Beacon
Legal

Privacy Policy

This page is maintained by Logiqal Space and explains how personal data is handled on the Beacon website and platform.

Last updated: 6 August 2026

1. Who we are

Beacon is a WhatsApp Business API platform operated by Logiqal Space. This policy covers the beacon.logiqal.space website and the Beacon platform (together, the "Service").

For data you submit through this website, such as the contact form, Logiqal Space acts as the data controller. For data your business processes through the platform, such as your customers' messages and contact records, Logiqal Space acts as a data processor on your instructions.

If you have questions about this policy or about how your data is handled, you can reach us through the contact form on this site. We will route your enquiry to the Logiqal Space privacy contact.

2. Data we collect

We collect different categories of data depending on whether you are visiting the website or using the platform.

Website data: When you visit beacon.logiqal.space, we collect the IP address of your device, the type and version of browser you are using, the pages you viewed and how long you spent on them, the referring URL (the page you came from), and the date and time of your visit. When you submit the contact form, we collect the name, email address, company name, and message you provide, along with any optional information you choose to include.

Platform data: When you use the Beacon platform, we collect account and workspace details (name, plan, settings), authentication data (login timestamps, session tokens, IP addresses), API key metadata (creation date, last used, scopes), and the customer data your business chooses to send through the Service. Customer data includes contact phone numbers, message content and media files, delivery and read events, consent records with opt-in source and timestamp, template content and approval status, campaign configurations and performance metrics, link and QR code tracking data, webhook delivery logs, and analytics derived from your use of the platform.

We do not collect biometric data, financial account numbers, or government-issued identification numbers through the Service.

3. How we collect data

We collect data in the following ways:

Directly from you: when you submit the contact form, create an account, configure your workspace, or communicate with our support team.

Automatically: when you visit the website or use the platform, through cookies, server logs, and similar technologies. We use cookies to maintain your session, remember your preferences, and understand how the platform is used. Our Cookie Policy explains the specific cookies we use and how to control them.

From your use of the platform: when you send messages, manage contacts, create campaigns, configure webhooks, or use integrations, the data you submit and the actions you take are recorded to provide and improve the Service.

From third parties: when you connect a third-party integration (for example a CRM, e-commerce platform, or helpdesk tool), data flows from those services to Beacon under your instruction and their own terms.

4. Why we use it

We use personal data for the following purposes:

To respond to your enquiries submitted through the contact form and to maintain a record of our correspondence.

To provide, operate, and maintain the Service, including processing messages, managing contacts, delivering campaigns, and providing analytics.

To authenticate users and maintain the security of the platform, including detecting and preventing fraud, abuse, and unauthorised access.

To provide customer support and to communicate with you about your account, including service updates, security alerts, and billing matters.

To improve the platform, including analysing usage patterns, identifying performance issues, and developing new features.

To meet legal obligations, including responding to lawful requests from public authorities and maintaining records required by applicable law.

We do not sell personal data. We do not use your customers' message content to train machine learning models for other customers. We do not use your data for targeted advertising or profiling.

5. Legal bases

Where applicable law requires a legal basis for processing personal data, we rely on the following:

Performance of a contract: processing is necessary to provide the Service you have requested and to fulfil our obligations under the agreement between us. This includes processing messages, managing contacts, delivering campaigns, and providing support.

Legitimate interests: processing is necessary for our legitimate interests in operating and improving the Service, maintaining security, preventing fraud, and analysing usage, except where those interests are overridden by your rights and freedoms.

Consent: where you have given us specific consent to process your data for a particular purpose, such as receiving marketing communications or participating in a survey. You may withdraw consent at any time without affecting the lawfulness of processing that occurred before withdrawal.

Legal obligation: processing is necessary to comply with a legal obligation to which Logiqal Space is subject, such as responding to a valid court order or maintaining records required by law.

6. Sharing and subprocessors

We share personal data only as described in this policy and as necessary to provide the Service.

Service providers: we share data with service providers that support the platform, including cloud hosting and infrastructure providers, payment processors, analytics services, and communication tools. These providers are contractually bound to process data only on our instructions and in accordance with this policy.

WhatsApp and Meta: when you send messages through the Service, the data you submit is transmitted to WhatsApp and Meta to the extent required to deliver those messages. WhatsApp and Meta act as independent data controllers for the data they process. Their own privacy policies govern how they handle that data.

Integrations: where you enable a third-party integration, such as a CRM, e-commerce platform, or helpdesk connection, data flows to those providers under your instruction and their own terms. We do not control how those providers process your data.

Legal requirements: we may disclose personal data where required by applicable law, regulation, legal process, or governmental request, or where necessary to protect the rights, property, or safety of Logiqal Space, our customers, or the public.

A current list of subprocessors is available to customers on request. We will notify customers of any material changes to our subprocessor list.

7. Cookies and tracking

We use cookies and similar technologies on the website and platform. Cookies are small text files stored on your device by your browser. Similar technologies include local storage, session storage, and pixel tags.

Strictly necessary cookies are essential for the Service to function. They maintain your session after sign-in, remember your workspace selection, support load balancing, and protect against cross-site request forgery. These cookies cannot be switched off through the site because the Service does not function without them.

Preference cookies remember choices you make, such as interface density, saved views in the inbox, and dismissed notices. They exist to keep the product from resetting itself every visit.

Analytics cookies help us understand which pages are read, where navigation breaks down, and how the platform performs. We configure analytics to minimise the personal data collected.

Campaign attribution cookies store UTM parameters when you arrive from a tracked link, so we can attribute an enquiry to the campaign that produced it. This is used for our own marketing measurement and is not sold to third parties.

For full details on the specific cookies we use, their durations, and how to control them, please see our Cookie Policy.

8. Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law.

Website enquiry data: the name, email address, company, and message you submit through the contact form is retained for as long as needed to respond to your enquiry and to keep a record of our conversation, unless you ask us to delete it earlier. We typically retain website enquiry data for up to 24 months after the last communication.

Account and platform data: account details, workspace settings, and authentication data are retained for the duration of your agreement and for a limited period after termination to allow you to export your data. We typically retain this data for up to 90 days after termination, after which it is deleted or anonymised.

Message and contact data: the messages you send, contacts you manage, and media you upload are retained for the duration of your agreement. On termination, you may export this data within a reasonable period. After export or after the export window closes, this data is deleted.

Consent records: consent records are retained for the duration of the contact relationship and for a period thereafter to demonstrate compliance with applicable law.

Specific retention windows can be agreed in writing as part of your service agreement.

9. Security

We take the protection of personal data seriously and implement appropriate technical and organisational measures to safeguard it.

Encryption: all data is encrypted in transit using TLS and at rest using AES encryption. HMAC-SHA256 signed webhooks with timestamp tolerance ensure webhook integrity.

Access control: role-based access control (RBAC) across workspaces, with per-session permission scoping and multi-factor authentication support. Where enabled, single sign-on with SAML adds further protection for your team.

Monitoring: immutable activity audit trails for all platform actions, session health monitoring over WebSocket, and webhook delivery logs with retry tracking.

Environment separation: production and testing environments are separated, with sandbox sessions available for safe development.

No system is perfectly secure. If a breach affecting your data occurs, we will notify affected customers without undue delay in line with applicable law and any commitments in your agreement.

10. International transfers

Data may be processed in countries other than the country in which you are established. The Service is operated from infrastructure that may be located in multiple jurisdictions.

Where personal data is transferred across borders, we put appropriate safeguards in place to ensure the data receives an adequate level of protection. These safeguards include standard contractual clauses approved by relevant supervisory authorities, contractual commitments with subprocessors, and technical measures such as encryption.

By using the Service, you acknowledge that cross-border processing of personal data is necessary for the delivery of the Service, and you authorise such transfers where they are required.

11. Your rights

Depending on where you live and the applicable data protection law, you may have the following rights regarding your personal data:

Right of access: you may request a copy of the personal data we hold about you, along with information about how it is processed.

Right to rectification: you may request that we correct inaccurate or incomplete personal data.

Right to erasure: you may request that we delete your personal data, subject to certain exceptions where retention is required by law or for the performance of a contract.

Right to restriction: you may request that we restrict the processing of your personal data in certain circumstances, such as while we verify its accuracy or where you have objected to processing.

Right to object: you may object to the processing of your personal data where we rely on legitimate interests as the legal basis, and we will cease processing unless we demonstrate compelling legitimate grounds.

Right to data portability: you may request that we provide your personal data in a structured, commonly used, and machine-readable format, or transmit it directly to another controller where technically feasible.

Right to withdraw consent: where we rely on consent as the legal basis for processing, you may withdraw consent at any time without affecting the lawfulness of processing that occurred before withdrawal.

If your data was submitted to the platform by one of our customers, we will refer your request to that customer as the controller and support them in responding. We will not respond directly to data subject requests where the customer is the controller, unless authorised by the customer or required by applicable law.

12. CCPA and CPRA rights (California)

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you additional rights regarding your personal information.

Right to know: you may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purpose for collecting the information, and the categories of third parties with whom we share the information.

Right to delete: you may request that we delete personal information we have collected from you, subject to certain exceptions where retention is necessary for legal compliance, security, or other permitted purposes.

Right to correct: you may request that we correct inaccurate personal information we maintain about you.

Right to opt-out of sale: we do not sell personal information as defined by the CCPA. We do not have actual knowledge that we sell personal information of consumers under 16 years of age.

Right to non-discrimination: we will not discriminate against you for exercising your rights under the CCPA or CPRA. You will not receive different pricing, a different quality of service, or be denied service for exercising your rights.

Right to limit use of sensitive personal information: we do not use sensitive personal information for purposes other than those permitted by the CCPA and CPRA.

To exercise any of these rights, please contact us through the contact form on this site. We will verify your identity before processing your request and respond within the timeframes required by applicable law.

13. Children's privacy

The Service is not directed at children under the age of 16 (or such higher age as required by applicable law in your jurisdiction). We do not knowingly collect personal data from children.

If you are a parent or guardian and believe that your child has provided personal data to us, please contact us through the contact form on this site. We will take steps to delete such data without undue delay.

If we become aware that we have collected personal data from a child without verification of parental consent, we will delete that data as soon as practicable.

14. Changes and contact

We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify account owners through the platform or by email before the changes take effect. The "Last updated" date at the top of this page indicates when the policy was last revised.

Continued use of the Service after the effective date of any changes constitutes acceptance of the updated policy.

If you have questions about this privacy policy, about how we handle your data, or if you wish to exercise any of your rights, please contact us through the contact form on this site. We will route your enquiry to the Logiqal Space privacy contact and respond within a reasonable timeframe.