Legal · privacy
Privacy Policy
How we collect, use and protect personal data — both for people who visit this site and for the data our customers entrust to the platform.
Last updated
ThirdSectorBee Ltd
Effective date: 30/07/2026 Last updated: 30/07/2026
1. Introduction
This Privacy Policy explains how ThirdSectorBee Ltd (“ThirdSectorBee”, “we”, “us”, “our”) collects, uses, shares and protects personal data when you:
- visit our website at thirdsectorbee.com (the “Website”);
- enquire about, register for, or use the ThirdSectorBee charity data platform (the “Platform”); or
- otherwise interact with us, for example by email, by attending an event, or as a contact at a prospective customer.
We are committed to protecting your personal data and handling it in line with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where applicable to customers and users in the European Economic Area, the EU General Data Protection Regulation (EU GDPR).
Please read this policy alongside our Terms and Conditions of Use and, where you are a customer, your Data Processing Agreement with us.
2. Who we are
The data controller responsible for the personal data described in this policy is:
ThirdSectorBee Ltd Registered in England and Wales, company number 17359072 Registered office: 124 City Road, London, EC1V 2NX ICO registration number: Pending
For any privacy question, request or complaint, contact us at hello@thirdsectorbee.com.
ThirdSectorBee’s Data Protection Officer is Rich Bee, co-founder, to whom queries may be directed via the above address.
3. Important: the difference between data we control and data we process
ThirdSectorBee is a B2B platform used by charitable and non-profit organisations. It is important to understand the two distinct roles we play.
We are a data controller for the personal data described in this policy — that is, data about Website visitors, prospective customers, the staff and individuals who hold accounts and use the Platform on behalf of a customer, billing contacts, and people who contact us. This policy governs that data, and we decide how it is used.
We are a data processor for the personal data that our customers upload to, store in, or generate within the Platform — for example records relating to a customer’s donors, supporters, leads, beneficiaries, service users, volunteers and contacts (“Customer Personal Data”). For that data, the customer is the controller and decides how it is used. We process it only on the customer’s documented instructions, as set out in our Terms and Conditions of Use and Data Processing Agreement.
If you are a donor, beneficiary or other contact of a charity that uses ThirdSectorBee, this policy does not govern how that charity uses your data. Please contact the relevant charity directly, and refer to that charity’s own privacy notice.
4. The personal data we collect
As a controller, we collect and use the following categories of personal data.
Information you give us. When you enquire about the Platform, request a demo, register an account, or correspond with us, we collect your name, work email address, telephone number, job title, the name of the organisation you represent, and the content of your communications with us.
Account and usage information. When you or your colleagues use the Platform, we collect account credentials and authentication data, configuration and preference settings, support tickets, and records of how the Platform is used (for example logins, features used, and actions taken). The Platform uses Amazon Cognito for authentication.
Billing information. Where you are a billing contact, we collect billing names, addresses, contact details, your chosen plan and Weighted Contact volumes, and transaction history. Card and payment details are collected and processed directly by our payment provider, Stripe — we do not store full card numbers ourselves.
Technical and device information. When you visit the Website or use the Platform, we automatically collect IP address, browser type and version, device and operating system information, time-zone and language settings, and pages or screens viewed, primarily through cookies and similar technologies.
Marketing information. Where you have subscribed to updates or are a relevant business contact, we hold your contact details and a record of your communication preferences and engagement (for example whether you have opened an email).
We do not intentionally collect special category personal data (such as health or political opinions) about you in our role as controller. Where such data exists within Customer Personal Data, we handle it only as a processor under the relevant customer’s instructions.
5. How we use your personal data and our legal bases
We use personal data only where we have a lawful basis under the UK GDPR. The table below summarises our main purposes and the corresponding legal bases.
| Purpose | Legal basis |
| Responding to enquiries and providing demos | Legitimate interests (responding to a request); steps prior to entering a contract |
| Creating and administering accounts and providing the Platform | Performance of a contract |
| Authenticating users and securing the Platform | Performance of a contract; legitimate interests (security and fraud prevention) |
| Billing, invoicing and collecting payment | Performance of a contract; legal obligation (accounting and tax records) |
| Providing customer support | Performance of a contract; legitimate interests |
| Monitoring, maintaining, troubleshooting and improving the Platform | Legitimate interests (operating and improving our service) |
| Sending service and administrative messages | Performance of a contract; legitimate interests |
| Sending marketing communications about our products and services | Consent, or legitimate interests for existing business contacts; we always offer an opt-out |
| Complying with legal and regulatory obligations | Legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interests |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and freedoms, and have concluded they are not. You may ask us for further detail about this assessment.
Where we rely on consent (for example for certain cookies or marketing), you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
6. Cookies and similar technologies
The Website and Platform use cookies and similar technologies to function correctly, to keep you signed in, to remember preferences, and to understand how our services are used. Some cookies are strictly necessary; others — including analytics cookies — are used only where you have given consent through our cookie banner. You can manage your preferences at any time via the banner or your browser settings.
Embedded booking calendar. Our booking page embeds a scheduling calendar provided by Cal.id. When you open that page the calendar loads directly from Cal.id, which means Cal.id receives your IP address and browser information and may set its own cookies or similar technologies in your browser. This happens only on that page; the rest of the Website does not load it.
[A separate, detailed Cookie Policy is recommended once your cookie set is finalised. List the specific analytics or other tooling you use, e.g. a privacy-focused analytics provider, so this section can be made accurate.]
7. Who we share your personal data with
We do not sell your personal data. We share it only in the circumstances below.
Service providers and sub-processors. We use trusted third parties to operate the Platform and our business. These include:
- Amazon Web Services (AWS): cloud hosting and infrastructure for the Platform;
- Stripe: payment processing and billing;
- Amazon Simple Email Service (SES): transactional and service email delivery;
- Pendo: product analytics;
- Algolia: in-app search
- Cal.id: scheduling, where you book a call or demo with us through our website;
- professional advisers such as accountants and lawyers, and other operational tools we may use from time to time.
These providers act on our instructions and are bound by contractual obligations to keep personal data secure and to use it only for the purposes we specify.
Corporate transactions. If we are involved in a merger, acquisition, financing or sale of assets, personal data may be disclosed to the parties involved, subject to appropriate confidentiality protections.
Legal and regulatory disclosures. We may disclose personal data where required to comply with the law, a court order, or a request from a regulator or law enforcement body, or to protect our rights, property or safety, or those of others.
A current list of sub-processors used to deliver the Platform is maintained and made available to customers in connection with our Data Processing Agreement.
8. International data transfers
The Platform is primarily hosted in the United Kingdom (AWS region eu-west-2, London). We design the service so that customer and account data is stored in the UK [and/or EEA] wherever practicable.
Some of our service providers — including Stripe and certain AWS and email services — may process limited personal data outside the UK and EEA, including in the United States. Where personal data is transferred outside the UK or EEA, we ensure an appropriate safeguard is in place, such as:
- the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses; or
- the EU Standard Contractual Clauses for transfers from the EEA; or
- transfer to a country covered by UK or EU adequacy regulations.
You can ask us for more information about the safeguards applied to a particular transfer.
9. How long we keep your personal data
We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting or reporting requirements. In general:
- enquiry and prospect data — kept for up to 36 months from the last contact, unless you become a customer;
- account and usage data — kept for the duration of the customer relationship and for a reasonable period afterwards;
- billing and financial records — kept for at least 7 years to meet UK accounting and tax obligations;
- marketing data — kept until you unsubscribe or object, and reviewed periodically.
Customer Personal Data held in our role as processor is retained and deleted in accordance with the relevant customer’s instructions and our Terms and Conditions of Use.
10. How we protect your personal data
We take the security of personal data seriously and use appropriate technical and organisational measures, which include encryption of data in transit and at rest, access controls and the principle of least privilege, authentication via Amazon Cognito, logging and monitoring, regular backups, and a documented process for handling personal data breaches. No system can be guaranteed completely secure, but we work continuously to protect personal data against unauthorised access, loss, alteration or disclosure.
11. Your rights
Under the UK GDPR (and the EU GDPR where it applies to you), you have the right to:
- be informed about how your personal data is used (this policy);
- access the personal data we hold about you;
- rectification of inaccurate or incomplete data;
- erasure of your data in certain circumstances;
- restrict our processing of your data in certain circumstances;
- data portability — to receive certain data in a structured, commonly used, machine-readable format;
- object to processing based on legitimate interests, and to direct marketing at any time;
- withdraw consent where we rely on it; and
- not be subject to solely automated decisions producing legal or similarly significant effects (we do not currently make such decisions about you).
To exercise any right, contact us at hello@thirdsectorbee.com. We will respond within one month, though we may extend this by up to two further months for complex requests, and we will tell you if we do. There is normally no charge, although we may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive.
If you wish to exercise these rights in relation to data held by a charity that uses our Platform, please contact that charity directly, as it is the controller of that data.
12. Children
The Platform is a business tool intended for use by staff and authorised representatives of charitable and non-profit organisations. It is not directed at children, and we do not knowingly collect personal data from children in our role as controller.
13. Changes to this policy
We may update this policy from time to time. When we make material changes we will update the “Last updated” date above and, where appropriate, notify customers directly. We encourage you to review this policy periodically.
14. How to contact us and how to complain
For any question or request about this policy or your personal data, contact:
ThirdSectorBee Ltd hello@thirdsectorbee.com 124 City Road, London EC1V 2NX
If you are not satisfied with how we have handled your personal data, you have the right to complain to the relevant supervisory authority:
- in the UK, the Information Commissioner’s Office (ICO) — ico.org.uk;
- in Denmark, Datatilsynet (the Danish Data Protection Agency) — datatilsynet.dk;
- elsewhere in the EEA, your local data protection authority.
We would, however, appreciate the chance to address your concerns before you approach a regulator, so please consider contacting us first.