Data Processing Agreement
When Beacon processes personal data contained in the systems you connect, it does so on your behalf — you decide the purposes, Beacon carries out the processing. This agreement sets the terms for that relationship, including the safeguards, subprocessors and transfer mechanisms that apply.
1 · Parties & scope
This Data Processing Agreement ("DPA") supplements the Terms of Service between the customer ("Controller") and Startup Academy LLC, trading as Beacon Revenue® ("Processor", "Beacon"). It applies where Beacon processes personal data on the Controller's behalf in providing the service. Where the customer is itself a processor for its own customers, Beacon acts as a subprocessor and these terms apply accordingly.
2 · Roles
The Controller determines the purposes and means of processing the personal data it connects to Beacon. Beacon is the Processor and processes that data only to provide the service and only on the Controller's documented instructions — these include the Terms, this DPA, and the configuration choices the Controller makes in the product. Beacon informs the Controller if, in its opinion, an instruction infringes applicable data-protection law.
3 · Details of the processing
The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex I. Processing continues for the duration of the Terms and as needed to provide the service.
4 · Beacon's obligations
- Instructions. Process personal data only on the Controller's documented instructions, including for international transfers, unless required by law (in which case Beacon notifies the Controller, where lawful).
- Confidentiality. Ensure personnel authorised to process personal data are bound by confidentiality.
- Security. Implement appropriate technical and organisational measures, described in Annex II and in Beacon's Security statement.
- Data-subject requests. Assist the Controller, by appropriate measures, to respond to requests from data subjects exercising their rights.
- Assistance. Assist the Controller with security, breach notification, data-protection impact assessments and prior consultation, taking into account the nature of processing and the information available to Beacon.
- Breach notification. Notify the Controller without undue delay after becoming aware of a personal-data breach, with the information the Controller needs to meet its own obligations.
- Deletion or return. At the end of the service, delete or return personal data at the Controller's choice, and delete existing copies unless retention is required by law. Where personal data sits within a sealed, reproducible financial record, Beacon removes the personal details and retains only a de-identified aggregate, so the record still reconciles without identifying any individual.
5 · Subprocessors
The Controller gives Beacon general authorisation to engage the subprocessors listed in Annex III to provide the service. Beacon imposes data-protection obligations on each subprocessor no less protective than those in this DPA, and remains responsible for their performance. Beacon will give the Controller advance notice of any intended change (addition or replacement) of a subprocessor, and the Controller may object on reasonable data-protection grounds.
6 · International transfers
By default, Beacon hosts Controller data in the United States; EU data residency (Frankfurt, with backups in Dublin) is available on the appropriate plan. Where personal data is transferred out of the EEA, UK or Switzerland to a country without an adequacy decision, the transfer is governed by the Standard Contractual Clauses, which are incorporated into this DPA by reference and completed by its Annexes.
7 · Audits
Beacon makes available the information necessary to demonstrate compliance with this DPA, and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates — subject to reasonable notice, confidentiality, and frequency, and satisfied where possible through Beacon's documentation and third-party reports.
8 · Liability & precedence
The liability provisions of the Terms of Service apply to this DPA. In the event of a conflict between this DPA and the Terms on the processing of personal data, this DPA prevails; in the event of a conflict between this DPA and the Standard Contractual Clauses, the Clauses prevail.
Annex I · Details of the processing
| Element | Detail |
|---|---|
| Subject matter | Provision of Beacon's revenue-intelligence service to the Controller. |
| Duration | The term of the Terms of Service, plus any legally required retention. |
| Nature & purpose | Reading from the Controller's connected systems; computing revenue metrics; storing derived data; presenting it to authorised users and readers; generating alerts and reasoning outputs. |
| Types of personal data | Business-contact and account identifiers within connected records — e.g. names, work emails, and roles of the Controller's customers and staff. Beacon does not require special-category data. |
| Categories of data subjects | The Controller's customers, prospects, and personnel whose details appear in the connected systems; the Controller's own users of Beacon. |
| Frequency | Continuous / on a synchronisation schedule while systems are connected. |
Annex II · Technical & organisational measures
Beacon's security measures are described in full in the Security statement. In summary: credentials are never held by Beacon (each source is authorised in its own system and revocable there); raw records remain at source while Beacon holds derived data; access is scoped by role with restricted data as a separate grant; write-back is suggestion-only with human approval and never touches the Controller's books; every figure is produced deterministically and sealed with its inputs; and an append-only record captures seals, approvals and access changes.
Annex III · Subprocessors
| Subprocessor | Purpose | Region |
|---|---|---|
| Airtable | Data layer (derived data store) | US default; EU (Frankfurt) on Enterprise |
| Notion | Workspace / data layer | US default; EU (Frankfurt) on Enterprise |
| Anthropic (Claude) | AI reasoning & drafting | [verify] |
| Clerk | Authentication | [verify] |
| Stripe | Payment processing | [verify] |
| Vercel | Frontend hosting | [verify] |
| Railway | Backend hosting | [verify] |
| Resend | Transactional email | [verify] |
| Sentry | Error monitoring | [verify] |
| HubSpot | Customer & marketing communications | [verify] |