Beamstage
ProductHow it worksBroadcastPricing
ENFR
Sign in Start free
Legal
TermsPrivacyDPA
Language ENFR

Legal

Data Processing Agreement

The processing terms between an organisation using Beamstage, as controller, and [[RAISON SOCIALE]], as processor.

Last updated 2 August 2026

Template, not legal advice

This document was drafted from what the product actually does, and it has not been reviewed by a lawyer. Have counsel read and complete it before you publish it or rely on it. Everything highlighted in brackets is a blank the publisher still has to fill in.

On this page

  1. 01 Parties and purpose
  2. 02 Definitions
  3. 03 Subject matter, duration and description of the processing
  4. 04 Processing on documented instructions
  5. 05 Security measures
  6. 06 Confidentiality
  7. 07 Subprocessors
  8. 08 International transfers
  9. 09 Assistance to the controller
  10. 10 Return and deletion
  11. 11 Audits
  12. 12 What the controller undertakes
  13. 13 Liability, precedence and signature

01 Parties and purpose

This agreement is concluded between the organisation using Beamstage, the controller, and [[RAISON SOCIALE]], [[ADRESSE]], the processor. It forms part of the Terms of Service and applies as soon as the organisation processes personal data through the platform.

Where it conflicts with the Terms of Service on anything concerning personal data, this agreement prevails.

02 Definitions

Personal data, processing, controller, processor, data subject, supervisory authority
the meanings given to them by Regulation (EU) 2016/679, the General Data Protection Regulation.
Attendee
a person who registers for or takes part in a webinar published by the controller.
Platform
the Beamstage service: its application, its public registration pages, its live rooms and its replays.
Subprocessor
a third party engaged by the processor to carry out part of the processing.

03 Subject matter, duration and description of the processing

ItemContent
Subject matterproviding the Beamstage platform to the controller
Durationthe term of the subscription, plus the deletion period in section 10
Nature and purposeregistration, sending of transactional email, running a live session, recording and replay, attendance and engagement analytics, live subtitles when the option is enabled
Categories of data subjectsattendees, invited speakers, and the members of the controller’s own team
Categories of personal dataidentity (first name, last name, email address), acquisition data (source, utm parameters), participation data (presence, watch time, chat, poll answers, reactions), audio and video of participants published on stage, subtitle transcripts, email delivery events
Special categoriesnone is requested by the platform. The controller must not introduce any without a prior written agreement

04 Processing on documented instructions

We process personal data only on the controller’s documented instructions. Using the platform’s features is such an instruction: publishing a registration page, sending reminders, starting a recording, opening a poll, enabling subtitles.

We do not use attendee data for our own purposes, we do not sell it, and we do not use it to train a model. We tell the controller if an instruction appears to us to breach applicable data protection law.

05 Security measures

The measures below are the ones in force. They may change over time, provided the level of protection is never lowered.

  • All traffic encrypted in transit, with automatic issuance and renewal of certificates for organisation subdomains and custom domains.
  • Passwords hashed with scrypt. Provider credentials held in the platform’s secret store, never in the database in clear text.
  • Tenant isolation: every query is scoped to a single organisation identifier and preceded by a membership check.
  • Signed, time-limited tokens for personal join links, participant video tokens and replay playback.
  • Enforcement at both doors: a banned attendee is refused by the room’s socket and by the video token.
  • Least privilege for platform staff. Support impersonation is read only, and every staff action on an organisation is written to an audit trail.
  • Signature verification on every incoming webhook, and idempotent handling so a replayed event changes nothing.
  • Separation from any other product: dedicated provider accounts, no shared credentials, no shared infrastructure.

06 Confidentiality

Everyone we authorise to access personal data is bound by a confidentiality obligation and is granted only the access their role requires.

07 Subprocessors

The controller gives a general authorisation to engage the subprocessors listed below. Each one is bound by data protection obligations at least as strict as those in this agreement.

SubprocessorRoleLocation
Cloudflare, Inc.hosting, database, object storage, video, live rooms, transcription and translationglobal network, persistent storage in [[REGION DE STOCKAGE]]
Resendsending of transactional emailEuropean Union, United States
Stripepayment for subscriptions and for ticketsEuropean Union, United States
Google LLCauthentication of team members who sign in with Googleglobal

We announce any addition or replacement at least 30 days in advance. The controller may object on reasonable data protection grounds within that period. If we cannot offer an alternative, the controller may terminate the affected part of the service without penalty.

08 International transfers

Transfers outside the European Economic Area are covered by the standard contractual clauses adopted by the European Commission: module two (controller to processor) between the controller and us, and module three (processor to processor) between us and our subprocessors, together with the additional measures each provider documents.

09 Assistance to the controller

  • Data subject requests: the platform gives the controller the tools to read, correct, export and delete a registration and everything attached to it. A request that reaches us directly is forwarded to the controller without undue delay and never answered in its place.
  • Personal data breaches: we notify the controller without undue delay after becoming aware of one, and in any event within 72 hours. The notice describes the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences and the measures taken.
  • We assist the controller, taking the nature of the processing into account, with data protection impact assessments and with any prior consultation of a supervisory authority.

10 Return and deletion

At the end of the contract the controller has 30 days to export its data. After that period, or immediately on written request, we delete it: database rows, stored objects, recorded videos, replay assets and the storage of the rooms concerned.

Deleting a single webinar or a single registration works the same way and is available to the controller at any time from the application.

11 Audits

We make available the information needed to demonstrate compliance with this agreement: this document, the security measures in section 5 and the subprocessor list. Where that is not enough, the controller may carry out an audit once per calendar year, with 30 days’ notice, during working hours, without disrupting the service and under confidentiality. The controller bears the cost, unless the audit reveals a material breach on our side.

12 What the controller undertakes

  • To have a lawful basis for the data it collects through the platform, and to inform its attendees of the processing, including of the recording where a session is recorded.
  • To collect any consent its own law requires, in particular for recording participants and for any email that is not strictly transactional.
  • Not to introduce special categories of personal data, nor data relating to criminal convictions, without a prior written agreement.
  • To keep its team’s access rights current, and to withdraw them when someone leaves.

13 Liability, precedence and signature

The liability terms of the Terms of Service apply to this agreement. In case of conflict, the order of precedence is: the standard contractual clauses, then this agreement, then the Terms of Service. This agreement is governed by [[DROIT APPLICABLE]].

Accepting the Terms of Service accepts this agreement. A countersigned copy can be requested at [[EMAIL VIE PRIVEE]].

Read next

Terms of Service Privacy Policy
Beamstage

Premium webinars: live, on your brand, and simple to run.

Product

FeaturesHow it worksBroadcast modesWhat we measured

Plans

PricingCompare plansStart free

Company

Sign inSecurity
© 2026 Beamstage, Inc. Privacy Terms DPA
ENFR