This Information Security Policy describes how HiveKeeper (operated by Culshaw Consulting Ltd, Company No. 16938477) collects, stores, processes and protects user data. It covers all systems used in the delivery of the HiveKeeper service.
HiveKeeper is a UK beekeeping management application accessible at gethivekeeper.com and via native iOS and Android apps. All processing is conducted in accordance with UK GDPR and the Data Protection Act 2018.
This document should be read alongside our Privacy Policy, which covers your data-protection rights in detail.
| System | Provider | Purpose | Data location |
|---|---|---|---|
| Supabase | Supabase Inc. | Database, authentication, file storage | AWS eu-west-2 (London, UK) |
| Cloudflare Workers | Cloudflare Inc. | API proxy for voice transcription, AI analysis, payments, iCal calendar | Cloudflare edge (UK/EU primary) |
| GitHub Pages | GitHub Inc. / Microsoft | Static web hosting for marketing pages โ no user data stored | Global CDN |
| OpenAI Whisper | OpenAI Inc. | Voice transcription of inspection notes โ processed in real time via paid API, not retained | US (via Cloudflare Worker) |
| Anthropic Claude | Anthropic PBC | AI frame analysis and beekeeping advice โ processed in real time via paid API, not retained | US (via Cloudflare Worker) |
| Stripe | Stripe, Inc. / Stripe Payments UK Ltd | Subscription payment processing | UK / Ireland |
| Resend | Resend.com | Transactional and marketing email delivery | US |
| Open-Meteo | Open-Meteo GmbH | Live weather data per apiary โ coordinates only, no personal data | EU (Germany) |
| postcodes.io / Nominatim | Open Source / OSM | Geocoding apiary locations โ no personal data | UK / EU |
| Leaflet.js / ESRI | ESRI / OpenStreetMap | Satellite map tiles for apiary map โ no personal data transmitted | Global CDN |
| Google Charts API | Google LLC | QR code generation โ hive URLs only, no personal data | Google global CDN |
| HiveKeeper Analytics | Culshaw Consulting Ltd (via Supabase) | In-app usage analytics โ screen views, feature usage, paywall interactions. No third party involved. | AWS eu-west-2 (London, UK) |
| Median | Median.co | Native app wrapper โ no user data stored by Median itself | US |
| Data | How we use it | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Email address | Account authentication, password reset, service notifications | Contract โ necessary to provide the service |
| Apiary and hive data | Displaying your beekeeping records within the app | Contract โ the core purpose of HiveKeeper |
| Inspection records and photos | Building your hive history, health scores, AI analysis (if requested) | Contract |
| GPS coordinates / postcode | Live weather data, nectar calendar, Asian Hornet Watch alerts, satellite map | Legitimate interests โ core app functionality |
| Analytics events | Understanding how the app is used to improve features and fix bugs | Legitimate interests โ product improvement. No personal content is logged. |
| Referral data | Tracking referral rewards and calculating incentives | Contract โ part of the referral scheme you opt into |
| Policy consent timestamp | Recording that you have agreed to our policies | Legal obligation โ UK GDPR compliance |
| SOS emergency contact | Sending an alert in an apiary emergency | Explicit consent โ you provide this voluntarily |
Data minimisation: We only collect data that is directly necessary for the purposes listed above. If we cannot justify collecting a piece of data, we do not collect it.
In the event of a sale, merger, acquisition or transfer of HiveKeeper or Culshaw Consulting Ltd, user data forms part of the business assets and may transfer to the acquiring party. We will notify all registered users by email before any transfer takes effect and give users a minimum of 30 days to export and delete their data. User data will never be sold as a standalone asset.
| Data type | Retention |
|---|---|
| User account and hive data | Until account deletion is requested |
| Frame and cover photos | Until deleted by user or account deletion |
| Voice recordings (OpenAI Whisper) | Processed in real time โ not retained by OpenAI under paid API terms |
| Photo data sent for AI analysis | Processed in real time โ not retained by Anthropic under paid API terms |
| SOS emergency contact details | Until updated or account deleted |
| Deleted account data | Removed within 30 days; backups purged within 90 days |
| Invoices and subscription records | 6 years (UK tax and accounting law) |
| Error logs and security logs | 90 days |
| Inactive accounts | Reviewed at 24 months inactivity โ user contacted before any deletion |
| Right | How to exercise |
|---|---|
| Access | Request a copy of all personal data held โ we will provide a CSV export within 30 days |
| Rectification | Update data directly in the app, or contact us for corrections |
| Erasure | Use Settings โ Start fresh, or email us for full account deletion |
| Data portability | Use Settings โ Export all data to CSV at any time |
| Object to processing | Contact us โ we will cease processing within 30 days where lawful |
| Withdraw consent | Delete your account at any time โ no questions asked |
To exercise any right, contact [email protected]. We will respond within 30 days.
HiveKeeper uses its own privacy-first analytics system built on Supabase. No third-party analytics tools, tracking pixels, cookies or advertising networks are used.
HiveKeeper is intended for users aged 18 or over. By signing up, you confirm that you are at least 18 years old. This reflects that paid subscriptions are processed via standard payment cards, which are generally only available to adults.
We do not knowingly collect personal data from anyone under 18. If you believe a minor has signed up for HiveKeeper, please contact [email protected] and we will delete the account and any associated data as soon as reasonably possible.
This policy will be reviewed annually or when significant changes to our systems occur. Users will be notified of material changes via the app and/or by email. The current version is always available at gethivekeeper.com/security-policy.html.
Data Controller: Culshaw Consulting Ltd
Registered office: 30 Stanion Road, Brigstock, Northamptonshire NN14 3HW
Company No: 16938477
Privacy contact: [email protected]
Website: gethivekeeper.com
Culshaw Consulting Ltd is registered with the Information Commissioner's Office under registration number CSN4273098.