organisations to provide accurate age information.
- We do not use automated age verification.
Parents or guardians may contact support@bleepy.co.uk to remove a minor's data.
14. International Users
We comply with:
- UK GDPR and Data Protection Act 2018
- EU GDPR (where applicable)
- California Consumer Privacy Act (CCPA) and CPRA
- Canada's PIPEDA (where applicable)
- Australia's Privacy Act 1988 (where applicable)
15. Your Rights
You have the right to:
- Access your data
- Request correction or deletion
- Withdraw marketing consent
- Request data portability
- Object to processing
- Restrict processing (e.g., pending verification of accuracy)
- Lodge a complaint with the ICO or your supervisory authority
To Exercise These Rights
- Email support@bleepy.co.uk
- Specify your request
- We verify identity within 2 working days
- We respond within 30 days (extendable for complex cases)
16. California (CCPA/CPRA) Rights
California residents have the right to:
- Access, correct, or delete personal information
- Know categories of data collected, disclosed, or sold
- Opt out of sale or sharing of personal data
- Limit use of sensitive personal information
- Be free from discrimination for exercising these rights
We verify identity before processing such requests. We verify your identity by confirming your registered email address and account details. For security, we may request additional information to prevent fraudulent requests.
17. Automated Decision-Making and Profiling
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
18. Business Transfers
If Bleepy or its assets are acquired, data may be transferred under equivalent privacy obligations.
Users will be notified as required by law.
19. Third-Party Links
Our services may include links to external websites.
We are not responsible for their content or privacy practices.
Please review their privacy policies before sharing personal information.
20. Updates to This Policy
We may update this policy periodically.
Material changes will be notified via the platform or email.
21. Contact Us
Data Protection Contact
Email: support@bleepy.co.uk
We aim to respond within 2 working days and resolve formal data requests within 1 month.
This Privacy Policy is effective as of 15 November 2025 and was last updated on 15 November 2025.