BenivoFlowBanner

Benivo Users Privacy Policy

We are committed to respecting your privacy and complying with data protection laws. By registering on the Website or otherwise using the Services, you give your consent to the use of your data in accordance with the terms contained in this section.

Last updated: June 2025

Introduction

At Benivo Limited (“Benivo”, “we”, “us”, or “our”), safeguarding privacy, ensuring security, and promoting transparency are integral components of our services. To this end, this privacy policy (the “Policy”) outlines privacy practices regarding the collection and handling of personal information by Benivo when Users consume our services.

This Policy explains how Benivo handles personal data and protects the privacy of the users (“User” or “Users”) of our services (“Services”). This Policy applies to all Users of our Services. Any other capitalised terms in this Policy are as described and defined in the Benivo Users Terms and Conditions.

 

Legal basis for data collection

Benivo processes personal data based on several lawful grounds as required under applicable data protection laws, including the General Data Protection Regulation (GDPR). The lawful bases for our processing activities include:

Performance of a Contract

We process personal data to provide our Services as per the contracts we have with our clients (User Employers). This includes processing necessary for account registration, service delivery, customer support, and communication.

Legitimate Interests

We process personal data for our legitimate business interests, provided these interests are not overridden by Users' data protection rights. These interests include:

      • Improving our Services and developing new features.
      • Ensuring the security of our systems and services.
      • Conducting marketing activities, where permitted.
      • Analyzing user behavior to enhance user experience.

Consent

We obtain Users' consent for specific processing activities, such as by agreeing to this Privacy Policy. Users have the right to withdraw their consent at any time by contacting us at datarequest@datarep.com quoting <Benivo Limited> in the subject line.

Legal Obligations

We process personal data to comply with our legal obligations, such as maintaining records for tax and accounting purposes, responding to lawful requests from public authorities, and ensuring compliance with anti-money laundering regulations.

 

How We Collect User Data

We collect different types of personal data and other information from Users who consume our Services, complete surveys, correspond via email/phone with Benivo employees, or submit data via approved third-party apps employed by Benivo. Some of your data might be provided by your Employer ahead of your registration to Benivo.

 

What data do we collect

We collect different categories of personal data regarding Users as necessary for the provision of our Services including:

  • Identity Data: full name, gender, date of birth, photo.
  • Contact Data: address, email, phone number.
  • Employment Data: employer name, job title, employment dates.
  • Financial Data: bank account details (if using payment services).
  • Transaction Data: payments/transaction history (if applicable).
  • Technical Data: IP addresses, browser type and version, time zone.
  • Activity Data: pages visited, navigation patterns, clicks.
  • Profile Data: username, password, preferences.
  • Survey Data: information provided in surveys.
  • Correspondence data: information contained in freeform emails.

You may voluntarily provide additional details on your Benivo profile, such as your profile picture, photos, information regarding your relocation (e.g. your bank of choice, local transportation, company culture etc.), such information may be visible to Benivo and other authorised Benivo users.

We may also collect personal data about User dependents as necessary to provide certain relocation Services.

We seek to minimize collection of personal data not directly relevant and necessary to provide the specific Services requested. Individuals using the Service have control through privacy settings to limit additional data collected.

We are committed to protecting the privacy of children. We will not knowingly or intentionally collect, process or store  personal information online from or about children under the age of 16 unless necessary to provide the relocation Services

 

Why we need your data

The information we collect about you may be used by us to provide the Services to you, as subscribed by your Employer, and to process your registration, communicate with you, monitor, develop and improve the Services, process and deal with any complaints or enquiries made by or about you, monitor and investigate any suspected breach of our terms and conditions made by or otherwise relating to you.

 

Who Has Access to User Data

We do not sell User personal data to any parties or share data with third parties for marketing purposes. We only disclose personal data to:

  • Benivo employees and contractors, based on role-based access control, who require the information for the purpose of providing and administering the Services.
  • Third-party service providers who require select data relevant to perform contracted data processing services. These providers undergo vendor risk assessments and are bound by security and confidentiality commitments.
  • Our third party relocation service providers (“Benivo Service Providers” or “BSPs”), only to the extent they need specific personal information to fulfill their services. These partners are under written confidentiality commitments.
  • An individual’s employer, based on role-based access control, who requires the information to receive and obtain the benefit of the Benivo services, and for other internal administration and employment-related functions.

In order to consume some Services, you may be required to provide bank, credit card or PayPal details via the Service. This data is transferred to an FCA or equivalent regulated payment provider. Credit card details are not stored or processed by Benivo, nor will Benivo ever contact individuals and request passwords or credit card details.

It is possible that Benivo may share personal information to potential buyers or sellers of Benivo Limited under confidentiality arrangements.

Your data, including your feedback on the Services, your Employer, or your destination, may also be shared with your Employer and other Employees and published for testimonial purposes. Your feedback will only be attributed on a first-name basis should it be published on the Benivo platforms.

Beyond these situations, Benivo will not disclose User personal data to any external third parties unless required by law enforcement authorities. Where we do legally share data, it will be limited to the extent absolutely necessary and legally permissible.

 

Third Party Service Providers (“TPSP”)

Benivo utilizes vetted third-party service providers to assist in delivering and improving our Services. We conduct thorough due diligence checks on data security practices for all TPSPs. We have confidentiality agreements and data processing terms in place requiring TPSPs to keep User data secure and prohibiting use of information for any purpose other than performing services on behalf of Benivo.

TPSPs may provide services including:

  • cloud hosting, storage and database services;
  • payment processing;
  • email communications and marketing automation; and
  • data analytics to improve our offerings.

Where TPSPs process or access any personal data, their access is limited strictly to what is necessary to perform contracted services. TPSPs may be provided categories of data including Identify, Contact, Financial or Transactional information but wherever possible, access will be to aggregated non-identifiable data sets.

As part of our Welcome Pack service, the User name and contact details may be shared with pre-approved partners strictly for fulfillment of delivery. These TPSPs are vetted and bound against stringent data protection requirements.

We conduct regular oversight checks on all TPSPs to ensure adherence to both contractual security and data processing provisions as well as alignment with overall Benivo data policies and standards. TPSP partnerships may be terminated for any data incidents or non-conformance.

 

How We Store User Data

Benivo leverages industry best practice security measures to protect User data in storage and transit. This includes:

  • encryption using TLS/SSL 1.2 and higher protocols for data in transit and 256-bit AES encryption for data at rest;
  • access controls using 2-factor authentication for web platforms and VPN connections;
  • role-based access restrictions allowing only authorized personnel data access; and
  • annual third-party penetration tests and vulnerability assessments.

Although we may use overseas cloud hosting providers or processors, we conduct thorough due diligence around applicable data center security and ensure compliance with data localization laws. Cloud platforms undergo independent audits across standards like ISO 27001, SOC 2 Type II, ISO 27017/18, and PCI DSS. We regularly review international data transfer mechanisms including Standard Contractual Clauses or the Data Protection Framework to legitimize cross-border data flows.

Benivo’s IT and network infrastructure is reviewed by external auditors annually and comprehensive information security policies are enforced within Benivo. Your data is backed up every day and Benivo have well-tested backup and restoration procedures that allow swift recovery from a major disaster.

 

How long we keep your data

Benivo retains personal data only as long as necessary to fulfill the purposes for which it was collected, as required by law, or as appropriately advised for business requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

For Instance,

  • Identity, Contact and Employment Data: Retained for duration of Service relocation effort plus the minimal statutory period of time required by the jurisdiction to comply with audit and compliance purposes in that geography.
  • Financial Data: Retained for 7 years post transaction as required under tax and anti-money laundering regulations.
  • Any outbound data shared with third parties will be retained according to the partner's own data retention schedules.

We regularly review all systems and archives to ensure data removal in line with the above schedules. Legacy system backups may retain data until the end of their lifecycle; they are carefully secured and access-controlled.

In cases where we decide the means and purpose of processing and act as Controller, you can ask us to delete your data and we shall address it in a timely manner, subject to legal and regulatory obligations and keep you informed of it. In other cases where we act as Service Provider or Processor, we will route your requests to the Business or Controller for actioning your request to delete your data.

Removed personal data is either completely deleted or fully anonymized such that it cannot identify Users. Anonymized analytics data derived from activities may be retained indefinitely for service improvement and delivery purposes.

 

International transfers

As a global company, Benivo may transfer some personal data to countries outside of the European Economic Area (EEA) or the United Kingdom. We take reasonable steps to ensure all data exports receive protections equivalent to those required under the GDPR or equivalent data protection laws.
Data transfers to any third countries without a decision of adequacy are legitimized through the following mechanisms:

  • Standard Contractual Clauses with importing entities.
  • Binding Corporate Rules.
  • Data Protection Framework.

We conduct due diligence assessments on all overseas entities to validate data protection regulations in destination countries and ensure appropriate security provisions are contractually required. Personal data will only be exported to nations demonstrating comprehensive rule of law, enforceable rights and effective legal remedies for data subjects.

Cross-border data transfer impact assessments are performed periodically factoring in guidance such as EDPB Recommendation 01/2020 covering supplementary measures for transfers. Additional data handling controls may be mandated for higher risk jurisdictions. Regional data localization requirements are respected.

Data Protection Rights

Benivo recognizes and respects the rights of all data subjects under GDPR and local privacy laws, including:

  • Right of Access: The right to confirm that User personal data is being processed, including access to a copy of the data, and supplementary information about handling practices.
  • Right to Rectification: Inaccurate or incomplete information may be corrected without delay.
  • Right to Erasure: Under certain circumstances, the right to delete User personal data from our systems. This right may be limited under laws related to legal claims, freedom of expression and certain processing circumstances.
  • Right to Restriction: The right to temporarily restrict processing when contesting User data accuracy, objecting to processing or wanting us to keep but not process the data for legal claims.
  • Right to Objection: The right to object to any processing of User personal data which has our legitimate interests as its legal basis unless we have compelling overriding grounds.
  • Right to Data Portability: Where processing is automated and based on consent or contractual terms, the User can request to obtain or have transferred to another company, your personal data for your own purposes.
  • Rights Related to Automated Decision-Making: A User has the right not to be subject to a decision based solely on automated processing which materially affects a individual unless necessary for a contract, legally authorized or you provide explicit consent.

 

For EU citizens: 

Benivo may process the personal data of individuals in the European Union, European Economic Area and/or UK as data controller or data processor and has appointed DataRep as its Data Protection Representative for the purposes of GDPR*

If Benivo has processed or is processing your personal data, you may be entitled to exercise your rights under GDPR in respect of that personal data. For more details on the rights you have in respect of your personal data, please refer to the European Commission (https://ec.europa.eu/info/law/law-topic/data-protection/data-protection-eu_en) or the national Data Protection Authority in your country.

Benivo has appointed DataRep as their Data Protection Representative in the European Union so that you can contact them directly in your home country.

If you want to raise a question to Benivo, otherwise exercise your rights in respect of your personal data, you may do so by:

      • sending an email to DataRep at datarequest@datarep.com quoting <Benivo Limited> in the subject line,
      • contacting us on our online webform at www.datarep.com/data-request, or
      • mailing your inquiry to DataRep at the most convenient of the addresses in the subsequent pages.

PLEASE NOTE: when mailing inquiries, it is ESSENTIAL that you mark your letters for ‘DataRep’ and not ‘Benivo Limited', or your inquiry may not reach us. Please refer clearly to Benivo Limited in your correspondence. On receiving your correspondence, Benivo is likely to request evidence of your identity to ensure your personal data and information connected with it is not provided to anyone other than you.

If you have any concerns over how DataRep will handle the personal data we will require to undertake their services. please refer to their privacy notice at www.datarep.com/privacy-policy.

DataRep locations and contact information

 

For China citizens: 

You confirm that Benivo may collect and store your personal data including, but not limited to, your name, contact details, ID / passport number and ID / passport copy for the purpose of your relocation.  You understand that this information may be transferred to third party relocation service providers (“Benivo Service Providers” or “BSPs”), located both within China and overseas.

Your personal data will be safeguarded according to the regulations set in place by all relevant China legislation, including PIPL.

By agreeing to this policy you agree that you are providing explicit consent to Benivo to process your personal data as noted above.

 

Changes to this Privacy Policy

We may change this policy if necessary, and if we do we will post any changes on this page. If you continue to use Benivo after those changes are in effect, you agree to the revised policy.