Data Processing Addendum
Last updated:
This Data Processing Addendum ('DPA') forms part of the agreement between you ('Customer') and Beanoc when Customer's use of the service involves Beanoc processing personal data on Customer's behalf.
Roles of the parties
For personal data that Customer submits into Beanoc (e.g. within briefs, brand-voice profiles or team member details), Customer is the controller and Beanoc is the processor, acting only on Customer's documented instructions as set out in the Terms of Service and this DPA.
Processor obligations (Art. 28)
- Process personal data only on Customer's documented instructions, including as regards international transfers;
- Ensure persons authorised to process personal data are bound by confidentiality;
- Implement the technical and organisational measures described in Annex II;
- Engage subprocessors only as permitted under "Sub-processing" below;
- Assist Customer in responding to data subject requests and in meeting its GDPR obligations, taking into account the nature of processing;
- Notify Customer without undue delay after becoming aware of a personal data breach affecting Customer's data;
- Delete or return personal data at the end of the provision of services, as described below;
- Make available information necessary to demonstrate compliance and allow for audits as described below.
Sub-processing
Customer provides general authorisation for Beanoc to engage the subprocessors listed in Annex III. Beanoc will impose data protection terms on subprocessors that are no less protective than this DPA, and remains liable for their performance. Beanoc will notify Customer of any intended addition or replacement of a subprocessor by updating Annex III and, where the change is material, notifying Customer by email in advance.
Assistance with data subject rights
Taking into account the nature of the processing, Beanoc will assist Customer, insofar as reasonably possible, in responding to requests from data subjects exercising their rights, and in Customer's obligations relating to data protection impact assessments and prior consultation with supervisory authorities, where applicable.
Audit rights
Beanoc will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for, and contribute to, audits and inspections conducted by Customer or an auditor mandated by Customer, subject to reasonable notice, confidentiality, and no more than once per year unless required by a supervisory authority.
Deletion or return on termination
On termination of the services, Beanoc will, at Customer's choice, delete or make available for export all personal data processed on Customer's behalf, and delete existing copies within a reasonable period, unless applicable law requires continued storage (e.g. billing records).
International transfers
Where personal data is transferred outside the EEA, UK or Switzerland to a subprocessor listed in Annex III, the transfer is made under the EU Standard Contractual Clauses (Module 2: Controller to Processor) or an equivalent transfer mechanism offered by that subprocessor, incorporated by reference into this DPA.
Annex I — Parties and processing description
Data exporter: Customer, as identified in its Beanoc account.
Data importer: Beanoc — [Legal entity name — placeholder], [registered address — placeholder].
Subject matter and duration: Provision of the Beanoc AI marketing workspace for the duration of Customer's subscription.
Nature and purpose: Storage and processing of account, brand-voice, brief and output data to provide the service, including server-side calls to OpenAI to generate content.
Categories of data subjects: Customer's authorised users (e.g. employees, contractors) and, where included in briefs, individuals referenced in Customer's marketing content (e.g. named customers or personas Customer chooses to describe).
Categories of personal data: Name, email address, authentication data, brand-voice text, brief content, and any personal data Customer chooses to include within brief text.
Special category data: Beanoc does not request special category data and Customer should not submit it via briefs.
Annex II — Technical and organisational measures
- Row-level security (RLS) policies enforced on every database table, isolating each account's data;
- Server-side plan and quota checks on every AI generation request;
- Provider API keys (OpenAI, Stripe, Resend, Supabase) held server-side only and never exposed to the browser;
- Encryption in transit via TLS, and encryption at rest provided by our infrastructure providers (Supabase/Lovable Cloud);
- Authentication via hashed credentials and session tokens managed by Supabase Auth;
- Customer content is not used to train AI models and is not sold.
Annex III — Subprocessors
| Subprocessor | Purpose |
|---|---|
| Supabase (via Lovable Cloud) | Authentication, database, storage |
| Stripe | Payment processing and billing |
| Resend | Transactional email delivery |
| OpenAI | AI text generation |
| Lovable / Cloudflare | Application hosting and CDN |
Effective date and execution
This DPA takes effect when Customer accepts Beanoc's Terms of Service and continues to apply for as long as Beanoc processes personal data on Customer's behalf. For a signed, countersigned copy of this DPA (for example, for your own vendor-management records), contact privacy@beanoc.com.