BeaconRelay
TermsPrivacyDPARetention
Home
Pre-release legal draft. Provider legal name, registered address, governing jurisdiction, hosting subprocessor, and transfer locations must be completed and reviewed by qualified counsel before commercial launch.
Legal centerTerms of ServicePrivacy PolicyData Processing AgreementData Retention Schedule
Version2026-09-26legal@beaconrelay.dev
Article 28 terms

Data Processing Agreement

This DPA applies when BeaconRelay processes Customer Personal Data on behalf of a customer and forms part of the Terms or applicable order.

Effective
2026-09-26
Contact
legal@beaconrelay.dev

1. Parties and scope

“Customer” is the entity accepting the Terms or named in an order and is controller or processor as applicable. “Provider” is the BeaconRelay operator identified in the completed provider notice or order and is Customer’s processor. This DPA covers Customer Personal Data submitted through connected Salesforce organizations, delivery destinations, and support instructions.

2. Documented instructions

Provider will process Customer Personal Data only on Customer’s documented instructions, including the Terms, configured topics, destinations, retention plan, redrive actions, support requests, and this DPA. Provider will notify Customer if an instruction appears to violate applicable data-protection law, unless prohibited by law. Provider will notify Customer before legally compelled processing unless prohibited.

3. Confidentiality

Provider will ensure persons authorized to process Customer Personal Data are bound by confidentiality and receive access only as needed for their role. Access to payload content is restricted to Customer-authorized reveal actions and limited support or security operations.

4. Security

Provider will implement measures appropriate to risk, including those in Annex II. Customer is responsible for secure Salesforce configuration, field selection, destination security, receiver idempotency, user access, and evaluating whether the service is suitable for the data it sends.

5. Subprocessors

Customer gives general authorization for subprocessors listed in Annex III. Provider will impose data-protection obligations no less protective than this DPA and remains responsible for their performance. Provider will give reasonable prior notice of a new subprocessor so Customer may object on reasonable data-protection grounds. If no reasonable alternative is available, either party may terminate the affected service.

6. Data-subject requests

Taking account of the processing, Provider will reasonably assist Customer with requests to exercise data-subject rights. Provider will not respond directly concerning Customer Personal Data except on Customer’s instruction or where legally required.

7. Assistance and incidents

Provider will reasonably assist with security, breach notifications, data-protection impact assessments, and prior consultations, considering the nature of processing and available information. Provider will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data and provide available details, mitigation, and updates. Notification is not an admission of fault.

8. Return and deletion

During the service Customer can receive data through configured delivery and product views. On termination, Provider will, at Customer’s choice and documented instruction, delete or return Customer Personal Data and delete copies unless applicable law requires storage. Plan retention continuously deletes eligible payload content as described in Annex I and the Retention Schedule. Integrity evidence may be retained only as instructed, legally required, or necessary to establish legal claims.

9. Information and audits

Provider will make available information reasonably necessary to demonstrate compliance. No more than once annually, unless following a breach or regulator request, Customer may request an audit by an independent qualified auditor bound by confidentiality. Audits require reasonable notice, must minimize disruption and exposure of other customers’ data, and are at Customer’s cost unless they identify material non-compliance.

10. Transfers and precedence

Restricted transfers require a lawful mechanism, including adequacy or applicable Standard Contractual Clauses. The transfer module, exporter/importer details, countries, and supplementary measures must be completed once Provider and hosting locations are confirmed. If this DPA conflicts with the Terms on personal-data processing, this DPA controls.

Annex I: Processing details

Subject matter
Reliable receipt, storage, delivery, retry, replay, monitoring, verification, and support for Salesforce events.
Duration
For the service term and deletion period described by Customer’s plan and termination instructions.
Nature and purpose
Collection from Salesforce, encrypted storage, extraction of routing metadata, HTTPS transmission, response capture, incident monitoring, integrity signing, receipt generation, and deletion.
Data subjects
Customer users; Customer’s prospects, customers, employees, contractors, and other persons represented in selected Salesforce records.
Personal data
Account identifiers, contact and business-record fields selected by Customer, Salesforce IDs, event metadata, destination responses, IP/security metadata, and support data.
Sensitive data
Not intended. Customer must not select special-category, criminal-offence, payment-card, credential, or similarly high-risk fields without an executed written amendment.
Frequency
Continuous or event-driven according to configured Salesforce topics.

Annex II: Security measures

  • TLS for external transport and HTTPS-only customer destinations.
  • AES-256-GCM envelope encryption for retained payload and receiver-response content; encrypted OAuth tokens.
  • Ed25519 event and receipt signatures with restricted private-key access and retained public verification keys.
  • Password hashing, authenticated owner checks, CSRF protection, secure session cookies, rate limits, and least-privilege service separation.
  • Destination validation against private/internal addresses and redirect refusal to reduce server-side request forgery.
  • Database-first event persistence, replay cursors, controlled retry schedules, Dead Letter state, and operational audit records.
  • Retention enforcement that removes eligible encrypted content while preserving non-content integrity evidence.
  • Incident classification, monitoring, recovery procedures, dependency patching, backups, and access review appropriate to risk. Backup specifics must be completed before launch.

Annex III: Authorized subprocessors and recipients

ProviderPurposeDataLocation/safeguard
Infrastructure host: launch detail requiredCompute, database, storage, networking and backupsAll hosted service dataMust be completed
Brevo (Sendinblue SAS)Transactional email deliveryRecipient, sender, subject, message and delivery metadataConfirm account region and transfer safeguard
StripeSubscription billing and invoicesAccount, customer, subscription and transaction metadataPer Stripe DPA and configured account
SalesforceCustomer-directed source connectionOAuth and selected event dataCustomer’s Salesforce agreement and region

Customer-configured webhook destinations are Customer recipients, not Provider-selected subprocessors.

Execution

This web DPA becomes binding only when the Provider legal identity and Annex III launch details are completed and Customer accepts the Terms or signs an order incorporating it. Until then it is a pre-release template for legal review.

BeaconRelay

Reliable, replayable and verifiable Salesforce events.

Product documentation