Beacon — Data Processing Addendum (DPA)
Last updated: June 17, 2026 Version: 1.0 (draft)
This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Beacon Terms of Service or other written or electronic agreement (the "Agreement") between [LEGAL ENTITY NAME] ("Beacon," "we," "us," or "Processor") and the customer that has accepted the Agreement ("Customer," "you," or "Controller"). It governs Beacon's processing of Customer Personal Data on Customer's behalf in connection with the Beacon service at warmbeacon.com and related applications, APIs, and features (the "Service").
This DPA reflects the parties' agreement on the processing of personal data in accordance with the requirements of Regulation (EU) 2016/679 ("EU GDPR"), the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), and, where applicable, U.S. state privacy laws (collectively, "Data Protection Laws"). To the extent there is any conflict between this DPA and the Agreement with respect to the processing of Customer Personal Data, this DPA controls (see Section 13).
> Plain-language summary. When you upload prospects/contacts and have Beacon research them and draft outreach, you are the controller and Beacon is your processor — we act only on your documented instructions. This DPA sets out how we protect that data, the small fixed list of subprocessors we use (Anthropic, Supabase, Vercel, Stripe, and your own SMTP/email provider), how international transfers are handled, how we help you with data-subject requests and breaches, and how data is deleted or returned when you leave. Your own account, billing, and usage data is separate — Beacon is the controller of that data and it is governed by our Privacy Policy, not this DPA.
1. Definitions
1.1 Capitalized terms not defined in this DPA have the meaning given in the Agreement.
1.2 For the purposes of this DPA:
- "Controller," "Processor," "Data Subject," "Personal Data," "Personal Data Breach," "Processing," "Special Categories of Personal Data," and "Supervisory Authority" have the meanings given in the EU GDPR (and their equivalents under the UK GDPR and other Data Protection Laws, including "business," "service provider," "process," "sell," and "share" under U.S. state privacy laws).
- "Customer Personal Data" means Personal Data contained within Customer Data (as defined in the Agreement) that Beacon Processes on Customer's behalf as a Processor under this DPA — principally the prospect/contact data Customer uploads or syncs and the related AI-generated research and engagement data. It does not include Account Data.
- "Account Data" means Personal Data relating to Customer and its Authorized Users that Beacon Processes as a Controller for its own purposes — for example account registration, authentication, billing/subscription, support, and product usage/telemetry data — as described in the Privacy Policy. Account Data is outside the scope of this DPA (see Section 4.3).
- "Authorized User," "Customer Data," and "Output" have the meanings given in the Agreement.
- "Data Protection Laws" has the meaning in the preamble above.
- "EU SCCs" means the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, as may be amended, superseded, or replaced from time to time.
- "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under s.119A(1) of the Data Protection Act 2018, in force 21 March 2022, as may be amended or replaced.
- "DPF" means the EU-U.S. Data Privacy Framework and its UK Extension and the Swiss-U.S. Data Privacy Framework, as administered by the U.S. Department of Commerce.
- "Restricted Transfer" means a transfer (or onward transfer) of Customer Personal Data from Customer to Beacon, or from Beacon to a Subprocessor, that is subject to the transfer restrictions of Chapter V of the EU GDPR, the UK GDPR, or the FADP and that, absent an appropriate safeguard under Section 7, would breach those laws.
- "Subprocessor" means any third party engaged by Beacon (or by a Subprocessor) to Process Customer Personal Data in the course of providing the Service.
- "Privacy Policy" means Beacon's privacy policy at /privacy, as updated from time to time.
- "Standard Contractual Clauses" or "SCCs" means, as the context requires, the EU SCCs and/or the EU SCCs as completed and amended by the UK Addendum and/or the Swiss adaptations in Annex 1.
2. Subject-matter, duration, nature and purpose of Processing (Art. 28(3))
2.1 Subject-matter. Beacon's Processing of Customer Personal Data as a Processor in order to provide the Service to Customer in accordance with the Agreement and Customer's documented instructions.
2.2 Duration. Processing continues for the term of the Agreement, plus any period after termination during which Beacon is required or permitted to retain Customer Personal Data to provide the Service, return or delete the data under Section 11, or comply with Data Protection Laws.
2.3 Nature and purpose of Processing. Beacon Processes Customer Personal Data to make the Service available to Customer, including to:
- store and host the prospect/contact records, product information, and related content Customer uploads or generates;
- submit relevant content to Beacon's AI subprocessor to research prospects from publicly available web sources and to draft outbound message copy;
- transmit outreach to Customer's own email/SMTP provider for sending at Customer's direction;
- record and report engagement (opens, clicks, replies) where Customer has enabled tracking;
- maintain suppression / do-not-contact lists, one-click unsubscribe handling, and bounce suppression;
- provide support, security, backup, troubleshooting, and the self-serve export and deletion features; and
- perform any other Processing strictly necessary to provide the Service per the Agreement and Customer's documented instructions.
2.4 Beacon does not sell or "share" Customer Personal Data, does not retain, use, or disclose it for any commercial purpose other than providing the Service, does not use it to build cross-customer profiles, does not use it for its own marketing, and does not use it (or knowingly permit any Subprocessor to use it) to train, develop, or improve any AI model. [Confirm Anthropic zero-retention / no-training contractual terms applicable to Beacon's account and reference the specific commercial terms or DPA — see Annex 3.]
3. Types of Personal Data and categories of Data Subjects (Art. 28(3); Art. 30)
3.1 Categories of Data Subjects. The prospects, contacts, and business recipients that Customer chooses to upload, research, and/or contact through the Service — typically Customer's potential or existing business contacts and the individuals associated with target accounts. Incidentally, individuals named in product documentation or other content Customer uploads, and Customer's Authorized Users to the extent their Personal Data appears within Customer Personal Data (e.g., as the author of call notes or message copy).
3.2 Types of Customer Personal Data. As determined and controlled by Customer, typically:
- Business contact identifiers: first and last name, job title/role, business email address, business phone number, and employer/company.
- Professional/profile information: LinkedIn or other public profile URLs and the professional context they contain.
- AI-researched dossiers: summaries, personas, signals, and research logs compiled by Beacon's AI from publicly available web sources (including live web search), together with the sources cited.
- Outreach content and history: drafted and sent message copy, templates, merge variables, scheduling, replies, call notes, and deal/pipeline records associated with a prospect.
- Engagement records: open, click, and reply status with timestamps (where tracking is enabled), and bounce/suppression status.
- Suppression / opt-out data: addresses on Customer's do-not-contact list.
3.3 No Special Categories. The Service is not designed or intended to Process Special Categories of Personal Data (Art. 9), "sensitive personal information" under U.S. state law, or data relating to criminal convictions or offences (Art. 10). Customer is contractually required (in the Agreement and here) not to upload such data into prospect records or product content. Customer warrants it will not provide such data to the Service, and, to the maximum extent permitted by Data Protection Laws, Beacon has no liability arising from Customer's breach of this restriction.
3.4 Children. The Service is a B2B product not directed to children and is restricted to business and professional users aged 18 or over under the Agreement. Customer will not upload Personal Data of any individual it knows or should reasonably know to be a child under the applicable age of digital consent (and in any event under [16]).
4. Roles and responsibilities of the parties
4.1 Customer as Controller. With respect to Customer Personal Data, Customer is the Controller (or "business" / equivalent). Customer determines the purposes and means of the Processing, decides which individuals to contact, and is solely responsible for: (a) establishing and maintaining a lawful basis for the Processing under Art. 6 (and any required consent); (b) providing all required privacy notices to, and obtaining any required consents from, Data Subjects; (c) the accuracy, quality, legality, and provenance of the Customer Personal Data; and (d) compliance with all marketing, anti-spam, and privacy laws applicable to its outreach (including GDPR/UK GDPR, ePrivacy/PECR, CAN-SPAM, CASL, TCPA, and CCPA/CPRA and equivalents). Customer warrants that (i) its instructions and the Processing it directs comply with Data Protection Laws, and (ii) it has the authority to act, and has the right to provide Customer Personal Data and instruct the Processing, on behalf of any third party whose Personal Data is included in Customer Personal Data (e.g., where Customer is itself a processor for one of its own customers).
4.2 Beacon as Processor. With respect to Customer Personal Data, Beacon is the Processor (or "service provider" / equivalent) and will Process it only as set out in Section 5. As a service provider/processor under U.S. state privacy laws, Beacon will not (a) sell or share Customer Personal Data; (b) retain, use, or disclose it for any purpose other than the specific business purpose of providing the Service, or as otherwise permitted by Data Protection Laws; (c) retain, use, or disclose it outside the direct business relationship between the parties; or (d) combine it with Personal Data Beacon receives from, or on behalf of, other persons, or collects from its own interaction with Data Subjects, except as permitted by those laws. Beacon certifies that it understands and will comply with these restrictions. Beacon will notify Customer if it determines it can no longer meet its obligations as a service provider/processor under applicable U.S. state privacy laws, and Customer may, on notice, take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.
4.3 Account Data is separate. With respect to Account Data, Beacon is the Controller and Processes it for its own purposes (operating, securing, billing for, and improving the Service) as described in the Privacy Policy. This DPA does not govern Account Data; the Privacy Policy does.
4.4 Customer's own email/SMTP provider. Where Customer sends outreach through its own email/SMTP provider, Customer (not Beacon) determines the means and configuration of that sending. As between Customer and Beacon, Customer is the Controller of any Processing carried out by that provider, and that provider is Customer's processor under Customer's own agreement with it (see Section 6.2).
4.5 Independent compliance. Each party is responsible for its own compliance with the Data Protection Laws applicable to it in its respective role.
5. Beacon's obligations as Processor (Art. 28(3)(a)–(h))
5.1 Processing on documented instructions (Art. 28(3)(a)). Beacon will Process Customer Personal Data only on Customer's documented instructions, including with respect to international transfers, unless required to do otherwise by EU/Member State, UK, or other applicable law to which Beacon is subject; in that case, Beacon will (where not legally prohibited) inform Customer of that legal requirement before Processing. The Agreement, this DPA, the applicable order form, Customer's configuration of and use of the Service, and any subsequent written instructions agreed by the parties constitute Customer's complete and final documented instructions. Beacon will inform Customer if, in its opinion, an instruction infringes Data Protection Laws (without obligation to monitor Customer's compliance or to provide legal advice). Processing outside the scope of these instructions requires prior written agreement of the parties, and Beacon may charge a reasonable fee for it.
5.2 Confidentiality of personnel (Art. 28(3)(b)). Beacon ensures that persons authorized to Process Customer Personal Data are bound by an appropriate, enforceable obligation of confidentiality (whether contractual or statutory) that survives the end of their engagement, and Process the data only as instructed by Beacon, on a least-privilege/need-to-know basis.
5.3 Security (Art. 28(3)(c); Art. 32). Beacon implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as further described in Section 8 and Annex 2.
5.4 Subprocessors (Art. 28(3)(d); Art. 28(2), (4)). Beacon engages Subprocessors only in accordance with Section 6.
5.5 Assistance with Data-Subject requests (Art. 28(3)(e)). Taking into account the nature of the Processing, Beacon assists Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests by Data Subjects to exercise their rights, as set out in Section 9.
5.6 Assistance with security, breach, and DPIAs (Art. 28(3)(f)). Beacon assists Customer in ensuring compliance with its obligations under Arts. 32 to 36 — i.e. security of Processing (Art. 32), Personal Data Breach notification (Arts. 33–34, see Section 10), data protection impact assessments (Art. 35), and prior consultation with a Supervisory Authority (Art. 36) — taking into account the nature of Processing and the information available to Beacon.
5.7 Deletion or return on termination (Art. 28(3)(g)). At the end of the provision of the Service, Beacon deletes or returns Customer Personal Data as set out in Section 11.
5.8 Information and audits (Art. 28(3)(h)). Beacon makes available to Customer all information necessary to demonstrate compliance with the obligations in Art. 28, and allows for and contributes to audits, as set out in Section 12.
5.9 Records of Processing (Art. 30(2)). Beacon maintains a written record of the categories of Processing carried out on behalf of Customer as required by Art. 30(2), and makes the relevant portions available to Customer or a Supervisory Authority on reasonable request.
6. Subprocessors (Art. 28(2), (4))
6.1 General authorization. Customer provides Beacon with a general written authorization to engage Subprocessors to Process Customer Personal Data, subject to this Section and to Clause 9 (Option 2) of the EU SCCs where they apply. The Subprocessors approved as of the effective date of this DPA are listed in Annex 3, currently:
| Subprocessor | Purpose | Location / notes | |---|---|---| | Anthropic | AI Processing of prospect and product data — research and drafting — including the live web-search tool | United States; inputs not used to train models [confirm contractual basis and DPF/SCC status] | | Supabase | Managed PostgreSQL database hosting (stores Customer Data) | United States — AWS us-east-1 (N. Virginia); sub-subprocessor: Amazon Web Services | | Vercel | Application hosting and serverless/edge compute (serves the app and APIs) | United States (Washington, D.C. region, AWS us-east-1); sub-subprocessor: Amazon Web Services | | Stripe | Payment processing and subscription billing | Primarily processes Account/billing Data; limited or no Customer Personal Data |
6.2 Customer's own email/SMTP provider. The email/SMTP provider that Customer selects, configures, and controls to send outreach (and, where applicable, to read replies) is not a Beacon Subprocessor. It operates under Customer's own agreement with that provider and acts as Customer's processor. Customer is responsible for that relationship, its terms, any Restricted Transfer it entails, and for entering into any required data-processing terms with it. Beacon transmits messages to it at Customer's direction. Likewise, any data, enrichment, or other third-party service Customer connects to the Service is Customer's own relationship and is not a Beacon Subprocessor.
6.3 Flow-down terms. Before a Subprocessor Processes Customer Personal Data, Beacon imposes on it, by written contract, data-protection obligations that are no less protective than, and that materially reflect, those imposed on Beacon under this DPA — in particular sufficient guarantees to implement appropriate technical and organizational measures meeting the requirements of the Data Protection Laws (Art. 28(3)–(4) flow-down), including the relevant SCCs / transfer safeguards for any Restricted Transfer. Where a Subprocessor fails to fulfill its data-protection obligations, Beacon remains fully liable to Customer for the performance of that Subprocessor's obligations, subject to Section 13.
6.4 Change notice and right to object. Beacon maintains the current list of Subprocessors at [SUBPROCESSOR LIST URL — e.g. warmbeacon.com/subprocessors], where Customer may subscribe to notifications. Beacon will give Customer at least [30] days' prior notice (by email and/or by updating that page and notifying subscribers) before authorizing any new or replacement Subprocessor that Processes Customer Personal Data. Customer may object on reasonable, documented data-protection grounds within [14] days of the notice. The parties will work in good faith to resolve the objection (which may include Beacon offering an alternative or additional safeguard). If they cannot resolve it within [30] days of the objection, Customer may, as its sole and exclusive remedy, terminate the affected part of the Service that cannot be provided without the objected-to Subprocessor by giving written notice, and Beacon will refund any prepaid, unused fees for the terminated portion on a pro-rata basis. Pending resolution or termination, Beacon may suspend the affected Processing by the objected-to Subprocessor where reasonably practicable, or refrain from onboarding the new Subprocessor for that Customer.
6.5 Emergency replacement. Where a change of Subprocessor is required on shorter notice to address a security, legal, or availability risk, Beacon may make the change immediately and will notify Customer as soon as reasonably practicable, after which the objection right in Section 6.4 applies.
7. International transfers (Chapter V GDPR)
7.1 Beacon and its Subprocessors Process Customer Personal Data primarily in the United States and may Process it in other countries. Where a Restricted Transfer occurs, the parties agree the following appropriate safeguards apply, in the following order of priority for each transfer: (a) an adequacy decision covering the recipient; failing which (b) a valid DPF certification of the recipient covering the relevant data (Section 7.4); failing which (c) the applicable SCCs as completed in Annex 1.
- EU transfers. The EU SCCs are hereby incorporated into and form part of this DPA by reference, and the parties agree to be bound by them. Module Two (Controller-to-Processor) applies as between Customer (data exporter) and Beacon (data importer) where Customer is a Controller; Module Three (Processor-to-Processor) applies (i) as between Customer and Beacon where Customer is itself acting as a processor for a third-party controller, and (ii) to onward transfers from Beacon to Subprocessors. The clause selections, options, and details are set out in Annex 1.
- UK transfers. The UK Addendum is incorporated and completes/amends the EU SCCs for transfers subject to the UK GDPR, as set out in Annex 1.
- Swiss transfers. For transfers subject to the FADP, the EU SCCs apply with the adaptations set out in Annex 1 (references to the GDPR read as the FADP, the Swiss FDPIC as the competent Supervisory Authority, and the clauses protect Swiss-resident Data Subjects, etc.).
7.2 Deemed execution. By accepting this DPA, each party is deemed to have signed the SCCs (including their Annexes, which are populated by Annex 1 and Annexes 2–3 of this DPA) in the capacity set out above, as of the effective date of this DPA. Where Module Three applies between Customer and Beacon, Customer instructs Beacon to act, and Beacon acts, in accordance with the relevant controller's documented instructions as relayed by Customer.
7.3 Conflict. If and to the extent the SCCs / UK Addendum apply, and they conflict with any other term of this DPA or the Agreement, the SCCs / UK Addendum prevail with respect to the relevant Restricted Transfer.
7.4 DPF. [If Beacon and/or a Subprocessor (e.g., Anthropic, Stripe, Vercel) is self-certified under the EU-U.S. DPF, the UK Extension, and/or the Swiss-U.S. DPF, identify each certified entity and the data it covers here; for transfers to a DPF-certified recipient, the DPF may serve as the transfer mechanism in lieu of the SCCs for so long as the certification remains valid, after which the SCCs in Annex 1 apply automatically. Insert DPF certification details / placeholder.]
7.5 Transfer impact and government access. Beacon will, on reasonable request and taking into account the information available to it, assist Customer with any transfer impact assessment, and will, to the extent legally permitted, notify Customer of any legally binding request by a public authority for disclosure of Customer Personal Data, and challenge or seek to minimize any such request that it considers unlawful, in each case consistent with Clause 15 of the EU SCCs.
7.6 Beacon will, on request, make available the relevant transfer mechanism and provide reasonable information about the transfers it makes.
8. Security (Art. 32)
8.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to Data Subjects, Beacon implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures are described in Annex 2 and currently include:
- Encryption of Customer Personal Data in transit (TLS/HTTPS) and at rest for the managed database and backups;
- Per-workspace (multi-tenant) data isolation — every tenant query is scoped to the requesting workspace (
workspace_id-scoped), so each Customer's data is segregated from every other Customer's; - Hashed password storage (no plaintext credentials), signed/HTTP-only session cookies, and role-based access controls;
- Least-privilege access for personnel and vetted Subprocessors;
- Durable rate limiting and abuse protections on sensitive and public endpoints, and SSRF protections on outbound webhooks;
- Audit logging of significant actions;
- application-level safeguards including an anti-fabrication research guardrail (the AI is instructed not to invent facts about prospects), one-click List-Unsubscribe, automatic hard-bounce suppression, and a suppression list; and
- regular backups and monitoring, logging, and incident-response processes.
8.2 Beacon may update its security measures from time to time provided the updates do not materially reduce the overall level of security of the Service.
8.3 Customer is responsible for its own security in its use of the Service, including safeguarding its credentials and API keys, managing Authorized Users and their access, configuring tracking/suppression correctly, and securing its own email/SMTP provider and any integrations it connects.
8.4 Pseudonymization and minimization. Customer acknowledges that it controls what Customer Personal Data is uploaded and is responsible for data minimization at the point of input; Beacon's role-based access controls, isolation, and redaction-on-export support pseudonymization and minimization in the Processing, as described in Annex 2.
9. Assistance with Data-Subject requests (Art. 28(3)(e))
9.1 Because Customer is the Controller of Customer Personal Data, requests from Data Subjects (prospects) to exercise rights of access, rectification, erasure, restriction, objection, or portability are directed to, and the responsibility of, Customer.
9.2 If Beacon receives such a request directly from a Data Subject relating to Customer Personal Data, Beacon will, without undue delay and unless legally prohibited, inform the Data Subject to contact Customer and/or notify Customer, and will not respond to the request itself except on Customer's documented instructions or as legally required.
9.3 Self-serve and assisted tooling. Taking into account the nature of the Processing, Beacon assists Customer in fulfilling such requests by providing:
- In-app self-serve export — a workspace administrator can export the workspace's Customer Data (including contacts, companies, activity/engagement, deals, suppression, and audit records) as a single machine-readable JSON bundle at any time, supporting access and portability. For security, the export deliberately excludes/redacts secret material (password hashes, API-key hashes, webhook signing secrets, and live session tokens).
- In-app record-level and account/workspace deletion — administrators can delete individual records, suppress/opt-out individual prospects, and permanently hard-delete the workspace (see Section 11), supporting erasure and restriction.
- Reasonable further assistance to locate, correct, restrict, port, or delete specific Customer Personal Data where the self-serve tools are insufficient.
9.4 Beacon may charge a reasonable fee, or decline, for assistance that is manifestly unfounded, excessive, or repetitive, or that goes materially beyond the standard assistance described above, having first notified Customer of the basis and (where charged) the estimated fee.
10. Personal Data Breach notification (Arts. 28(3)(f), 33–34)
10.1 Beacon will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and in any event consistent with the timeframe in Clause 8.6(c) of the EU SCCs where they apply.
10.2 The notification will, to the extent then known and taking into account the information available to Beacon, describe: (a) the nature of the breach, including, where possible, the categories and approximate number of Data Subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address it and mitigate adverse effects; and (d) a contact point for further information. Where it is not possible to provide all information at once, Beacon may provide it in phases without undue further delay.
10.3 Beacon will take reasonable steps to investigate, contain, and remediate the breach, and will reasonably cooperate with and assist Customer so that Customer can meet its own obligations to notify Supervisory Authorities (Art. 33) and affected Data Subjects (Art. 34).
10.4 As between the parties, Customer (as Controller) is responsible for determining whether the breach is notifiable and for making any required notifications to Supervisory Authorities and Data Subjects. Beacon's notification or assistance is not an acknowledgment of fault or liability. Customer is responsible for keeping its notification contact details current in the Service.
11. Deletion or return of data on termination (Art. 28(3)(g))
11.1 Self-serve deletion. Customer may, at any time, permanently delete Customer Personal Data using the Service's record-level deletion or its account/workspace deletion feature. Workspace deletion is an irreversible hard delete (subject to typed confirmation) of the workspace and every record tied to it — including contacts, companies, engagement events, calls, outbox, deals, bookings, templates, suppression, product docs, stored credentials, sessions, and users. There is no soft-delete or undo.
11.2 On termination. Upon termination or expiry of the Agreement, at Customer's choice (made before termination, where the Service permits), Beacon will return Customer Personal Data to Customer (Customer may self-serve export it as a JSON bundle before access ends) and/or delete it. Unless Customer instructs return/export beforehand or applicable law requires retention, Beacon will delete or de-identify Customer Personal Data within a commercially reasonable period after termination (target: [30] days after the effective date of termination). Beacon will, on Customer's written request made before access ends, make Customer Personal Data available for export for up to [30] days after termination.
11.3 Exceptions. Beacon may retain Customer Personal Data to the extent and for as long as required by applicable law, and residual copies may persist in routine, secured, encrypted backups until they age out on the normal rotation cycle ([BACKUP RETENTION PERIOD]), during which time the data remains protected by this DPA and is not actively Processed and is isolated from active Processing.
11.4 Shared/demo environment. The shared free/demo environment cannot be self-deleted for technical reasons; to remove data from it, Customer must contact Beacon at [PRIVACY CONTACT EMAIL], and Beacon will action the request within a reasonable period.
11.5 On Customer's written request, Beacon will certify deletion in writing in accordance with Clause 8.5/16(d) of the EU SCCs where they apply.
12. Audit rights (Art. 28(3)(h))
12.1 Beacon makes available to Customer the information necessary to demonstrate compliance with Art. 28 and this DPA, including, where available, this DPA, the Privacy Policy, the security measures in Annex 2, and any third-party certifications, audit reports, penetration-test summaries, or attestations Beacon holds [e.g. SOC 2 Type II, ISO 27001 — list / placeholder; if none currently held, state the security questionnaire / documentation Beacon will provide instead].
12.2 Where the information made available under Section 12.1 is not sufficient to demonstrate compliance, Customer (or a mutually agreed, independent, suitably qualified auditor bound by confidentiality and not a competitor of Beacon) may conduct an audit, subject to the following: (a) Customer gives at least [30] days' prior written notice; (b) audits occur during business hours, no more than once per 12-month period (except where required by a Supervisory Authority, following a Personal Data Breach affecting Customer, or where required to exercise audit rights under the SCCs); (c) the scope is limited to information and systems relevant to the Processing of Customer Personal Data; (d) the audit must not unreasonably disrupt Beacon's business or compromise the security or confidentiality of other customers' data or of any third party; and (e) each party bears its own costs of the audit, except that Customer bears Beacon's reasonable costs of supporting an on-site audit and, where the audit reveals a material breach by Beacon, Beacon bears its own costs.
12.3 Where the EU SCCs apply, the audit provisions of the SCCs (Clause 8.9) also apply and, in the event of conflict with this Section, prevail with respect to the relevant transfer.
13. Liability and order of precedence
13.1 Order of precedence. In the event of any conflict between this DPA and the Agreement with respect to the Processing of Customer Personal Data, this DPA prevails. Where the SCCs or UK Addendum apply, they prevail over this DPA to the extent of any conflict regarding the relevant Restricted Transfer. Consistent with the Agreement's order of precedence, the overall order of precedence is: (1) the SCCs / UK Addendum (as to Restricted Transfers); (2) any signed order form or master agreement between the parties (as to the matters it expressly addresses); (3) this DPA (as to the Processing of Customer Personal Data); (4) the Agreement (including the Terms of Service); and (5) the Privacy Policy. [Confirm this mirrors the precedence clause in the Agreement (currently ToS Section 24.1), which ranks a signed order form/master agreement above the DPA; if so, the DPA still controls over the Terms on personal-data Processing as stated in the Agreement.]
13.2 Liability. Each party's and its affiliates' total liability arising out of or related to this DPA, whether in contract, tort, or any other theory, is subject to the limitations of liability and exclusions of damages set out in the Agreement, and any reference there to a party's aggregate liability means the aggregate liability across the Agreement and this DPA together, which together form a single aggregate cap and are not cumulative. [Confirm alignment with ToS Section 17: the cap is the greater of fees paid in the prior 12 months or US$100, and the indirect-damages exclusion applies; confirm this cap is acceptable for the data-protection risk and consider a higher or separate super-cap for data-protection / breach / confidentiality liability.] Nothing in this DPA or the Agreement limits or excludes either party's liability: (a) to a Data Subject under the third-party-beneficiary or liability provisions of the SCCs; (b) under Art. 82 GDPR to the extent it cannot be limited by contract; or (c) for any liability that cannot be limited or excluded under Data Protection Laws.
13.3 This DPA does not relieve either party of any obligations under the Data Protection Laws that apply to it directly in its own role.
14. Governing law, term, and miscellaneous
14.1 Governing law and jurisdiction. Except where the SCCs, UK Addendum, or Data Protection Laws mandate otherwise (e.g., the SCCs' own choice of EU Member State law and forum, as completed in Annex 1, and the mandatory protections for Data Subjects thereunder), this DPA is governed by, and construed in accordance with, the governing law and subject to the dispute-resolution and venue provisions of the Agreement (Governing Law and Dispute Resolution section) — currently [GOVERNING LAW: State/Country] and [VENUE].
14.2 Term. This DPA takes effect on the effective date of the Agreement (or on Customer's acceptance of it, if later) and remains in force for as long as Beacon Processes Customer Personal Data. Provisions that by their nature should survive termination (including Sections 4, 7, 11, 12, and 13) survive.
14.3 Changes. Beacon may update this DPA to reflect changes in Data Protection Laws, Subprocessors, transfer mechanisms, or its security measures, provided no update materially reduces the protections afforded to Customer Personal Data; material changes will be notified in accordance with the Agreement's change-notice provisions. Where a successor or replacement version of the SCCs or UK Addendum comes into force, the parties will work in good faith to put the updated mechanism in place, and it will be deemed incorporated in place of the prior version on its applicable date.
14.4 Severability. If any provision of this DPA is held invalid or unenforceable, the remainder continues in effect, and the invalid provision is modified to the minimum extent necessary to make it enforceable while preserving the parties' intent.
14.5 Signature and acceptance. Acceptance of the Agreement (including by clicking "I agree," creating an account or workspace, or otherwise accessing or using the Service) constitutes acceptance of this DPA and, where applicable, execution of the SCCs as set out in Section 7.2, in each case by a person with authority to bind Customer. Customers requiring a separately countersigned copy may request one at /dpa; a countersigned copy does not change the substantive terms unless expressly agreed in a signed order form.
Annex 1 — Standard Contractual Clauses details / UK Addendum / Swiss adaptations
(To be completed by counsel.)
- EU SCCs — Modules. Module Two (Controller→Processor): Customer = data exporter; Beacon = data importer. Module Three (Processor→Processor): (i) where Customer acts as a processor for a third-party controller, and (ii) for onward transfers to Subprocessors.
- Clause 7 (Docking clause): [included / not included — recommend included to allow additional Customer affiliates to accede].
- Clause 9 (Subprocessors): Option 2 — General written authorization, with a minimum [30]-day prior notice period (see Section 6.4).
- Clause 11 (Redress): optional independent dispute-resolution body [included / not included].
- Clause 17 (Governing law of the SCCs): the law of [EU MEMBER STATE — e.g. Republic of Ireland].
- Clause 18 (Forum and jurisdiction): the courts of [EU MEMBER STATE].
- Annex I.A (Parties): [Customer and Beacon identities, roles, activities relevant to the transfer, contact details, signatures — populated from the account/order form].
- Annex I.B (Description of transfer): categories of Data Subjects and Personal Data, frequency (continuous), nature/purpose, retention, and Subprocessor transfers — as set out in Sections 2, 3, 6, and 11 of this DPA.
- Annex I.C (Competent Supervisory Authority): [the supervisory authority of the EU Member State in Clause 17, or the Member State where the EU representative is established / where Data Subjects are — placeholder].
- Annex II (Technical and organizational measures): as set out in Annex 2 of this DPA.
- Annex III (List of Subprocessors): as set out in Annex 3 of this DPA.
- UK Addendum: Tables 1–3 completed by reference to the EU SCCs above; Table 4 — the party that may end the Addendum under its Section 19: [Importer / Exporter / neither]. UK governing law and courts: England and Wales [confirm].
- Swiss (FADP) adaptations: references to the GDPR are to the FADP where applicable; the competent authority is the Swiss FDPIC; "Member State" does not bar Swiss-resident Data Subjects from bringing claims in Switzerland; the SCCs also protect legal entities until the FADP's entry into force is fully reflected.
Annex 2 — Technical and Organizational Measures (Art. 32)
The measures described in Section 8 of this DPA, including: encryption in transit (TLS/HTTPS) and at rest for the managed database and backups; per-workspace (multi-tenant) data isolation with workspace_id-scoped queries; hashed passwords and signed/HTTP-only session cookies; role-based, least-privilege access controls; durable rate limiting and abuse protections; outbound-webhook SSRF protections; audit logging of significant actions; an anti-fabrication research guardrail; one-click List-Unsubscribe, automatic hard-bounce suppression, and suppression lists; secret-redaction on data export; regular encrypted backups; and monitoring, logging, and incident-response processes.
[Counsel/security to expand into the full Annex II format required by the EU SCCs, mapping each item to the SCC categories, including: measures of pseudonymization and encryption; measures for ensuring ongoing confidentiality, integrity, availability, and resilience of systems; measures for restoring availability and access after an incident; processes for regularly testing and evaluating effectiveness; measures of user identification and authorization; protection of data in transit and at rest; physical security of processing locations (delegated to hosting Subprocessors); event logging; system configuration including default configuration; internal IT and security governance; certification/assurance; data minimization and quality; retention; accountability; data portability and erasure; and the measures the Subprocessors are required to apply. Note current certification status (e.g., SOC 2 / ISO 27001) or state "none yet — roadmap."]
Annex 3 — List of approved Subprocessors
As set out in Section 6.1 and maintained at /security: Anthropic (AI research/drafting incl. web search; United States), Supabase (database hosting; [region + underlying infrastructure provider]), Vercel (application hosting; [region + underlying infrastructure provider]), and Stripe (payment/billing). For each, identify: the entity name and address, the Processing it carries out, the categories of Customer Personal Data it Processes, its location(s), its transfer mechanism (adequacy / DPF / SCCs), and any sub-subprocessors. Customer's own email/SMTP provider and any data/enrichment provider Customer connects are configured and controlled by Customer and are not Beacon Subprocessors (Section 6.2).
This DPA is a template and does not constitute legal advice. Have qualified counsel review and complete it — in particular Annex 1 (SCCs module/clause selections, UK Addendum, Swiss adaptations), the DPF note (Section 7.4), the liability-cap alignment (Section 13.2), the audit/certification placeholders (Section 12.1, Annex 2), and the bracketed placeholders — for your legal entity and jurisdictions before publishing.