Bentokai

Privacy Policy

This Privacy Policy explains how Bentokai collects, uses, and protects personal data when you use this website and our platform at app.bentokai.com, including the optional bank-connection (open banking) and social media features, and when you visit a website or use a page that one of our customers runs with Bentokai.

1. Who we are

Bentokai is operated by Umai Media, S.L. (VAT ESB26634485), Calle San Gerardo 50, 28035 Madrid, Spain ("Umai Media", "we", "us"). You can reach us at privacy@bentokai.com.

Where we are the controller. Umai Media, S.L. is the data controller for the personal data of the people who have a Bentokai account and use it (their account, profile and authentication data), for the security and technical data described in section 2, and for the data processed through this website. This policy mainly describes that processing.

Where we process data for our customers. The business data our customers put into Bentokai, such as their contacts, the clients and suppliers in their invoices and other records, the people who appear in the bank transactions they import, and the personal data of other people in the social media profiles they connect (such as the names and content in comments, reviews and messages), is processed by Umai Media on the customer's behalf, under the data processing agreement in section 11 of our Terms of Service. So is the data about the people our customers serve through Bentokai: the visitors to their websites, the people who search on them, and the people who subscribe to their status pages or use their support and project portals (see section 2). For that data, the customer is the controller and decides why and how it is used; we act only on its instructions.

2. Information we collect

3. Bank account information and open banking

Bentokai's Treasury feature lets you connect your own bank accounts to view their balances and movements inside the platform. This access is:

Accounts at Wise and Qonto can instead be connected directly through those providers' own interfaces, by signing in at the provider or with an API key you create there, which we store encrypted; this access is read-only too.

The imported balances and transactions are used solely to display your financial information within your Bentokai workspace and are visible only to users you have granted access to that brand.

4. Social media accounts

Bentokai's Social feature lets a business connect the social media profiles it manages so that it can publish and schedule posts, see how its profiles and posts perform and, when it uses the inbox feature, read and answer comments and messages in one place.

How connection works. A user with permission on a brand connects a Facebook Page, an Instagram professional account, a LinkedIn company page or a Google Business Profile location through that platform's own authorisation screen, which shows what Bentokai is asking to access. We never see or store your password for that platform. The access can be revoked at any time, in Bentokai or at the platform (see "Disconnecting and deleting" below).

What we receive and store.

Purpose. We use this data only to provide the features the user asked for: publishing and scheduling posts, showing the performance of the profiles and their posts, and reading and replying to comments, reviews and messages. We do not sell it, use it for advertising, use it to build profiles of individuals or use it to train artificial intelligence models. We share it only with the platform itself, when a user publishes or replies, and, as needed to deliver the service, with the service providers named in section 6, such as our hosting provider. Within Bentokai it is visible only to the users who have been given access to the Social feature on that brand.

Our role. For the account data of the person who connects a profile (their platform user id and name, and the authorisation itself), Umai Media acts as controller. For the personal data of other people that reaches Bentokai through a connected profile, such as the names and content in comments, reviews and messages from members of the public, Umai Media acts as a processor on behalf of the business customer that connected the profile, under the data processing agreement in section 11 of our Terms of Service; that customer decides why and how the data is used. If your comment, review or message reached a business through Bentokai, you can contact that business, or write to privacy@bentokai.com and we will pass your request on to it.

Data received from Google. Bentokai's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Our staff do not read this data unless the user has given permission (for example, to resolve a support request), it is necessary for security purposes, or it is required to comply with the law.

How long we keep it.

Disconnecting and deleting.

When you remove Bentokai at Facebook or Instagram you can also ask Meta to have your data deleted. Meta passes the request to us and we automatically delete the authorisations you gave and the profiles connected through them, with their data; Meta then shows you a confirmation code and a link to a page where you can check the status of your request. You can also ask us to delete this data by writing to privacy@bentokai.com: we complete the request within 10 days for data received from LinkedIn and within 30 days otherwise.

The platforms' own terms. Our access to each platform is governed by the Meta Platform Terms, the LinkedIn API Terms of Use and the Google API Services User Data Policy. What each platform does with your data is described in its own privacy policy: Meta, LinkedIn and Google.

5. How we use your data and our legal bases

This section describes the purposes and legal bases of the processing for which we are the controller. For the business data we process on our customers' behalf (section 1), such as the contents of imported documents or the data about the visitors to their websites, we act only on the customer's instructions to provide the features it uses, and the customer determines the legal basis.

6. Sharing and processors

We do not sell personal data. We share it only with the service providers below, which act on our instructions under appropriate agreements, and only as needed to deliver the service. For the business data we process on our customers' behalf (section 1), these providers are our sub-processors, engaged under the general authorisation in section 11 of our Terms of Service; we will update this list at least 30 days before adding or replacing one.

When you use the Social feature (section 4), the platform you connect receives the content you publish or reply with and the requests we make on your behalf: Meta Platforms Ireland Ltd. (Facebook and Instagram), LinkedIn Ireland Unlimited Company (LinkedIn) and Google Ireland Ltd. / Google LLC (Google Business Profile). These platforms are not our sub-processors: each handles that data under its own terms and privacy policy.

Public services and authorities. Some features send a request to a public service, which receives only what it needs to answer and is not our sub-processor. When the website icon of a contact, a supplier or a brand cannot be fetched from the website itself, our server asks Google's public favicon service (t0.gstatic.com) for it, which sends Google that website's domain name, for example example.com (for a contact, this can be the domain of their business email address), and nothing else about the contact or supplier. The Speed feature sends Google's PageSpeed Insights and Chrome UX Report services the public web addresses of the pages a customer asks it to measure. When a customer activates the submission of its invoicing records to the Spanish Tax Agency (VERI*FACTU), the records of the invoices it issues, including its clients' names and tax identification numbers, are sent to the Agencia Estatal de Administración Tributaria, which receives them as a public authority, as the law requires.

7. International transfers

The data Bentokai stores is kept on servers in the European Union (section 6), and your data is primarily processed within the European Economic Area. The providers of AI document extraction and of location lookups (at sign-in and for web analytics) named in section 6 process data in the United States, and our email provider, Google, may also do so; for these and any other transfer outside the EEA we rely on appropriate safeguards such as the European Commission's standard contractual clauses. The social media platforms named in section 6 may also process data in the United States; where that involves a transfer outside the EEA, it relies on the standard contractual clauses or, where the recipient is certified under it, the EU-US Data Privacy Framework.

8. Data retention

We keep your data for as long as your account is active and as needed to provide the service. When you disconnect a bank account, its stored balances and transactions are removed from that connection. Data from connected social media profiles follows the specific rules in section 4, including the shorter limits for data received from LinkedIn. You can ask us to delete your account and associated data as described below.

For the data about the people our customers serve (section 2):

9. Your rights

Under the GDPR you have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent at any time. To exercise these rights, contact privacy@bentokai.com. You also have the right to lodge a complaint with your local data protection authority (in Spain, the Agencia Española de Protección de Datos).

If your data reached Bentokai as part of a customer's business data (section 1), for example because you visited that customer's website or used its portal, that customer is the controller and the one to contact; if you write to us instead, we will pass your request on to it and help it respond.

10. Security

We protect data with encryption in transit, hashing of credentials, and encryption at rest for sensitive fields such as contact details, status-page subscribers' email addresses, connected financial credentials and social media access tokens. Access is gated by per-user permissions.

11. Children

Bentokai is a business tool intended for use by authorised representatives of companies. It is not directed at children, and we do not knowingly collect personal data from anyone under 18.

12. Cookies

We use only first-party cookies that are strictly necessary to provide the service or that store a preference you chose, and no advertising or third-party tracking cookies. Each cookie, its purpose and its lifetime are described in our Cookie Policy. The web-analytics and page-speed scripts our customers add to their websites set no cookies and store nothing on their visitors' devices.

13. Changes to this policy

We may update this policy from time to time. Material changes will be reflected here.

14. Contact

Questions about this policy or your data: privacy@bentokai.com, or by post to Umai Media, S.L., Calle San Gerardo 50, 28035 Madrid, Spain.