Beeto.biz

Legal

Data Processing Agreement

Last updated: July 28, 2026

This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between the Customer ("Controller") and Edge Shore Technology LLC ("Processor") for the Beeto.biz service. It reflects the requirements of Article 28 GDPR and equivalent laws.

1. Subject matter & duration

Processor processes personal data on Controller's behalf for the purpose of providing the Beeto.biz platform, for the duration of the subscription plus any statutory retention period.

2. Nature & purpose of processing

Hosting, storing, organizing, enriching (including AI summarization and scoring), transmitting, and deleting personal data submitted by Controller and/or collected from public sources on Controller's instructions.

3. Categories of data subjects and personal data

  • Data subjects: Controller's authorized users; Controller's business contacts (prospects, customers, partners); publicly identifiable representatives of monitored companies.
  • Personal data: name, business email, business phone, job title, employer, professional biography, publicly available news and filings referencing the individual, activity metadata created by users of the platform.

The Service is not intended for processing special categories of data (Article 9 GDPR). Do not upload such data.

4. Controller obligations

  • Ensure a valid legal basis exists for the personal data provided to the Service.
  • Provide required notices to data subjects.
  • Respond to data-subject requests as controller of the data.

5. Processor obligations

  • Process personal data only on documented instructions of the Controller (including these Terms and in-product configuration).
  • Ensure personnel authorized to process personal data are under confidentiality obligations.
  • Implement the technical and organizational measures described in Section 8.
  • Assist Controller in responding to data-subject requests and in Article 32–36 obligations to the extent required by law.
  • Notify Controller without undue delay (and in any case within 72 hours of confirmation) of a personal data breach affecting Controller data.
  • At Controller's choice, delete or return personal data at the end of the Service, subject to legal retention obligations.
  • Make available information reasonably necessary to demonstrate compliance and allow for audits under Section 9.

6. Sub-processors

Controller provides general authorization for Processor to engage the following sub-processors:

Sub-processorPurposeLocation
Cloudflare, Inc.Edge hosting, CDN, DDoS protectionGlobal
Supabase, Inc.Managed Postgres, authentication, storageUS / EU
Google (Gemini API)AI inference for summaries, scoring, reportsUS / EU
FirecrawlPublic web content retrieval for signal discoveryUS
Resend, Inc.Transactional email deliveryUS

Processor will notify Controller of any intended addition or replacement of a sub-processor with at least 30 days' notice, during which Controller may object on reasonable grounds.

7. International transfers

Where personal data is transferred outside the EEA/UK, Processor relies on the EU Standard Contractual Clauses (2021/914) with the UK International Data Transfer Addendum where applicable, together with supplementary technical measures such as encryption and access controls.

8. Technical & organizational measures

Aligned with SOC 2 and ISO/IEC 27001 control objectives:

  • TLS 1.2+ in transit; AES-256 at rest for databases and backups.
  • Multi-tenant isolation enforced via Postgres row-level security.
  • Role-based access control (Admin / Member / Viewer); principle of least privilege for internal access; MFA required for administrative accounts.
  • Centralized secret management; keys rotated on personnel change.
  • Audit logs of authentication and administrative actions retained up to 12 months.
  • Automated dependency and vulnerability scanning; timely patching.
  • Documented incident-response, change-management, and business-continuity procedures.
  • Vendor security reviews before onboarding sub-processors.

The current status of independent audits (SOC 2, ISO/IEC 27001) is available on request from security@beeto.biz.

9. Audits

Processor will make available to Controller, on reasonable request and subject to confidentiality, summary reports of independent audits and responses to a reasonable security questionnaire, no more than once per year except where required by a supervisory authority or following a confirmed incident.

10. Liability & term

Liability under this DPA is subject to the limitations of liability in the Terms & Conditions. This DPA terminates automatically upon termination of the Terms.

11. Acceptance

By using the Service, Controller accepts this DPA. A countersigned copy is available on request at privacy@beeto.biz.

Operating company

Edge Shore Technologies LLC · 1521 Concord Pike, Ste 301 #212, Wilmington, DE 19803, USA

Contact: privacy@beeto.biz · security@beeto.biz