Account and identity data
Name, email, phone, date of birth, account type, language, login and verification information.
This Policy explains in detail how Besouria collects, uses, discloses, protects and retains personal data across accounts, profiles, opportunities, the Business Directory, communications, verification and security operations.
The Policy applies to visitors, registered users, opportunity publishers, employers, business owners, reviewers and anyone who contacts or interacts with the Platform.
Name, email, phone, date of birth, account type, language, login and verification information.
Professional, business, location, opportunity, directory, review, rating, comment and contact information.
IP address, device, browser, session, cookie choice, timestamps, security events and activity records.
Messages, reports, complaints, moderation appeals, legal requests and correspondence with the Platform.
This document reflects the Platform’s current operation and settings. Administrators must update it when adding a new provider, data category or purpose.
This Privacy Policy applies to Besouria, its public pages, account area, dashboards, opportunity listings, Business Directory, profiles, comments, ratings, reviews, reports, moderation tools and related services (the “Platform”). It applies when you visit, register, publish, apply, contact another user, submit verification materials or communicate with us.
Besouria is the organisation responsible for deciding why and how personal data is processed for the core operation, security and administration of the Platform. Its legal and contact information appears at the end of this Policy.
A publisher, employer, company or business owner may separately determine how it uses personal data received from applicants, customers or contacts outside the Platform. In that situation, the publisher may be an independent controller and must provide its own privacy information and comply with applicable law.
Back to contents ↑“Personal data” means information relating to an identified or reasonably identifiable person. “Processing” includes collecting, recording, organising, storing, viewing, using, sharing, restricting, deleting or otherwise handling personal data.
“Public content” means information intentionally placed in a public profile, opportunity, business listing, review, comment or other publicly accessible area. “Service provider” or “processor” means a company that handles data for us under instructions, such as hosting, email, security, storage or analytics providers.
References to “you” include visitors, account holders, applicants, publishers, employers, business owners, representatives and persons who contact us.
Back to contents ↑The data collected depends on how you use the Platform. You can browse some public pages without an account, but registration, publishing, verification, communication and moderation features require additional information.
We do not ask users to provide more information than reasonably required for a feature. Some fields are mandatory because they are needed to create an account, prevent abuse, review a listing or satisfy a legal requirement; other fields are optional.
For operational security and an administrator-only live activity view, we may temporarily record a session identifier, signed-in account details where available, country code supplied by trusted hosting or CDN headers, device/browser category, current page URL, page title and last-activity time. Anonymous visitors have no account name or email attached.
Most data is provided directly by you when you create an account, complete a profile, publish content, upload a document, communicate with another user or contact the Platform.
We also generate data through normal use of the Platform, including login records, security alerts, activity logs, cookie choices and moderation history. We may receive information from another user who reports content, names you as a representative, invites you to participate or communicates with you.
Where legally permitted, we may verify public professional or business information using official registers, company websites, public social profiles, sanctions lists, fraud-prevention sources or documents supplied by an authorised representative. We do not treat publicly available data as exempt from privacy obligations.
Back to contents ↑We use personal data only for specified operational, safety, communication and legal purposes. The legal basis depends on the data, purpose, location and relationship involved.
Where European, UK or similar laws apply, processing may rely on performance of a contract, steps requested before entering a contract, consent, compliance with a legal obligation, protection of vital interests, or our legitimate interests where those interests are not overridden by your rights. Where consent is used, it may be withdrawn at any time without affecting earlier lawful processing.
Where another legal framework applies, we process data on the equivalent grounds available under that framework and honour mandatory rights that cannot be excluded.
Account credentials and private account controls are not intended to be public. Profile information may be public, visible only to registered users or private depending on the feature and settings available at the time.
You are responsible for reviewing your profile and listing visibility before publication. Search engines and third parties may copy or index public information, and removing content from the Platform may not immediately remove copies held by search engines, archives or recipients.
We may retain an internal record of previous usernames, status decisions or ownership changes when reasonably necessary to prevent impersonation, resolve disputes or maintain audit integrity.
Back to contents ↑Information submitted to public opportunities, business listings, public profiles, reviews or comments is intentionally made accessible to others. This may include a name, business identity, city, professional details, website, telephone number, email or social link when you choose to publish it.
Do not publish home addresses, identity-document numbers, financial credentials, health data, children’s data or other sensitive information unless the Platform specifically requests it through a protected workflow and publication is legally permitted.
Other users may contact you using information you publish. Their independent use of information outside the Platform is governed by their own responsibilities and applicable law. Report scraping, harassment, spam or misuse to us.
Back to contents ↑Verification may require documents or evidence showing identity, business registration, authority to represent an organisation, professional qualification or ownership of a listing. Verification is intended to reduce risk but is not a guarantee of honesty, solvency, legality or future conduct.
Verification materials are treated as restricted data and are not displayed publicly unless you separately choose to publish information that is lawful and appropriate. Access should be limited to authorised personnel and service providers who need it for review, security, legal compliance or dispute handling.
Do not upload a passport, national identity card, bank record, criminal record, health record or similarly sensitive document unless it is specifically requested in an official verification channel. We may reject, redact or delete unnecessary sensitive material.
Back to contents ↑We use contact details to send essential service communications such as account notices, verification outcomes, moderation decisions, security warnings, password or login messages, replies to requests and material changes to legal documents.
Optional newsletters, promotional messages or non-essential notifications are sent only where permitted and may be disabled using the available preference, unsubscribe method or privacy contact. You may still receive essential administrative or security messages.
Private messages are not publicly visible, but we may access or preserve relevant messages when a participant reports them, when necessary to investigate fraud, threats or Terms violations, or when required by law. We do not routinely read private communications without a legitimate operational reason.
When profile-visit notifications are enabled, we record a limited event so the profile owner can know that the public profile was viewed. A visitor name may appear only for a registered member with an approved public profile; anonymous visitors are not identified and their email or technical address is not exposed. Repeated visits are grouped to reduce noise.
Back to contents ↑The Platform uses strictly necessary cookies or similar storage to maintain sessions, remember language and theme choices, protect forms, prevent abuse and preserve your cookie preference. These technologies are required for requested functionality and cannot always be disabled through our interface.
Optional analytics or advertising technologies are not loaded before consent where consent is required and the consent setting is enabled. You can accept or reject optional analytics using the cookie banner or the controls on this page.
Browser settings may block or delete cookies, but doing so can sign you out, reset preferences or prevent parts of the Platform from working. Cookie duration and provider details may change as technical services are updated; material changes will be reflected in this Policy or a dedicated cookie notice.
Back to contents ↑If analytics is enabled, we may use configured measurement providers to understand page usage, device types, referral sources, errors and broad performance trends. Optional providers may place identifiers or receive technical data only after the applicable consent or other lawful condition is satisfied.
The Platform does not sell personal data for money. If an optional advertising or analytics disclosure is legally classified as a “sale”, “sharing”, targeted advertising or cross-context behavioural advertising in a particular jurisdiction, we will provide the required notice and choice and will honour recognised opt-out preference signals where applicable.
A Global Privacy Control signal detected by the Platform is treated as a request to keep optional analytics disabled for that browser. The signal does not affect strictly necessary processing.
Back to contents ↑We disclose personal data only as reasonably necessary for the purposes described in this Policy, at your direction, or where required or permitted by law. Recipients are expected to use appropriate confidentiality, security and data-protection measures.
We do not give verification documents or private account data to other users merely because they request them.
Besouria is designed for users in multiple countries. Data may therefore be accessed, stored or processed in countries other than the country where you live, including countries where the Platform or its approved providers operate infrastructure.
Where transfer restrictions apply, we use a legally recognised mechanism appropriate to the transfer, which may include an adequacy decision, standard contractual clauses, an international data transfer agreement, approved contractual terms, consent in limited circumstances, or another lawful safeguard.
No transfer mechanism removes all risk. We assess providers, limit access, use contractual and technical safeguards where appropriate, and consider the nature of the data and destination. You may contact us for available information about safeguards relevant to your data.
Back to contents ↑We use administrative, organisational and technical measures intended to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include password hashing, access controls, session protection, upload restrictions, protected storage, logging, backups and review of suspicious activity.
No website, storage system or transmission method is completely secure. You must use a strong unique password, protect devices and email accounts, sign out from shared devices and promptly report suspected compromise.
We may temporarily restrict an account, reset sessions, preserve evidence or require additional verification when we reasonably suspect account takeover, fraud or a security incident.
Back to contents ↑We retain personal data only for as long as reasonably necessary for the purpose collected, including providing the service, maintaining security, complying with law, resolving disputes and enforcing agreements. Retention is determined by the data category, account status, visibility, legal requirements, limitation periods, risk and backup cycles.
Account and profile data is generally kept while the account remains active. After closure or deletion, some data may remain for a limited period in backups, audit records, fraud-prevention records, legal files or de-identified statistics. Public content may be retained or removed according to account status, moderation decisions, legal obligations and legitimate recordkeeping needs.
Verification documents should be deleted or minimised when they are no longer required for verification, security, dispute or legal purposes. We may retain proof that verification occurred without retaining the full underlying document.
The administrator-only online-presence record is designed to expire after 20 minutes without activity. Expired rows are removed automatically on the next Platform or administrator request and are not intended as a long-term browsing-history log.
Back to contents ↑Depending on the law that applies, you may have rights to be informed, access personal data, receive a copy, correct inaccurate data, delete data, restrict processing, object to processing, withdraw consent, obtain portable data, opt out of certain disclosures or targeted advertising, and complain to a supervisory authority.
Rights are not absolute. We may deny or limit a request where permitted, including to protect another person’s rights, preserve evidence, comply with legal duties, maintain security, complete a transaction requested by you, or address manifestly unfounded or excessive requests.
We will not discriminate against you for exercising a legally protected privacy right. Account features may become unavailable where the requested deletion or restriction makes the service impossible to provide.
Back to contents ↑Submit a request through the Contact page or email doughouzander@gmail.com and clearly state that it is a privacy request. Describe the account, data and right involved. We may ask for information reasonably necessary to verify identity and authority before acting.
An authorised agent may submit a request where permitted, but we may require evidence of authority and direct confirmation from the person concerned. Do not send identity documents by ordinary email unless specifically requested through a secure method.
We respond within the period required by applicable law. Complex or numerous requests may require an extension where allowed, and we will explain the reason. Requests are normally free, but a reasonable fee or refusal may apply to manifestly unfounded, excessive or repetitive requests where law permits.
Back to contents ↑The Platform is not directed to children below the configured minimum registration age of 16. We do not knowingly create accounts for persons who do not satisfy the applicable age requirement.
Parents, guardians, schools, employers and publishers must not post children’s personal data, photographs, contact information or documents unless they have a valid legal basis, required permissions and appropriate safeguards. Content involving minors may receive stricter moderation or be removed.
If you believe a child provided personal data unlawfully or without required permission, contact us promptly. We may request information to verify the report before restricting or deleting the data.
Back to contents ↑Employers, opportunity publishers and business owners must use personal data obtained through the Platform only for the stated legitimate purpose, protect it, limit access and delete it when no longer needed. They must not build unrelated marketing lists, sell applicant data, conduct unlawful background checks or request excessive sensitive data.
Where a business user exports, copies or receives applicant, customer or contact data and independently determines how it will be used, that business user may become a separate controller. It is then responsible for its own lawful basis, notice, security, retention, rights handling and cross-border transfers.
Besouria may investigate credible privacy complaints against publishers and may restrict listings, suspend accounts, preserve evidence or cooperate with authorities where appropriate.
Back to contents ↑The Platform may use automated tools to detect spam, duplicates, suspicious activity, prohibited content, security events, incomplete fields or possible policy violations, and to organise or rank content. Automated signals may assist human review but can be inaccurate.
We do not intend to make solely automated decisions that produce legal or similarly significant effects on individuals without safeguards required by law. Where such processing is introduced, we will provide additional information and rights where applicable.
Do not submit confidential, highly sensitive or third-party personal data to any AI-assisted feature unless the interface specifically explains how that data will be handled and you are authorised to provide it.
Back to contents ↑Listings, profiles and articles may link to external websites, maps, social networks, payment providers, messaging services or other third parties. Their privacy practices are controlled by them, not by Besouria.
Opening an external link or using an embedded service may allow that provider to collect device, account or usage data. Review the provider’s privacy notice and settings before sending personal information or making a payment.
We are not responsible for independent third-party processing, but we may remove integrations or links that present a credible privacy or security risk.
Back to contents ↑This section provides additional information for users in regions with comprehensive privacy laws. It applies only where the relevant law covers the Operator and the processing.
For the EEA and United Kingdom, users may have GDPR or UK GDPR rights, may object to legitimate-interest processing and may complain to the data-protection authority in their country. International transfers are made using an available lawful mechanism.
For the United Arab Emirates, data subjects may have rights under Federal Decree-Law No. 45 of 2021, including access, correction, restriction, objection and data transfer rights, subject to statutory conditions and exceptions.
For Türkiye, relevant processing may be subject to Law No. 6698 and related rules, including rights to learn whether data is processed, request information, correction or deletion, and object to certain results.
For California residents, if the CCPA/CPRA applies to the Operator, rights may include knowing, accessing, correcting, deleting, opting out of sale or sharing, limiting certain sensitive-data uses and non-discrimination. Besouria does not sell personal data for money. Other US state rights will be honoured where applicable.
Back to contents ↑If a personal-data breach occurs, we will investigate, take reasonable containment and remediation steps, document the incident and notify affected persons or authorities when required by applicable law.
We may update this Policy to reflect legal, technical, organisational or service changes. The version and effective date appear at the top. Material changes may be announced through the Platform, email or another appropriate channel.
Continued use after a change does not replace consent where consent is legally required. Previous versions may be retained for audit and transparency purposes.
Back to contents ↑When you use Besouria AI, we process the text you submit, the selected assistance mode, conversation language, timestamps, free-credit usage and technical request information needed to provide, secure and improve the service. If conversation history is enabled, messages are stored in protected runtime storage and associated with your account or an anonymous browser identifier.
The Human Compass processes answers you voluntarily provide to create a non-clinical work-style reflection. It is designed for self-understanding and opportunity guidance, not medical diagnosis, psychological treatment or automated employment decisions. Results may be saved so you can revisit them or discuss them with the AI assistant.
The AI provider may be a locally hosted model or an administrator-configured compatible endpoint. The active provider and retention settings determine whether prompts leave Besouria infrastructure. Administrators must configure providers consistently with this Policy and applicable contracts. Do not submit passwords, payment-card details, identity documents, confidential employer information or data about another person without authority.
The privacy contact is doughouzander@gmail.com. Include “Privacy Request” or “Privacy Complaint” in the subject and provide enough information to identify the account or content involved without sending unnecessary sensitive documents.
You may also contact the data-protection officer or regional representative shown below, if one has been appointed. We encourage you to contact us first so we can investigate and respond.
You may lodge a complaint with the competent privacy or data-protection authority where you live, work, where the Operator is established, or where an alleged violation occurred, subject to applicable law.
Back to contents ↑