Privacy & Cookie Policy
How Benedict Corp. collects, uses, and safeguards data across our website, applications, and demo environments.
Effective date: August 22, 2026
1. Introduction
Dmytro Belykh & Benedict Corp. ("we", "our", "us") respects your privacy and is committed to protecting your personal information.
This Privacy & Cookie Policy explains how we collect, use, and safeguard your data when you visit our website (https://benedictcorp.com), use our applications, participate in demos, or engage with us through partner platforms such as Gumroad, Upwork, or Fiverr (collectively, the "Services").
By using our website or submitting any form, you agree to the practices described in this Policy.
2. Who We Are
Dmytro Belykh, operating under the Individual Activity certificate in the Republic of Lithuania and trading under the brand name "Benedict Corp."
Contact: info@benedictcorp.com
Website: https://benedictcorp.com
We build and distribute digital solutions based on Microsoft technologies.
Our website is hosted on Microsoft Azure Static Web Apps, and demo applications are operated within our Microsoft 365 tenant.
3. What Personal Data We Collect
We collect only the minimum information required to provide and improve our services.
a) Website Contact Form
When you submit our contact form, we collect the information you provide — your name, email address, company name (optional), and your message — for the purpose of responding to your inquiry, providing information, or scheduling a demo.
Submitting the form also involves the following technical processing, described in more detail in Section 4:
- A verification check (Cloudflare Turnstile) to confirm the submission is not automated.
- Temporary, short-lived logging of your IP address for spam and abuse prevention.
b) During Sales or Purchase
When you purchase a product or service, or enter into a contractual engagement with us, we may collect:
- Full name
- Company name
- Email address
- Billing address
- Bank account or payment details
- Tax or business registration information
This information may be securely stored within Benedict App, our internal system used for managing client relationships, licenses, and invoicing.
It is used solely for:
- Contract execution and license management
- Issuing invoices and maintaining accounting records
- Providing client support and updates
We retain this data for as long as necessary to comply with legal and financial obligations — typically up to 10 years for accounting purposes.
We do not share this information with third parties other than payment processors or accounting partners when legally required.
c) Pilot & Demo Testing and Trial Access
If you participate in a demo or pilot version of our applications:
- You connect to our Microsoft 365 tenant environment.
- Your Microsoft account information (name, email, organization) and activity logs may be collected automatically by Microsoft for security and performance monitoring.
This data is processed strictly for demonstration purposes and is deleted automatically after each demo session.
4. Technical Data, Contact Form Security, and Data Flow
Our website itself does not use tracking or advertising cookies, and does not run general visitor analytics. The technical processing described below exists solely to operate and protect the contact form.
a) Hosting
Our website is hosted on Microsoft Azure Static Web Apps. The underlying server infrastructure is located within Microsoft's European data centers.
b) Spam and Bot Protection (Cloudflare Turnstile)
Our contact form uses Cloudflare Turnstile to verify that a submission comes from a real visitor rather than an automated script.
- Turnstile may set a small number of cookies on your device as part of this verification. These are strictly necessary, security-purpose cookies used only to assess the submission — they are not used for tracking or advertising, and do not follow you across other websites.
- As part of this verification, Cloudflare receives your IP address to assess the request. We do not store this raw IP address ourselves — see below.
- Cloudflare acts as an independent data controller for this processing. See Cloudflare's Privacy Policy.
c) Rate Limiting and IP Address Handling
To prevent abuse of the contact form (e.g. automated flooding), our system temporarily records submission attempts. Rather than storing your IP address directly, we store a one-way cryptographic hash of it — a value that cannot practically be reversed back into your original IP address.
- This hashed value, together with a timestamp, is stored in Azure Table Storage, located in Microsoft's European infrastructure.
- It is used solely to detect and limit an unusually high number of submissions from the same origin within a short window.
- This data is automatically deleted, typically within 24 hours of being recorded. In periods of very low website traffic, deletion may occasionally take somewhat longer, since cleanup runs as part of normal form processing rather than on a separate fixed schedule.
d) How a Submission Is Processed (Data Flow)
When you submit the contact form, your information (name, email, company, message) is sent to an Azure Function operating on infrastructure located in Europe. After the security checks described above, your submission is forwarded — over an authenticated, non-public connection — to a Microsoft Power Automate flow, which:
- Creates a corresponding record in a SharePoint list used internally to manage inquiries; and
- Sends an email notification to us, and an automatic confirmation email to you.
Power Automate and SharePoint operate within our own Microsoft 365 tenant, subject to Microsoft's own data processing and retention practices, including the standard operational logging Microsoft applies to flow runs. See Microsoft's Privacy Statement.
5. How We Use Your Data
We use your data to:
- Respond to inquiries and schedule demos
- Provide and maintain our products and services
- Manage licenses, billing, and accounting
- Communicate about updates, releases, or technical support
- Ensure system security, prevent misuse, and comply with legal obligations
We do not sell or rent personal data.
6. Marketing and Business Communication
We may contact our existing or prospective clients through professional channels such as email, LinkedIn, Upwork, or other business platforms to share relevant information about our products, updates, or new releases. These communications are limited to legitimate business purposes and are never performed in bulk or through advertising networks. You can opt out of receiving such messages at any time by replying "unsubscribe" or contacting info@benedictcorp.com.
We do not sell or share contact data for marketing purposes.
7. Business Outreach
From time to time, we may reach out to potential business clients using publicly available contact information (such as business emails or LinkedIn profiles) to introduce our products or services that may be relevant to their professional role. Such outreach is limited to legitimate B2B communication and is never automated or performed in bulk. Recipients can request not to be contacted again at any time by replying "unsubscribe" or by emailing info@benedictcorp.com.
8. Legal Basis for Processing (GDPR)
Depending on the situation, we process data based on:
- Performance of a contract (to provide purchased or demo services)
- Legitimate interest (business communication, product updates, contact form security and abuse prevention)
- Legal obligation (accounting, tax compliance)
- Consent, where applicable
9. Data Retention
- Contact form submissions (name, email, company, message): retained in our SharePoint inquiry list for up to 12 months after last interaction, unless a longer period is required to pursue or defend a business relationship.
- Hashed IP addresses used for rate limiting: typically deleted within 24 hours, as described in Section 4(c).
- Client and billing records: up to 10 years (legal requirement).
- Demo environment data: deleted automatically after each demo.
10. Data Sharing and Transfers
We may share limited data with:
- Microsoft Corporation — for website hosting (Azure), Power Automate, SharePoint, and demo environments;
- Google LLC — for Google Ads conversion tracking, only with your consent, or in a reduced, cookieless form if you decline (see Section 13);
- Microsoft Clarity (operated by Microsoft Corporation) — for session analytics, only with your consent (see Section 13);
- Cloudflare, Inc. — for contact form spam/bot protection (Turnstile);
- Upwork Global Inc. and Fiverr International Ltd. — when business communication or contracting occurs through their platforms;
- Stripe, LLC — for payment processing;
- Other payment processors or accounting partners, as required by law;
- Legal authorities, when necessary for compliance.
Each company acts as an independent data controller and processes data under its own privacy policy:
- Microsoft Privacy Statement
- Google Privacy Policy
- Microsoft Clarity Privacy
- Cloudflare Privacy Policy
- Upwork Privacy Policy
- Fiverr Privacy Policy
- Stripe Privacy Policy
All third-party providers we work with are GDPR-compliant or meet equivalent standards.
Client Environments
When the Benedict App, Benedict Finance, or Benedict Invoice is deployed inside a client's own Microsoft 365 environment (tenant), all data entered, stored, or processed there remains under the sole control and responsibility of the client. Benedict Corp. does not access, monitor, or manage the client's tenant or its contents, and cannot be held liable for how the client or its users handle, store, or share any information within that environment. Each client acts as the data controller for their environment, while Benedict Corp. functions only as a software provider, not a data processor or administrator of that tenant.
11. Payment Processing
Payments for certain products or services offered by Benedict Corp. may be made either by bank transfer or through third-party payment processors, including Stripe. Processing of payment-related data is necessary for the performance of a contract.
When payments are made through Stripe, certain information required to process the transaction (such as your name, billing information, and payment details) may be transmitted directly to the payment provider.
Benedict Corp. does not store or process full payment card details. All card transactions are processed securely by Stripe in accordance with their security and compliance standards, including PCI-DSS.
When payments are made by bank transfer, only the information necessary to complete the transaction (such as billing details and invoice information) is processed.
You can review Stripe's privacy policy here: https://stripe.com/privacy
12. Voluntary Contributions
Users may choose to support Benedict Corp. or its open-source projects through voluntary contributions processed via Stripe.
Benedict Corp. does not collect or store full payment card details. All payment transactions are securely processed by Stripe in accordance with their own privacy and security policies.
Depending on the transaction, Stripe may process personal data such as name, email address, and payment information.
For more information, please refer to Stripe's Privacy Policy: https://stripe.com/privacy
13. Cookies and Tracking Technologies
Our website uses a cookie consent banner, shown on your first visit, that lets you accept or reject non-essential cookies. Strictly necessary cookies are used regardless of your choice, since some parts of the site cannot function securely without them — this includes Cloudflare Turnstile (see Section 4(b)), used solely to verify that contact form submissions are not automated.
Your choice is stored in your browser (not as a cookie itself) and is not shared with any third party. You can change it at any time using the "Manage cookie preferences" link in the footer of every page.
For the complete list of cookies we use, what each one does, how long it lasts, and how long your consent choice is remembered, see our Cookie Policy.
If you use our demo environment, Microsoft may also set temporary cookies to ensure secure access and authentication. See Microsoft's Privacy Statement.
You can also manage or delete cookies in your browser settings at any time.
Google Ads
We use Google Ads to measure the effectiveness of our advertising, including recording when a visitor who arrived through one of our ads submits our contact form (a "conversion"). This uses Google's Consent Mode, which adjusts what data is sent based on your choice:
- If you reject non-essential cookies, no advertising cookies are set and no advertising identifiers are used. Google may still receive an anonymous, cookieless signal that a conversion occurred, which cannot be linked back to you individually.
- If you accept, conversion tracking operates normally, which may include cookies used to attribute a conversion to a specific ad or campaign.
See the Google Privacy Policy for how Google itself processes this data.
Microsoft Clarity
We use Microsoft Clarity, a session-recording and heatmap tool, to understand how visitors use our website — for example, which pages get the most attention, where visitors click, and where they run into friction. Clarity only loads if you accept non-essential cookies; if you reject, it does not load at all.
Clarity is configured to mask input fields by default, so text typed into form fields (such as our contact form) is not captured in session recordings. Clarity is a Microsoft Corporation product, separate from Microsoft's role hosting our infrastructure (see Section 10) — see Microsoft Clarity Privacy for how Microsoft itself processes this data.
14. Social Media
Benedict Corp. maintains official pages on third-party social media platforms, including but not limited to LinkedIn, Instagram, and Facebook.
Please note that Benedict Corp. has no control over the data collection, processing, or privacy practices of these platforms. Any personal data you provide while interacting with our pages is processed under the respective platform's own privacy policy and terms of service. We strongly recommend reviewing those policies before sharing any personal or corporate information.
If you contact us via social media, we may process only the minimum personal data necessary to respond to your enquiry — such as your name, contact details, and message content. The lawful basis for such processing is our legitimate interest in responding to your request (Article 6(1)(f) GDPR).
Your personal or corporate data will not be shared, by us, with third parties or used for direct marketing purposes unless you have provided explicit consent.
To the fullest extent permitted by law, Benedict Corp. shall not be held liable for any processing of personal data, tracking, or security incidents occurring on third-party social media platforms.
15. Data Security
We use reasonable technical and organizational measures to protect your data against unauthorized access, alteration, or loss. These measures include, where appropriate to the data involved, restricting outbound connections to authenticated origins, hashing identifiers such as IP addresses rather than storing them in plain form, and limiting the retention of technical data to what is operationally necessary.
Microsoft and Cloudflare provide encryption, access control, and data isolation as part of their own infrastructure and compliance programs.
No system is 100% secure, but we take privacy and data protection seriously.
16. Your Rights Under GDPR
You have the right to:
- Access your data and receive a copy
- Correct inaccurate information
- Request deletion of your data
- Restrict or object to processing
- Withdraw consent at any time
- Request data portability
- File a complaint with a supervisory authority (in Lithuania: State Data Protection Inspectorate)
To exercise your rights, contact us at info@benedictcorp.com
17. Changes to This Policy
We may update this Privacy & Cookie Policy periodically. The latest version will always be available on our website with the "Effective date" shown above. We suggest you review this page periodically.
18. Additional Notice for U.S. Residents (California and Similar Laws)
If you are a resident of the United States, including the State of California, you may have certain privacy rights under local laws such as the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).
We do not sell or share personal information as defined by these laws.
However, you may request to:
- Access the information we hold about you
- Correct or delete your personal data
- Opt out of any future marketing communications
To exercise these rights, please contact us at info@benedictcorp.com. Requests will be handled in accordance with applicable U.S. state privacy laws.
19. Children's Data
Our services and products are intended for professional and business use only and are not directed toward children under 16.
We do not knowingly collect or process data from minors.
If you believe a child has provided us with personal information, please contact us immediately at info@benedictcorp.com, and we will delete it.
20. Benedict PDF (Open-Source Tool)
Benedict PDF is an open-source solution designed to operate within the user's own Microsoft 365 environment.
Benedict Corp. does not collect, receive, process, or store PDF documents processed using Benedict PDF.
All document processing occurs within the user's own infrastructure, including Microsoft 365 services such as Power Apps, Power Automate, Azure Functions, and SharePoint or OneDrive.
Benedict Corp. does not have access to user files, document content, or processing results, unless explicitly agreed as part of separate support, implementation, or consulting services.
Any personal data processed through Benedict PDF remains solely under the control of the user's organization and is subject to their internal policies and Microsoft's data processing terms.
Any website interactions (such as contact forms or voluntary contributions) are governed by the general Privacy Policy described above. All provisions described above in this Privacy Policy do not apply to document processing performed through Benedict PDF, unless explicitly stated otherwise.