Policy version 1.0
Data processing addendum
This applies where we process personal data on your behalf as your processor. A countersigned copy is available on request.
Parties
Processor: The Global Company, registered address [PLACEHOLDER - registered address], ABN [PLACEHOLDER - ABN]. Controller: the customer entity that uses Beamy AI. Contact for data matters: privacy@beamy-ai.com.
Subject matter and duration
We process personal data only to provide the Beamy AI service: running scans, producing reports, tracking visibility over time, and supporting your use of the product. Processing lasts for the term of your use of the service.
Categories of data and data subjects
Data subjects are your staff who use the product, and any individuals identified in material you submit. Categories are limited to account contact details, usage records, and the brand and domain information you provide.
We do not require, and ask you not to submit, special category data or payment card data.
Our obligations
We process personal data only on your documented instructions, keep it confidential, apply appropriate technical and organisational security measures, and assist you with data subject requests, impact assessments and breach notification.
We notify you without undue delay after becoming aware of a personal data breach affecting your data.
Sub-processors
We use sub-processors for hosting and database services, email delivery, bot protection on the free scan, and the AI providers whose engines we query, including the operators of ChatGPT, Gemini, Perplexity and Claude.
Each sub-processor is bound by terms no less protective than these. We give notice before adding a new sub-processor, and you may object on reasonable data protection grounds.
International transfers
Some sub-processors operate outside your country. Where that happens we rely on the transfer mechanisms permitted by applicable law, including standard contractual clauses.
Security measures
Encryption in transit, access control on a least-privilege basis, salted hashing of IP addresses and device fingerprints rather than raw storage, logging of administrative access, and regular review of the above.
Return and deletion
On termination we delete or return personal data at your choice, subject to any retention required by law. Anonymous scan records are deleted after 30 days regardless.
Audit
We provide the information reasonably needed to demonstrate compliance with these terms, and will accommodate a proportionate audit on reasonable notice.