Parties and purpose
This agreement is concluded between the organisation using Beamstage, the controller, and VOLLAND SARL, 357 avenue de Pessicart, 06100 Nice, France, the processor. It forms part of the Terms of Service and applies as soon as the organisation processes personal data through the platform.
Where it conflicts with the Terms of Service on anything concerning personal data, this agreement prevails.
Definitions
- Personal data, processing, controller, processor, data subject, supervisory authority
- the meanings given to them by Regulation (EU) 2016/679, the General Data Protection Regulation.
- Attendee
- a person who registers for or takes part in a webinar published by the controller.
- Platform
- the Beamstage service: its application, its public registration pages, its live rooms and its replays.
- Subprocessor
- a third party engaged by the processor to carry out part of the processing.
Subject matter, duration and description of the processing
| Item | Content |
|---|---|
| Subject matter | providing the Beamstage platform to the controller |
| Duration | the term of the subscription, plus the deletion period in section 10 |
| Nature and purpose | registration, sending of transactional email, running a live session, recording and replay, attendance and engagement analytics, live subtitles when the option is enabled |
| Categories of data subjects | attendees, invited speakers, and the members of the controller’s own team |
| Categories of personal data | identity (first name, last name, email address), acquisition data (source, utm parameters), participation data (presence, watch time, chat, poll answers, reactions), audio and video of participants published on stage, subtitle transcripts, email delivery events |
| Special categories | none is requested by the platform. The controller must not introduce any without a prior written agreement |
Processing on documented instructions
We process personal data only on the controller’s documented instructions. Using the platform’s features is such an instruction: publishing a registration page, sending reminders, starting a recording, opening a poll, enabling subtitles.
Security measures
The measures below are the ones in force. They may change over time, provided the level of protection is never lowered.
- All traffic encrypted in transit, with automatic issuance and renewal of certificates for organisation subdomains and custom domains.
- Passwords hashed with scrypt. Provider credentials held in the platform’s secret store, never in the database in clear text.
- Tenant isolation: every query is scoped to a single organisation identifier and preceded by a membership check.
- Signed, time-limited tokens for personal join links, participant video tokens and replay playback.
- Enforcement at both doors: a banned attendee is refused by the room’s socket and by the video token.
- Least privilege for platform staff. Support impersonation is read only, and every staff action on an organisation is written to an audit trail.
- Signature verification on every incoming webhook, and idempotent handling so a replayed event changes nothing.
- Separation from any other product: dedicated provider accounts, no shared credentials, no shared infrastructure.
Confidentiality
Everyone we authorise to access personal data is bound by a confidentiality obligation and is granted only the access their role requires.
Subprocessors
The controller gives a general authorisation to engage the subprocessors listed below. Each one is bound by data protection obligations at least as strict as those in this agreement.
| Subprocessor | Role | Location |
|---|---|---|
| Cloudflare, Inc. | hosting, database, object storage, video, live rooms, transcription and translation | global network, persistent storage in [[REGION DE STOCKAGE]] |
| Resend | sending of transactional email | European Union, United States |
| Stripe | payment for subscriptions and for tickets | European Union, United States |
| Google LLC | authentication of team members who sign in with Google | global |
We announce any addition or replacement at least 30 days in advance. The controller may object on reasonable data protection grounds within that period. If we cannot offer an alternative, the controller may terminate the affected part of the service without penalty.
International transfers
Transfers outside the European Economic Area are covered by the standard contractual clauses adopted by the European Commission: module two (controller to processor) between the controller and us, and module three (processor to processor) between us and our subprocessors, together with the additional measures each provider documents.
Assistance to the controller
- Data subject requests: the platform gives the controller the tools to read, correct, export and delete a registration and everything attached to it. A request that reaches us directly is forwarded to the controller without undue delay and never answered in its place.
- Personal data breaches: we notify the controller without undue delay after becoming aware of one, and in any event within 72 hours. The notice describes the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences and the measures taken.
- We assist the controller, taking the nature of the processing into account, with data protection impact assessments and with any prior consultation of a supervisory authority.
Return and deletion
At the end of the contract the controller has 30 days to export its data. After that period, or immediately on written request, we delete it: database rows, stored objects, recorded videos, replay assets and the storage of the rooms concerned.
Deleting a single webinar or a single registration works the same way and is available to the controller at any time from the application.
Audits
We make available the information needed to demonstrate compliance with this agreement: this document, the security measures in section 5 and the subprocessor list. Where that is not enough, the controller may carry out an audit once per calendar year, with 30 days’ notice, during working hours, without disrupting the service and under confidentiality. The controller bears the cost, unless the audit reveals a material breach on our side.
What the controller undertakes
- To have a lawful basis for the data it collects through the platform, and to inform its attendees of the processing, including of the recording where a session is recorded.
- To collect any consent its own law requires, in particular for recording participants and for any email that is not strictly transactional.
- Not to introduce special categories of personal data, nor data relating to criminal convictions, without a prior written agreement.
- To keep its team’s access rights current, and to withdraw them when someone leaves.
Liability, precedence and signature
The liability terms of the Terms of Service apply to this agreement. In case of conflict, the order of precedence is: the standard contractual clauses, then this agreement, then the Terms of Service. This agreement is governed by French law.
Accepting the Terms of Service accepts this agreement. A countersigned copy can be requested at [[EMAIL VIE PRIVEE]].