Data Processing Agreement — Summary
Version 1.0 · Effective: 6 February 2026
Overview
This page provides a high-level overview of how BeamPay Ltd ("BeamPay", "we", "us", or "our") processes personal data when acting as a processor or sub-processor on behalf of our business customers.
The full legal terms governing the processing of Customer Data are set out in our Data Processing Agreement ("DPA"), which forms part of the contractual framework between BeamPay and its Customers.
This summary is provided for transparency purposes only and does not replace the legally binding terms of the full Data Processing Agreement. In the event of any inconsistency, the terms of the full DPA will prevail.
For questions regarding our data processing practices, please contact: privacy@beampay.tech.
Roles and Responsibilities
| Scenario | BeamPay's Role | Data Controller |
|---|---|---|
| Website visitors, business contacts | Controller | BeamPay |
| Customer Data (platform/API) | Processor | The Customer |
| Customer acts as processor for a third party | Sub-processor | The Customer's controller |
Key Commitments
When acting as a Processor or Sub-processor, BeamPay commits to the following principles in accordance with UK GDPR and EU GDPR.
Processing on Instructions
BeamPay processes Customer Data only on documented instructions from the Customer, including as specified in:
- the Data Processing Agreement
- the relevant Customer Agreement
- the Customer's lawful configuration and use of the Service
BeamPay will not process Customer Data for its own independent purposes.
Security Measures
BeamPay implements and maintains appropriate technical and organisational measures ("TOMs") designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
These measures include, among others:
- Encryption of data in transit and at rest
- Access control mechanisms and least-privilege access principles
- Infrastructure monitoring, logging and alerting
- Vulnerability management and security reviews
- Incident response procedures and escalation processes
Security controls are reviewed periodically and updated to reflect evolving security risks and industry best practices.
Confidentiality
All BeamPay personnel authorised to process Customer Data are bound by confidentiality obligations and receive appropriate training on data protection and information security.
Access to Customer Data is restricted to personnel who require such access to perform their duties.
Sub-processors
BeamPay may engage carefully selected sub-processors to support the delivery of the Service.
We maintain an up-to-date list of sub-processors and will provide advance notice (typically 10 days) before adding or replacing a sub-processor.
Customers may object to a new sub-processor on reasonable data protection grounds.
All sub-processors are bound by written agreements imposing data protection obligations materially equivalent to those contained in our DPA.
Data Subject Rights
BeamPay provides reasonable assistance to Customers in responding to data subject requests, including:
- access
- rectification
- erasure
- restriction of processing
- data portability
- objection to processing
Where BeamPay receives a request directly from a data subject relating to Customer Data, the request will be promptly forwarded to the relevant Customer, unless legally prohibited.
Personal Data Breach Notification
BeamPay maintains internal procedures for detecting and responding to Personal Data Breaches.
If BeamPay becomes aware of a breach affecting Customer Data, we will:
- notify the Customer without undue delay
- provide available information regarding the nature of the incident and its likely impact
- provide updates as further information becomes available
- cooperate with the Customer in investigating and mitigating the incident
International Data Transfers
Where Customer Data is transferred outside the United Kingdom or European Economic Area, BeamPay ensures that appropriate safeguards are in place in accordance with applicable data protection laws.
These safeguards may include:
- EU Standard Contractual Clauses (SCCs)
- UK International Data Transfer Agreement (IDTA)
- UK Addendum to the SCCs
- additional technical safeguards such as encryption and access controls
BeamPay also implements supplementary technical and organisational safeguards where appropriate to ensure an adequate level of protection.
Data Retention and Deletion
Upon termination or expiry of the applicable agreement, BeamPay will, at the Customer's election:
- return Customer Data; or
- securely delete Customer Data
within a reasonable period (typically within 60 days for production systems), unless retention is required by applicable law.
Deletion confirmation may be provided upon request.
Audit and Compliance Information
Customers may request information reasonably necessary to demonstrate compliance with applicable data protection obligations.
This may include:
- security summaries
- compliance documentation
- relevant third-party assurance reports
Customer audit rights may be exercised in accordance with the DPA, typically no more than once per 12-month period and subject to reasonable notice and confidentiality obligations.
No Sale or Misuse of Data
BeamPay does not sell Customer Data, use Customer Data for independent advertising or marketing purposes, or combine Customer Data with data from other customers for profiling or analytics unrelated to the provision of the Service.
Security Incident Response
BeamPay maintains a structured security incident response programme aligned with UK GDPR and EU GDPR requirements.
The programme includes:
- defined severity classification
- escalation pathways
- containment and remediation procedures
- structured customer notifications
- post-incident review and continuous improvement
Request the Full DPA
Business customers and prospective customers may request a copy of the full Data Processing Agreement by contacting:
- BeamPay Ltd
- 128 City Road
- London EC1V 2NX
- United Kingdom
Privacy and legal enquiries: privacy@beampay.tech