Data Processing Agreement
This DPA applies when BeaconRelay processes Customer Personal Data on behalf of a customer and forms part of the Terms or applicable order.
- Effective
- 2026-09-26
- Contact
- legal@beaconrelay.dev
1. Parties and scope
“Customer” is the entity accepting the Terms or named in an order and is controller or processor as applicable. “Provider” is the BeaconRelay operator identified in the completed provider notice or order and is Customer’s processor. This DPA covers Customer Personal Data submitted through connected Salesforce organizations, delivery destinations, and support instructions.
2. Documented instructions
Provider will process Customer Personal Data only on Customer’s documented instructions, including the Terms, configured topics, destinations, retention plan, redrive actions, support requests, and this DPA. Provider will notify Customer if an instruction appears to violate applicable data-protection law, unless prohibited by law. Provider will notify Customer before legally compelled processing unless prohibited.
3. Confidentiality
Provider will ensure persons authorized to process Customer Personal Data are bound by confidentiality and receive access only as needed for their role. Access to payload content is restricted to Customer-authorized reveal actions and limited support or security operations.
4. Security
Provider will implement measures appropriate to risk, including those in Annex II. Customer is responsible for secure Salesforce configuration, field selection, destination security, receiver idempotency, user access, and evaluating whether the service is suitable for the data it sends.
5. Subprocessors
Customer gives general authorization for subprocessors listed in Annex III. Provider will impose data-protection obligations no less protective than this DPA and remains responsible for their performance. Provider will give reasonable prior notice of a new subprocessor so Customer may object on reasonable data-protection grounds. If no reasonable alternative is available, either party may terminate the affected service.
6. Data-subject requests
Taking account of the processing, Provider will reasonably assist Customer with requests to exercise data-subject rights. Provider will not respond directly concerning Customer Personal Data except on Customer’s instruction or where legally required.
7. Assistance and incidents
Provider will reasonably assist with security, breach notifications, data-protection impact assessments, and prior consultations, considering the nature of processing and available information. Provider will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data and provide available details, mitigation, and updates. Notification is not an admission of fault.
8. Return and deletion
During the service Customer can receive data through configured delivery and product views. On termination, Provider will, at Customer’s choice and documented instruction, delete or return Customer Personal Data and delete copies unless applicable law requires storage. Plan retention continuously deletes eligible payload content as described in Annex I and the Retention Schedule. Integrity evidence may be retained only as instructed, legally required, or necessary to establish legal claims.
9. Information and audits
Provider will make available information reasonably necessary to demonstrate compliance. No more than once annually, unless following a breach or regulator request, Customer may request an audit by an independent qualified auditor bound by confidentiality. Audits require reasonable notice, must minimize disruption and exposure of other customers’ data, and are at Customer’s cost unless they identify material non-compliance.
10. Transfers and precedence
Restricted transfers require a lawful mechanism, including adequacy or applicable Standard Contractual Clauses. The transfer module, exporter/importer details, countries, and supplementary measures must be completed once Provider and hosting locations are confirmed. If this DPA conflicts with the Terms on personal-data processing, this DPA controls.
Annex I: Processing details
- Subject matter
- Reliable receipt, storage, delivery, retry, replay, monitoring, verification, and support for Salesforce events.
- Duration
- For the service term and deletion period described by Customer’s plan and termination instructions.
- Nature and purpose
- Collection from Salesforce, encrypted storage, extraction of routing metadata, HTTPS transmission, response capture, incident monitoring, integrity signing, receipt generation, and deletion.
- Data subjects
- Customer users; Customer’s prospects, customers, employees, contractors, and other persons represented in selected Salesforce records.
- Personal data
- Account identifiers, contact and business-record fields selected by Customer, Salesforce IDs, event metadata, destination responses, IP/security metadata, and support data.
- Sensitive data
- Not intended. Customer must not select special-category, criminal-offence, payment-card, credential, or similarly high-risk fields without an executed written amendment.
- Frequency
- Continuous or event-driven according to configured Salesforce topics.
Annex II: Security measures
- TLS for external transport and HTTPS-only customer destinations.
- AES-256-GCM envelope encryption for retained payload and receiver-response content; encrypted OAuth tokens.
- Ed25519 event and receipt signatures with restricted private-key access and retained public verification keys.
- Password hashing, authenticated owner checks, CSRF protection, secure session cookies, rate limits, and least-privilege service separation.
- Destination validation against private/internal addresses and redirect refusal to reduce server-side request forgery.
- Database-first event persistence, replay cursors, controlled retry schedules, Dead Letter state, and operational audit records.
- Retention enforcement that removes eligible encrypted content while preserving non-content integrity evidence.
- Incident classification, monitoring, recovery procedures, dependency patching, backups, and access review appropriate to risk. Backup specifics must be completed before launch.
Annex III: Authorized subprocessors and recipients
| Provider | Purpose | Data | Location/safeguard |
|---|---|---|---|
| Infrastructure host: launch detail required | Compute, database, storage, networking and backups | All hosted service data | Must be completed |
| Brevo (Sendinblue SAS) | Transactional email delivery | Recipient, sender, subject, message and delivery metadata | Confirm account region and transfer safeguard |
| Stripe | Subscription billing and invoices | Account, customer, subscription and transaction metadata | Per Stripe DPA and configured account |
| Salesforce | Customer-directed source connection | OAuth and selected event data | Customer’s Salesforce agreement and region |
Customer-configured webhook destinations are Customer recipients, not Provider-selected subprocessors.
Execution
This web DPA becomes binding only when the Provider legal identity and Annex III launch details are completed and Customer accepts the Terms or signs an order incorporating it. Until then it is a pre-release template for legal review.