In short. Intelligence by Bearingbridge is operated from Hong Kong by Beyond Border Group Limited. We hold the data needed to run your account and your organization, and we process the content you put into the product on your organization's instructions. Prompts and the files attached to them are sent to the AI providers that run the models you choose, through a single gateway; we do not train models on your content and we do not sell personal data. Card details never reach us: payments are handled by Stripe. You can ask us at any time what we hold about you, have it corrected, or have it erased where no law requires us to keep it. The full text below is the policy; this summary is only a courtesy.
01Who we are and what this policy covers
Beyond Border Group Limited, a company incorporated in the Hong Kong Special Administrative Region of the People's Republic of China ("Beyond Border", "we", "us", "our"), operates the platform known as Intelligence by Bearingbridge, reachable through the bearingbridge.ai and bearingbridge.com domains and any related application, interface or API (together, the "Services").
This policy explains what personal data the Services process, why, with whom it is shared, how long it is kept and what you may ask of us. It applies to visitors of the sign-in pages, to the individuals who hold an account, and to the personal data contained in the content an organization puts into the Services. It sits alongside our Terms of Service, which govern the use of the Services themselves.
02Our role: controller and processor
We act in two different capacities, and your rights are exercised differently in each.
- As controller, for the data needed to open, run, secure and bill an account: identity, sign-in, organization membership, credit balance, purchases, support exchanges and the technical records of use of the Services. We decide why and how that data is processed, and this policy is your reference.
- As processor, for the content an organization puts into the Services: files, records, prompts, connected systems and the results produced from them ("Customer Data"). We process it on the documented instructions of the organization, which is the controller of it. If you are an employee, a client or a contact of an organization using the Services and you want to know what it holds about you, ask that organization; we will refer your request to it.
03The data we process
- Account data. Your name, your e-mail address, your interface language, your role, the organization and the brands you belong to, and your notification preferences. Passwords are never stored in readable form: authentication is operated by our database provider, which keeps only a cryptographic hash.
- Sign-in and security records. Sign-ins, sign-outs and password reset requests, each with its date and time, the network address the request came from and the browser's user agent string. Your acceptance of the Terms of Service is recorded the same way, as evidence of that acceptance.
- Usage records. The work run in the product: which module, at what time, by which account, on which model, how long it took, what it cost in credits, and whether it succeeded. These records are what the product shows you in the Activity log and in the spend ledger.
- Billing data. Purchases of credits, their amount and currency, the state of each payment, invoices, and the reference of the payment held by our payment processor. We never receive or store full card numbers.
- Customer Data. Everything an organization or its users submit: uploaded files and the assets generated from them, client, supplier and contact records, tasks and projects, prompts and the text, images and video produced in reply, feeds, and the data read from the systems the organization connects. It may contain personal data about third parties, and we process it as a processor (section 2).
- Communications. The e-mails the Services send you, kept in a log with their date, recipient, subject and purpose so that support can confirm what was sent and resend it, and the messages you send us through the contact and bug report forms.
04Where the data comes from
Most of it comes from you: what you type, upload, connect or buy. Some comes from the administrator of your organization, who creates accounts, sets roles and grants access to brands and to connected systems. Some is produced by the Services themselves as you use them: usage records, costs, activity. And some is read, on the organization's instruction, from the third-party systems it connects, such as advertising accounts, customer relationship systems, social accounts, search data providers and any server or interface it links to the product.
05Why we process it, and on what basis
- To provide the Services you and your organization asked for: running the modules, keeping balances and history, storing files, sending the results. Basis: performance of our contract with you or with your organization.
- To bill correctly: price each run, deduct credits, record purchases, issue invoices, and keep the accounting records the law requires. Basis: performance of the contract, and legal obligation for the accounting part.
- To keep the Services secure and available: detect abuse, investigate incidents, prevent fraudulent use of credits, and keep the sign-in records that let us answer "who accessed this account, and when". Basis: our legitimate interest in a secure service, and the security duty owed to our customers.
- To support and inform you: answer your messages, tell you about a failed run, a scheduled publication, a low balance, a change to these documents, or the weekly summary of product changes, which you can switch off at any time. Basis: performance of the contract for service messages, consent for anything you can unsubscribe from.
- To improve the product: understand which parts are used, where runs fail, what they cost. This is done on aggregated and de-identified figures wherever it can be. Basis: our legitimate interest, weighed against your privacy.
We do not sell personal data, we do not rent it, and we do not use it for advertising.
06Artificial intelligence and model providers
Every AI run sends what it needs to the model that runs it: your prompt, the instructions of the agent or module, and the files, texts or images attached to the request. These calls leave through a single gateway operated by our hosting provider, which routes them to the provider of the model chosen for that module or organization. The name of the model, the provider behind it and the price of each run are shown in the product before the run and recorded after it.
We do not use Customer Data to train models, our own or anyone else's, and we select providers whose interface terms do not use the content submitted through them to train their models by default. The providers process the content as needed to return the result and under their own terms and retention rules, which we cannot vary for you; where a provider's terms change in a way that matters, we say so in the product.
AI results are produced by statistical models and can be wrong. Nothing in the product decides anything about a person on its own (section 17).
07Systems you connect
An organization may connect its own systems to the Services: advertising and analytics accounts, customer relationship systems, social accounts, search data providers, and any other server or interface it chooses to link. Only the administrators of an organization may add, change or remove a connection, and who may read each connected system is set person by person on the Users page.
Connecting a system stores the credential the connection needs and the settings of the connection. That credential is used only to make the calls the product needs for the work asked of it, is never shown back in full, and can be revoked by an administrator at any time, in the product and at the provider. What each provider then does with the requests we send is governed by that provider's own privacy policy.
08Payments
Credit purchases are handled by Stripe, which is the payment processor and is the controller of the card data it collects. Card numbers and authentication details are entered on Stripe's own pages and never reach our servers. We receive and keep what we need to show your purchase history and to keep our accounts: the amount, the currency, the date, the method used, the state of the payment, its reference, and the invoice.
09E-mail and notifications
Service e-mails, such as a password reset, an invitation, a validation request, a failed publication or a receipt, are sent through our e-mail provider. Every e-mail the Services send is written to a log with its date, its recipient, its subject and the reason it was sent, so that support can confirm a delivery and, when a link has expired, send it again. Messages you can unsubscribe from carry a link that works without signing in and stops them at once.
10Cookies and local storage
The Services use no advertising cookie and no third-party tracking. What is stored in your browser is what a signed-in session needs:
- bbg_lang, a cookie remembering your interface language;
- bbg_at, a cookie readable only by the server, which lets pages be rendered for a signed-in person;
- the session token and its refresh token, kept in the browser's local storage so that a tab you reopen is still signed in, and removed when you sign out.
11Who else processes the data
We rely on a small number of providers, each engaged under a written agreement, each limited to what the Services need from it: a database, authentication and file storage provider; a hosting provider, which also operates the AI gateway; the providers of the AI models reached through that gateway; a payment processor; an e-mail sending provider; and providers of search and market data where a module needs them. In addition, the platforms an organization connects itself (section 7) receive the requests that organization asks us to send them.
We also disclose data where the law requires it, to protect our rights or the safety of a person, and to a successor if our business is transferred, in which case this policy continues to apply to the data transferred.
12International transfers
We operate from Hong Kong, and our providers operate from several countries, so personal data is processed outside Hong Kong and, for European users, outside the European Economic Area. Where such a transfer takes place, it is covered by the contractual protections our agreement with the provider requires, including the European Commission's standard contractual clauses where they apply.
13How long we keep it
- Account data: while the account exists.
- Customer Data: while the organization keeps it. Deleting a file, a record or an asset in the product removes it from the product; copies held in ordinary backups age out with those backups.
- Sign-in, security and usage records: kept while they are useful for security and for answering billing questions, then removed or reduced to figures that identify no one.
- Billing records and invoices: seven years, as Hong Kong company and tax law requires.
- The e-mail log: while the account exists, so that a message can be confirmed or resent.
A login is deactivated rather than erased when a person leaves an organization: the billing history, the activity log and the audit trail of the organization stay truthful and continue to name what was done. On request, we erase the personal data of a person that we are not required to keep, and replace their name in the records we must keep with a reference that does not identify them.
14Security
Access to data follows the organization, the brand and the role: a person sees the organization they belong to, the brands they were granted, and the connected systems an administrator opened to them, and nothing else. Traffic is encrypted in transit, passwords are stored as hashes by our authentication provider, administrative actions and sign-ins are logged, and access to production systems is limited to the people who need it. No system is perfectly secure; if a breach affects your personal data and is likely to harm you, we will tell you and the competent authority as the law requires.
15Your rights
Wherever you are, you may ask us to tell you what personal data we hold about you, to correct it, to give you a copy in a portable form, to erase it, to restrict or object to a particular processing, and to withdraw a consent you gave, without that withdrawal affecting what was done before.
Hong Kong law (the Personal Data (Privacy) Ordinance, Cap. 486) gives you a right of access and of correction, which we answer within forty days. If the General Data Protection Regulation applies to you, you hold the rights it grants and may complain to your supervisory authority. If the Personal Information Protection Law of the People's Republic of China applies to you, you hold the rights it grants, including the right to ask for an explanation of how your information is handled.
Write to us as set out in section 18. We answer free of charge, and we may ask you to confirm your identity before acting. Where the request concerns Customer Data held for an organization, we pass it to that organization and support it in answering.
16Children
The Services are a professional product and are not directed at children. We do not knowingly create accounts for persons under 18. If you believe a child's personal data has reached the Services, tell us and we will remove it.
17Automated decisions
The Services generate text, images, analyses and recommendations with AI, and they price and deduct credits automatically. They take no decision producing legal effects on a person, or similarly affecting a person, without a human deciding. The proposals a module makes are for a person to read, judge and act on.
18Changes, contact and complaints
We may amend this policy. The current version, identified by the version date at the top of this page, is always available at this address, and a material change is announced in the product or by e-mail.
For any question about this policy, any request about your data, or any complaint, write to Beyond Border Group Limited, Hong Kong SAR, through the contact form in the product or at bearingbridge.com, giving the e-mail address of your account and the name of your organization. If you are not satisfied with our answer, you may complain to the Office of the Privacy Commissioner for Personal Data in Hong Kong, or to the supervisory authority of your country where one has jurisdiction over you.