Privacy Policy
This Privacy Policy explains how Bentokai collects, uses, and protects personal data when you use this website and our platform at app.bentokai.com, including the optional bank-connection (open banking) and social media features, and when you visit a website or use a page that one of our customers runs with Bentokai.
1. Who we are
Bentokai is operated by Umai Media, S.L. (VAT ESB26634485), Calle San Gerardo 50, 28035 Madrid, Spain ("Umai Media", "we", "us"). You can reach us at privacy@bentokai.com.
Where we are the controller. Umai Media, S.L. is the data controller for the personal data of the people who have a Bentokai account and use it (their account, profile and authentication data), for the security and technical data described in section 2, and for the data processed through this website. This policy mainly describes that processing.
Where we process data for our customers. The business data our customers put into Bentokai, such as their contacts, the clients and suppliers in their invoices and other records, the people who appear in the bank transactions they import, and the personal data of other people in the social media profiles they connect (such as the names and content in comments, reviews and messages), is processed by Umai Media on the customer's behalf, under the data processing agreement in section 11 of our Terms of Service. So is the data about the people our customers serve through Bentokai: the visitors to their websites, the people who search on them, and the people who subscribe to their status pages or use their support and project portals (see section 2). For that data, the customer is the controller and decides why and how it is used; we act only on its instructions.
2. Information we collect
- Account & profile data: name, email, language and display preferences, and authentication data (passwords are stored only as salted hashes; passkeys where you enable them).
- Content you add: the accounts, brands, contacts, invoicing details and similar records you create in the platform, and the supplier bills delivered by the integrations and email mailboxes a brand connects (to find bills in a mailbox, Bentokai reads the sender, subject and attachment details of its messages, and never changes the mailbox). The personal data of other people in these records, such as contacts, clients and suppliers, is business data we process on the customer's behalf (see section 1).
- Bank account information: where you choose to connect a bank account, the balances and transaction history of that account (see section 3). The people who appear in those transactions are part of the customer's business data (see section 1).
- Social media data: where a brand connects its social media profiles, the authorisation for each one, the profiles' public details, the content published through Bentokai, the profiles' performance statistics and, if the inbox feature is used, the comments, reviews and messages they receive (see section 4, which also explains which of this data we process on the customer's behalf).
- Technical data: sign-in sessions, device and browser information, IP address and approximate location (country and internet provider, looked up at sign-in and shown on your Security page), and an activity log of actions taken in the panel, used for security and support. Our web servers also log each request they receive, including those made by the visitors to our customers' websites and public pages (IP address, browser user agent, the address requested, the referring page and the time), for security and troubleshooting.
- Email engagement: for the emails the platform sends (invoice and support emails; security emails such as password resets are not tracked), we record delivery, whether the email was opened (a tracking pixel) and which of its links were clicked, with timestamps. For the emails a customer sends to its own clients through Bentokai, such as invoices, this record is part of that customer's business data (see section 1).
- Data about the people our customers serve: where a
customer uses the features below, we process, on that customer's behalf
(see section 1), data about the visitors to its websites and the people
who use its public pages. If you visited or used one of them, the customer
that runs it is the controller and the first one to contact. On all of
these pages and endpoints, the IP address is also used briefly to prevent
abuse (rate limiting).
- Web analytics: a script (the "tag") on the
customer's website sends us, for each page viewed, the page's address
and title, the referring page, any campaign parameters in the link
(such as
utm_source), the browser's language, the screen and window size and the time spent on the page and, where the customer enables it, the addresses of the links clicked. From the request we work out the type of device, the browser and operating system, whether the visit comes from an automated crawler, and the country, region and city. To count visitors without identifying them, we derive a visitor code from the IP address and the browser's user agent with a secret key that changes every day; each day's key is destroyed after two days, and from then on no one, including us, can link that day's codes to an IP address. The IP address itself is not stored with the analytics data. For the location, only the network part of the address (the first three of the four numbers of an IPv4 address, or the first 48 bits of an IPv6 address) is sent to ip-api.com. The tag sets no cookies and stores nothing on the visitor's device and, unless the customer has switched this off, a browser that sends the Global Privacy Control signal sends only an empty signal, which is counted without any other data. The data is stored in a database on our own servers (section 6). - Crawler detection: to count visits from automated crawlers, such as search engines and AI crawlers, the customer may also add an image to its pages or have its own server report the crawler visits it receives, with the page, the user agent and the IP address. We check each report against our own list of crawlers, and a crawler's claimed identity against the address ranges its operator publishes, and discard reports about people.
- Page speed: a script the customer can add to its pages reports how quickly they load and respond for its visitors, and the type of device. It is kept only as counts per range of values and per day, with no page address, IP address, user agent or other identifier; visits from crawlers are discarded.
- Site search: the terms that visitors typed into the search on the customer's website and how many times each was searched, read from the customer's own search server. We receive terms and counts, not who searched, although a term can contain personal data if a visitor typed it.
- Search performance: the Google Search queries and pages through which the customer's website was found, with click and impression totals, as Google Search Console provides them; Google does not tell us who searched.
- Status pages: the email address of anyone who subscribes to a customer's status page to be told about incidents (stored encrypted), whether they have confirmed the subscription, and the emails sent to them. Every notification includes a link to unsubscribe.
- Support portal: when someone opens a ticket on a customer's support portal (at portal.bentokai.com) or through a form on the customer's website that sends it to Bentokai, their name, email address and, if given, phone number, the ticket's subject, the messages and attached images and, for a ticket sent from the customer's website, the technical details that website sends with it (such as the IP address, the browser's user agent and the referring page).
- Project client portal: when a customer invites one of its contacts to follow a project on its portal, the invitation, when the portal was last used, and the comments and files the contact adds there.
- Web analytics: a script (the "tag") on the
customer's website sends us, for each page viewed, the page's address
and title, the referring page, any campaign parameters in the link
(such as
3. Bank account information and open banking
Bentokai's Treasury feature lets you connect your own bank accounts to view their balances and movements inside the platform. This access is:
- Explicitly authorised by you at your own bank. You authenticate directly on your bank's or provider's page; we never see or store your online banking credentials.
- Read-only. We retrieve account details, balances and transactions only. Bentokai does not initiate payments or move money.
- Provided through licensed account-information service providers (AISPs), Enable Banking and, where applicable, GoCardless Bank Account Data, which are regulated to provide open-banking access under PSD2. They facilitate the connection to your bank on your instruction.
Accounts at Wise and Qonto can instead be connected directly through those providers' own interfaces, by signing in at the provider or with an API key you create there, which we store encrypted; this access is read-only too.
The imported balances and transactions are used solely to display your financial information within your Bentokai workspace and are visible only to users you have granted access to that brand.
4. Social media accounts
Bentokai's Social feature lets a business connect the social media profiles it manages so that it can publish and schedule posts, see how its profiles and posts perform and, when it uses the inbox feature, read and answer comments and messages in one place.
How connection works. A user with permission on a brand connects a Facebook Page, an Instagram professional account, a LinkedIn company page or a Google Business Profile location through that platform's own authorisation screen, which shows what Bentokai is asking to access. We never see or store your password for that platform. The access can be revoked at any time, in Bentokai or at the platform (see "Disconnecting and deleting" below).
What we receive and store.
- The authorisation: the access and refresh tokens the platform issues (encrypted at rest), the permissions granted and when they expire, and the platform user id and name of the person who connected the profile.
- The connected profiles: each profile's id, name, username, web address, profile picture and follower count, refreshed daily while the profile is connected.
- Content to publish: the text, links, images and videos users create in Bentokai for publication, which are sent to the platform when the post is published, and afterwards the published post's id and link. Some platforms fetch images and videos from a web address instead of accepting an upload, so while a post is being published a temporary public copy of the file exists at an unguessable address, for at most 48 hours.
- Performance statistics: figures for the connected profiles and their posts, such as views, reach, engagements, followers and clicks (and, for Google Business Profile, figures such as calls, website clicks and direction requests), and for each post its text excerpt, a thumbnail image, its link and its date, including posts made directly on the platform rather than through Bentokai. These figures are totals; we do not receive the identities of the people counted in them.
- Comments, reviews and messages, when the inbox feature is used: comments on the brand's posts, reviews of its Google Business Profile locations and messages sent to its Facebook and Instagram profiles, with the sender's public name, username and profile picture as the platform provides them, and the replies users write in Bentokai, which are sent to the platform. For LinkedIn this covers comments only.
Purpose. We use this data only to provide the features the user asked for: publishing and scheduling posts, showing the performance of the profiles and their posts, and reading and replying to comments, reviews and messages. We do not sell it, use it for advertising, use it to build profiles of individuals or use it to train artificial intelligence models. We share it only with the platform itself, when a user publishes or replies, and, as needed to deliver the service, with the service providers named in section 6, such as our hosting provider. Within Bentokai it is visible only to the users who have been given access to the Social feature on that brand.
Our role. For the account data of the person who connects a profile (their platform user id and name, and the authorisation itself), Umai Media acts as controller. For the personal data of other people that reaches Bentokai through a connected profile, such as the names and content in comments, reviews and messages from members of the public, Umai Media acts as a processor on behalf of the business customer that connected the profile, under the data processing agreement in section 11 of our Terms of Service; that customer decides why and how the data is used. If your comment, review or message reached a business through Bentokai, you can contact that business, or write to privacy@bentokai.com and we will pass your request on to it.
Data received from Google. Bentokai's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Our staff do not read this data unless the user has given permission (for example, to resolve a support request), it is necessary for security purposes, or it is required to comply with the law.
How long we keep it.
- Access tokens, profile details and statistics are kept while the profile is connected. When a profile is disconnected, its profile details, statistics and inbox data are deleted, and so are its access tokens once no other connected profile uses them.
- When access is revoked at Facebook or Instagram, Meta notifies us and we delete the tokens straight away. On any platform, a profile whose access has been revoked or has expired can no longer be used and stays marked for reconnection until it is reconnected or disconnected.
- Data received from LinkedIn: post content (text excerpt, thumbnail and link) is kept for at most 6 months and statistics for at most 12 months. Where a platform's terms set a shorter limit for any data, we apply it.
- Media uploaded for publication stays with its post until the post is deleted; temporary public copies are removed within 48 hours.
- Posts created in Bentokai, with the name of each profile they were published to and the link to the published post, stay in the brand's post history until the post is deleted, including after the profile is disconnected.
Disconnecting and deleting.
- In Bentokai: a user with permission disconnects a profile under Social → Profiles; its data is deleted as described above. Once nothing in Bentokai uses an authorisation any more, we also ask Facebook or Google to revoke it. For Instagram accounts connected directly with Instagram, and for LinkedIn, the platform offers no such request, so use its settings below.
- At Facebook: Settings & privacy → Settings → Business integrations, then remove Bentokai.
- At Instagram: Settings → Website permissions → Apps and websites, then remove Bentokai.
- At LinkedIn: Me → Settings & Privacy → Data privacy → Permitted services, then remove Bentokai.
- At Google: remove Bentokai's access in your Google Account at myaccount.google.com/permissions.
When you remove Bentokai at Facebook or Instagram you can also ask Meta to have your data deleted. Meta passes the request to us and we automatically delete the authorisations you gave and the profiles connected through them, with their data; Meta then shows you a confirmation code and a link to a page where you can check the status of your request. You can also ask us to delete this data by writing to privacy@bentokai.com: we complete the request within 10 days for data received from LinkedIn and within 30 days otherwise.
The platforms' own terms. Our access to each platform is governed by the Meta Platform Terms, the LinkedIn API Terms of Use and the Google API Services User Data Policy. What each platform does with your data is described in its own privacy policy: Meta, LinkedIn and Google.
5. How we use your data and our legal bases
This section describes the purposes and legal bases of the processing for which we are the controller. For the business data we process on our customers' behalf (section 1), such as the contents of imported documents or the data about the visitors to their websites, we act only on the customer's instructions to provide the features it uses, and the customer determines the legal basis.
- To provide the service you have signed up for (performance of a contract).
- To connect and display your bank data (your explicit consent, which you can withdraw at any time by disconnecting the account).
- To connect and use social media profiles: publishing, statistics and the inbox (performance of the contract with the business customer; for other people's data in those profiles, such as comments and messages, we act on the business customer's instructions, and the customer relies on its legitimate interest in managing its own social media presence).
- To keep the service secure: authentication, fraud prevention, the activity log and our web servers' request logs (our legitimate interest in operating a secure service).
- To read documents you import: when you import an invoice PDF, or a supplier bill or receipt as an expense, and it cannot be read fully automatically, we send our AI provider (Anthropic) the document's text (for an invoice, up to the first ~12,000 characters) or, for a photographed receipt, its image, to identify its fields, solely to complete the import you requested. The same provider powers optional interface translations.
- To measure email engagement: delivery, opens and link clicks on platform emails (our legitimate interest in confirming that transactional email reaches its recipient; for the emails a customer sends to its own clients, such as invoices, we do this on that customer's behalf).
- To comply with legal obligations where they apply.
6. Sharing and processors
We do not sell personal data. We share it only with the service providers below, which act on our instructions under appropriate agreements, and only as needed to deliver the service. For the business data we process on our customers' behalf (section 1), these providers are our sub-processors, engaged under the general authorisation in section 11 of our Terms of Service; we will update this list at least 30 days before adding or replacing one.
- OVH SAS (OVHcloud), 2 rue Kellermann, 59100 Roubaix, France: hosts the servers on which Bentokai runs and stores its data, including the web-analytics database, in the European Union;
- the open-banking providers named in section 3, when you connect an account;
- Google Ireland Limited / Google LLC (Google Workspace): Bentokai sends its emails through Google Workspace's SMTP relay service, which processes each email's recipients and content, including attachments; this covers invoices and payment reminders sent to your clients, notifications, scheduled reports, support replies, the emails of status pages and customer portals, and sign-in and security emails;
- Anthropic, PBC (United States): processes the text of the documents you import, or the image of a photographed receipt, when they need automated extraction as described in section 5, the text of catalog and help-content translations, and page-speed measurements when a user asks for an explanation of them;
- ip-api.com: receives your IP address at sign-in to provide the country and internet-provider information shown on your Security page (processing for which we are the controller) and, for customers that use web analytics, the network part of their visitors' IP addresses, to provide the country, region and city (section 2).
When you use the Social feature (section 4), the platform you connect receives the content you publish or reply with and the requests we make on your behalf: Meta Platforms Ireland Ltd. (Facebook and Instagram), LinkedIn Ireland Unlimited Company (LinkedIn) and Google Ireland Ltd. / Google LLC (Google Business Profile). These platforms are not our sub-processors: each handles that data under its own terms and privacy policy.
Public services and authorities. Some features send a request
to a public service, which receives only what it needs to answer and is not our
sub-processor. When the website icon of a contact, a supplier or a brand cannot be
fetched from the website itself, our server asks Google's public favicon service
(t0.gstatic.com) for it, which sends Google that website's domain name, for
example example.com (for a contact, this can be the domain of their
business email address), and nothing else about the contact or supplier. The
Speed feature sends Google's PageSpeed Insights and Chrome UX Report services the
public web addresses of the pages a customer asks it to measure. When a customer
activates the submission of its invoicing records to the Spanish Tax Agency
(VERI*FACTU), the records of the invoices it issues, including its clients' names
and tax identification numbers, are sent to the Agencia Estatal de Administración
Tributaria, which receives them as a public authority, as the law requires.
7. International transfers
The data Bentokai stores is kept on servers in the European Union (section 6), and your data is primarily processed within the European Economic Area. The providers of AI document extraction and of location lookups (at sign-in and for web analytics) named in section 6 process data in the United States, and our email provider, Google, may also do so; for these and any other transfer outside the EEA we rely on appropriate safeguards such as the European Commission's standard contractual clauses. The social media platforms named in section 6 may also process data in the United States; where that involves a transfer outside the EEA, it relies on the standard contractual clauses or, where the recipient is certified under it, the EU-US Data Privacy Framework.
8. Data retention
We keep your data for as long as your account is active and as needed to provide the service. When you disconnect a bank account, its stored balances and transactions are removed from that connection. Data from connected social media profiles follows the specific rules in section 4, including the shorter limits for data received from LinkedIn. You can ask us to delete your account and associated data as described below.
For the data about the people our customers serve (section 2):
- Web analytics: each page view and event is kept for the period the customer sets, from 1 to 800 days (365 by default), and then deleted; the daily totals built from them, which contain no visitor code or IP address, are kept until the customer's brand is deleted or the service ends. Each day's secret key is destroyed after two days, the location found for a network is kept for up to 90 days, and backups of the analytics database are kept for 7 days.
- Page speed and site search: for the period the customer sets, 24 months by default (up to 60 months for page speed and 120 months for site search). Search performance data: while the customer's website stays connected.
- Status-page subscriptions: until the person unsubscribes or the customer removes the subscriber or the page.
- Support tickets and project portal content: for as long as the customer keeps them in Bentokai, and at the latest until the end of the service (section 11 of our Terms of Service).
- Our web servers' request logs: only as long as needed for security and troubleshooting.
9. Your rights
Under the GDPR you have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent at any time. To exercise these rights, contact privacy@bentokai.com. You also have the right to lodge a complaint with your local data protection authority (in Spain, the Agencia Española de Protección de Datos).
If your data reached Bentokai as part of a customer's business data (section 1), for example because you visited that customer's website or used its portal, that customer is the controller and the one to contact; if you write to us instead, we will pass your request on to it and help it respond.
10. Security
We protect data with encryption in transit, hashing of credentials, and encryption at rest for sensitive fields such as contact details, status-page subscribers' email addresses, connected financial credentials and social media access tokens. Access is gated by per-user permissions.
11. Children
Bentokai is a business tool intended for use by authorised representatives of companies. It is not directed at children, and we do not knowingly collect personal data from anyone under 18.
12. Cookies
We use only first-party cookies that are strictly necessary to provide the service or that store a preference you chose, and no advertising or third-party tracking cookies. Each cookie, its purpose and its lifetime are described in our Cookie Policy. The web-analytics and page-speed scripts our customers add to their websites set no cookies and store nothing on their visitors' devices.
13. Changes to this policy
We may update this policy from time to time. Material changes will be reflected here.
14. Contact
Questions about this policy or your data: privacy@bentokai.com, or by post to Umai Media, S.L., Calle San Gerardo 50, 28035 Madrid, Spain.