Legal
Data Processing Agreement
Effective date: July 16, 2026
This Data Processing Agreement ("DPA") applies whenever Beily Inc. ("Beily", "we", "us") processes personal data on your behalf while providing the services, and it forms part of our Terms of Service. For that personal data, you are the controller and Beily is the processor within the meaning of the EU General Data Protection Regulation (GDPR). Where this DPA and the Terms conflict on the subject of personal data, this DPA prevails.
1. Scope and our role
Beily processes personal data only to provide the services you subscribe to, for example handling the booking details, review content, or contacts that flow through the tools we run for you. The details of that processing (its subject matter, duration, nature, and the types of data and people involved) are set out in the Annex below. You confirm that your instructions, including your use of the services, comply with data-protection law.
2. Our obligations as processor
We will:
- process personal data only on your documented instructions, including for transfers, unless the law requires otherwise (in which case we will tell you, unless the law forbids it);
- ensure that people we authorize to process the data are bound by confidentiality;
- put in place appropriate technical and organizational security measures (see Section 5);
- engage sub-processors only as described in Section 3;
- help you respond to requests from individuals exercising their rights (see Section 7);
- help you meet your obligations around security, breach notification, and data-protection impact assessments;
- delete or return the data at the end of the services (see Section 9); and
- make available the information you reasonably need to show compliance, and allow for audits as described in Section 8.
3. Sub-processors
You give us general authorization to engage the sub-processors listed in the Annex to help deliver the services. We impose data-protection terms on each of them that are no less protective than this DPA, and we remain responsible for their performance. If we plan to add or replace a sub-processor, we will give you reasonable notice so you can object on reasonable data-protection grounds.
4. International transfers
Beily is based in the United States, and some sub-processors process data outside the EEA. Where we transfer personal data of people in the EEA to a country without an adequacy decision, the transfer is covered by an approved safeguard, either the EU-US Data Privacy Framework (for certified providers) or the European Commission's Standard Contractual Clauses. The Standard Contractual Clauses (controller-to-processor module) are incorporated into this DPA for the transfer of your data to Beily and apply where required.
5. Security
We maintain appropriate technical and organizational measures to protect personal data, taking into account the risk. These include encryption of data in transit, access controls and least-privilege access, multi-factor authentication on administrative accounts, row-level access rules in our database, and regular backups. We review these measures and may update them, provided the level of protection is not reduced.
6. Personal data breaches
If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and in any event within 48 hours, with the information you reasonably need to meet your own notification duties, and we will take reasonable steps to mitigate it.
7. Helping you with individuals' requests
If an individual contacts us directly to exercise a right (such as access or deletion) in relation to data we process for you, we will forward the request to you without undue delay. Taking into account the nature of the processing, we will give you reasonable assistance, including the tools to find, export, correct, or delete the relevant data.
8. Demonstrating compliance and audits
On reasonable written request, and no more than once a year unless a supervisory authority or a suspected breach requires otherwise, we will make available information reasonably necessary to demonstrate compliance with this DPA. Audits will respect confidentiality and the security of other customers' data.
9. Return or deletion of data
On termination of the services, and at your choice, we will return or delete the personal data we process for you, and delete existing copies, unless the law requires us to keep it. Note that removing data from our database does not automatically remove copies from backups; backups are overwritten on their normal cycle.
10. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms.
Annex A, details of the processing
- Subject matter and duration: processing of personal data for as long as you use the services, plus any legally required retention.
- Nature and purpose: providing done-for-you digital operations, which may include online booking, review management, a hosted website, and social content, depending on your plan.
- Types of personal data: typically names, email addresses, phone numbers, appointment and booking details, review text, and messages. We do not require special-category data.
- Categories of individuals: your customers and the people who contact your business.
Annex B, sub-processors
- Stripe, payments and subscription billing (United States).
- Supabase, database and file storage, hosted in the EU (Frankfurt, Germany).
- Resend, transactional email (United States).
- Vercel, website and application hosting (United States and EU regions).
- Cloudflare, DNS and network delivery (United States).
Contact
Beily Inc.2261 Market Street, STE 65437
San Francisco, CA 94114
hello@beily.io