Beacon Privacy Policy
Last updated: June 17, 2026 Version: 1.0 (draft)
This Privacy Policy explains how [LEGAL ENTITY NAME] ("Beacon", "we", "us", or "our"), which operates the Beacon platform at warmbeacon.com and related subdomains, collects, uses, discloses, and protects personal data. It also explains the rights available to individuals under the EU/UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable laws.
Beacon is an AI-native B2B outbound sales platform. Our customers (typically sales teams and the businesses that employ them) upload information about their own products and about the prospects they wish to contact. Our AI then researches those prospects using publicly available web sources and drafts outreach emails, which are sent through the customer's own email/SMTP provider. We record opens, clicks, and replies so the customer can measure engagement.
> Plain-language summary. We are the controller of your account and usage data. For the prospect data our customers upload and have us process, our customer is the controller and Beacon is only a processor — we act on the customer's documented instructions. We do not sell or "share" personal data, and we do not use your data to train AI models. We use a small, fixed set of subprocessors (Anthropic, Supabase, Vercel, Stripe, and the customer's own email provider) listed in Section 6. You have rights to access, export, and delete your data, much of which an account administrator can exercise directly inside the app.
1. Who we are and the scope of this policy
Controller of account and platform data. [LEGAL ENTITY NAME] is the data controller for personal data relating to our customers and their authorized users — for example, account registration details, billing data, and product usage/telemetry. Our contact details are in Section 16.
Scope. This policy applies to:
- the Beacon web application and dashboard;
- the warmbeacon.com marketing website, free tools (such as our deliverability and email-grading tools), and demo experiences;
- our APIs; and
- related communications (support, billing, and product notifications).
This policy does not govern the privacy practices of our customers in their capacity as senders of outreach, nor the practices of third-party websites or services we link to. For prospect data, see Section 2.2 (the controller/processor distinction) and Section 12.
2. Key roles: controller vs. processor
Beacon plays two different roles depending on the data in question. This distinction is central to understanding your rights and who is responsible.
2.1 Where Beacon is the controller
For the following data, Beacon decides why and how it is processed, and Beacon is the controller:
- Account data about customers and their authorized users (e.g., name, work email, hashed password, role, workspace membership).
- Billing data processed to manage subscriptions and payments (Beacon stores subscription/plan metadata; card data is held by Stripe — see Section 3.4).
- Usage, telemetry, and diagnostic data generated as customers use the platform.
- Marketing-site, lead, and free-tool data collected from prospective customers and website visitors.
2.2 Where Beacon is the processor (customer-uploaded prospect data)
When a customer uploads or syncs a list of prospects/contacts (and the related AI-generated research and engagement data), Beacon processes that data on the customer's behalf and on the customer's documented instructions. In that context:
- The customer is the data controller. The customer decides which individuals to contact, must establish a lawful basis for processing their personal data, must provide any required notices, and must honor opt-outs and applicable marketing laws (e.g., GDPR, CAN-SPAM in the US, CASL in Canada, and the ePrivacy/PECR rules in the EU/UK).
- Beacon is the data processor. We process prospect data only to provide the service to that customer — for example, to research a prospect, draft outreach, send via the customer's SMTP, and record engagement. We do not use prospect data for our own purposes, do not sell or "share" it, do not use it to build cross-customer profiles, and do not use it to train AI models (see Section 5).
- A Data Processing Agreement ("DPA") governs this relationship. Our customers may request and execute our DPA at /dpa, which incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where applicable.
If you are a prospect (you received outreach sent through Beacon and you are not a Beacon customer), please read Section 12, which explains how to exercise your rights — generally by contacting the company that sent you the message, with our assistance.
3. Categories of personal data we process
3.1 Account data (Beacon = controller)
- Identity and contact: name, work email address, job title, and the role/permissions assigned within a workspace.
- Credentials: a hashed (not plaintext) password, session tokens, and an authentication cookie.
- Workspace and team data: workspace name, team membership, invitations, and seat assignments.
- Communications: support requests, feedback, NPS responses, and correspondence with us.
3.2 Customer content, including prospect personal data (Beacon = processor)
When customers use the platform, we process the content they provide or generate, which may include personal data about their prospects:
- Prospect identifiers and business contact details: first and last name, job title, business email address, phone number, LinkedIn/profile URLs, and employer/company.
- AI-researched dossiers: summaries, "personas," signals, and research logs that our AI compiles from publicly available web sources (including live web search) to inform outreach. These dossiers describe a prospect's professional role and context, and cite their sources.
- Outreach content and history: drafted and sent emails, message templates, merge variables, scheduling, replies, call notes, and deal/pipeline records associated with a prospect.
- Engagement records: whether a given message was opened or clicked, and reply status, with timestamps (see Section 3.3).
- Suppression and opt-out (do-not-contact) lists the customer maintains.
- Product and company information the customer uploads (e.g., product docs) to ground the AI — this may incidentally contain personal data the customer chooses to include.
We do not require, and ask customers not to upload, special-category / sensitive personal data about prospects (see Section 3.6).
3.3 Usage, telemetry, and engagement data
- Usage/telemetry (Beacon = controller): pages and features used, actions taken, timestamps, device/browser information, IP address, approximate location derived from IP, and diagnostic/error logs, for customers and their authorized users.
- Email engagement tracking (processed on the customer's behalf): when a customer sends outreach through Beacon with tracking enabled, we record opens (via a 1×1 tracking pixel), link clicks (via redirect tracking), and replies, together with timestamps. This engagement data is tied to the specific prospect and is processed as customer content under Section 2.2. Customers can disable open and/or click tracking per workspace.
3.4 Billing data (Beacon = controller)
- Subscription tier, seat count, billing/subscription status, and billing-period dates. Card and payment details are collected and stored by Stripe, not by Beacon; Beacon stores only Stripe customer/subscription identifiers and the plan metadata above so we can manage entitlements.
3.5 Marketing, lead, and free-tool data (Beacon = controller)
- Demo / contact requests and free-tool submissions: name, work email, company, team size, current tooling/stack, and the pain or context the visitor describes.
- Anti-abuse metadata: IP address, used to rate-limit and detect automated submissions on public endpoints.
3.6 Sensitive / special-category data
Beacon is a B2B product centered on business contact and professional context. We do not intentionally collect special categories of personal data under GDPR Art. 9 (e.g., health, race, religion, political opinions, sexual orientation, biometric/genetic data) or "sensitive personal information" as defined by the CCPA/CPRA, and we do not use any such data for inferring characteristics. Customers are contractually required not to upload sensitive data into prospect records or product docs. If you believe sensitive data has been provided to us, contact us at [PRIVACY CONTACT EMAIL] and we will work with the relevant controller to remove it.
3.7 Cookies and similar technologies
Beacon uses a strictly necessary cookie for authentication and session security. We do not currently set advertising cookies or third-party tracking cookies. See Section 13.
4. How and why we use personal data, and the legal bases (GDPR Art. 6)
Where GDPR/UK GDPR applies and Beacon is the controller, we rely on the following legal bases. (For prospect data we process as a processor, the controlling customer is responsible for establishing the lawful basis under Art. 6 — see Section 2.2.)
| Purpose | Categories used | Legal basis (GDPR Art. 6(1)) | |---|---|---| | Provide, operate, and secure the platform; authenticate users | Account data, credentials, usage/telemetry | (b) Performance of a contract; (f) Legitimate interests in securing our service | | Process subscriptions and payments | Account data, billing data | (b) Contract; (c) Legal obligation (tax/accounting) | | AI processing: research prospects and draft outreach (on the customer's instruction) | Customer content incl. prospect data | Beacon acts as processor; the customer relies on its own Art. 6 basis (typically (f) legitimate interests or (a) consent) | | Email open/click/reply tracking | Engagement data | Beacon acts as processor for the customer; the customer relies on its own basis/consent | | Customer support and service communications | Account data, communications | (b) Contract; (f) Legitimate interests | | Product analytics, abuse prevention, and improving the service | Usage/telemetry, lead/anti-abuse metadata (controller data) | (f) Legitimate interests | | Marketing our own services to prospective and existing customers | Lead data, account data | (f) Legitimate interests; (a) Consent where required | | Comply with law and enforce our terms | As relevant | (c) Legal obligation; (f) Legitimate interests |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms; you may object as described in Section 10. Where we rely on consent, you may withdraw it at any time without affecting prior processing.
5. Artificial intelligence and automated processing
Beacon uses Anthropic's Claude models, including Anthropic's live web-search tool, to research prospects and draft outreach. Important points:
- Inputs. To generate research and drafts, we send relevant customer content (including prospect identifiers and product context) to Anthropic for processing, and Anthropic's web-search tool issues queries to public search engines.
- No model training on your data. We do not train any AI models, and the customer content and prospect data we send to Anthropic are processed only to return results to the customer and are not used by Anthropic to train its models, consistent with Anthropic's commercial terms applicable to our account. [Confirm Anthropic zero-retention / no-training terms and reference the specific contract or DPF status — see Section 6.]
- Sources. Research is drawn from publicly available web sources; the platform records and surfaces the sources cited for each signal.
- Human in the loop. The AI drafts outreach; a customer's authorized user reviews and decides whether to send. Beacon does not make decisions producing legal or similarly significant effects about prospects without human involvement, and the platform is designed to keep a human in control of sending.
- Accuracy. AI-generated dossiers are drawn from public sources and may be incomplete or inaccurate. Customers are responsible for reviewing content before use. Prospects may request correction or deletion as described in Sections 10 and 12.
6. Subprocessors and third parties
We use a limited, fixed set of subprocessors to deliver the service. Each is bound by data-protection obligations consistent with this policy and our DPA.
| Subprocessor | Purpose | Location / notes | |---|---|---| | Anthropic | AI processing of prospect and product data (research and drafting), including the web-search tool | United States; inputs not used to train models | | Supabase | Managed PostgreSQL database hosting (stores account data and customer content) | Primary data store; United States — AWS us-east-1 (N. Virginia) | | Vercel | Application hosting, serving, and serverless/edge compute | Hosts the web app and APIs; United States (Washington, D.C. region, AWS us-east-1) | | Stripe | Payment processing and subscription billing | Stores payment-card details directly; Beacon does not | | Customer's own email / SMTP provider | Sending outreach email and (where applicable) reading replies | Chosen and controlled by the customer; not a Beacon subprocessor in the strict sense — the customer configures it and it operates under the customer's own agreement with that provider |
We do not currently use third-party web analytics, advertising, or external error-monitoring providers. If we add such a provider (for example, for product analytics or error monitoring), we will update the subprocessor list below before or promptly after the change, as required by our DPA.
Current subprocessor list. The authoritative, up-to-date list of subprocessors is maintained at [SUBPROCESSOR LIST URL — e.g. warmbeacon.com/subprocessors]. Customers may subscribe there to receive advance notice of changes and may object to a new subprocessor as set out in our DPA.
7. International data transfers
We and our subprocessors process personal data in the United States and may process it in other countries outside your own. Where we transfer personal data out of the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards, primarily:
- the EU Standard Contractual Clauses (SCCs);
- the UK International Data Transfer Addendum to the SCCs; and
- additional technical and organizational measures as needed.
A copy of the relevant transfer mechanism is available on request at [PRIVACY/DPA CONTACT EMAIL]. [If Beacon or a subprocessor (e.g., Anthropic, Stripe, Vercel) participates in the EU-US Data Privacy Framework, state that here: DPF CERTIFICATION DETAILS / PLACEHOLDER.]
8. Data retention
We retain personal data only as long as necessary for the purposes described in this policy:
- Account data: for the life of the account and as needed afterward to meet legal, tax, and accounting obligations, then deleted or anonymized.
- Customer content, including prospect data (processed as processor): retained for the duration of the customer's subscription, then deleted or returned per the customer's instructions and our DPA. Customers can also delete individual records (e.g., contacts, companies, deals) within the app at any time, and can suppress/opt-out individual prospects.
- Account deletion ("right to be forgotten"): when a workspace administrator deletes their account/workspace (a destructive action requiring typed confirmation), we perform an irreversible, hard deletion of the workspace and every record tied to it — including contacts, companies, engagement events, calls, outbox, deals, bookings, templates, stored credentials, sessions, and users. There is no soft-delete or undo. Our shared free/demo environment cannot be self-deleted for technical reasons; to remove data from it, contact us.
- Usage/telemetry and logs: retained for [RETENTION PERIOD — e.g. 12–24 months], then deleted or aggregated/anonymized.
- Backups: residual copies may persist in our hosting providers' encrypted backups for [BACKUP RETENTION PERIOD] before being overwritten on rotation; deleted records age out of backups on that cycle.
- Legal holds: we may retain data longer where required to comply with law or to establish, exercise, or defend legal claims.
9. How we protect personal data
We maintain technical and organizational measures appropriate to the risk, including:
- Encryption of data in transit (TLS) and at rest for our managed database and backups;
- Hashed password storage (passwords are never stored in plaintext);
- Authentication, session management, and role-based access controls, with per-workspace (multi-tenant) isolation so each workspace's data is segregated and queries are scoped to the requesting workspace;
- Rate limiting and abuse protections on sensitive and public endpoints;
- Audit logging of significant actions;
- Least-privilege access for personnel and vetted subprocessors; and
- monitoring, logging, and [INCIDENT RESPONSE / BREACH NOTIFICATION PROCESS].
No method of transmission or storage is perfectly secure. If we become aware of a personal-data breach, we will notify affected customers and regulators as required by law and our DPA, and where Beacon is a processor we will notify the affected customer-controller without undue delay so they can meet their own notification obligations.
10. Your rights (GDPR / UK GDPR)
Subject to applicable law, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten");
- Restrict or object to processing (including processing based on legitimate interests, and direct marketing);
- Data portability — receive your data in a structured, machine-readable format;
- Withdraw consent where processing is based on consent; and
- Lodge a complaint with a supervisory authority (see Section 14).
Self-serve and assisted options. Where Beacon is the controller, several of these rights are available directly in the app to a workspace administrator:
- Export. A workspace administrator can export the workspace's data — including contacts, companies, activity/engagement, deals, and audit records — as a single machine-readable JSON bundle from in-app settings at any time. For security, the export deliberately excludes secret material (password hashes, API-key hashes, webhook signing secrets, and live session tokens).
- Deletion. A workspace administrator can permanently delete the account/workspace from in-app settings, subject to a typed confirmation (see Section 8).
You can also exercise any right by emailing [PRIVACY CONTACT EMAIL]. We will respond within the timeframes required by law (generally within one month under GDPR). We may need to verify your identity first, and we will not charge a fee except where permitted.
> Note on prospect data. Because we process prospect data as a processor, requests about a specific prospect's data are generally routed to, or require the involvement of, the customer who controls that data (see Sections 2.2 and 12).
11. Your rights (CCPA / CPRA and other US state laws)
If you are a California resident (and, where applicable, a resident of another US state with comparable privacy laws), you have the right to:
- Know / access the categories and specific pieces of personal information we collect, use, and disclose;
- Delete personal information we hold about you (subject to exceptions);
- Correct inaccurate personal information;
- Opt out of "sale" or "sharing" of personal information and of targeted advertising;
- Limit use of sensitive personal information; and
- Non-discrimination for exercising your rights.
We do not "sell" personal data, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have not sold or shared personal information (including the personal information of anyone we know to be under 16) in the preceding 12 months. The categories of personal information we collect and the purposes for which we use them are described in Sections 3–4. We disclose personal information to the service providers / subprocessors in Section 6 for the business purposes described, under contracts that prohibit their use of it for any other purpose. We do not use or disclose sensitive personal information beyond the purposes permitted under CCPA/CPRA § 7027(m), so the "limit" right does not change our practices.
To exercise these rights, use the in-app tools or contact [PRIVACY CONTACT EMAIL]. You may use an authorized agent to submit requests, subject to verification. We will not discriminate against you for exercising your rights.
12. Information for prospects (non-customers who received outreach)
If you received an outreach email sent through Beacon, please note:
- The sender — our customer — is the controller of your personal data. They decided to contact you, hold the lawful basis for doing so, and are responsible for honoring your opt-out and other rights.
- To opt out or unsubscribe, use the unsubscribe/opt-out link in the message (including the one-click unsubscribe supported by most mailbox providers) or reply to the sender directly. Doing so adds you to that sender's do-not-contact (suppression) list and stops further messages from them. The sender is required to honor opt-outs under applicable law (e.g., CAN-SPAM, CASL, GDPR/PECR).
- To exercise access, correction, or deletion rights over the data used to contact you, please contact the sending company (the controller). Beacon, as processor, will assist that company in fulfilling your request.
- You may also contact Beacon at [PRIVACY CONTACT EMAIL]. Where appropriate we will route your request to the relevant customer and, on the data we directly hold, take action ourselves — for example, suppressing your address or removing or correcting AI-researched information.
13. Cookies and similar technologies
Beacon currently uses only a strictly necessary cookie to authenticate you and keep your session secure. Disabling this cookie will break sign-in and core functionality.
We do not currently use functional, analytics, or advertising cookies, and we do not set third-party tracking cookies. If we introduce optional cookies in the future, we will present appropriate controls (and, where required, a consent mechanism) and update this section. For more detail, see our [COOKIE POLICY URL, if separate].
Separately, the open-tracking pixel and click-redirect used in customer outreach (Section 3.3) are not website cookies — they are engagement-measurement technologies that operate within emails the customer sends, and the customer can disable them per workspace.
14. Complaints and supervisory authorities
If you have a concern, please contact us first at [PRIVACY CONTACT EMAIL] so we can try to resolve it. You also have the right to lodge a complaint with a supervisory authority:
- EEA: your local Data Protection Authority, or our [EU LEAD SUPERVISORY AUTHORITY, if applicable].
- UK: the Information Commissioner's Office (ICO).
- California: the California Privacy Protection Agency and/or the California Attorney General.
15. Children's data
Beacon is a business-to-business product intended for use by professionals. It is not directed to children, and we do not knowingly collect personal data from anyone under [16 / 18 — SELECT AGE THRESHOLD]. If you believe a child's data has been provided to us, contact [PRIVACY CONTACT EMAIL] and we will delete it.
16. Contact us
[LEGAL ENTITY NAME] [REGISTERED BUSINESS ADDRESS] Privacy/data inquiries: [PRIVACY CONTACT EMAIL — e.g. privacy@warmbeacon.com] General contact: [GENERAL CONTACT EMAIL]
Data Protection Officer (if appointed): [DPO NAME / EMAIL — or "We have not appointed a DPO because we are not required to; data-protection queries go to the address above."]
EU Representative (GDPR Art. 27, if applicable): [EU REPRESENTATIVE NAME AND ADDRESS — required if you have no EU establishment but offer services to / monitor individuals in the EU]
UK Representative (UK GDPR Art. 27, if applicable): [UK REPRESENTATIVE NAME AND ADDRESS]
17. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify customers by email or in-app notice. The current version always lives at /privacy. Your continued use of Beacon after an update takes effect constitutes acceptance of the revised policy, except where additional consent is required by law.