Data Processing Addendum
Our GDPR-aligned Data Processing Addendum, included on every paid tier. The DPA defines our role as a Processor and yours as a Controller, the obligations of each, and the safeguards around international data transfers.
Roles
You (the customer) are the Controller of any personal data flowing through Beetony. We (Atulo, Inc.) are the Processor, acting only on your documented instructions. The DPA codifies this and incorporates the EU Standard Contractual Clauses by reference.
Subprocessor list
Current subprocessor list, with the contractual status of each, at /legal/subprocessors. We notify you at least 30 days before adding or replacing a subprocessor; you can object within that window.
International transfers
Data is processed in the United States. For EU-resident data subjects, transfers rely on the EU-US Data Privacy Framework where applicable, and SCCs as a fallback. UK data subjects are covered via the UK addendum to the SCCs.
Data subject rights
Access, rectification, erasure, restriction, portability, and objection requests are processed within 30 days. Export is self-serve from your dashboard. Erasure is handled manually by us on request, because live audit records are append-only at the database level and cannot be deleted through the product.
Security measures
Annex II of the DPA enumerates the technical and organizational measures: encryption, access control, append-only audit semantics, and incident response. A formal personnel training program is planned and not yet in place. The current text mirrors /legal/security.