Beamstage
ProductHow it worksBroadcastPricing
ENFR
Sign in Start free
Legal
TermsPrivacyDPA
Language ENFR

Legal

Privacy Policy

What Beamstage collects, why it collects it, who processes it alongside us, and how long it stays.

Last updated 2 August 2026

Template, not legal advice

This document was drafted from what the product actually does, and it has not been reviewed by a lawyer. Have counsel read and complete it before you publish it or rely on it. Everything highlighted in brackets is a blank the publisher still has to fill in.

On this page

  1. 01 The two hats we wear
  2. 02 Data about account holders
  3. 03 Data about the organisation
  4. 04 Data about the people who attend a webinar
  5. 05 Payments
  6. 06 Technical and security data
  7. 07 Why we process it, and on what basis
  8. 08 Cookies and local storage
  9. 09 Who processes data alongside us
  10. 10 Where the data lives
  11. 11 How long we keep it
  12. 12 Your rights
  13. 13 How we protect it
  14. 14 Children
  15. 15 Changes to this policy
  16. 16 Contact

01 The two hats we wear

Beamstage plays two different roles depending on whose data is at stake, and rights are exercised in a different place accordingly.

  • For people who hold a Beamstage account (owners, admins and members of an organisation) we are the controller. [[RAISON SOCIALE]], [[ADRESSE]], is responsible for that processing.
  • For people who register for a webinar we are the processor. The organisation running the webinar decides what happens to that data.

If you registered for a webinar and want your data corrected or deleted, ask the organisation that invited you. We act on its instructions and we forward to it any request that reaches us directly.

02 Data about account holders

DataWhy we hold it
Name and email addressidentify you, sign you in, contact you about the service
Password, kept only as a scrypt hashsign you in without us ever knowing your password
Google account identifier, if you sign in with Googlesign you in without a password
Sessions, with their creation date and the technical characteristics of the requestkeep you signed in and let you spot a session you do not recognise
Organisation membership and team roledecide what you are allowed to do
Invitations you send or receiverun team invitations, which expire after 48 hours

03 Data about the organisation

  • Name, subdomain slug, default language, reply-to address.
  • Branding: logo, colours, typeface, favicon.
  • Plan, quotas and consumption counters.
  • Stripe customer and subscription identifiers, and for organisations that sell tickets, the identifier of their connected account.
  • Custom domains you connect, with the state of their certificate and of the WebSocket check we run before activation.
  • Single sign-on configuration when you use it: your email domain and the settings of your identity provider.

04 Data about the people who attend a webinar

We process the following on behalf of the organisation running the webinar, and only to run it.

CategoryWhat exactlyWhere it is stored
Registrationfirst name, last name, email address, acquisition source and any utm parameters on the link, status (registered, attended, no show), unsubscribe flag, ban flagplatform database (Cloudflare D1)
Presencejoin and leave events, watch time, peak concurrency, session durationaggregated inside the live room, then written to the database per webinar
Interactionchat messages with their author and timestamp, poll answers tied to the registration, emoji reactions, raise handthe room’s own storage (a Durable Object), plus aggregate counts in the database
Mediathe audio and video published on stage, the recording of the session, the replayCloudflare Stream and Cloudflare R2
Subtitlesshort audio excerpts sent for transcription, the resulting text and its translationsCloudflare Workers AI, transcripts kept in R2
Emailrecipient address, kind of email, provider message identifier, delivery status, bounce and complaint eventsplatform database, plus Resend for 30 days

A personal join link is a signed token that stands for one registration. Anyone holding the link can join as that person, which is why our emails ask attendees not to forward it.

05 Payments

Card data never reaches Beamstage. Stripe collects and processes it on its own systems. We keep the identifiers Stripe returns, the amounts, the currency, the status of a payment or a subscription, and the events Stripe sends us. For organisations that sell tickets we also keep the identifier of their connected account and the service fee taken on each ticket.

06 Technical and security data

  • Request and error logs produced by the infrastructure, kept for diagnosis.
  • Webhook events received from Cloudflare, Stripe and Resend, stored so that a retried event is never processed twice.
  • Platform staff actions on an organisation: quota adjustment, suspension, read-only impersonation for support. Each one is written to an audit trail with the operator’s identity.

07 Why we process it, and on what basis

PurposeLegal basis
Running the service you asked forperformance of the contract
Billing and accountinglegal obligation, performance of the contract
Keeping the platform safe: abuse detection, quota enforcement, bounce and complaint monitoringlegitimate interest
Improving the product from aggregated usagelegitimate interest
Product and marketing email to account holdersconsent, which you can withdraw at any time
Confirmation, reminder and replay email to registrantsperformance of the contract, on the organiser’s instruction

08 Cookies and local storage

Beamstage sets no advertising cookie, embeds no third-party analytics and performs no cross-site tracking. What your browser stores is limited to this:

NamePurposeLife
session cookiekeeps you signed inuntil you sign out or the session expires
langremembers the language you pickeduntil you change it
bs-theme, in local storageremembers the light or dark themeuntil you clear it

All of these are either strictly necessary or record a preference you set yourself, which is why no consent banner stands between you and the site. If we ever add a measurement or advertising tool, we will ask first.

09 Who processes data alongside us

ProviderWhat it doesWhat it seesWhere
Cloudflare, Inc.hosting, database, object storage, video, live rooms, AI transcription and translationeverything the service stores and transportsglobal network, persistent storage in [[REGION DE STOCKAGE]]
Resenddelivery of transactional emailrecipient name and address, email content, delivery eventsEuropean Union, United States
Stripesubscription payments and ticket paymentspayer identity, card data collected directly by Stripe, amountsEuropean Union, United States
Google, only if you sign in with Googleauthentication of account holdersyour Google account identifier and email addressglobal

The list kept up to date, together with the right for a customer organisation to object to a new subprocessor, is in the Data Processing Agreement.

10 Where the data lives

Beamstage runs on Cloudflare’s global network, so a request is served from the location closest to the visitor. Persistent storage (database, objects, video) is anchored in [[REGION DE STOCKAGE]]. Transfers outside the European Economic Area rest on the standard contractual clauses adopted by the European Commission, backed by the data protection agreement of each provider listed above.

11 How long we keep it

DataRetention
Account and organisationfor as long as the account exists, then 30 days to allow reversal, then deletion
Registrations and attendanceuntil the organisation deletes the webinar or closes its account
Chat messages and poll answerswith the room, until the webinar is deleted
Recordings and replaysthe retention window of the organisation’s plan, then deletion from Stream and R2
Live subtitle transcriptscopied to our storage within seven days, because the media provider expires them at that point, then kept with the webinar
Email send log24 months. The provider itself keeps delivery events for 30 days only
Invoices and accounting recordsthe period required by [[DROIT APPLICABLE]]
Staff action audit trail24 months
Technical logs30 days

Deleting an organisation triggers a purge: database rows, stored objects, recorded videos and the storage of the rooms concerned. Backups expire on their own cycle, which can leave a copy for a few more days.

12 Your rights

Where [[DROIT APPLICABLE]] grants them, you may request access to your data, its correction, its deletion, a restriction on its use and its portability, and you may object to processing based on our legitimate interest. Where processing rests on consent, you may withdraw it at any time, without affecting what was done before.

  • If you hold a Beamstage account, write to [[EMAIL VIE PRIVEE]]. We answer within one month.
  • If you registered for a webinar, ask the organisation that ran it. We assist that organisation in answering you.
  • You may also lodge a complaint with [[AUTORITE DE CONTROLE]].

13 How we protect it

  • Traffic is encrypted in transit. Certificates for organisation subdomains and custom domains are issued and renewed automatically.
  • Passwords are hashed with scrypt. We never hold them in a readable form.
  • Every database query is scoped to a single organisation and preceded by a membership check.
  • Join links, participant video tokens and replay playback URLs are signed and time limited. A banned attendee is stopped at both doors: the room’s socket and the video token.
  • Platform staff access is limited to the people who need it, support impersonation is read only, and every staff action on an organisation is logged.
  • Incoming webhooks are verified by signature before anything is written, and handled idempotently.

14 Children

Beamstage is a professional tool and is not aimed at children. We do not knowingly collect data from a child under 16. An organisation running a webinar for minors is responsible for the notices and consents its own law requires.

15 Changes to this policy

The version in force is always the one on this page, with the date shown at the top. A change that affects your rights is announced by email or inside the application before it applies.

16 Contact

Write to [[EMAIL VIE PRIVEE]] for anything about personal data, and to [[EMAIL DE CONTACT]] for anything else. Postal address: [[RAISON SOCIALE]], [[ADRESSE]].

Read next

Terms of Service Data Processing Agreement
Beamstage

Premium webinars: live, on your brand, and simple to run.

Product

FeaturesHow it worksBroadcast modesWhat we measured

Plans

PricingCompare plansStart free

Company

Sign inSecurity
© 2026 Beamstage, Inc. Privacy Terms DPA
ENFR