Privacy Policy
This Policy forms part of, and should be read together with, the Beginso Terms of Use, Acceptable Use Policy, Fair Use / Free Plan Policy, Cookie Policy, and any applicable Subscription Plan, enterprise agreement or Data Processing Agreement.
1. Introduction and Scope
1.1 About This Policy
This Privacy Policy ("Policy" or "Privacy Policy") describes how Beginso ("Beginso", "we", "us" or "our"), and/or its parent company, affiliates, subsidiaries and group entities, collects, uses, stores, discloses, transfers and otherwise processes personal data in connection with the Beginso software-as-a-service platform available through https://beginso.com/ and any associated websites, web applications, mobile applications, services, interfaces, tools and features made available by Beginso from time to time (collectively, the "Platform").
Beginso is a form-management, information-collection, response-management, reporting and workspace-collaboration software-as-a-service platform. The Platform may enable Users to create and configure Forms, build multi-page Forms, apply conditional logic, customise branding, publish Forms, generate public URLs, embed Forms, generate QR codes, collect information from Respondents, receive file uploads, review and manage Submissions, analyse responses, generate CSV and PDF reports, use Templates, create and manage Workspaces, invite Team Members, assign roles and permissions, share Forms, review activity and audit information, and manage account, security, notification, session and device settings.
The Platform may evolve over time, and this Policy applies to existing features as well as new or modified features to the extent they involve processing of personal data.
1.2 Who This Policy Covers
This Policy applies, as relevant, to:
- Registered Users who create or maintain a Beginso Account
- individuals using the Platform on behalf of a company, organisation, partnership, institution or other entity
- Workspace Owners, administrators, Team Members and other Authorised Users
- Form Owners and persons authorised to manage Forms
- Respondents who access, partially complete or submit Public Forms
- individuals whose personal data is entered into the Platform by another person
- visitors to Beginso websites, landing pages and support resources
- trial, beta, free-plan, paid-plan and enterprise Users
- persons who contact Beginso for support, privacy, security, abuse, legal or grievance matters
- any other person whose personal data is processed by Beginso in connection with the Platform
1.3 Beginso's Role: Data Fiduciary / Controller and Data Processor
The role Beginso plays depends on the nature and purpose of the relevant processing.
A. Beginso as Data Fiduciary / Controller. For personal data that Beginso collects and for which Beginso determines the purposes and means of processing for its own operational, security, legal or business purposes, Beginso generally acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), to the extent that framework is in force and applicable, and as a Data Controller under the GDPR, UK GDPR or analogous privacy laws where applicable. This may include processing for Account administration, authentication, Platform security, billing, fraud and abuse prevention, support, service analytics, legal compliance and Beginso's own business administration.
B. Beginso as Data Processor / Service Provider. Where a Form Owner, Workspace Owner, organisation or enterprise customer uses Beginso to collect or otherwise process personal data from or about Respondents and determines what information is requested, why it is collected, who should provide it, how it will be used, who may access it and how long it should be retained, that customer generally acts as the relevant Data Fiduciary / Controller and Beginso may act as its Data Processor, service provider or equivalent processor. In such cases, Beginso processes the relevant data primarily on the customer's instructions, subject to Beginso's independent legal obligations and the functionality of the Platform.
Where appropriate, Beginso may enter into a separate Data Processing Agreement ("DPA") with an enterprise or organisational customer. If a DPA expressly governs a particular processing activity, the DPA will apply to that activity to the extent stated in it.
1.4 Form Owner Responsibility
A Form Owner is independently responsible for determining whether it has a lawful basis, authority and any required consent for requesting, collecting, using, sharing, exporting and retaining Respondent Data. A Form Owner must, as applicable:
- comply with Applicable Law and applicable contractual obligations
- provide Respondents with any privacy notice required by law
- obtain valid consent where consent is legally required
- collect only data reasonably necessary for the stated purpose
- ensure that each Form is used for a lawful and legitimate purpose
- obtain appropriate authority before collecting personal data on behalf of another person or organisation
- configure and maintain appropriate access controls and permissions
- ensure that Team Members and other persons with access are properly authorised
- protect exported or downloaded copies of Respondent Data
- comply with heightened obligations applicable to sensitive, regulated, confidential or specially protected data
Beginso provides the technical infrastructure through which Forms, Submissions and related data may be created, processed, stored and managed. Except where Beginso independently determines a processing purpose, Beginso does not determine the business purpose for which an independent Form Owner collects Respondent Data.
1.5 Global Application and Applicable Privacy Laws
Beginso may be offered internationally. This Policy is intended to address applicable privacy and data-protection requirements including, where relevant, the DPDP Act and rules made thereunder in India, applicable provisions of the Information Technology Act, 2000 and related rules, the GDPR, the UK GDPR, applicable United States privacy laws including California privacy laws, and other mandatory privacy or data-protection laws applicable to Beginso based on the jurisdiction in which the Platform is offered or the individual is located. References to a law apply only to the extent that law is in force and applicable to the relevant processing activity.
Nothing in this Policy is intended to remove or waive a mandatory privacy or consumer right that cannot lawfully be excluded or waived.
1.6 Scope Exclusions
This Policy does not govern:
- the independent privacy practices of a Form Owner, customer or Workspace administrator acting for its own purposes
- third-party websites, applications, integrations, identity providers or services governed by their own terms and privacy notices
- information processed independently by a customer after it has been exported or downloaded from Beginso
- information that has been irreversibly anonymised so that no identifiable individual can reasonably be identified
1.7 Policy Evolution
Beginso is an evolving SaaS Platform. Features, Subscription Plans, integrations, collaboration capabilities, analytics, reporting functions, AI-assisted functionality and other services may change over time. Beginso may update this Policy where reasonably necessary to reflect changes in the Platform, Applicable Law or processing practices. Material changes may be communicated by email, in-Platform notice, prominent website notice or another reasonable method. Where Applicable Law requires fresh consent for a particular processing activity, Beginso will seek such consent.
2. Definitions and Interpretation
In this Policy, unless the context otherwise requires:
"Account" means a registered Beginso user account, including associated profile, settings, authentication and subscription information.
"Applicable Law" means all statutes, regulations, rules, directions, orders and legally binding obligations applicable to Beginso, a User, Respondent or a relevant processing activity in a relevant jurisdiction.
"Authorised User" means a person authorised to access or use Beginso through a Workspace, organisation, enterprise account or other permitted arrangement.
"Content" means Forms, questions, field labels, descriptions, branding, logic, configuration, files, documents, images, text, Submissions, Respondent Data, reports, comments, Workspace information, activity information and other material created, entered, uploaded, collected, submitted, stored or processed through the Platform.
"Data Fiduciary" has the meaning given under the DPDP Act, to the extent applicable.
"Data Principal" has the meaning given under the DPDP Act, to the extent applicable.
"Data Processor" means a person or service provider processing personal data on behalf of a Data Fiduciary, Controller or customer, as applicable under relevant law.
"Form" means a form, questionnaire, data-collection interface or similar collection mechanism created or managed using Beginso.
"Form Owner" means the User, customer or organisation that creates, owns, controls or administers a Form or on whose behalf the Form is operated.
"Personal Data" means information relating to an identified or identifiable natural person, including digital personal data within the meaning of the DPDP Act where applicable.
"Processing" means any operation performed on personal data, including collection, recording, organisation, storage, retrieval, consultation, use, analysis, sharing, disclosure, transmission, alteration, deletion or destruction.
"Public Form Link" means a URL, QR-code-linked interface, embedded Form or other access mechanism through which a Respondent may access a Form.
"Respondent" means a person who accesses, views, partially completes or submits information through a Form, whether or not that person has a Beginso Account.
"Respondent Data" means information entered, uploaded, submitted or otherwise provided through a Form or generated directly in connection with a Respondent's interaction with that Form.
"Sensitive or Specially Protected Data" means personal data or information subject to heightened or sector-specific protection under Applicable Law, which may include health information, financial information, biometric information, government-issued identifiers, identity documents, children's data, confidential records and other regulated information.
"Submission" means information submitted or saved by a Respondent through a Form.
"Subprocessor" means a third party engaged by Beginso to process personal data on Beginso's behalf.
"Team Member" means an individual granted access to a Workspace, Form or related data by a Workspace Owner, administrator or other authorised person.
"User" means any person or organisation accessing or using the Platform, including Registered Users, Workspace Users and Authorised Users.
"Workspace" means a Beginso environment through which Forms, Team Members, permissions, activity and related work may be organised and managed.
3. Categories of Information Collected
3.1 Overview
Beginso may obtain information directly from Users, directly from Respondents, from organisations administering Workspaces, automatically through Platform operation, from authentication providers, from service providers, or from third-party integrations authorised by a User. The categories collected depend on how the Platform is used.
3.2 Account and Profile Information
When a User creates, maintains or uses an Account, Beginso may process information such as:
- name and display name
- email address
- profile photograph or avatar, if provided
- organisation or company name
- job title, role or professional information, if provided
- authentication and account-verification information
- Account preferences
- notification preferences
- Workspace associations
- Subscription Plan information
- other Account information voluntarily provided by the User
Where authentication credentials are managed by a third-party identity provider, Beginso may receive authentication tokens, account identifiers and profile information necessary to enable login. Beginso does not intentionally retain plaintext passwords.
3.3 Google Sign-In and Other Identity Providers
Where a User signs in through Google or another identity provider, Beginso may receive information authorised by that provider, such as the User's name, email address, profile image, provider-specific account identifier and authentication or verification information. Beginso uses such information for authentication, Account operation, security and related Platform functions. The third-party identity provider's own terms and privacy practices also apply to its services.
3.4 Form Configuration and User-Created Content
Beginso processes information created or configured by Form Owners and authorised Users, including Form titles, descriptions, questions, field types, field labels, conditional logic, required-field settings, page organisation, branding, logos, appearance settings, publishing state, Public Form Links, sharing settings, access configuration, status information and other Form settings.
3.5 Respondent Data and Form Submissions
When a Respondent uses a Form, Beginso may process any information requested by the Form Owner and provided by the Respondent. Depending on the Form, this may include name, email address, telephone number, address, dates, numerical information, business information, employment information, questionnaire answers, selections, free-text responses, documents, photographs, attachments and other information requested through the Form.
The nature and scope of Respondent Data are determined primarily by the Form Owner. Beginso does not independently require a Form Owner to collect any particular category of Respondent Data unless such information is necessary for Platform operation, security, legal compliance or another purpose expressly described in this Policy.
3.6 Uploaded Files and Documents
Where file-upload functionality is enabled, Respondents and Users may upload documents or files through the Platform. Beginso may process the file content and related metadata, including file name, file type, file size, upload time, associated Form, associated Submission, uploader information where available, preview information, storage location and security-related metadata. Uploaded files may be processed as necessary for storage, retrieval, preview, download, security, malware or abuse detection, Platform operation and legal compliance.
3.7 Workspace, Team and Permission Information
Where Users create or join Workspaces, Beginso may process Workspace name, organisation details, Team Member names and email addresses, invitation status, roles, permissions, access rights, shared-Form permissions, administrative actions and Workspace configuration information.
3.8 Activity and Audit Information
Beginso may process logs and activity information relating to Form creation and modification, publication, Workspace changes, invitations, membership changes, role and permission changes, response review, exports, authentication events, session activity, security events, administrative actions and other relevant Platform activity. Such information may be used for security, accountability, auditability, troubleshooting, abuse detection and organisational administration.
3.9 Analytics and Reporting Data
Beginso may generate analytics based on Form activity and Submissions, including response totals, trends, status information, question-level breakdowns, aggregated statistics, response activity, completion information and other reporting or operational insights. Analytics may be shown to Form Owners and authorised Workspace Users according to applicable permissions.
3.10 Reports and Exports
Users may generate, download or export CSV files, PDF reports, Submission information, Form information, analytics and other permitted reports. Once information has been exported from Beginso and stored independently by a User, Beginso may no longer control how that external copy is stored, used, shared, retained or deleted. The User is responsible for protecting and lawfully handling exported copies.
3.11 Automatically Collected Technical Information
When the Platform is accessed, Beginso may automatically process technical information such as IP address, browser type, device type, operating system, application version, language, approximate location derived from IP where used, session identifiers, authentication events, referring URLs, pages or screens viewed, navigation activity, feature interaction, timestamps, error logs, crash or diagnostic data, performance information, security logs and other technical information reasonably necessary to operate, secure and improve the Platform.
3.12 Sessions and Device Information
Because Beginso includes account-security and session/device-management functionality, the Platform may process information about active sessions, login events, device type, browser, IP information, approximate session location where derived from IP, authentication status and security events. Such information may be used to help Users review or terminate sessions and to protect Accounts.
3.13 Support, Grievance and Communications Data
When a person contacts Beginso, we may process the person's name, email address, telephone number if supplied, support request, correspondence, screenshots, attachments, diagnostic information, relevant Account/Form/Workspace identifiers, complaint or grievance details, and resolution history.
3.14 Subscription, Billing and Payment Information
Where Beginso offers paid Subscription Plans or paid features, Beginso may process Subscription Plan details, billing contact information, billing address, transaction identifiers, invoice details, subscription status, renewal and cancellation information, tax-related information and payment status. Payments may be processed through third-party payment processors. Beginso does not intend to store full payment-card details on its own systems where such details are handled directly by a compliant third-party payment processor.
3.15 Cookies and Similar Technologies
Beginso may use cookies, local storage, software development kits, analytics technologies, security technologies and similar mechanisms for authentication, security, functionality, preferences, analytics and other purposes described in Section 8 and the separate Cookie Policy.
4. Purposes of Processing and Lawful Bases
4.1 Account Creation, Authentication and Administration
Beginso may process personal data to create and maintain Accounts, authenticate Users, secure Accounts, maintain sessions, administer settings, manage Workspaces, provide invitations, manage permissions and support access to the Platform.
4.2 Platform Service Delivery
Beginso may process data to provide the Platform, including to create, configure and publish Forms; enable Public Form Links, embeds and QR-based access; receive and store Submissions; process uploaded files; manage Workspaces and Team access; provide analytics; generate reports and exports; maintain activity and audit information; and provide other requested Platform functions.
4.3 Processing on Behalf of Form Owners and Customers
Where Beginso processes Respondent Data on behalf of a Form Owner or organisational customer, the processing is undertaken principally to provide the services requested by that customer and according to the customer's instructions, subject to Beginso's independent legal obligations, security requirements and applicable Platform terms.
4.4 Security, Fraud and Abuse Prevention
Beginso may process data to detect and prevent unauthorised access, spam, automated abuse, fraudulent activity, misuse of Public Forms, credential compromise, malicious uploads, security incidents and other conduct that may threaten Users, Respondents, the Platform or third parties.
4.5 Product Analytics and Improvement
Beginso may analyse technical and usage information to measure Platform performance, identify bugs, understand feature use, improve usability, optimise infrastructure, prioritise development and improve existing or future functionality. Where Applicable Law requires consent for non-essential analytics or tracking technologies, Beginso will use such technologies only in accordance with the applicable consent requirements.
4.6 Communications
Beginso may use contact information to send transactional messages, security alerts, Account notifications, Workspace invitations, product notices, support responses, legal notices, policy updates and other service-related communications. Marketing or promotional communications will be sent in accordance with Applicable Law and applicable consent or opt-out requirements.
4.7 Legal, Regulatory and Rights Protection
Beginso may process data to comply with Applicable Law, respond to lawful governmental or judicial requests, maintain legally required records, investigate abuse, enforce Platform terms, establish or defend legal claims, preserve evidence, protect Beginso's rights and comply with regulatory obligations.
4.8 Lawful Bases
Depending on the jurisdiction and processing activity, Beginso may rely on one or more lawful bases, including performance of a contract, consent, legitimate interests, compliance with a legal obligation, protection of rights or systems, processing on a customer's instructions, or another lawful basis permitted by Applicable Law. Where Beginso relies on consent, the individual may withdraw consent as permitted by Applicable Law, without affecting the lawfulness of processing carried out before withdrawal.
5. Data Sharing and Disclosure Practices
5.1 General Principle
Beginso does not sell personal data as part of its ordinary Platform business model. Beginso may disclose personal data only as described in this Policy, at a User's direction, with valid consent where required, or where permitted or required by Applicable Law. If Beginso later introduces a practice that constitutes a "sale" or "sharing" of personal information under a law that assigns those terms a special legal meaning, Beginso will update its disclosures and provide any legally required choices before or when such practice applies.
5.2 Service Providers and Subprocessors
Beginso may engage third-party service providers and Subprocessors to operate and support the Platform. To keep this Policy provider-neutral and adaptable to infrastructure changes, providers may be described by category rather than by commercial name. These categories may include:
- cloud hosting and computing providers
- database and object-storage providers
- content-delivery and network infrastructure providers
- identity and authentication providers
- email and notification-delivery providers
- analytics, monitoring, performance and error-reporting providers
- security, anti-abuse, bot-prevention and fraud-prevention providers
- customer-support and communications tooling providers
- payment processors and billing providers, where paid plans are offered
- other technical service providers necessary to operate the Platform
Beginso seeks to engage Subprocessors under contractual or equivalent obligations appropriate to the nature of the services and Applicable Law, including obligations relating to confidentiality, security and permitted processing.
5.3 Cloud Infrastructure and Hosting Risk Disclosure
The Platform may be hosted on cloud infrastructure maintained by third-party Infrastructure Providers. Data may be stored or processed on systems located in one or more jurisdictions. Infrastructure Providers operate under their own contractual and security frameworks, and Beginso cannot guarantee absolute control over every aspect of infrastructure-level processing, resilience or availability. Beginso will use commercially reasonable measures appropriate to its role to select and manage such providers.
5.4 Authentication Providers
Where a User authenticates through Google or another identity provider, relevant information may be exchanged with that provider as necessary to complete authentication, maintain security and operate the Account. The identity provider's independent privacy practices apply to its own processing.
5.5 Workspace and Form-Level Sharing
Information within a Workspace may be visible to Workspace Owners, administrators, Team Members, persons with Form-specific permissions and other persons authorised through Platform settings. Visibility depends on the roles and permissions configured by the relevant customer. Users responsible for Workspace administration must ensure that access is granted only to appropriate persons and promptly revoked when no longer required.
5.6 Respondent Data Disclosure to Form Owners
Information submitted through a Form is generally made available to the Form Owner and any Team Members or Authorised Users who have been granted access to that Form or its responses. Respondents should understand that the Form Owner receives the information submitted and may process it under the Form Owner's own privacy notice, policies and legal obligations.
5.7 Corporate Affiliates
Beginso may share personal data with its parent company, affiliates, subsidiaries or group entities where reasonably necessary for Platform operation, administration, security, support, legal compliance or legitimate internal business purposes, subject to appropriate safeguards and Applicable Law.
5.8 Business Transactions
In connection with a merger, acquisition, investment, financing, restructuring, reorganisation, sale of assets or similar corporate transaction, personal data may be disclosed or transferred to relevant counterparties subject to confidentiality, due diligence and Applicable Law. Where required, affected persons will be provided notice.
5.9 Legal and Regulatory Disclosure
Beginso may disclose personal data, Content or records to courts, regulators, governmental authorities or law-enforcement agencies where required by Applicable Law, a valid court order, warrant, subpoena, regulatory direction or other binding legal process. Where legally permissible and reasonably appropriate, Beginso may seek clarification, challenge, narrow or require proper legal process for requests that appear overbroad or legally deficient.
5.10 Safety, Security and Rights Protection
Beginso may disclose information where reasonably necessary to prevent or address fraud, abuse, cyberattacks, unauthorised access, serious threats, legal violations or other harm; protect the rights, property or safety of Beginso, Users, Respondents or the public; or enforce Platform terms and policies.
6. International Data Transfers
6.1 Cross-Border Processing
Beginso may rely on cloud infrastructure, Subprocessors, affiliates or service providers located in jurisdictions other than the User's or Respondent's own jurisdiction. Accordingly, personal data may be stored, accessed, transferred or processed internationally, subject to Applicable Law.
6.2 Transfer Safeguards
Where required by Applicable Law, Beginso may use appropriate mechanisms for international transfers, including contractual protections, data-processing agreements, recognised standard contractual clauses, approved transfer instruments, organisational safeguards, technical safeguards, adequacy mechanisms or other lawful transfer bases.
6.3 India
Where Indian data-protection rules governing cross-border transfers apply to a relevant processing activity, Beginso will seek to comply with any applicable restriction, notification, contractual, security or other requirement in force at the relevant time.
6.4 EEA and United Kingdom
Where GDPR or UK GDPR international-transfer rules apply, Beginso may use adequacy decisions, Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, legally recognised derogations, or another authorised transfer mechanism as appropriate.
6.5 Other Jurisdictions
Where local data-localisation or cross-border-transfer restrictions apply, Beginso will seek to comply to the extent such requirements apply to the relevant processing activity.
7. Data Retention and Deletion
7.1 Retention Principles
Beginso retains personal data only for as long as reasonably necessary for Platform operation, fulfilment of contractual obligations, customer instructions, security, fraud prevention, legal compliance, dispute resolution, enforcement and legitimate business purposes. Different categories of information may have different retention periods depending on the nature of the data, Account status, Workspace status, Subscription Plan, customer configuration and Applicable Law.
7.2 Account Information
Account and profile information may be retained while an Account remains active. After Account deletion or termination, such information may be deleted, anonymised or retained for a limited period where reasonably necessary for legal, security, fraud-prevention, accounting, dispute-resolution or other lawful purposes.
7.3 Forms, Submissions and Uploaded Files
Forms, Submissions, Respondent Data and uploaded files may remain available for the period permitted by the applicable Subscription Plan, User or Workspace configuration, customer instructions, Platform retention rules and Applicable Law. Beginso may introduce different retention rules for free, paid and enterprise plans, which will be communicated through the applicable plan terms or product notices.
7.4 Account Deletion Requests
Users may request deletion of their Beginso Account through available Platform controls where provided, or by contacting privacy@beginso.com. Where deletion is permitted and technically applicable, Beginso will delete or anonymise personal data associated with the Account, subject to Workspace ownership, organisation-admin rights, legal retention obligations, security requirements, fraud-prevention needs, legal holds and other requirements permitted by Applicable Law. Mere deactivation is not treated as deletion where a valid deletion request requires deletion under Applicable Law or an applicable platform-store requirement.
Beginso may maintain a publicly accessible web resource through which Account deletion requests can be initiated. The applicable deletion path and any required steps may be updated from time to time and should be followed as displayed on the Platform or website.
7.5 Workspace-Owned or Organisation-Controlled Data
Deletion of an individual Team Member's Account does not necessarily require deletion of Forms, Submissions, files, audit records or other information owned or controlled by an organisation or Workspace. Where Content belongs to a Workspace or organisation, the Workspace Owner or authorised administrator may retain control over that Content, subject to Applicable Law and any applicable customer agreement.
7.6 Respondent Privacy and Deletion Requests
Where Beginso processes Respondent Data on behalf of a Form Owner or organisational customer, the Form Owner may be the primary Data Fiduciary / Controller responsible for responding to a Respondent's access, correction, deletion or other privacy request. Beginso may direct the Respondent to the relevant Form Owner and will reasonably assist the customer where required by Applicable Law or an applicable DPA.
7.7 Legal, Security and Audit Records
Beginso may retain limited records after deletion where reasonably necessary for legal compliance, fraud investigation, cybersecurity, dispute resolution, regulatory investigation, financial recordkeeping, legal defence, enforcement or other lawful purposes. Such information may include access logs, security logs, transaction records, support correspondence, audit records and legal records. Retention will be limited to what is reasonably necessary for the applicable purpose or required by law.
7.8 Backups, Caches and Technical Residuals
Deleted information may temporarily remain in encrypted or otherwise protected backups, caches, logs or disaster-recovery systems until overwritten or deleted in the ordinary course of system operations. Such residual copies are not ordinarily restored for active use except where necessary for disaster recovery, security, legal compliance or another legitimate operational purpose.
8. Cookies and Tracking Technologies
8.1 Cookie and Technology Categories
Beginso may use cookies, local storage, SDKs and similar technologies for the following purposes:
- Essential / strictly necessary technologies required for authentication, session operation, security, load balancing, fraud prevention and core Platform functionality
- Functional technologies used to remember interface preferences, language, Workspace settings or other user choices
- Analytics and performance technologies used to understand Platform usage, diagnose errors and improve reliability or usability
- Security technologies used to detect abuse, suspicious activity, bot traffic or unauthorised access
- Marketing or advertising technologies, if introduced, used only in accordance with Applicable Law and applicable consent requirements
8.2 Consent and Controls
Where Applicable Law requires consent before non-essential cookies, SDKs or similar tracking technologies are used, Beginso will provide an appropriate consent or preference mechanism. Essential technologies may operate without separate consent where permitted because they are necessary to provide or secure the service. Users may also control certain technologies through browser or device settings, subject to possible loss of functionality.
8.3 Separate Cookie Policy
A separate Cookie Policy may provide more detailed information about cookie categories, purposes, durations, providers and available controls. Where that Cookie Policy expressly addresses a cookie-specific issue, it should be read together with this Policy.
9. Data Principal and Privacy Rights
9.1 Available Rights
Depending on the jurisdiction and Beginso's role in the processing, an individual may have rights relating to access, confirmation of processing, correction, completion, updating, erasure, withdrawal of consent, objection, restriction, portability, grievance redress, nomination, and certain automated processing. The exact rights available depend on Applicable Law and the relevant processing context.
9.2 Exercising Rights
Privacy requests may be submitted to privacy@beginso.com. Beginso may require reasonable verification of identity and authority before acting on a request. Beginso will respond within the period prescribed by Applicable Law. Where Beginso acts solely as a Data Processor for Respondent Data, Beginso may refer or forward the request to the relevant Form Owner or organisational customer.
9.3 Limitations and Exceptions
A request may be limited, declined or modified where permitted by Applicable Law, including where retention is legally required, information is necessary for legal claims or security, the request would adversely affect another person's rights, Beginso acts only on a customer's documented instructions, the request is fraudulent or manifestly abusive, or another lawful exception applies.
9.4 Consent Withdrawal
Where Beginso relies on consent, consent may be withdrawn through the available Platform mechanism or by contacting Beginso where appropriate. Withdrawal does not affect the lawfulness of processing carried out before withdrawal and may prevent continued use of a feature where the processing is necessary to provide that feature.
10. Children's Privacy
10.1 Account Holders
Beginso Accounts are intended to be created and administered by persons who are legally capable of entering into binding agreements. The minimum age and eligibility requirements for Account holders are governed by the Beginso Terms of Use and Applicable Law.
10.2 Forms Concerning Children
Because Beginso enables customers to create Forms for many legitimate purposes, a Form Owner may create a Form that lawfully collects information relating to children or minors, for example in an education, parental, event, community or administrative context. The Form Owner is responsible for determining whether such collection is permitted and for obtaining verifiable parental or guardian consent where required, providing appropriate privacy notices, complying with restrictions on children's data, avoiding prohibited tracking or profiling, and implementing suitable safeguards.
10.3 Beginso Enforcement Rights
Beginso may suspend, restrict, disable or remove Forms that unlawfully collect children's data or otherwise create a material risk to minors. Where Beginso becomes aware of unlawful processing of children's data, Beginso may take appropriate remedial steps, including restricting access, deleting data where appropriate, notifying the relevant customer, or making legally required reports or disclosures.
11. Workspaces, Teams and Organisational Data
11.1 Administrator Controls
Workspace Owners and administrators may have authority, according to Platform functionality and permissions, to invite or remove Team Members, assign roles, change permissions, access Forms and Submissions, access uploaded files, view analytics, generate or export reports, review activity and administer Workspace settings. Beginso does not control the internal employment, contractual or organisational authority through which an administrator exercises these powers.
11.2 Organisation Responsibility
Organisations using Beginso are responsible for granting appropriate permissions, providing required notices to personnel, controlling internal access, revoking access promptly when no longer required, and maintaining appropriate internal data-governance and security procedures.
11.3 Per-Form Permissions
Where Beginso permits access to specific Forms based on Workspace roles or Form-level permissions, a person receiving shared access must not access, copy, export, disclose or use information beyond the authority granted by the relevant organisation or Form Owner.
11.4 Workspace Activity and Audit Information
Workspace activity and audit information may be visible to authorised administrators or other permitted Team Members and may identify actions taken by individual Users. Organisations are responsible for providing any notice to personnel required by Applicable Law in relation to such administrative visibility or monitoring.
12. Security Measures and Breach Management
12.1 Technical and Organisational Measures
Beginso implements technical and organisational measures designed to protect personal data and Content against unauthorised access, disclosure, alteration, misuse, loss or destruction. Measures may include, as appropriate to the feature and risk, encryption in transit, authentication controls, role-based or permission-based access, session controls, infrastructure security, monitoring, logging, vulnerability management, secure development practices, restricted personnel access and other safeguards reasonably designed for a SaaS platform. Specific controls may vary by feature, infrastructure provider, plan and deployment configuration.
12.2 Security Disclaimer
No online platform, cloud service, database, transmission method or storage system can guarantee absolute security. Beginso therefore does not warrant that the Platform or personal data will be completely immune from cyberattack, hacking, malware, unauthorised access, data breach, service compromise or other security incident. Nothing in this provision excludes or limits liability that cannot lawfully be excluded or limited under Applicable Law.
12.3 Personal Data Breach Response
Where a personal-data breach occurs, Beginso will take measures appropriate to the nature and severity of the incident, which may include investigating the incident, containing and mitigating the breach, preserving relevant evidence, assessing affected data, notifying relevant customers, notifying affected persons where legally required, notifying competent authorities within applicable statutory timeframes, and implementing corrective measures.
12.4 User Security Responsibilities
Users are responsible for protecting credentials, securing devices, maintaining appropriate Workspace and Form permissions, terminating unused sessions, promptly removing former Team Members, protecting exported data, avoiding credential sharing and promptly reporting suspected unauthorised access or vulnerabilities to security@beginso.com.
13. User-Controlled Data Collection and Third-Party Risks
13.1 Form Owner Controls the Collection
Form Owners determine the fields and information requested through their Forms. Except where Beginso independently determines a processing purpose, Beginso generally does not decide why the Form Owner needs the information, which persons should complete the Form, whether the Form Owner has a lawful basis, whether a sufficient privacy notice has been provided, or how exported data will later be used. The Form Owner is independently responsible for those matters.
13.2 Public Form Links, Embeds and QR Codes
A Public Form Link, embedded Form or QR code may be accessible to any person who receives or discovers the access mechanism unless additional access controls apply. Form Owners are responsible for controlling distribution, configuring available access settings appropriately and avoiding publication of Forms intended to remain private. Beginso is not responsible for exposure caused solely by a Form Owner's decision to make or distribute a Form publicly, subject to liability that cannot lawfully be excluded.
13.3 Respondent Notices
Where required by Applicable Law, the Form Owner is responsible for providing Respondents with an appropriate privacy notice or other disclosure explaining the identity of the person collecting the data, the purpose of collection, relevant sharing, retention and available rights. Beginso may provide technical fields, notices or other tools to help customers communicate such information, but the Form Owner remains responsible for the legal adequacy of its own notice unless Beginso expressly agrees otherwise in writing.
13.4 Sensitive, Regulated and Specially Protected Data
Because Beginso can be used to create flexible Forms, Users may attempt to collect identity documents, government-issued identifiers, financial information, health information, biometric information, employment records, education records, information relating to children, confidential corporate data or other regulated information. The Form Owner is responsible for ensuring that it has a lawful basis, any necessary consent or authorisation, appropriate notices, and suitable technical and organisational safeguards before collecting or processing such data.
Beginso may impose additional restrictions, plan requirements, contractual terms, DPAs, security requirements or prior-approval conditions for certain high-risk or regulated processing, and may prohibit particular categories of data where the Platform is not designed or certified to meet the regulatory safeguards applicable to that processing.
Unless Beginso expressly agrees otherwise in a separate written agreement, use of the Platform does not by itself constitute or guarantee compliance with any sector-specific regulatory regime applicable to a customer's industry, such as healthcare, financial-services, education, employment, government, identity-verification or other regulated-data requirements. Customers are responsible for determining whether Beginso is suitable for their particular legal and compliance obligations and for implementing any additional controls required by Applicable Law.
13.5 Third-Party Integrations and Services
Where a User connects Beginso to an external service, identity provider, application or integration, information disclosed to that service becomes subject to the third party's own terms and privacy practices. Beginso does not control and is not responsible for independent third-party processing, except to the extent Beginso has legal obligations regarding the selection or management of its own Subprocessors.
13.6 Exports and Downloaded Copies
Once a User exports Respondent Data, downloads a file, generates a report or otherwise transfers information outside Beginso, Beginso may no longer control local copies, spreadsheets, downloaded PDFs, emailed copies, external storage or subsequent sharing. The User is responsible for securing, retaining and deleting such copies in accordance with Applicable Law and its own obligations.
14. Regional Privacy Rights and Addenda
This Section supplements the general Policy with region-specific provisions. A regional provision applies only where the relevant law is in force and applicable to the person or processing activity. If a mandatory regional rule conflicts with the general Policy, the mandatory regional rule prevails to the extent of the conflict.
14.1 India: DPDP Act and Related Framework
To the extent the DPDP Act and rules made under it are in force and applicable to a relevant processing activity, Beginso will seek to comply with obligations applicable to it in its role as Data Fiduciary or Data Processor. Indian Data Principals may exercise such rights as are available under the law in force at the relevant time, which may include rights relating to access to prescribed information, correction, completion, updating, erasure, withdrawal of consent, grievance redress and nomination.
Requests may be sent to privacy@beginso.com and grievances to grievance@beginso.com. Beginso will address valid requests and grievances within the timeframe prescribed by Applicable Law. Where Beginso processes Respondent Data on behalf of a Form Owner, the Form Owner may remain the party primarily responsible for the request.
14.2 European Economic Area and United Kingdom
Where the GDPR or UK GDPR applies and Beginso acts as Controller for a processing activity, eligible individuals may have rights including access, rectification, erasure, restriction, portability, objection, withdrawal of consent and rights concerning certain automated decision-making. Individuals may also lodge a complaint with the competent data-protection authority. Where Beginso acts solely as Processor, requests may be handled through the relevant customer/Controller.
14.3 California
Where the California Consumer Privacy Act / California Privacy Rights Act applies, eligible California residents may have rights including the right to know or access, correct and delete certain personal information, opt out of certain sale or sharing, limit certain uses of sensitive personal information where applicable, and receive non-discriminatory treatment for exercising statutory rights. Beginso does not sell personal information as part of its ordinary Platform business model. Requests may be submitted to privacy@beginso.com, subject to verification and statutory exceptions.
14.4 Other Jurisdictions
Individuals located in other jurisdictions retain mandatory privacy rights granted by Applicable Law that cannot lawfully be waived. Beginso may publish additional regional notices or addenda as the Platform expands or as required by law.
15. AI, Machine Learning and Automated Processing
15.1 No AI Training on Form Content or Respondent Data Without Appropriate Authorisation
Beginso will not use the substantive content of Forms, Respondent Submissions or uploaded User files to train, develop or fine-tune general-purpose generative AI or machine-learning models unless there is an appropriate lawful basis and, where required, clear express authorisation or consent. Beginso may use aggregated, statistical, technical or appropriately de-identified operational information for security, diagnostics, service reliability and product improvement where legally permitted.
15.2 Current Automated Processing
Beginso may use automated processing for operational purposes such as anti-spam protection, bot prevention, authentication, security, abuse detection, technical validation, analytics generation, reporting, file processing, search, performance monitoring and other Platform operations. Such processing may evolve as features change.
15.3 Automated Decisions with Legal or Similarly Significant Effects
Beginso does not intend to make decisions producing legal or similarly significant effects about individuals solely through automated processing unless such functionality is specifically introduced with appropriate notice, lawful basis and safeguards required by Applicable Law.
15.4 Future AI Features
Beginso may introduce AI-assisted features in the future. Where a new AI feature materially changes how personal data or Content is processed, Beginso may update this Policy, provide additional notices, obtain consent where required, implement appropriate contractual or technical safeguards and conduct appropriate internal assessments before or when the feature is introduced.
16. Contact, Grievance and Regulatory Matters
For privacy, support, legal, security, abuse and intellectual-property matters, Beginso may be contacted through the following channels:
| Purpose | Contact |
|---|---|
| Privacy and data-protection requests | privacy@beginso.com |
| General support | support@beginso.com |
| Legal notices | legal@beginso.com |
| Grievances | grievance@beginso.com |
| Security / vulnerability reports | security@beginso.com |
| Abuse reports | abuse@beginso.com |
| Copyright / intellectual-property matters | copyright@beginso.com |
| Website | https://beginso.com/ |
| Postal location | Mumbai, Maharashtra, India |
16.1 Grievance Handling
Grievances concerning privacy or data protection may be submitted to grievance@beginso.com. Beginso will endeavour to acknowledge, investigate and respond to valid grievances within the timeframe prescribed by Applicable Law. Where the grievance concerns processing controlled by a Form Owner or organisational customer, Beginso may refer the matter to that customer while providing reasonable assistance where legally required.
16.2 Regulatory Escalation
Where Applicable Law provides a right to complain to a competent privacy or data-protection regulator, an individual may exercise that right after or in parallel with contacting Beginso, as permitted by law. Applicable authorities may include the Data Protection Board of India to the extent its jurisdiction applies, relevant EEA supervisory authorities, the UK Information Commissioner's Office, California privacy regulators, or another competent authority in the individual's jurisdiction.
17. Platform Rights, Disclaimers and General Provisions
17.1 Legal Preservation and Disclosure
Beginso may preserve personal data, Content and records beyond ordinary retention periods where reasonably necessary to comply with law or legal process, enforce Platform terms, investigate fraud or security threats, protect rights or safety, respond to regulatory inquiries, preserve evidence, comply with a legal hold or fulfil another lawful obligation. Such preservation will be limited to what is reasonably necessary for the relevant purpose.
17.2 No Guarantee of Absolute Privacy or Confidentiality
Nothing in this Policy is a guarantee of absolute privacy, confidentiality, security or availability. This Policy describes Beginso's privacy practices and commitments subject to Applicable Law and the limitations inherent in internet and cloud-based services.
17.3 User-Caused Privacy Violations
A User is responsible for privacy or data-protection violations caused by that User's unlawful Form, unlawful data collection, failure to provide required notices or obtain required consent, improper disclosure, improper export, misuse of Respondent Data, unauthorised Workspace access, excessive collection, unlawful sensitive-data processing or other violation of Applicable Law. Subject to the Terms of Use and Applicable Law, Beginso may seek indemnification or other remedies for Claims arising from such conduct.
17.4 Policy Updates
Beginso may amend this Policy from time to time. The updated version will identify its revised effective or last-updated date. Where a change materially affects privacy rights or processing, Beginso may provide reasonable notice by email, in-Platform notification, prominent website notice or another appropriate method. Where law requires separate consent, Beginso will seek that consent.
17.5 Governing Law and Dispute Resolution
This Privacy Policy is governed by the laws of the Republic of India, subject to mandatory rights that cannot lawfully be excluded. Disputes relating to this Policy are subject to the dispute-resolution provisions of the Beginso Terms of Use, including any applicable arbitration provisions. The intended seat of arbitration under the Beginso legal framework is Mumbai, Maharashtra, India. This clause does not deprive an individual of any mandatory privacy or consumer right that cannot lawfully be waived.
17.6 International Users
Users and Respondents accessing the Platform from outside India acknowledge that their use may also be subject to mandatory local privacy, consumer-protection or data-transfer laws. Beginso does not represent that the same privacy rights apply identically in every jurisdiction.
17.7 Survival
Provisions of this Policy that by their nature should continue after Account termination or cessation of use, including provisions concerning retention, legal compliance, security, disputes, rights protection and lawful disclosure, survive to the extent necessary to give them effect.
17.8 Severability and Interpretation
If any provision of this Policy is held unlawful, invalid or unenforceable, that provision shall be modified to the minimum extent necessary to make it lawful and enforceable, or severed if necessary, without affecting the remaining provisions. This Policy should be interpreted consistently with Applicable Law and the legal role Beginso performs in the relevant processing activity.
17.9 Entire Privacy Framework
This Privacy Policy, together with any applicable regional addenda, Cookie Policy, Data Processing Agreement, enterprise privacy terms and other expressly incorporated privacy notices, constitutes the privacy framework applicable to Beginso. Where a separate DPA or enterprise agreement expressly governs a particular processing activity, that document will apply to the extent stated in it.
18. Acknowledgement
BY ACCESSING OR USING BEGINSO, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY. WHERE APPLICABLE LAW REQUIRES CONSENT FOR A PARTICULAR PROCESSING ACTIVITY, SUCH PROCESSING WILL BE UNDERTAKEN ONLY ON AN APPROPRIATE LAWFUL BASIS. IF YOU DO NOT AGREE WITH THIS POLICY, YOU SHOULD DISCONTINUE USE OF THE PLATFORM, SUBJECT TO ANY RIGHTS OR OBLIGATIONS THAT CONTINUE UNDER APPLICABLE LAW OR AN EXISTING CUSTOMER AGREEMENT.
Privacy-related requests may be submitted to privacy@beginso.com. General support requests may be submitted to support@beginso.com.
This Privacy Policy was last reviewed on 23 September 2026.