Beta launches 15 October: use BevoraX free until 31 December 2026, no credit card - and get up to 50% off in 2027.

Data Processing Addendum

Last updated: September 26, 2026

This Data Processing Addendum ("DPA") applies where a customer ("Controller") uses the BevoraX service and BevoraX LLC ("Processor") processes personal data contained in Customer Data on the Controller's behalf. It forms part of the Terms of Service and, in the event of a conflict on the subject of data protection, prevails over them.

1. Subject matter and duration

The subject matter is the processing of personal data necessary to provide the service described in the Terms. Processing lasts for the term of the Terms and the period required for return or deletion of data afterwards.

2. Nature and purpose

BevoraX processes personal data to host, operate, secure and support the service and to provide its features, as instructed by the Controller through the configuration and use of the service.

3. Categories of data and data subjects

  • Data subjects: the Controller's staff, team members, and business contacts entered into the service.
  • Personal data: identification and contact data, account and role data, and operational records the Controller chooses to enter.
  • No special categories of personal data are intended to be processed.

4. Controller instructions

BevoraX processes personal data only on the Controller's documented instructions, including as set out in this DPA and the Terms, unless required otherwise by law (in which case BevoraX informs the Controller unless the law prohibits it). BevoraX will inform the Controller if, in its opinion, an instruction infringes applicable data protection law.

5. Confidentiality

BevoraX ensures that persons authorised to process the personal data are bound by confidentiality.

6. Security

BevoraX implements appropriate technical and organisational measures under Art. 32 GDPR, including encryption in transit, database row-level security, least-privilege access controls, and mandatory two-factor authentication for administrative access. A summary is available on request.

7. Subprocessors

The Controller gives general authorisation for BevoraX to engage subprocessors. The current list is at Subprocessors. BevoraX imposes data protection obligations on each subprocessor that are no less protective than this DPA and remains liable for their performance. BevoraX will update the subprocessors page before adding or replacing a subprocessor; the Controller may raise a reasonable, data-protection-based objection within 30 days.

8. Assistance to the Controller

Taking into account the nature of the processing, BevoraX assists the Controller by appropriate technical and organisational measures with: responding to data subject requests; the security of processing; personal data breach notification; data protection impact assessments; and prior consultation with a supervisory authority.

9. Personal data breach

BevoraX notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, with the information the Controller reasonably needs to meet its own notification duties, and in any event within 72 hours of becoming aware of it. Where not all information is available at once, BevoraX provides it in phases.

10. Return and deletion

When the Controller deletes its company account or the Terms end, BevoraX keeps Customer Data archived for 180 days. During that time the Controller can restore the company account or request the Customer Data for export; at its request BevoraX deletes it sooner. After the 180 days, Customer Data is deleted permanently unless applicable law requires continued storage.

11. Audits

BevoraX makes available the information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, on reasonable notice, at the Controller's cost, and subject to confidentiality.

12. International transfers

BevoraX LLC is located in the USA and is not certified under the EU-US Data Privacy Framework. Transfers of personal data from the Controller to BevoraX are therefore governed by the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914 ("SCCs"), which are incorporated into this DPA by reference:

  • Module 2 (controller to processor) applies where the Controller is a controller; Module 3 (processor to processor) where the Controller is itself a processor.
  • Clause 7 (docking clause) does not apply. Under Clause 9, option 2 (general written authorisation) applies, with the notice period in section 7 of this DPA. The optional wording in Clause 11 does not apply.
  • Under Clauses 17 and 18, the SCCs are governed by the law of Ireland, and the courts of Ireland have jurisdiction.
  • Annexes I and II of the SCCs are completed by the annexes of this DPA. The competent supervisory authority is that of the Controller's EU establishment, or of its EU representative.

For transfers from the United Kingdom, the UK International Data Transfer Addendum to the SCCs applies; for transfers from Switzerland, the SCCs apply with the adaptations required by the Swiss Federal Act on Data Protection. BevoraX ensures that onward transfers to subprocessors outside the EEA/UK are covered by the SCCs or, where the subprocessor is certified, by the EU-US Data Privacy Framework.

13. Liability and governing law

Liability under this DPA is subject to the limitations in the Terms. This DPA is governed by the law that governs the Terms (State of New Mexico, USA), without prejudice to mandatory data protection law and to the SCCs.

Annexes

  • Annex A - Description of processing: as set out in sections 1–3 above.
  • Annex B - Technical and organisational measures: as summarised in section 6; full description on request.
  • Annex C - Subprocessors: the list published at Subprocessors, as updated from time to time.