The two hats we wear
Beamstage plays two different roles depending on whose data is at stake, and rights are exercised in a different place accordingly.
- For people who hold a Beamstage account (owners, admins and members of an organisation) we are the controller. VOLLAND SARL, 357 avenue de Pessicart, 06100 Nice, France, is responsible for that processing.
- For people who register for a webinar we are the processor. The organisation running the webinar decides what happens to that data.
Data about account holders
| Data | Why we hold it |
|---|---|
| Name and email address | identify you, sign you in, contact you about the service |
| Password, kept only as a scrypt hash | sign you in without us ever knowing your password |
| Google account identifier, if you sign in with Google | sign you in without a password |
| Sessions, with their creation date and the technical characteristics of the request | keep you signed in and let you spot a session you do not recognise |
| Organisation membership and team role | decide what you are allowed to do |
| Invitations you send or receive | run team invitations, which expire after 48 hours |
Data about the organisation
- Name, subdomain slug, default language, reply-to address.
- Branding: logo, colours, typeface, favicon.
- Plan, quotas and consumption counters.
- Stripe customer and subscription identifiers, and for organisations that sell tickets, the identifier of their connected account.
- Custom domains you connect, with the state of their certificate and of the WebSocket check we run before activation.
- Single sign-on configuration when you use it: your email domain and the settings of your identity provider.
Data about the people who attend a webinar
We process the following on behalf of the organisation running the webinar, and only to run it.
| Category | What exactly | Where it is stored |
|---|---|---|
| Registration | first name, last name, email address, acquisition source and any utm parameters on the link, status (registered, attended, no show), unsubscribe flag, ban flag. If the organiser offers text messages and you ticked the box: your mobile number, the date you agreed, and whether you have since replied STOP. Without that tick the number is not stored at all | platform database (Cloudflare D1) |
| Presence | join and leave events, watch time, peak concurrency, session duration | aggregated inside the live room, then written to the database per webinar |
| Interaction | chat messages with their author and timestamp, poll answers tied to the registration, emoji reactions, raise hand | the room’s own storage (a Durable Object), plus aggregate counts in the database |
| Media | the audio and video published on stage, the recording of the session, the replay | Cloudflare Stream |
| Post-session transcript | the recorded speech processed after the session ends, with speaker passages and downloadable JSON, VTT and SRT archives. Nothing is transcribed or displayed while the room is live. Beamstage copies the private archives into its object storage before the provider download URLs expire | Cloudflare RealtimeKit, private archives kept in Cloudflare R2 |
| Session summaries | the post-session transcript, read by a language model when a member of the organisation asks for a summary, and the summary it writes. Never automatic: nothing is sent to the model unless somebody presses the button | Cloudflare Workers AI, summary kept in the platform database |
| recipient address, kind of email, provider message identifier, delivery status, bounce and complaint events | platform database, plus Resend for 30 days |
Payments
Card data never reaches Beamstage. Stripe collects and processes it on its own systems. We keep the identifiers Stripe returns, the amounts, the currency, the status of a payment or a subscription, and the events Stripe sends us. For organisations that sell tickets we also keep the identifier of their connected account and the service fee taken on each ticket.
Technical and security data
- Request and error logs produced by the infrastructure, kept for diagnosis.
- Webhook events received from Cloudflare, Stripe and Resend, stored so that a retried event is never processed twice.
- Platform staff actions on an organisation: quota adjustment, suspension, and support impersonation. Impersonation opens a session with the same rights as the user it borrows, including the right to write, so anything done during it is recorded as that user’s own action. Its start is written to an audit trail with the operator’s identity, and so is its end when the operator ends it; a session left open expires on its own within one hour, which is the longest such an access can last.
Why we process it, and on what basis
| Purpose | Legal basis |
|---|---|
| Running the service you asked for | performance of the contract |
| Billing and accounting | legal obligation, performance of the contract |
| Keeping the platform safe: abuse detection, quota enforcement, bounce and complaint monitoring | legitimate interest |
| Improving the product from aggregated usage | legitimate interest |
| Product and marketing email to account holders | consent, which you can withdraw at any time |
| Confirmation, reminder and replay email to registrants | performance of the contract, on the organiser’s instruction |
Cookies and local storage
Beamstage sets no advertising cookie, embeds no third-party analytics and performs no cross-site tracking. Here is everything your browser stores, including the ones only a live room or a meeting sets:
| Name | Purpose | Life |
|---|---|---|
| session cookie | keeps you signed in | until you sign out or the session expires |
| lang | remembers the language you picked | one year, renewed when you change it |
| bs_room_pass | holds the pass that lets you back into a live room you were already admitted to. Sent only to that one room’s address | as long as the join link it came from, which is up to 60 days |
| bs_meet_guest | remembers that you were admitted to a meeting as a guest, so a reload does not send you back to the code. Sent only to that meeting’s address | 12 hours |
| bs_open_join_guest | strictly necessary to remember that you entered a webinar through its open link, so a reload keeps the same guest identity. Sent only to that webinar’s public page | 12 hours |
| bs_join_retry | set only when a room turned you away because it was full, so the page can offer to try again. Sent only to that retry page | 1 hour |
| bs-theme, in local storage | remembers the light or dark theme | until you clear it |
| bs.device.mic, bs.device.cam, bs.device.speaker, in local storage | remember which microphone, camera and speaker you chose, so a meeting does not ask again | until you clear them |
All of these are either strictly necessary or record a preference you set yourself, which is why no consent banner stands between you and the site. If we ever add a measurement or advertising tool, we will ask first.
Who processes data alongside us
| Provider | What it does | What it sees | Where |
|---|---|---|---|
| Cloudflare, Inc. | hosting, database, object storage, video, live rooms, post-session transcription and session summaries | everything the service stores and transports | global network; database and stored files in Western Europe; video and live rooms not tied to a region |
| Resend | delivery of transactional email | recipient name and address, email content, delivery events | European Union, United States |
| Stripe | subscription payments and ticket payments | payer identity, card data collected directly by Stripe, amounts | European Union, United States |
| Google, only if you sign in with Google | authentication of account holders | your Google account identifier and email address | global |
The list kept up to date, together with the right for a customer organisation to object to a new subprocessor, is in the Data Processing Agreement.
Where the data lives
Beamstage runs on Cloudflare’s global network, so a request is served from the location closest to the visitor. Where the data then comes to rest depends on which store holds it, and the stores do not all behave the same way.
- The database holds accounts, organisations, webinars, registrations, attendance, transcripts and session summaries. It runs in Western Europe.
- The object storage holds calendar files, private audio recordings and transcript archives. It runs in Western Europe.
- Video, meaning the live broadcast and the replay recorded from it, goes to Cloudflare Stream, which offers no region control. We cannot confine it to Europe and we do not claim to.
- A live room, meaning the chat and the poll answers it holds, is placed close to whoever connects to it first. Its location follows the audience rather than a region we choose.
No jurisdiction restriction is set on the database or on the object storage, so Western Europe is where they run today rather than a residency guarantee we owe you. Transfers outside the European Economic Area rest on the standard contractual clauses adopted by the European Commission, backed by the data protection agreement of each provider listed above.
How long we keep it
| Data | Retention |
|---|---|
| Account and organisation | for as long as the account exists, then 30 days to allow reversal, then deletion |
| Registrations and attendance | until the organisation deletes the webinar or closes its account |
| Chat messages and poll answers | with the room, until the webinar is deleted |
| Recordings and replays | the retention window of the organisation’s plan, then deletion from Cloudflare Stream |
| Post-session transcripts | the retention window of the organisation’s plan, counted from the end of the session. Expiry or explicit session deletion removes every private archive |
| Session summaries | the same window, counted from the moment the summary was written, AND never longer than the transcript it was made from: a summary whose transcript has been deleted is deleted on the next daily pass |
| Email send log | 24 months. The provider itself keeps delivery events for 30 days only |
| Invoices and accounting records | the period required by French law |
| Staff action audit trail | 24 months |
| Technical logs | 30 days |
Deleting an organisation triggers a purge: database rows, stored objects, recorded videos and the storage of the rooms concerned. Backups expire on their own cycle, which can leave a copy for a few more days.
Your rights
Where French law grants them, you may request access to your data, its correction, its deletion, a restriction on its use and its portability, and you may object to processing based on our legitimate interest. Where processing rests on consent, you may withdraw it at any time, without affecting what was done before.
- If you hold a Beamstage account, write to privacy@beamstage.app. We answer within one month.
- If you registered for a webinar, ask the organisation that ran it. We assist that organisation in answering you.
- You may also lodge a complaint with the CNIL, the French supervisory authority (Commission nationale de l’informatique et des libertés, 3 place de Fontenoy, 75007 Paris, France, cnil.fr).
How we protect it
- Traffic is encrypted in transit. Certificates for organisation subdomains and custom domains are issued and renewed automatically.
- Passwords are hashed with scrypt. We never hold them in a readable form.
- Every database query is scoped to a single organisation and preceded by a membership check.
- Join links, participant video tokens and replay playback URLs are signed and time limited. A banned attendee is stopped at both doors: the room’s socket and the video token.
- Platform staff access is limited to the people who need it. When support impersonates a user, the session it opens carries that user’s own rights and can write as they can; the start of every impersonation is logged with the operator’s identity, as is its end when the operator ends it, and a session left open expires within one hour. Every other staff action on an organisation is logged too.
- Incoming webhooks are verified by signature before anything is written, and handled idempotently.
Children
Beamstage is a professional tool and is not aimed at children. We do not knowingly collect data from a child under 16. An organisation running a webinar for minors is responsible for the notices and consents its own law requires.
Changes to this policy
The version in force is always the one on this page, with the date shown at the top. A change that affects your rights is announced by email or inside the application before it applies.
Contact
Write to privacy@beamstage.app for anything about personal data, and to contact@beamstage.app for anything else. Postal address: VOLLAND SARL, 357 avenue de Pessicart, 06100 Nice, France.