Data Processing Agreement
1. Purpose and scope
This Data Processing Agreement (the "DPA") sets out the terms on which BEEMM, a SAS (société par actions simplifiée) under French law whose registered office is at 34 route de Saclay, 91430 Vauhallan, France ("Beemm"), processes personal data on behalf of a professional customer (the "Customer") in the course of providing the Beemm Vision service.
It forms an integral part of the Terms of Sale and applies automatically, without further signature, to any professional Customer, whatever the plan subscribed. Where the Customer requires a signed counterpart, Beemm provides one on request at [email protected].
Version 2.0, in force since 2026-08-07. It is governed by Regulation (EU) 2016/679 ("GDPR") and, in particular, by its article 28.
2. Roles of the parties
The allocation of roles depends on the data concerned, and it is not the same throughout the service.
- Beemm acts as controller for the data it needs in order to run its own business: the Customer's account and its members' accounts, authentication, billing, security of the service, audience measurement. That processing is described in our Privacy Policy and is outside the scope of this DPA.
- Beemm acts as processor for the personal data that the Customer, or a member of the Customer's organisation, submits to the service or generates through it — prompts, uploaded files, generated content, workflow data — where those contain personal data of which the Customer is the controller.
The Customer is responsible for having a lawful basis for that processing, and for informing the persons concerned. In particular, where the Customer uploads the image or the voice of an identifiable person, the Customer warrants that it has obtained the necessary authorisations, as provided in article 8 of the Terms of Service.
3. Details of the processing
| Subject matter | Providing the Beemm Vision service: executing the Customer's requests on third-party AI models, and hosting the resulting content. |
|---|---|
| Duration | For the term of the Terms of Sale, plus the retention periods set out in article 12. |
| Nature and purpose | Collection, storage, transmission to the selected model provider, generation, display, deletion. |
| Categories of data | Any personal data contained in the content submitted or generated: images of persons, voices, names, and any data appearing in a prompt or an uploaded file. Beemm does not determine those categories: the Customer does. |
| Categories of data subjects | Any person whose data the Customer chooses to submit — in particular the Customer's own customers, employees, models, or any identifiable third party. |
| Excluded data | Special categories of data within the meaning of article 9 of the GDPR, and data relating to criminal convictions, may not be submitted (Terms of Service, art. 10). Beemm's service is not designed for them and no additional safeguard is implemented for them. |
4. Instructions
Beemm processes the personal data only on documented instructions from the Customer. The use of the service by the Customer, and the parameters it selects — the model chosen, the workflow built, the content submitted — constitute those instructions. This DPA and the Terms of Sale constitute the remainder.
Where an instruction appears to Beemm to infringe the GDPR or another provision on data protection, Beemm informs the Customer without delay and may suspend the execution of that instruction.
Beemm does not process the data for its own purposes, does not sell it, and does not use it to train any artificial intelligence model.
5. Confidentiality
Beemm ensures that the persons authorised to process the data are bound by an appropriate obligation of confidentiality, and that access is limited to what each person needs. Access by our staff to the content of a Customer's prompts or files is limited to what an incident, an error report or a suspected breach of the Terms of Service requires.
6. Security measures
Beemm implements the following technical and organisational measures, in accordance with article 32 of the GDPR:
- encryption of data in transit (TLS 1.3) and at rest;
- authentication of users through a managed identity provider, with protection against automated abuse;
- access control based on roles, and rules enforced server-side rather than in the browser;
- restriction of administrative access to identified persons, and logging of administrative write operations;
- logging of administrative access and of security events;
- storage of accounts, files and generated content within the European Union (France), the application logic running in the United States as stated in article 11;
- daily backups of the database, retained for seven days, together with point-in-time recovery over the same window;
- monitoring of the service's error rate, with alerting on abnormal spikes.
These measures may evolve with the state of the art. Beemm will not degrade the overall level of security during the term of the contract.
7. Sub-processors
The Customer gives Beemm a general authorisation to engage sub-processors. The current list is published in section 7 of the Privacy Policy, and the AI model gateways and model editors are identified on the page Models and providers.
Beemm imposes on each sub-processor obligations equivalent to those of this DPA, and remains fully liable to the Customer for their performance.
Beemm publishes any addition or replacement of a sub-processor on the pages referred to above, which carry the date of their last update, at least thirty (30) days before it takes effect. The Customer may object on reasonable data protection grounds within that period; failing agreement, the Customer may terminate the contract free of charge in respect of the service concerned.
Point of attention the Customer must weigh. Executing a generation necessarily transmits the content to the editor of the model selected. Several available editors are established outside the European Union, including in China. The choice of model belongs to the Customer, and so does the resulting transfer: the Models and providers page allows that choice to be made in full knowledge.
8. Assisting you with data subject rights
Taking into account the nature of the processing, Beemm assists the Customer, by appropriate technical and organisational measures, in fulfilling its obligation to respond to requests to exercise the rights of data subjects. The service allows the Customer to access, correct, export and delete the content it holds, directly from the interface.
Where a data subject addresses a request directly to Beemm concerning data processed on behalf of the Customer, Beemm forwards it to the Customer without undue delay and does not respond in its place.
This assistance is provided free of charge for requests of ordinary scope.
9. Personal data breaches
Beemm notifies the Customer of any personal data breach affecting the data processed on its behalf without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of it, in accordance with article 33(2) of the GDPR.
The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where the information cannot be provided at the same time, it is provided in phases without further undue delay.
It is for the Customer, as controller, to notify the supervisory authority and, where applicable, the data subjects.
10. Impact assessments and prior consultation
Beemm assists the Customer, taking into account the nature of the processing and the information available to it, in carrying out data protection impact assessments and, where applicable, in the prior consultation of the supervisory authority, in accordance with articles 35 and 36 of the GDPR. This assistance is provided free of charge to the extent it relies on information Beemm already holds.
11. International transfers
Accounts, files and generated content are stored within the European Union, in France. The application logic that processes them runs in the United States (Cloud Functions, us-central1): every request transits there. Further transfers occur where the Customer selects a model whose gateway or editor is established in a third country, and for the support tools identified in the Privacy Policy.
Those transfers are governed by the Standard Contractual Clauses adopted by the European Commission, supplemented by additional measures — encryption in transit, minimisation of the data transmitted. Where the recipient is certified under the EU–US Data Privacy Framework, that framework applies in addition. A copy of the guarantees in place is provided on request.
12. End of the contract
On termination of the Terms of Sale, and at the Customer's choice, Beemm returns or deletes the personal data processed on its behalf, and deletes the existing copies, unless retention is required by law.
The Customer may export its content from the interface at any time, free of charge, and may request a complete copy which Beemm provides within one month. Return and deletion are free of charge: no exit fee, of any kind, is charged for the retrieval of the Customer's own data.
13. Audit and evidence of compliance
Beemm makes available to the Customer all information necessary to demonstrate compliance with the obligations of article 28 of the GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or by an auditor it mandates.
Audits are carried out at reasonable notice of at least thirty (30) days, during business hours, without disproportionate disruption to the service, and are limited to one per calendar year — save where an audit follows a personal data breach or an instruction from a supervisory authority, in which case no such limit applies. The auditor may be required to sign an undertaking of confidentiality.
The first day of audit each year is at Beemm's expense.
14. Miscellaneous
In the event of a conflict between this DPA and the Terms of Sale, this DPA prevails on matters of personal data protection.
This DPA is governed by French law. It is amended under the conditions of article 20 of the Terms of Sale, and in any event to reflect any change in the applicable regulation.
Contact for any question relating to this DPA: [email protected].