This Privacy Policy explains how furbsh-Tech Ltd, operator of BCircle, handles personal data when BCircle itself determines why and how that data is processed.
Controller: furbsh-Tech Ltd, Kenya
Registered office: Western Heights, Karuna Road, Westlands, 1911 - 00606, Nairobi, Kenya
Privacy contact: care@bcircle.app
EU Representative: C. J. Deg L. Ferraz, Finland — care@bcircle.app
BCircle is being built first with doulas in Finland and is intended to operate in accordance with applicable European data-protection requirements where they apply, including the EU General Data Protection Regulation (GDPR).
1. BCircle's different privacy roles
BCircle has two important roles.
When furbsh-Tech is the controller
furbsh-Tech generally acts as controller for data needed to:
- create and administer BCircle accounts;
- authenticate users and secure the service;
- operate and improve the BCircle platform;
- provide support;
- administer BCircle subscriptions and related entitlement, including through our third-party Merchant of Record (Creem);
- secure, maintain and operate BCircle payment initiation and reconciliation functionality, including through Stripe Connect;
- maintain security, audit and operational records; and
- comply with our own legal obligations.
When a professional is the controller
When a doula or other professional uses BCircle to create and manage records about a client, that professional normally decides why the client information is collected and how it is used in the professional relationship. The professional is therefore normally the controller and furbsh-Tech acts as processor on the professional's instructions.
If you are a client asking about information held in your doula's professional workspace, your doula may therefore be the appropriate controller for the request. BCircle will help route or support the request where appropriate.
The legal role always depends on the actual processing activity.
2. Information we may process as controller
Depending on how you use BCircle, we may process:
- name, email address and account identifiers;
- professional/business profile information;
- role and permission information;
- authentication/session information;
- account preferences such as theme or locale when available;
- invitations and account relationships;
- support enquiries and correspondence;
- technical and security information such as request, device, browser, IP and audit information where generated by the service or hosting infrastructure;
- BCircle subscription, entitlement and billing information;
- records of acceptance of Terms and policy versions; and
- records of a professional's acknowledgement of responsibility for their business and tax information, together with the server-generated acknowledgement timestamp.
When a professional uses BCircle's professional finance and invoicing features, we may also process the professional's finance and tax settings. These may include:
- country;
- legal or trading/business name;
- business registration identifier;
- business address;
- VAT/tax registration status;
- VAT/tax identifier;
- a professional-entered tax rate;
- an exemption or non-registration note;
- the chosen invoicing mode; and
- the selected external invoicing provider or external billing arrangement, where the professional records one, or its name.
When a professional connects online payment through Stripe Connect, we may also process the professional's Stripe connection metadata, including:
- the professional's Stripe connected account ID;
- charges-enabled status;
- payouts-enabled status;
- details-submitted/onboarding status;
- connection and update timestamps; and
- minimal reconciliation or payment-status identifiers.
BCircle does not receive or store the professional's bank account credentials, bank login credentials, Stripe password or card credentials entered through Stripe. Professional business and bank onboarding information is entered directly into Stripe-hosted interfaces, and Stripe may independently receive and process that information under its own terms and privacy arrangements.
When a client pays a professional's BCircle invoice online, BCircle may store Stripe-generated identifiers and status needed for payments, including where applicable:
- Checkout Session ID;
- PaymentIntent ID;
- Stripe Customer ID;
- PaymentMethod ID;
- SetupIntent or setup-session ID;
- payment state;
- paid timestamp;
- a connected-account identifier;
- scheduled-payment authorization state;
- authorization timestamp;
- the exact authorized schedule snapshot;
- an authorization version; and
- an authorization revocation timestamp.
BCircle does not store card numbers (PANs), CVC values or other full card credentials. The client enters payment-method details directly into Stripe-hosted payment or setup interfaces.
When you purchase or manage a BCircle subscription, Creem (operated by Armitage Labs OÜ) acts as the Merchant of Record for the subscription transaction and processes the payment. BCircle may receive or process subscription-related information relating to that transaction, which may include:
- name;
- email address;
- country and billing information;
- subscription and product identifiers;
- order and checkout identifiers; and
- payment/transaction information handled by Creem, such as transaction status and references.
BCircle does not receive or store full card or payment credentials for BCircle subscriptions. Card and payment details are entered into Creem-hosted checkout and are handled by Creem. BCircle processes the subscription and account data it receives for account access, entitlement, support, reconciliation and compliance.
Creem may act as an independent controller, a joint controller or a processor depending on the processing context and its agreements — for example, in connection with payment processing, fraud prevention, invoicing and applicable tax handling. Creem's handling of personal data is described in the Creem Privacy Notice at https://www.creem.io/privacy.
We do not currently use advertising trackers or product-analytics platforms.
3. Client and health-related information
BCircle can be used by professionals to store information connected with pregnancy, birth, postpartum support, bereavement, family circumstances and related records. Some of this may be health data or other special-category personal data under GDPR.
Where a professional enters or manages this information for their work, BCircle normally processes it as a processor on the professional's instructions. The professional is responsible for identifying an appropriate lawful basis and, where required, an applicable GDPR Article 9 condition for special-category data.
BCircle seeks to minimise unnecessary sensitive-data collection and does not use client health information for advertising.
4. Why we use personal data and our legal bases
Where furbsh-Tech acts as controller, we may rely on:
- Contract: to create and operate your account and provide BCircle features you request.
- Legitimate interests: to secure, maintain and improve BCircle, prevent misuse, troubleshoot problems and protect users and the service, where those interests are not overridden by your rights.
- Legal obligation: where we must process or retain information to comply with applicable law.
- Consent: where a feature genuinely requires consent, such as optional marketing or non-essential cookies if introduced. Consent can be withdrawn where it is the basis for processing.
We do not treat acceptance of this Privacy Policy as blanket consent for processing.
A professional's finance and tax settings are used to configure and operate BCircle's professional invoicing and finance functionality, to preserve the professional's settings, and to support, secure and maintain BCircle and its legal and business records. Where a professional enables invoicing within BCircle, these professional-entered settings are used as the professional-provided source of invoice information. BCircle does not determine a professional's tax liability. These finance and tax settings are not transmitted to any named third-party invoicing provider or external billing arrangement (payment processing through Stripe is described separately below).
Where online payment is enabled, the data BCircle sends to Stripe is deliberately minimal and may include:
- the payment amount;
- the currency;
- the BCircle invoice number and a payment description;
- an internal invoice/reconciliation identifier;
- the Stripe connected-account context; and
- return/cancel URLs for the payment flow.
For scheduled-payment setup and processing, this also includes the minimal setup and reconciliation identifiers needed to connect the saved payment method to the correct BCircle client and payment schedule.
BCircle does not send Stripe birth or health information, agreement contents, clinical notes, tax IDs or unnecessary client profile data. Professional onboarding and client card details are entered directly with Stripe by the user.
5. Service providers
BCircle currently relies on the following core service providers or categories:
- MongoDB Atlas — application database infrastructure;
- Cloudflare R2 — private file/document storage;
- SendGrid — transactional emails such as invitations and password resets;
- Stripe (Stripe Connect) — connected-account onboarding, payment-method setup, payment processing and payment reconciliation for online client payments;
- Creem (Armitage Labs OÜ) — Merchant of Record for BCircle subscription transactions, including payment collection, buyer invoicing and applicable indirect transaction tax handling; and
- Vercel — planned application hosting for the pilot/production deployment.
These providers process information only to the extent needed for the services they provide to us, subject to their applicable contractual and data-protection arrangements. Stripe and Creem do not receive all BCircle user data; only the limited payment- and subscription-related information described in this policy is involved in online-payment and subscription processing.
We may update the provider list as BCircle evolves. Material changes will be reflected in this policy or an associated sub-processor list.
6. Maps and calendar services
BCircle does not currently embed a paid maps SDK or continuously track a user's location.
When a user chooses an action such as Open in Apple Maps, Open in Google Maps or Add to Google Calendar, BCircle may construct a link containing the relevant route, address or appointment information. The user then chooses to open the third-party service, and that provider processes the information under its own privacy terms.
Apple/iCalendar .ics files are generated for the user rather than automatically sending event data from BCircle to Apple.
7. Cookies and local device storage
BCircle uses authentication/session technology needed to keep signed-in users securely authenticated. The public site currently has no analytics or advertising trackers.
BCircle may also use device storage to remember a user-requested interface preference, such as light/dark theme. See the Cookie Policy for current details. Stripe's payment and setup pages are hosted by Stripe, and Creem's subscription checkout pages are hosted by Creem; both are governed by the relevant provider's own cookie and privacy practices.
If BCircle later introduces non-essential analytics, marketing or similar tracking technologies, we will obtain consent where required before using them.
8. International processing and transfers
furbsh-Tech Ltd is established in Kenya, while BCircle is initially serving users in Finland and may use service providers operating infrastructure in more than one country.
Where GDPR applies and personal data is transferred from the EEA to a country without an applicable European Commission adequacy decision, BCircle and relevant professional controllers will use an appropriate transfer mechanism where required, such as the European Commission's Standard Contractual Clauses, together with any additional safeguards required by law.
For professional/client data where furbsh-Tech acts as processor, the applicable transfer arrangements form part of the professional's data-processing arrangement with BCircle.
Where a provider such as Creem or Stripe processes payment or subscription data under its own agreements, that provider is responsible for the transfer arrangements it puts in place for the data it controls or processes on its own behalf.
9. How long we keep data
We keep personal data only for as long as reasonably needed for the purpose for which it was collected, to provide the service, protect security and integrity, resolve disputes, comply with lawful instructions from a professional controller, and meet applicable legal obligations.
We do not apply one universal retention period to all BCircle data.
Stripe payment identifiers and payment status are kept only for as long as reasonably needed to reconcile and record payments, support the professional's and client's records, and meet applicable legal or accounting obligations.
BCircle subscription and entitlement records, together with the limited Creem transaction information we hold, are kept only for as long as reasonably needed to provide access, support reconciliation and compliance, and meet applicable legal or accounting obligations.
Where a professional is the controller of client records, the professional is responsible for determining the appropriate retention period for those records, subject to applicable law and professional obligations. BCircle will support deletion/return according to the data-processing arrangement and technical backup cycles.
10. Security
BCircle uses technical and organisational measures designed to protect personal data. Current measures include server-authoritative authentication and roles, access controls, private document storage, signed file access, validation of uploaded files, request-origin/CSRF protections, security headers, rate limiting and audit/security controls.
No system can guarantee absolute security. Users should also protect their devices and login credentials.
11. Your rights
Where GDPR applies and furbsh-Tech is the controller, you may have rights to:
- access your personal data;
- correct inaccurate personal data;
- request deletion of personal data;
- restrict certain processing;
- object to processing based on legitimate interests;
- receive certain personal data in a structured, commonly used and machine-readable format where portability applies;
- withdraw consent where processing relies on consent; and
- lodge a complaint with a competent data-protection supervisory authority.
Rights are not absolute and may be limited where applicable law permits or requires continued processing.
We normally respond to valid GDPR rights requests within the time required by GDPR, generally one month, subject to permitted extensions for complex or numerous requests.
12. Account export and deletion
BCircle is implementing controls that allow account holders to request or obtain their account data and to request account deletion/erasure.
A request to delete a BCircle account does not automatically mean that every professional record mentioning the person can be erased immediately. For example:
- the record may be controlled by a doula rather than BCircle;
- the record may contain personal data about other people;
- the controller may have a lawful retention obligation; or
- limited information may need to be retained for security, legal or dispute purposes.
Where another user is the controller, BCircle may route the request to that controller and assist them in responding.
13. Children
BCircle accounts are intended for adults unless we expressly support another arrangement.
Professional users may sometimes need to record information about babies, children or minors as part of lawful professional records. In those cases the professional is responsible for ensuring the collection and processing is lawful and proportionate.
14. Automated decision-making and AI
BCircle does not currently use an AI assistant to make decisions about users or clients, and it does not currently perform solely automated decision-making producing legal or similarly significant effects.
If BCircle introduces AI-assisted features in the future, this policy and the product disclosures will be updated before those features are used with personal or special-category data where required.
15. Changes to this policy
We may update this Privacy Policy when BCircle changes or legal requirements evolve. We will publish the current version and effective date and provide appropriate notice of material changes.
16. Complaints and contact
Privacy questions or requests may be sent to:
furbsh-Tech Ltd
Western Heights, Karuna Road, Westlands, 1911 - 00606, Nairobi, Kenya
care@bcircle.app
Where applicable, you may also complain to the data-protection authority competent for your circumstances. Users in Finland can contact the Office of the Data Protection Ombudsman.