Data Processing Agreement
Effective date: 22 September 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Beacon Info Tech Limited (“Beacon”, “we”, “us”), company number 16682371, registered office 696 Yardley Wood Road, Birmingham, B13 0HY, and the business that uses the Beacon platform (“you”). You accept it when you accept the Terms of Service. It sets out the terms that Article 28 of UK GDPR and, where it applies, EU GDPR require.
It covers only the personal data we process on your behalf through systems you connect to the Beacon platform, such as a property management system (PMS). It does not cover Beacon Pro, or personal data we handle as a controller, such as your account details, which our Privacy Policy covers. If this DPA and the Terms of Service conflict on the processing of your personal data, this DPA wins.
1. Definitions
- Data Protection Law means UK GDPR, the Data Protection Act 2018 and, where it applies, EU GDPR (Regulation (EU) 2016/679).
- Customer Personal Data means personal data we process on your behalf through a connected system, as described in section 3.
- Sub-processor means a supplier we use that processes Customer Personal Data.
- Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
- “Controller”, “processor”, “data subject” and “processing” have the meanings given in Data Protection Law.
2. Roles and instructions
- You are the controller of Customer Personal Data, and we are your processor. Your PMS and other system suppliers are your processors, not ours.
- We process Customer Personal Data only on your documented instructions, including on which countries it may be processed in. Your instructions are the Terms of Service, this DPA and the way you set up your connected systems in the Beacon platform. If the law requires us to process it in another way, we will tell you first, unless the law prevents that.
- We will tell you straight away if we think an instruction breaks Data Protection Law.
- You are responsible for having a lawful basis to share Customer Personal Data with us, for giving your guests the privacy information they need, and for having the right to connect your systems to the Beacon platform.
3. Details of the processing
- Subject matter: running the connection between your systems, such as your PMS, and the Beacon platform.
- Nature: receiving reservation and inventory records from your systems by whatever method each connection uses, reading them in memory, removing guest details, and keeping only booking and inventory figures that do not identify anyone.
- Purpose: providing the Beacon platform to you, using booking and inventory figures.
- Duration: for as long as a system is connected to your account, subject to section 10.
- Types of personal data: whatever personal data your system includes in reservation records, which may include guest and booker names, email addresses, phone numbers, postal addresses, and stay details linked to a named guest. We do not ask for special category data. If a reservation record contains any, for example in a free-text note, it is handled in the same way.
- Data subjects: your guests and the people who book for them, and any of your staff named in reservation records.
4. How guest data is handled
- Where a connected system lets us exclude guest personal data from the integration, we exclude it.
- Where it cannot be excluded, reservation records are processed in memory. Guest details are removed before anything is saved. They are never written to our databases or backups.
- If a technical error occurs while a record is being processed, fragments of Customer Personal Data may be captured in error logs, queues or crash reports. Access to these is limited to named staff, and they are deleted automatically within 30 days.
- We never use Customer Personal Data for our own purposes, never send it to AI providers, and never sell it.
5. Confidentiality and security
Everyone who can access Customer Personal Data is bound by a duty of confidentiality. We protect it with appropriate technical and organisational measures, which include:
- encrypted connections (TLS) for all data exchanged with your systems;
- processing reservation records in memory and removing guest details before anything is saved (section 4);
- production access limited to named Beacon staff;
- multi-factor authentication for anyone with server access;
- automatic deletion of error logs, queues and crash reports within 30 days; and
- hosting in OVH data centres in the UK and the EU.
We review these measures regularly and will not reduce the overall level of protection.
6. Sub-processors
You give us general authorisation to use the following sub-processors:
- OVH: hosting and processing, in the UK and the EU.
- Cloudflare: network security and delivery of data your systems send to us, on its global network.
Each sub-processor is bound by a written contract that gives Customer Personal Data the same protection as this DPA, and we remain responsible to you for what they do. We will tell you by email at least 30 days before we add or replace a sub-processor. You can object in writing within that 30 days, giving your data protection reasons. We will work with you in good faith to resolve the objection, for example by not using the new sub-processor for your data. If we cannot resolve it and still go ahead, you can end only the part of the Services that relies on that sub-processor, and we will refund prepaid fees for that part for the rest of the term. If you do not object within 30 days, the change is accepted.
7. International transfers
We process Customer Personal Data in the UK and the EEA. Cloudflare’s network may carry data your systems send to us through other countries. Where Customer Personal Data leaves the UK or EEA, it is protected by UK adequacy regulations or an EU adequacy decision, the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses. We will not transfer it in any other way without your agreement. If you are in the EEA, transfers of Customer Personal Data to us in the UK rely on the European Commission’s adequacy decision for the UK.
8. Individuals’ rights and other assistance
- Because we do not keep Customer Personal Data (section 4), we usually hold nothing to access, correct or delete. If we receive a request from one of your guests, we will pass it to you without undue delay and will not respond to it ourselves unless you ask us to.
- We will give you reasonable help to meet your duties under Data Protection Law, including on security, breach notification, data protection impact assessments and consulting a regulator, taking into account what we process and the information available to us.
9. Personal data breaches
We will tell you without undue delay, and within 48 hours of becoming aware, of any Personal Data Breach affecting Customer Personal Data. We will give you what we know: what happened, the types of data and the approximate number of people affected, the likely consequences, what we are doing about it, and who you can contact at Beacon for more information. We will update you as we learn more, and take reasonable steps to contain the breach and limit its effects.
10. Deletion at the end of processing
When you disconnect a system or close your account, we stop accessing and processing Customer Personal Data from it. We do not keep Customer Personal Data (section 4), so there is nothing to return. Any fragments in error logs, queues or crash reports are deleted within 30 days. We will confirm this in writing if you ask.
11. Information and audits
- We will give you the information you reasonably need to show that we meet this DPA. Where we can, we will do this by answering a written security questionnaire, which you can send us once a year.
- If that is not enough, or a regulator requires it, you or an independent auditor you appoint (who is not our competitor) can audit our compliance. Audits happen at most once a year, unless there has been a Personal Data Breach or a regulator requires one. You must give 30 days’ notice, carry out the audit during business hours under a duty of confidentiality, and pay for it.
12. Liability
Each party’s liability under this DPA is subject to the limits in section 24 of the Terms of Service, to the extent the law allows.
13. Duration, changes and signed copies
- This DPA applies for as long as we process Customer Personal Data for you. It is governed by the law of England and Wales, as set out in the Terms of Service.
- We may update this DPA to reflect changes in the law or in our sub-processors (section 6). We will give notice of material changes as set out in section 26 of the Terms of Service.
- This online version is binding without a signature. If you need a signed copy for your records, email [email protected].