Beamstage
ProductHow it worksBroadcastPricingMarket
ENFR
Sign in Start free
Legal
TermsPrivacyDPA
Language ENFR

Legal

Data Processing Agreement

The processing terms between an organisation using Beamstage, as controller, and VOLLAND SARL, as processor.

Last updated 4 August 2026

On this page

  1. 01 Parties and purpose
  2. 02 Definitions
  3. 03 Subject matter, duration and description of the processing
  4. 04 Processing on documented instructions
  5. 05 Security measures
  6. 06 Confidentiality
  7. 07 Subprocessors
  8. 08 International transfers
  9. 09 Assistance to the controller
  10. 10 Return and deletion
  11. 11 Audits
  12. 12 What the controller undertakes
  13. 13 Liability, precedence and signature

01 Parties and purpose

This agreement is concluded between the organisation using Beamstage, the controller, and VOLLAND SARL, 357 avenue de Pessicart, 06100 Nice, France, the processor. It forms part of the Terms of Service and applies as soon as the organisation processes personal data through the platform.

Where it conflicts with the Terms of Service on anything concerning personal data, this agreement prevails.

02 Definitions

Personal data, processing, controller, processor, data subject, supervisory authority
the meanings given to them by Regulation (EU) 2016/679, the General Data Protection Regulation.
Attendee
a person who registers for or takes part in a webinar published by the controller.
Platform
the Beamstage service: its application, its public registration pages, its live rooms and its replays.
Subprocessor
a third party engaged by the processor to carry out part of the processing.

03 Subject matter, duration and description of the processing

ItemContent
Subject matterproviding the Beamstage platform to the controller
Durationthe term of the subscription, plus the deletion period in section 10
Nature and purposeregistration, sending of transactional email, running a live session, recording and replay, attendance and engagement analytics, creating a transcript after the session, and writing a session summary when a member of the controller asks for one
Categories of data subjectsattendees, invited speakers, and the members of the controller’s own team
Categories of personal dataidentity (first name, last name, email address), acquisition data (source, utm parameters), participation data (presence, watch time, chat, poll answers, reactions), audio and video of participants published on stage, post-session transcripts and the session summaries written from them, email delivery events
Special categoriesnone is requested by the platform. The controller must not introduce any without a prior written agreement

04 Processing on documented instructions

We process personal data only on the controller’s documented instructions. Using the platform’s features is such an instruction: publishing a registration page, sending reminders, starting a recorded session with post-session transcription, opening a poll, asking for a summary.

We do not use attendee data for our own purposes, we do not sell it, and we do not use it to train a model. We tell the controller if an instruction appears to us to breach applicable data protection law.

05 Security measures

The measures below are the ones in force. They may change over time, provided the level of protection is never lowered.

  • All traffic encrypted in transit, with automatic issuance and renewal of certificates for organisation subdomains and custom domains.
  • Passwords hashed with scrypt. Provider credentials held in the platform’s secret store, never in the database in clear text.
  • Tenant isolation: every query is scoped to a single organisation identifier and preceded by a membership check.
  • Signed, time-limited tokens for personal join links, participant video tokens and replay playback.
  • Enforcement at both doors: a banned attendee is refused by the room’s socket and by the video token.
  • Least privilege for platform staff. Support impersonation opens a session with the same rights as the user it borrows, writing included, so what is done during it is attributed to that user rather than to the operator. Its start is written to an audit trail, as is its end when the operator ends it; a session left open expires within one hour, which bounds the duration of any such access. Every other staff action on an organisation is written to the same trail.
  • Signature verification on every incoming webhook, and idempotent handling so a replayed event changes nothing.
  • Separation from any other product: dedicated provider accounts, no shared credentials, no shared infrastructure.

06 Confidentiality

Everyone we authorise to access personal data is bound by a confidentiality obligation and is granted only the access their role requires.

07 Subprocessors

The controller gives a general authorisation to engage the subprocessors listed below. Each one is bound by data protection obligations at least as strict as those in this agreement.

SubprocessorRoleLocation
Cloudflare, Inc.hosting, database, object storage, video, live rooms, post-session transcription and session summariesglobal network; database and stored files in Western Europe; video and live rooms not tied to a region
Resendsending of transactional emailEuropean Union, United States
Stripepayment for subscriptions and for ticketsEuropean Union, United States
Google LLCauthentication of team members who sign in with Googleglobal

We announce any addition or replacement at least 30 days in advance. The controller may object on reasonable data protection grounds within that period. If we cannot offer an alternative, the controller may terminate the affected part of the service without penalty.

08 International transfers

Transfers outside the European Economic Area are covered by the standard contractual clauses adopted by the European Commission: module two (controller to processor) between the controller and us, and module three (processor to processor) between us and our subprocessors, together with the additional measures each provider documents.

09 Assistance to the controller

  • Data subject requests: the platform gives the controller the tools to read, correct, export and delete a registration and everything attached to it. A request that reaches us directly is forwarded to the controller without undue delay and never answered in its place.
  • Personal data breaches: we notify the controller without undue delay after becoming aware of one, and in any event within 72 hours. The notice describes the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences and the measures taken.
  • We assist the controller, taking the nature of the processing into account, with data protection impact assessments and with any prior consultation of a supervisory authority.

10 Return and deletion

At the end of the contract the controller has 30 days to export its data. After that period, or immediately on written request, we delete it: database rows, stored objects, recorded videos, replay assets and the storage of the rooms concerned.

Deleting a single webinar or a single registration works the same way and is available to the controller at any time from the application.

11 Audits

We make available the information needed to demonstrate compliance with this agreement: this document, the security measures in section 5 and the subprocessor list. Where that is not enough, the controller may carry out an audit once per calendar year, with 30 days’ notice, during working hours, without disrupting the service and under confidentiality. The controller bears the cost, unless the audit reveals a material breach on our side.

12 What the controller undertakes

  • To have a lawful basis for the data it collects through the platform, and to inform its attendees of the processing, including of the recording where a session is recorded.
  • To collect any consent its own law requires, in particular for recording participants and for any email that is not strictly transactional.
  • Not to introduce special categories of personal data, nor data relating to criminal convictions, without a prior written agreement.
  • To keep its team’s access rights current, and to withdraw them when someone leaves.

13 Liability, precedence and signature

The liability terms of the Terms of Service apply to this agreement. In case of conflict, the order of precedence is: the standard contractual clauses, then this agreement, then the Terms of Service. This agreement is governed by French law.

Accepting the Terms of Service accepts this agreement. A countersigned copy can be requested at privacy@beamstage.app.

Read next

Terms of Service Privacy Policy
Beamstage

Premium webinars: live, on your brand, and simple to run.

Product

FeaturesHow it worksBroadcast modesWhat we measured

Plans

PricingCompare plansBeamstage vs the marketStart free

Company

Sign inContact usSecurity
© 2026 VOLLAND SARL Privacy Terms DPA
ENFR