Privacy Policy
Effective date: January 1, 2026 · Last updated: March 1, 2026
Summary (Plain Language)
PerfBee is a B2B web performance analytics platform. We collect only what we need to operate the service. We do not sell your data. Our Real User Monitoring (RUM) script is designed to operate without collecting personally identifiable information (PII) from your visitors.
1. Who We Are & Our Role
Techpiks Bilgi Teknolojileri Ticaret ve Limited Şirketi (Techpiks Information Technologies Ltd.), operating as Techpiks Digital Solutions (“PerfBee”, “we”, “us”, or “our”) operates the web performance analytics platform PerfBee, available at perfbee.com and dashboard.perfbee.com.
Address: Ritim İstanbul, Cevizli, Zuhal Cd. A5 Blok No: 46E/179, 34846 Maltepe/İstanbul, Türkiye
- Data Controller: For account data and platform usage data we collect directly from you (the customer).
- Data Processor: For RUM visitor data collected on your website on your behalf. In this capacity, you (the customer) are the data controller and are responsible for ensuring a valid legal basis under GDPR for collecting visitor performance metrics.
Contact: [email protected]
2. Data We Collect
2.1 Account Data
When you create an account, we collect: name, email address, password (hashed), and billing information. Payment processing is handled by our payment provider — we never store raw card numbers on our servers.
2.2 Usage Data
We collect information about how you interact with the platform: pages visited, features used, audit results, credit consumption, and support requests.
2.3 Technical Data
IP address, browser type, device type, operating system, and session identifiers. IP addresses are anonymized within 24 hours.
2.4 RUM Script Data (Your Visitors)
The PerfBee Real User Monitoring script you embed on your website collects only web performance metrics:
- Core Web Vitals (LCP, CLS, INP, FID, TTFB)
- Navigation timing data
- Browser name and device category (mobile/desktop)
- Page URL (path only, no query parameters by default)
The RUM script does NOT collect: IP addresses, user IDs, cookies, names, emails, or any personally identifiable information. It is designed to operate without collecting personal data.
3. How We Use Your Data
- Service delivery: Running audits, crawls, and RUM analytics on your behalf.
- Billing: Processing payments and managing your subscription.
- Communication: Sending transactional emails (alerts, audit results, billing receipts).
- Support: Responding to your requests and troubleshooting issues.
- Security: Detecting fraud, abuse, and unauthorized access.
- Product improvement: Analyzing aggregate, anonymized usage patterns to improve features.
We do not use your data for advertising, profiling, or sell it to third parties.
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA) and United Kingdom, our legal bases are:
- Contract (Art. 6(1)(b)): Processing necessary to deliver the service you subscribed to.
- Legitimate interest (Art. 6(1)(f)): Security monitoring, fraud prevention, and service improvement.
- Consent (Art. 6(1)(a)): Marketing emails (you can unsubscribe at any time).
- Legal obligation (Art. 6(1)(c)): Tax and financial record-keeping.
5. Data Retention
- Account data: retained for the duration of your subscription plus 90 days after closure.
- Performance and RUM data: retained according to your plan's history limit (3 days to 365 days).
- Billing records: retained for 7 years to comply with financial regulations.
- Anonymized aggregate data: may be retained indefinitely for statistical purposes.
6. Data Sharing & Sub-processors
We share data with a limited set of service providers under data processing agreements:
- Payment processor: Billing and subscription management. We never store raw card numbers.
- Cloud infrastructure provider: Server hosting in the EU.
- Transactional email provider: Sending system emails (alerts, receipts, password resets).
- Error monitoring provider: Anonymized error tracking to improve platform stability.
We may update our sub-processors from time to time. We will notify customers of any material changes. We do not share data with analytics companies, advertising networks, or data brokers.
A full sub-processor list is available upon request at [email protected].
7. International Data Transfers
Our servers are hosted in the European Union (EU). Personal data collected from EEA users remains within the EU and is therefore not subject to cross-border transfer restrictions under GDPR. Where we engage sub-processors outside the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent safeguards. You may request further information at [email protected].
8. Your Rights
8.1 GDPR Rights (EEA / UK Residents)
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure / “right to be forgotten” (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Rights related to automated decision-making (Art. 22) — see Section 11
8.2 CCPA Rights (California Residents)
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of sale (we do not sell personal information)
- Right to non-discrimination for exercising CCPA rights
To exercise any of these rights, email [email protected]. We will respond within 30 days (GDPR) or 45 days (CCPA). We may verify your identity via your registered email address before fulfilling requests.
9. Cookies
We use strictly necessary cookies for session management and authentication. We do not use advertising or tracking cookies. Cookie types used:
- Session cookies: Required to keep you logged in. Expire when your browser session ends.
- Authentication tokens: Stored in localStorage for persistent login. Can be cleared by logging out.
A detailed cookie list is available upon request at [email protected]. You can control cookies through your browser settings; disabling session cookies will prevent you from logging in.
10. Security
We implement industry-standard security measures including TLS 1.2+ encryption in transit, AES-256 encryption at rest, bcrypt password hashing, regular vulnerability scanning, and access control with least-privilege principles. In the event of a data breach affecting your rights, we will notify you within 72 hours as required by GDPR.
11. Automated Decision-Making
PerfBee does not perform automated decision-making or profiling that produces legal or similarly significant effects on individuals, as described under Art. 22 GDPR. Platform features (e.g., anomaly alerts, credit limits) are rule-based and do not constitute automated individual decision-making in the legal sense.
12. Data Processing Agreement (DPA)
As a data processor for RUM visitor data collected on your behalf, we are prepared to enter into a Data Processing Agreement (DPA) with customers subject to GDPR. Customers may request a DPA by contacting [email protected].
13. Children's Privacy
PerfBee is a B2B service intended for businesses and developers aged 18 and over. We do not knowingly collect data from children under 13 (COPPA) or under 16 (GDPR). If we discover such data has been collected, we will delete it immediately.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you by email and by posting a notice in the dashboard at least 30 days before material changes take effect. Continued use after the effective date constitutes acceptance.
15. Contact & Complaints
For privacy questions, DPA requests, or to exercise your rights: [email protected]
If you believe we have not handled your data appropriately, you have the right to lodge a complaint with your local supervisory authority. In the EU, find your authority at edpb.europa.eu. In the UK, contact the ICO at ico.org.uk.