Data Processing Agreement
When Beacon processes personal data contained in the systems you connect, it does so on your behalf — you decide the purposes, Beacon carries out the processing. This agreement sets the terms for that relationship, including the safeguards, subprocessors and transfer mechanisms that apply.
1 · Parties & scope
This Data Processing Agreement ("DPA") supplements the Terms of Service between the customer ("Controller") and Startup Academy LLC, trading as Beacon Revenue® ("Processor", "Beacon"). It applies where Beacon processes personal data on the Controller's behalf in providing the service. Where the customer is itself a processor for its own customers, Beacon acts as a subprocessor and these terms apply accordingly.
2 · Roles
The Controller determines the purposes and means of processing the personal data it connects to Beacon. Beacon is the Processor and processes that data only to provide the service and only on the Controller's documented instructions — these include the Terms, this DPA, and the configuration choices the Controller makes in the product. Beacon informs the Controller if, in its opinion, an instruction infringes applicable data-protection law.
3 · Details of the processing
The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex I. Processing continues for the duration of the Terms and as needed to provide the service.
4 · Beacon's obligations
- Instructions. Process personal data only on the Controller's documented instructions, including for international transfers, unless required by law (in which case Beacon notifies the Controller, where lawful).
- Confidentiality. Ensure personnel authorised to process personal data are bound by confidentiality.
- Security. Implement appropriate technical and organisational measures, described in Annex II and in Beacon's Security statement.
- Data-subject requests. Assist the Controller, by appropriate measures, to respond to requests from data subjects exercising their rights.
- Assistance. Assist the Controller with security, breach notification, data-protection impact assessments and prior consultation, taking into account the nature of processing and the information available to Beacon.
- Breach notification. Notify the Controller without undue delay after becoming aware of a personal-data breach, with the information the Controller needs to meet its own obligations.
- Deletion or return. At the end of the service, delete or return personal data at the Controller's choice, and delete existing copies unless retention is required by law. Where personal data sits within a sealed, reproducible financial record, Beacon removes the personal details and retains only a de-identified aggregate, so the record still reconciles without identifying any individual.
5 · Subprocessors
The Controller gives Beacon general authorisation to engage the subprocessors listed in Annex III to provide the service. Beacon imposes data-protection obligations on each subprocessor no less protective than those in this DPA, and remains responsible for their performance.
- The current list. Annex III of this DPA, published at beaconrevenue.io/dpa, is the current subprocessor list. Each change is recorded in the "Last updated" date at the top of this page and in the change note under Annex III, so the version in force on any date can be read from the page.
- Notice. Beacon gives the Controller at least 30 days' written notice — by email to the workspace administrator — before engaging a new subprocessor or replacing an existing one. Notice is not required for a change in a subprocessor's hosting region within the same country, or for a subprocessor's own change of legal name.
- Objection. The Controller may object within the notice period on reasonable, documented data-protection grounds. Beacon and the Controller then work in good faith to resolve the objection — for example by not applying the change to the Controller's data where the service allows it, or by offering a commercially reasonable alternative.
- If no resolution is found within 30 days of the objection, the Controller may terminate the part of the service that depends on the new subprocessor by written notice, without penalty, and Beacon refunds any fees prepaid for the period after termination.
6 · International transfers
Beacon's own application servers, operational database, error monitoring and transactional email run inside the EU (Netherlands, Germany and Ireland). The analytics data store (Airtable), authentication (Clerk), the AI reasoning layer (Anthropic) and front-end hosting (Vercel) are provided from the United States, so Controller data is transferred to the United States in the ordinary course of the service. Beacon does not offer EU-only hosting. Where personal data is transferred out of the EEA, UK or Switzerland to a country without an adequacy decision, the transfer is governed by the Standard Contractual Clauses, which are incorporated into this DPA by reference and completed by its Annexes, and, where the subprocessor is certified under the EU–US Data Privacy Framework, by that framework.
- Which Clauses. The European Commission's Standard Contractual Clauses of 4 June 2021 (Decision (EU) 2021/914), Module Two (controller to processor), with the Controller as data exporter and Beacon as data importer. Where the Controller is itself a processor for its own customers, Module Three (processor to processor) applies instead.
- United Kingdom. For transfers from the UK, the Clauses apply as amended by the ICO's International Data Transfer Addendum (version B1.0, in force 21 March 2022), with the Addendum's tables completed by Annexes I–III and Part 2 mandatory clauses applying.
- Switzerland. For transfers from Switzerland, references to the GDPR are read as references to the Swiss Federal Act on Data Protection, the competent supervisory authority is the Federal Data Protection and Information Commissioner, and the Clauses also protect data relating to legal entities until Swiss law no longer requires it.
- Selections made in the Clauses. Clause 7 (docking clause): included. Clause 9: Option 2, general written authorisation, with the notice period in Section 5. Clause 11: the optional independent dispute-resolution body is not selected. Clause 13 and Annex I.C: the supervisory authority of the EEA member state in which the Controller is established. Clauses 17 and 18: the law and courts of Ireland.
- Annexes. Annex I of this DPA serves as Annex I to the Clauses (parties and description of the transfer), Annex II as Annex II (technical and organisational measures), and Annex III as the list of subprocessors under Clause 9. The Clauses are available from the European Commission and are provided in signed form with the countersigned DPA on request.
7 · Audits
Beacon makes available the information necessary to demonstrate compliance with this DPA, and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, on these terms:
- First, documentation. Audit requests are met first through Beacon's written documentation — this DPA, the Security statement, and written answers to the Controller's reasonable questions.
- Third-party reports in lieu. Once Beacon holds a SOC 2 or equivalent independent report, that report satisfies the audit right for the period it covers, and Beacon provides it under confidentiality on request. Beacon holds no such report today and says so in its Security statement.
- On-site or remote inspection is available where documentation and reports do not answer a documented concern: no more than once in any 12-month period, on at least 30 days' written notice, during business hours, without disrupting the service, at the Controller's cost, and under confidentiality — except that no limit on frequency or notice applies where a supervisory authority requires an audit or following a personal-data breach affecting the Controller's data.
8 · Liability & precedence
The liability provisions of the Terms of Service apply to this DPA. In the event of a conflict between this DPA and the Terms on the processing of personal data, this DPA prevails; in the event of a conflict between this DPA and the Standard Contractual Clauses, the Clauses prevail.
Annex I · Details of the processing
| Element | Detail |
|---|---|
| Subject matter | Provision of Beacon's revenue-intelligence service to the Controller. |
| Duration | The term of the Terms of Service, plus any legally required retention. |
| Nature & purpose | Reading from the Controller's connected systems; computing revenue metrics; storing derived data; presenting it to authorised users and readers; generating alerts and reasoning outputs. |
| Types of personal data | Business-contact and account identifiers within connected records — e.g. names, work emails, and roles of the Controller's customers and staff. Beacon does not require special-category data. |
| Categories of data subjects | The Controller's customers, prospects, and personnel whose details appear in the connected systems; the Controller's own users of Beacon. |
| Frequency | Continuous / on a synchronisation schedule while systems are connected. |
Annex II · Technical & organisational measures
Beacon's security measures are described in full in the Security statement. In summary: no login to a Controller system is ever asked for or stored by Beacon (each source is authorised in its own system and revocable there), and the scoped access token that authorisation yields is held under envelope encryption on Beacon's own backend; the Controller's systems remain the systems of record, while Beacon holds derived data and the invoice lines needed to reproduce each sealed figure, in a database section isolated per Controller; access is scoped by role with restricted data as a separate grant; write-back is suggestion-only with human approval and never touches the Controller's books; every figure is produced deterministically and sealed with its inputs; and an append-only record captures seals, approvals and access changes.
The measures in place on the date at the top of this page, stated as current status and not as a forward commitment:
- Encryption. All traffic in transit over HTTPS/TLS. Controller-authorised connection tokens encrypted at rest under envelope encryption — one data key per credential, data keys wrapped by a key-encryption key held outside the database. Our hosting providers document encryption of stored data at rest; Beacon states this as their claim and has not independently verified it.
- Access control and authentication. Production access to Controller data is limited to Beacon's founder; no employee or contractor holds production access. Customer users authenticate through Clerk; access inside the product is scoped by role and by area of responsibility, with restricted data as a separate explicit grant, and external readers receive sealed figures only. Multi-factor authentication is required on every one of Beacon's own administrative accounts.
- Isolation. Each Controller's retained records sit in their own database section with their own database role; the analytics tables for each Controller sit in their own base.
- Logging and monitoring. Application errors are captured in Sentry (EU). Seals, approvals and access changes are written to an append-only record.
- Backup and resilience. The operational database runs on a persistent volume in the EU. Daily and weekly backups of the production database are taken and retained by the hosting provider in the same EU region, with point-in-time recovery enabled; the Controller's systems of record are never modified by Beacon, so source data can always be re-read.
- Personnel. One person operates Beacon today. Anyone granted access in future is bound by written confidentiality and receives role-scoped access for a named purpose only.
- Incident response. Beacon notifies the Controller without undue delay after becoming aware of a personal-data breach, with what is known at the time and updates as the picture develops, and keeps a written record of each incident.
- Deletion. On termination or request, Controller data is deleted or returned as Section 4 describes; connection tokens are shredded on disconnect.
Annex III · Subprocessors
| Subprocessor | Purpose | Region | Transfer safeguard |
|---|---|---|---|
| Airtable | Data layer (derived data store) | United States | Standard Contractual Clauses in the vendor's data-processing terms |
| Notion | Workspace / data layer | United States | Standard Contractual Clauses in the vendor's data-processing terms |
| Anthropic (Claude) | AI reasoning & drafting | United States | Standard Contractual Clauses in the vendor's data-processing terms |
| Clerk | Authentication | United States | EU–US Data Privacy Framework (certified); Standard Contractual Clauses |
| Vercel | Front-end hosting | United States | Standard Contractual Clauses in the vendor's data-processing terms |
| Railway | Application servers and operational database | European Union (Netherlands) | None required — processed in the EU |
| Resend | Transactional email | European Union (Ireland) | None required — processed in the EU |
| Sentry | Error monitoring | European Union (Frankfurt, Germany) | None required — processed in the EU |
| PostHog | Product-usage analytics | European Union | None required — processed in the EU |
Change note — 18 September 2026: regions stated for every row; Stripe and HubSpot moved to the Privacy Notice; PostHog added; transfer safeguard column added.
Stripe (Beacon's own billing of the Controller) and HubSpot (Beacon's own customer communications) process the Controller's contact details on Beacon's own behalf as controller, not on the Controller's instructions, and are disclosed in the Privacy Notice rather than listed here. Accounting-data providers are added to this Annex before the first accounting system is connected.