Notice-and-Action Procedure in accordance with Article 16 Digital Services Act
Initlabs B.V. ("beebeeb.io") — Version 1.0 — 20 May 2026
This procedure describes how third parties can report suspected unlawful content hosted on beebeeb.io, in accordance with Article 16 of the Digital Services Act (Regulation (EU) 2022/2065). It applies to all content stored on or shared via the beebeeb.io service.
1. Purpose and legal basis
1.1 Article 16 of the Digital Services Act requires hosting service providers to have a mechanism through which any individual or entity can report the presence on their service of specific items of information that the reporter considers to be illegal content.
1.2 This procedure applies to all content stored on or shared via beebeeb.io, including files, shared links and any other material accessible through the Service.
1.3 Important limitation: beebeeb.io uses a Zero-Knowledge Architecture with end-to-end encryption. We cannot access or decrypt the content of files stored by users. Reports can therefore only be effective for content that has been shared via a public or shared link (which we can access by following the link) or for account-level measures based on metadata or external information. This limitation is explained in detail in Section 10.
2. How to submit a report
2.1 Reports of suspected unlawful content can be submitted by email to: legal@beebeeb.io.
2.2 In accordance with Article 16(2) of the Digital Services Act, a report must contain the following information:
- A sufficiently substantiated explanation of the reasons why the reporter considers the information in question to be illegal content.
- A clear indication of the exact electronic location of the content, such as the exact URL or URLs, and, where necessary, additional information enabling the identification of the illegal content.
- The name and email address of the individual or entity submitting the report, except for reports concerning suspected criminal offences as referred to in Article 240b of the Dutch Criminal Code (child sexual abuse material), in which case anonymity is permitted.
- A statement confirming the bona fide belief of the individual or entity submitting the report that the information and allegations contained therein are accurate and complete.
2.3 Reports that do not contain the required information may be returned to the reporter with a request for supplementation. In such cases, the timelines set out in Section 6 run from the date of receipt of the complete report.
2.4 Reports may be submitted in English or Dutch.
3. Assessment
3.1 Every report is processed and decided upon in a timely, diligent, non-arbitrary and objective manner, in accordance with Article 16(6) of the Digital Services Act.
3.2 The assessment is performed by a qualified person who was not involved in the reported content or in any prior interaction with the reporter concerning the same matter.
3.3 The assessment includes the following elements:
- Verification of whether the reported content exists and is accessible.
- Verification of whether the report contains all required information as set out in Section 2.2.
- Assessment of whether there is a sufficient legal basis to consider the content unlawful under applicable EU or Dutch law.
- Where relevant: consultation with external legal counsel or competent authorities.
3.4 Due to the Zero-Knowledge Architecture, we can only assess content that is accessible via a shared or public link. We cannot decrypt or inspect private files. If a report concerns content that we cannot access, we will inform the reporter accordingly and, where appropriate, advise them to contact the competent authorities directly.
4. Possible measures
4.1 If the report is well-founded, we may take one or more of the following measures, depending on the nature and severity of the reported content:
- Restrict or disable access to the shared link.
- Remove the content from public accessibility.
- Temporarily suspend the user's account.
- Permanently terminate the user's account (in serious or repeated cases).
- Forward relevant information to competent authorities where legally required, in particular in accordance with Article 18 of the Digital Services Act (suspicion of criminal offences involving a threat to the life or safety of a person or persons).
4.2 If the report is unfounded or insufficiently substantiated, we take no action against the reported content. The reporter is notified of this decision in accordance with Section 5.
5. Notification
5.1 We notify the reporter without undue delay of our decision regarding the report, including the reasons for that decision, in accordance with Article 16(6) of the Digital Services Act.
5.2 Where we decide to take action against reported content, we notify the affected user without undue delay and before the measure takes effect (unless immediate action is required to prevent imminent harm). The notification to the user includes:
- The measure taken and the reasons for taking it.
- The facts and circumstances relied upon, including, where applicable, reference to the report.
- The legal grounds on which the decision is based.
- Information about the right to lodge a complaint, including a reference to the Complaints Procedure (see Section 8).
5.3 Notification to the affected user may be delayed or omitted where:
- This is required by law, for example in the context of an ongoing criminal investigation where notification could jeopardise the investigation.
- We have no reasonable means to contact the user.
- A competent authority has instructed us to refrain from notification.
6. Timeline
6.1 We aim to acknowledge receipt of a report within two (2) business days.
6.2 We aim to reach a decision within five (5) business days of receiving a complete report.
6.3 Complex cases — for example where legal analysis, expert consultation or coordination with competent authorities is required — may take longer. In such cases, we inform the reporter of the expected extended timeline.
6.4 Emergency reports concerning content that poses an imminent danger to the life or safety of a person or persons are prioritised and handled without delay.
7. Trusted flaggers
7.1 Reports submitted by trusted flaggers designated under Article 22 of the Digital Services Act are processed with priority.
7.2 Trusted flagger status does not guarantee a different outcome. Reports from trusted flaggers are assessed on their merits using the same criteria as any other report.
7.3 At the time of publication of this procedure, no trusted flaggers have been designated for beebeeb.io. This section will be updated when trusted flagger relationships are established.
8. Right to complain and dispute resolution
8.1 A user whose content has been restricted, removed or otherwise affected on the basis of a report may lodge a complaint via our Complaints Procedure, available at beebeeb.io/complaints.
8.2 A reporter whose report has been rejected may also lodge a complaint via the same Complaints Procedure.
8.3 Both users and reporters may submit their dispute to an out-of-court dispute settlement body certified by the Dutch Digital Services Coordinator (the Authority for Consumers and Markets, ACM), as referred to in Article 21 of the Digital Services Act.
8.4 Nothing in this procedure limits the right of any party to seek judicial remedies before a competent court.
9. Abusive reports
9.1 Reports that are manifestly unfounded or abusive are rejected.
9.2 In accordance with Article 23 of the Digital Services Act, repeated submission of manifestly unfounded reports may result in the temporary or permanent suspension of access to the reporting mechanism.
9.3 Before deciding on suspension, we assess the proportion of manifestly unfounded reports submitted by the individual or entity in question relative to the total number of reports submitted by that individual or entity in the preceding twelve-month period.
10. Zero-Knowledge limitations
10.1 beebeeb.io uses end-to-end encryption with a Zero-Knowledge Architecture. Encryption keys are generated and held exclusively on the user's device. We cannot decrypt, inspect, or access the content of files stored by users.
10.2 As a consequence, we cannot proactively monitor what users store. This is consistent with Article 8 of the Digital Services Act, which prohibits general monitoring obligations.
10.3 Reports can only be effective for:
- Content shared via a public or shared link, which we can verify by accessing the link ourselves.
- Account-level measures based on metadata (such as account creation patterns, IP addresses or external information provided by competent authorities) or information provided by the reporter.
10.4 We cannot comply with requests — whether from reporters, authorities or courts — that require access to the unencrypted content of files, because we do not hold the decryption keys and therefore do not have access to the content.
10.5 The liability for factually incorrect reports lies with the reporter.
11. Contact
|
Purpose |
Contact |
|
Report suspected unlawful content |
|
|
PGP key (legal@beebeeb.io) |
|
|
Complaints about decisions |
|
|
General questions about this procedure |
12. Changes to this procedure
12.1 We may update this procedure to reflect changes in applicable law, regulatory guidance or our services.
12.2 The most recent version of this procedure is always available at beebeeb.io/notice-and-action.
12.3 Substantive changes are announced at least thirty (30) days in advance via the sub-processor and legal update notification mechanism described in our Terms of Service.
— End of Notice-and-Action Procedure —