Legal

Data processing addendum

Last updated June 2026

This addendum forms part of the agreement between your organization (the controller) and Beam (the processor) and sets out how customer personal data is processed under GDPR.

Roles and scope

Your organization is the data controller and determines the purposes of processing. Beam acts as a processor, processing personal data only on your documented instructions.

Sub-processors

Beam engages the following sub-processors: Vercel (web hosting), Render (API, database, and queue hosting), Clerk (authentication), Cloudflare (object storage), the model providers the customer enables (for example Anthropic, OpenAI, Google, Mistral), Pipedream and Composio (managed integration connectors, when used), Stripe (billing), and Resend (transactional email).

This list is updated here with notice of material changes.

Security measures

Beam applies encryption in transit, encryption at rest through its hosting providers, application-level encryption of stored integration credentials, role-based access control, per-workspace data isolation, and an audit log of administrative actions.

International transfers and deletion

The managed service is hosted in the United States (Vercel and Render). Model requests go to the providers the customer enables, under those providers' terms. Self-hosted deployments keep data on the customer's own infrastructure.

On termination, customer personal data is deleted or returned per documented procedures.

Questions about this document? Reach our team at legal@beamxp.com.