Legal

Data Processing Addendum

Our GDPR-aligned Data Processing Addendum, included on every paid tier. The DPA defines our role as a Processor and yours as a Controller, the obligations of each, and the safeguards around international data transfers.

Draft summary. The signed, countersignable version is exchanged during onboarding. For an early copy email legal@beetony.com.

Roles

You (the customer) are the Controller of any personal data flowing through Beetony. We (Atulo, Inc.) are the Processor, acting only on your documented instructions. The DPA codifies this and incorporates the EU Standard Contractual Clauses by reference.

Subprocessor list

Current subprocessor list, with the contractual status of each, at /legal/subprocessors. We notify you at least 30 days before adding or replacing a subprocessor; you can object within that window.

International transfers

Data is processed in the United States. For EU-resident data subjects, transfers rely on the EU-US Data Privacy Framework where applicable, and SCCs as a fallback. UK data subjects are covered via the UK addendum to the SCCs.

Data subject rights

Access, rectification, erasure, restriction, portability, and objection requests are processed within 30 days. Export is self-serve from your dashboard. Erasure is handled manually by us on request, because live audit records are append-only at the database level and cannot be deleted through the product.

Security measures

Annex II of the DPA enumerates the technical and organizational measures: encryption, access control, append-only audit semantics, and incident response. A formal personnel training program is planned and not yet in place. The current text mirrors /legal/security.

Back to homeEmail legal
TermsPrivacySecurityDPASubprocessors