← Beta AI

Privacy Policy

Effective date: 3 August 2026 · Last updated: 3 August 2026

This Privacy Policy explains how Beta AI collects, uses, distributes, transfers, stores, shares and deletes personal data. It covers our website at b-ta.ai, our client engagements, and the internal applications we register with the LinkedIn Developer Platform to manage our own LinkedIn presence.

1. Who is responsible and how to reach us

  • Responsible party (responsable / controller): Pablo Carmona Esparza, operating under the commercial name Beta AI, in Mexico.
  • Website: https://b-ta.ai
  • Designated address for notices, privacy requests and the exercise of rights (domicilio convencional): pablo@b-ta.ai. Our full postal domicile is provided on written request to that address.
  • Person in charge of personal data protection: Pablo Carmona Esparza, at the address above.

All responses to requests concerning personal data are sent from and received at that address, unless you ask us in your request to reply by another means and provide it.

2. Data we collect

2.1 From our website

  • Contact form submissions: the name, email address, company and message you choose to send us.
  • Technical data: standard server logs generated by our hosting provider (IP address, user agent, timestamp, requested path).

Pages of this website other than this Privacy Policy load web fonts from Google (fonts.googleapis.com and fonts.gstatic.com). When those pages load, your IP address and browser information are transmitted to Google as part of that request. This Privacy Policy page itself requests no fonts, scripts or other resources from any third-party domain: every asset it loads is served from b-ta.ai.

2.2 From LinkedIn, through our own applications

We operate applications registered on the LinkedIn Developer Platform. They act only on LinkedIn accounts we own and administer: the Beta AI Company Page, and the personal profile of the authenticated Beta AI team member who grants authorization. We do not operate them on behalf of third parties, and we do not query, search for, or collect data about LinkedIn members of our own initiative.

We do, however, receive data about other LinkedIn members when they choose to interact publicly with our content. Concretely, through these applications we process:

  • Authenticated member (a Beta AI team member): LinkedIn identifier (member URN) and basic profile fields returned at sign-in (name, headline, profile picture URL).
  • Credentials: OAuth access tokens and refresh tokens issued to us by LinkedIn.
  • Our own content: post text, documents and images we publish, and the resulting post/share URNs.
  • Aggregate analytics for our own posts and Page: impressions, reactions, comments, shares, clicks and follower counts. These are counts, not identities.
  • Other members who interact with our posts: when someone comments on or reacts to a post of ours, the LinkedIn APIs return that member’s URN, their public name and profile picture URL, and the text of their comment. We process this solely to read and reply to comments on our own content. We hold it only in transient memory or short-lived cache within the retention limits in section 5, we do not build profiles from it, and we never store it alongside any other dataset.
  • Organization data for the Beta AI Company Page we administer.

2.3 From client engagements

When we build automations for a client, we process the data that client makes available to us on their instructions and for their purposes, under the applicable services agreement. Data obtained through the LinkedIn APIs is never used in, combined with, or disclosed in any client engagement.

3. How we use data

  • Website enquiries: to reply to you and evaluate a possible working relationship.
  • LinkedIn data: exclusively to publish our own content to our own LinkedIn profile and Company Page, to measure how that content performs, and to read and reply to comments on it. This is a first-party marketing operation for Beta AI.
  • Client data: only to deliver the contracted service.

We do not use LinkedIn data for advertising or ad targeting, audience building, lead generation, recruiting, sales prospecting, CRM or profile enrichment, resale, or to build reference datasets. We do not combine LinkedIn data with data from any other source. We do not display LinkedIn content as a social feed on any website or intranet. We do not sell personal data.

4. Legal basis

Where the GDPR or comparable law applies we rely on: your consent (website enquiries, and the OAuth authorization granted to our LinkedIn application, which can be withdrawn at any time); our legitimate interest in operating and measuring our own marketing channels; and performance of a contract for client engagements. In Mexico we process personal data under the Ley Federal de Protección de Datos Personales en Posesión de los Particulares and its implementing regulations.

5. Retention

For data obtained through the LinkedIn APIs we apply retention periods that meet or are stricter than LinkedIn’s Data Storage Requirements:

DataMaximum retention
Other members’ identifiers (member URNs) received with comments and reactions on our posts48 hours; deleted together with the social activity data they arrived with, and never retained beyond it
Other members’ profile data (name, headline, profile picture URL)24 hours (cache only)
Members’ social activity data (comments and reactions on our posts)48 hours
Organization social activity data for our own Page6 weeks by default; up to 6 months only where the organization has authenticated into the application
Organization profile data for our own Page8 weeks where the organization has authenticated; otherwise we retain only the organization name and logo URL, for a maximum of 30 days
Page administration and reporting data (aggregate metrics only — contains no individual-member data)12 months
Authenticated member’s own identifier and basic profileWhile the authorization remains active
Access and refresh tokensUntil expiry, revocation, or deletion on request

Website enquiries are kept for up to 24 months and then deleted. Client data is retained per the applicable services agreement and returned or destroyed on termination.

6. Distribution, transfer and sharing

We do not sell, rent or trade personal data, and we do not export LinkedIn data out of the application that obtained it.

LinkedIn data specifically: data obtained through the LinkedIn APIs is processed on Beta AI’s own systems and is not transmitted to any contractor, agency, client, advertising network, analytics provider or other third party. The one exception is the cloud storage and workflow infrastructure that hosts the application processing it. We contract that infrastructure under the provider’s data processing terms, which restrict the provider to processing on our instructions; those servers may be located in the United States and the European Union. LinkedIn data is visible only to the Beta AI personnel associated with the Page and profile it came from.

Website and enquiry data: processed by our website hosting and content delivery provider and by our email provider, in each case only to operate the site and answer you.

We may disclose personal data where legally required, and will inform affected individuals unless prohibited from doing so.

7. Your rights, withdrawal of consent, and deletion

You may request access to your personal data, rectification of inaccurate or incomplete data, cancellation (deletion), or objection to processing — the ARCO rights — and you may separately ask us to limit the use or disclosure of your data.

How to submit a request. Send it to pablo@b-ta.ai including:

  • Your name and an address or electronic medium at which you wish to receive our reply.
  • Documents that establish your identity, or that of your legal representative together with proof of representation. We use these only to verify the request and delete them once it is resolved.
  • A clear and precise description of the personal data concerned and the right you are exercising.
  • Any element or document that helps us locate the data.
  • For rectification requests, the correction sought and supporting documentation.

How we respond. We reply from pablo@b-ta.ai to the medium you indicated. If information is missing we will tell you within 5 business days what to provide, and you will have 10 business days to complete it. We communicate our determination within 20 business days of receiving a complete request, and where it is well founded we implement it within the following 15 business days. Exercising these rights is free; we may charge only justified shipping or certification costs. Requests governed by other regimes are answered within the period that regime requires.

7.1 Withdrawing LinkedIn authorization

You can withdraw the authorization granted to our LinkedIn application at any time from LinkedIn → Settings & Privacy → Data privacy → Permitted services. Revoking authorization immediately ends our ability to make further API calls for that account. It does not by itself erase data already stored; the deletion described below is what removes it.

7.2 Deletion of LinkedIn data

We delete all data obtained through the LinkedIn APIs, together with the associated access and refresh tokens, immediately and without further notice when any of the following occurs: a member or LinkedIn requests deletion; a member closes their LinkedIn account or revokes our access; we no longer require the data for the purpose described in section 3; the application ceases to operate; or LinkedIn suspends or terminates our access.

8. Security

Data is transmitted over TLS. It is our practice to keep credentials and API tokens in access-restricted storage held separately from application source code, and to limit access to systems processing personal data to the Beta AI personnel who require it. No system is perfectly secure, and we do not represent that ours is. If we discover a security incident affecting data obtained through the LinkedIn APIs, we will notify LinkedIn within 24 hours of discovery, and will notify affected individuals and any competent authority without undue delay where the applicable law requires it.

9. International transfers

We operate from Mexico and use infrastructure providers that may process data in the United States and the European Union. Where a transfer is subject to the GDPR, we rely on whichever transfer mechanism the relevant provider makes available in its own data processing terms — in most cases the European Commission’s standard contractual clauses. We do not transfer personal data to any third party that is not an infrastructure provider processing it on our behalf, so no separate consent for onward transfer is sought or implied.

10. Children

Our website and services are not directed to anyone under 18, and we do not knowingly collect their data.

11. Changes to this policy

We may update this policy. The effective date at the top always reflects the current version, and the current version is always published at https://b-ta.ai/privacy. Where a change materially affects how we handle data we already hold, we will notify affected individuals by email where we hold an address, and otherwise by a notice on this page, before the change takes effect.