BeaconRelay
TermsPrivacyDPARetention
Home
Pre-release legal draft. Provider legal name, registered address, governing jurisdiction, hosting subprocessor, and transfer locations must be completed and reviewed by qualified counsel before commercial launch.
Legal centerTerms of ServicePrivacy PolicyData Processing AgreementData Retention Schedule
Version2026-09-26legal@beaconrelay.dev
Privacy notice

Privacy Policy

This notice explains how BeaconRelay handles personal data for its website, accounts, billing, support, and Salesforce event transport.

Effective
2026-09-26
Contact
legal@beaconrelay.dev

1. Roles

The Provider is a controller for account, security, billing, support, and service-administration data. For personal data inside Salesforce event payloads and receiver responses, the customer determines purposes and means and is normally the controller; Provider acts as processor under the DPA. Salesforce data subjects should first contact the relevant customer.

2. Data collected

CategoryExamplesSource
AccountName, work email, company, role, password hash, verification and recovery statusYou
Salesforce connectionOrg and user IDs, instance URL, encrypted OAuth client credentials, encrypted access and refresh tokens, topic configurationYou and Salesforce
Event transportEncrypted payload, object/operation metadata, replay ID, hashes, signatures, destination URL, receiver responsesSalesforce and your receiver
Operations and securityEvent states, attempts, timestamps, incidents, IP-derived rate-limit identifiers, audit actionsService use
BillingStripe customer, subscription, invoice and payment-status identifiers; BeaconRelay does not store full card detailsYou and Stripe
CommunicationsEmail address, transactional email content and delivery status, support messagesYou and Brevo

3. Purposes and legal bases

  • Contract: create accounts, authenticate users, connect Salesforce, transport events, provide plans, billing, support, and requested communications.
  • Legitimate interests: secure and diagnose the service, prevent fraud and abuse, maintain operational evidence, and improve reliability without using payload content for unrelated purposes.
  • Legal obligations: accounting, tax, compliance, lawful requests, and protection of legal claims.
  • Consent: where required for optional communications or non-essential technologies. BeaconRelay currently uses essential session and security cookies only.

4. Sharing and subprocessors

Data is disclosed only as needed to provide or protect the service, follow customer instructions, complete transactions, or comply with law. Current named service recipients include Salesforce for customer-authorized connectivity, Stripe for subscription billing, and Brevo for transactional email. The infrastructure hosting provider and processing region must be named before commercial launch. Customer-configured webhook receivers receive event data at Customer’s direction.

5. International transfers

Service providers or customer destinations may process data outside the data subject’s country. Where GDPR transfer restrictions apply, Provider will use an adequacy decision, approved Standard Contractual Clauses, or another lawful safeguard. The final notice must identify hosting and email processing locations and applicable transfer safeguards before commercial launch.

6. Retention

Event content follows the plan-specific, technically enforced schedule described in the Data Retention Schedule. OAuth tokens remain until revocation or organization deletion. Operational integrity evidence remains while the account exists unless deleted with an organization or on documented customer instruction, subject to legal obligations. Account, billing, email-audit, and backup periods must be finalized before commercial launch; BeaconRelay will not claim a shorter period than the system enforces.

7. Security

Measures include encrypted payload and OAuth-token storage, TLS transport, password hashing, scoped access controls, CSRF and session protections, rate limits, destination validation, restricted signing keys, and audit records. Security is risk-based and no internet service can guarantee absolute security.

8. Rights

Depending on applicable law, individuals may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent without affecting earlier processing. Contact legal@beaconrelay.dev. For payload data, identify the customer controlling the Salesforce organization. You may complain to the competent data-protection authority.

9. Automated decisions and children

BeaconRelay does not make decisions producing legal or similarly significant effects about individuals and is not directed to children. Customers must not knowingly use the service to collect children’s data without a valid legal basis and appropriate safeguards.

10. Changes and contact

Material changes will be announced through the service or account email. The final policy must provide the Provider’s legal name, registered address, privacy representative or DPO where required, and competent supervisory authority. Questions and requests may be sent to legal@beaconrelay.dev.

BeaconRelay

Reliable, replayable and verifiable Salesforce events.

Product documentation