Legal
Privacy Policy
Last updated: 23 June 2026
1. Who we are
Beginly (“we”, “us”, or “our”) is an independent UK settlement guidance platform. We help people arriving in the United Kingdom to navigate their first 90 days through personalised checklists, plain-English guidance, and scam alerts.
Contact: privacy@beginly.app
2. What personal data we collect
When you create a Beginly account and use our platform, we may collect the following information:
- Account information: your name, email address, and password (managed securely by Supabase Auth).
- Arrival profile: city, university, accommodation type, arrival date, nationality, English level, and work interest — collected during onboarding.
- Checklist data: tasks you complete or save, which reflect your settlement progress.
- Usage data: pages you visit, features you use, and general device/browser information (via standard server logs).
- Communication data: any messages you send us via the support form or Nia chatbot.
3. How we use your data (lawful basis)
Under UK GDPR, we must have a lawful basis for processing your personal data. We rely on the following:
- Contract (Art. 6(1)(b)): To provide our service to you — generating your personalised checklist and tracking your progress — we need your account and profile data.
- Legitimate interests (Art. 6(1)(f)): To improve our platform, send you service-related notifications (e.g. task reminders you have enabled), and prevent fraud.
- Consent (Art. 6(1)(a)): For any marketing communications or optional notifications. You can withdraw consent at any time via your account settings.
4. How we store and secure your data
Your data is stored in Supabase (hosted on servers within the United Kingdom or European Economic Area) and protected by Supabase's built-in Row Level Security (RLS) policies. Authentication is handled by Supabase Auth, which stores passwords using secure hashing (bcrypt). We do not store your raw password.
We regularly review our security measures and will notify you (as required by law) of any personal data breach that is likely to result in a risk to your rights and freedoms.
5. Who we share your data with
We do not sell, rent, or trade your personal data to third parties. We share data only in the following limited circumstances:
- Service providers: We use Supabase as our backend (database and authentication). Their use of your data is governed by their privacy policy.
- Nia: When you use the Nia chatbot, your messages are processed to provide relevant guidance. Nia is disclosed as an automated tool and does not receive your personal account data.
- Legal obligations: We may disclose data if required by law, court order, or to protect our legal rights.
6. Cookies
We use cookies to keep you signed in and to remember your preferences. Supabase Auth sets essential session cookies that are required for the platform to function. We do not use advertising or tracking cookies.
You can manage cookie preferences in your browser settings. Disabling essential cookies will prevent you from logging in.
7. How long we keep your data
We retain your account data for as long as your account is active. If you delete your account, we will erase your personal data within 30 days, unless we are required to retain it longer for legal, accounting, or compliance reasons (in which case it will be retained for no longer than necessary).
8. Your rights under UK GDPR
As a UK resident, you have the following rights regarding your personal data:
- Right of access — Request a copy of all data we hold about you.
- Right to rectification — Ask us to correct inaccurate data.
- Right to erasure — Request deletion of your account and data (“right to be forgotten”).
- Right to restriction — Ask us to stop processing your data in certain circumstances.
- Right to data portability — Receive your data in a structured, machine-readable format.
- Right to object — Object to processing based on legitimate interests.
- Rights related to automated decision-making — You have the right not to be subject to solely automated decisions that significantly affect you. Our Nia chatbot uses automated, rule-based logic and does not make automated decisions with legal or similarly significant effects.
To exercise any of these rights, email us at privacy@beginly.app. We will respond within one month of receiving your request, as required by UK GDPR.
9. Children's privacy
Beginly is not intended for use by anyone under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a minor, we will delete it promptly.
10. Changes to this policy
We may update this Privacy Policy from time to time. Any material changes will be communicated by posting the updated policy on this page with a revised “Last updated” date. We encourage you to review this page periodically.
11. Complaints
If you have concerns about how we handle your personal data, you have the right to complain to the Information Commissioner's Office (ICO), the UK's independent authority for data protection.