Data Processing Agreement
When Beacon processes personal data contained in the systems you connect, it does so on your behalf — you decide the purposes, Beacon carries out the processing. This agreement sets the terms for that relationship, including the safeguards, subprocessors and transfer mechanisms that apply.
1 · Parties & scope
This Data Processing Agreement ("DPA") supplements the Terms of Service between the customer ("Controller") and Startup Academy LLC, trading as Beacon Revenue® ("Processor", "Beacon"). It applies where Beacon processes personal data on the Controller's behalf in providing the service. Where the customer is itself a processor for its own customers, Beacon acts as a subprocessor and these terms apply accordingly.
2 · Roles
The Controller determines the purposes and means of processing the personal data it connects to Beacon. Beacon is the Processor and processes that data only to provide the service and only on the Controller's documented instructions — these include the Terms, this DPA, and the configuration choices the Controller makes in the product. Beacon informs the Controller if, in its opinion, an instruction infringes applicable data-protection law.
3 · Details of the processing
The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex I. Processing continues for the duration of the Terms and as needed to provide the service.
4 · Beacon's obligations
- Instructions. Process personal data only on the Controller's documented instructions, including for international transfers, unless required by law (in which case Beacon notifies the Controller, where lawful).
- Confidentiality. Ensure personnel authorised to process personal data are bound by confidentiality.
- Security. Implement appropriate technical and organisational measures, described in Annex II and in Beacon's Security statement.
- Data-subject requests. Assist the Controller, by appropriate measures, to respond to requests from data subjects exercising their rights.
- Assistance. Assist the Controller with security, breach notification, data-protection impact assessments and prior consultation, taking into account the nature of processing and the information available to Beacon.
- Breach notification. Notify the Controller without undue delay after becoming aware of a personal-data breach, with the information the Controller needs to meet its own obligations.
- Deletion or return. At the end of the service, delete or return personal data at the Controller's choice, and delete existing copies unless retention is required by law. Where personal data sits within a sealed, reproducible financial record, Beacon removes the personal details and retains only a de-identified aggregate, so the record still reconciles without identifying any individual.
5 · Subprocessors
The Controller gives Beacon general authorisation to engage the subprocessors listed in Annex III to provide the service. Beacon imposes data-protection obligations on each subprocessor no less protective than those in this DPA, and remains responsible for their performance. Beacon will give the Controller advance notice of any intended change (addition or replacement) of a subprocessor, and the Controller may object on reasonable data-protection grounds.For counselSet the notice period (commonly 30 days), the objection/resolution mechanics, and how the current subprocessor list is published and versioned.
6 · International transfers
By default, Beacon hosts Controller data in the United States; EU data residency (Frankfurt, with backups in Dublin) is available on the appropriate plan. Where personal data is transferred out of the EEA, UK or Switzerland to a country without an adequacy decision, the transfer is governed by the Standard Contractual Clauses, which are incorporated into this DPA by reference and completed by its Annexes.For counselConfirm the correct SCC module (Module Two: controller-to-processor; Module Three where Beacon is a subprocessor), the UK Addendum and the Swiss amendments, and attach the completed clauses. Confirm each subprocessor's transfer safeguards.
7 · Audits
Beacon makes available the information necessary to demonstrate compliance with this DPA, and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates — subject to reasonable notice, confidentiality, and frequency, and satisfied where possible through Beacon's documentation and third-party reports.For counselAlign audit scope/frequency with the certification approach (e.g. providing a SOC 2 report in lieu of on-site audits once available).
8 · Liability & precedence
The liability provisions of the Terms of Service apply to this DPA. In the event of a conflict between this DPA and the Terms on the processing of personal data, this DPA prevails; in the event of a conflict between this DPA and the Standard Contractual Clauses, the Clauses prevail.
Annex I · Details of the processing
| Element | Detail |
|---|---|
| Subject matter | Provision of Beacon's revenue-intelligence service to the Controller. |
| Duration | The term of the Terms of Service, plus any legally required retention. |
| Nature & purpose | Reading from the Controller's connected systems; computing revenue metrics; storing derived data; presenting it to authorised users and readers; generating alerts and reasoning outputs. |
| Types of personal data | Business-contact and account identifiers within connected records — e.g. names, work emails, and roles of the Controller's customers and staff. Beacon does not require special-category data. |
| Categories of data subjects | The Controller's customers, prospects, and personnel whose details appear in the connected systems; the Controller's own users of Beacon. |
| Frequency | Continuous / on a synchronisation schedule while systems are connected. |
Annex II · Technical & organisational measures
Beacon's security measures are described in full in the Security statement. In summary: credentials are never held by Beacon (each source is authorised in its own system and revocable there); raw records remain at source while Beacon holds derived data; access is scoped by role with restricted data as a separate grant; write-back is suggestion-only with human approval and never touches the Controller's books; every figure is produced deterministically and sealed with its inputs; and an append-only record captures seals, approvals and access changes.
Verify before publishAdd the concrete measures counsel and security expect in an Annex II: encryption in transit and at rest, access-control and authentication specifics, logging and monitoring, backup and resilience, personnel vetting and training, and incident response. These are the CTO-brief "verified facts" block — populate before offering the DPA.Annex III · Subprocessors
| Subprocessor | Purpose | Region |
|---|---|---|
| Airtable | Data layer (derived data store) | US default; EU (Frankfurt) on Enterprise |
| Notion | Workspace / data layer | US default; EU (Frankfurt) on Enterprise |
| Anthropic (Claude) | AI reasoning & drafting | [verify] |
| Clerk | Authentication | [verify] |
| Stripe | Payment processing | [verify] |
| Vercel | Frontend hosting | [verify] |
| Railway | Backend hosting | [verify] |
| Resend | Transactional email | [verify] |
| Sentry | Error monitoring | [verify] |
| HubSpot | Customer & marketing communications | [verify] |