Privacy
Version 2026-09-11-review-1 · draft for review
Status of this page
This is a draft prepared for review, version 2026-09-11-review-1. It incorporates source changes reviewed on 11 September 2026 and the earlier implementation team’s report of the live configuration. It is not an independent verification of the current production settings. The company must approve the operating practices and this page before release.
What this page covers
Three things: the public website, the enquiry form, and the customer account you can create to follow your projects, proposals, invoices and support requests. It also names the companies that process this information for us, and where they hold it.
When you send a brief
We store your name, your email address, your organisation if you give one, the brief itself and any systems, specification, quantity and timing you add, the product or package you were enquiring about together with the price shown to you at that moment, which language you were reading in and which you asked us to reply in, and the time it arrived.
We generate a reference number and two codes: a receipt code that opens your receipt page, and a claim code that lets you attach the enquiry to an account within 30 days. We keep only one-way hashes of both codes, so a copy of our database cannot be used to open your receipt or claim your enquiry. Your address is also recorded so that a confirmation can be sent to it.
When you create an account
We store your email address, your name, your preferred language, and a telephone number if you choose to add one in Settings. We do not store your password: it is handled by our authentication provider, Supabase, and held only as a hash.
A password must be at least 10 characters and is checked against passwords known from public data breaches; one that appears there is refused. Your address must be confirmed by a link we email you before you can sign in. The authentication provider keeps its own log of sign-in events, which includes the network address they came from; we do not copy that log into your account record.
You can instead sign in with Google or Apple. We receive the provider’s account identifier and the profile information it makes available under the requested permissions. This can include a name, email address or profile image; an email address may be unavailable or relayed by the provider. Social sign-in does not require a separate password with us and does not authorise posting on your behalf. Whether you can also use X depends on whether that option is shown; it appears only once it is configured.
The sign-in cookie
Signing in sets one cookie, named b2d_session. It is encrypted, marked so that scripts on the page cannot read it, sent only over secure connections, and lasts at most seven days. It holds the tokens that identify your session to our database. Signing out clears it and ends the session on every device.
While you finish signing in from an emailed link, a second short-lived cookie holds the verifier for that link for 10 minutes. We do not use advertising or analytics cookies in this release.
What your account holds
Everything shown in your account is a record we hold about your organisation: the customer accounts you belong to and your role in each; your projects and their milestones; proposals, each version’s scope and price, and a record of who accepted a version and when; orders; invoices and their payment records; documents issued to you; support requests you or your team have raised; team invitations you have sent; and the enquiries you have claimed.
Our staff can attach internal notes to an account that are not shown in the portal. Actions taken through the account, such as accepting a proposal or submitting an enquiry, are logged with who took them and when. Nothing in the account is deleted automatically.
Bank-transfer evidence
This portal takes no payments. When you settle an invoice by bank transfer you may upload the transfer confirmation: a PDF, PNG or JPEG file of up to 8 MB. It is stored in a private area of our file storage under your account, visible to your team and to the finance staff who verify it, and it stays attached to the payment record as evidence of settlement.
Invoices, payment records and the evidence attached to them are accounting records. They are kept for as long as the law requires the company to keep its accounting records.
Your team
An owner or administrator of an account can invite others by email. We store the invited address and the role offered; the invitation link works once, for that address, for 7 days, and we keep only a hash of it. Members of an account see the same records you do, subject to their role, so invite people you would show those records to.
Documents
Documents are stored in private file storage and served through links that expire 60 seconds after you request them. Open the document again from your account if a link has expired.
What we deliberately do not collect
The enquiry rate limiter uses a salted one-way hash of the network address to recognise repeat requests. This is pseudonymous information, not a guarantee of anonymity. The enquiry payload does not store the raw network address or browser user-agent. This release contains no advertising or analytics tags or tracking pixels.
Cloudflare and Supabase process network-level data, including IP addresses and authentication events, to deliver and secure their services. These operational logs are separate from the enquiry record.
Who processes it, and where
Supabase provides our database, authentication and private file storage. The implementation team reports that our project is hosted in Mumbai, India (ap-south-1), outside the United Arab Emirates. The company must verify the current location and document the applicable safeguards for international transfers before this draft is approved.
Cloudflare hosts and serves the website, rate-limit counters and a notification queue. Google serves the typefaces, so it receives your browser’s font requests. The production email service and its processing locations are still to be confirmed; this draft must be updated after that service is configured.
Ask B², the voice and chat assistant, is provided by ElevenLabs and is loaded only after you choose Continue in its opening dialog; while you use it, what you say and type is processed by ElevenLabs on our behalf. We do not sell your information or use it for advertising. Service providers may use subprocessors under their service arrangements; those arrangements are part of the company’s processor review.
Voice assistant
Ask B², the voice and chat assistant in the corner of each page, is provided by ElevenLabs. Nothing is loaded from ElevenLabs and nothing is sent to it until you choose Continue in its opening dialog; the account-sharing checkbox is off by default. A temporary random identifier is used for each opening instead of the widget’s persistent browser-fingerprint identifier. When you use it, what you say and type is processed by ElevenLabs on our behalf so that it can answer.
Only if you select the account-sharing option and continue while signed in, the assistant is given a short-lived reference to your session and a summary of your own account in words: the account name and the names and stages of your projects, orders and open invoices, never an amount. It cannot see any other customer and it never receives your password or sign-in tokens. Anything it files for you, a brief or a support request, is stored as described on this page and appears in your account.
The provider’s recording, transcript-retention and processing-location settings are being verified. This page will state them once they are confirmed rather than promise them now; until then, assume that what you say to the assistant may be retained by the provider.
How long
Enquiries and account records are not deleted automatically today. This does not authorise indefinite retention. Before release, the company must approve a schedule by record category, assign a person to carry out deletion and document any legal holds or accounting obligations. That approved schedule will replace this draft explanation.
Your requests
Write to info@b2dynamics.com to request access to your information, correction, account closure or deletion. Account closure is not yet self-service. We may need proportionate information to verify your identity. We will assess the request and explain any information that must be retained and the reason; deletion remains subject to applicable legal obligations and rights.