> ## Documentation Index
> Fetch the complete documentation index at: https://docs.beam.cloud/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Processing Addendum

> Terms that govern Beam's processing of personal data on behalf of customers.

**Effective date:** September 14, 2026

This Data Processing Addendum ("**DPA**") forms part of the Beam [Terms of Service](/v2/security/terms-and-conditions) or other written agreement between Smartshare, Inc. d/b/a Beam ("**Beam**") and the customer that accepted it ("**Customer**") (the "**Agreement**"). It applies where Beam processes Personal Data contained in Customer Data on Customer's behalf.

This DPA takes effect when Customer accepts the Agreement. No signature is required. If you need a countersigned copy for your records, email [legal@beam.cloud](mailto:legal@beam.cloud). Capitalized terms that are not defined here have the meaning given in the Agreement.

## 1. Definitions

* "**Applicable Data Protection Law**" means all laws that apply to the Processing of Personal Data under this DPA, including, as applicable: (a) Regulation (EU) 2016/679 (the "**GDPR**"); (b) the GDPR as incorporated into United Kingdom law by the Data Protection Act 2018 and the European Union (Withdrawal) Act 2018 (the "**UK GDPR**"); (c) the Swiss Federal Act on Data Protection (the "**FADP**"); and (d) United States state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (the "**CCPA**") and comparable laws of other states ("**US State Privacy Laws**").
* "**Customer Personal Data**" means Personal Data contained in Customer Data that Beam Processes on Customer's behalf under the Agreement.
* "**Personal Data**", "**Controller**", "**Processor**", "**Data Subject**", "**Processing**", "**Personal Data Breach**", and "**Supervisory Authority**" have the meanings given in the GDPR. "**Business**", "**Service Provider**", "**Consumer**", "**Sell**", and "**Share**" have the meanings given in the CCPA, and equivalent terms in other US State Privacy Laws are read accordingly.
* "**EU SCCs**" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
* "**UK Addendum**" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
* "**Restricted Transfer**" means a transfer of Customer Personal Data that would be prohibited by Applicable Data Protection Law without a lawful transfer mechanism.
* "**Subprocessor**" means a third party engaged by Beam to Process Customer Personal Data.
* "**Subprocessor List**" means the list published at [Subprocessor list](/v2/security/subprocessor-list).

## 2. Roles and scope

**2.1 Roles.** Customer is the Controller, or a Processor acting on behalf of its own Controllers, and Beam is a Processor of Customer Personal Data. Under US State Privacy Laws, Customer is a Business or Service Provider and Beam is a Service Provider.

**2.2 Customer as Processor.** Where Customer is a Processor for its own customers, Customer warrants that its instructions to Beam, including its appointment of Beam as a Subprocessor, are authorized by the relevant Controller.

**2.3 Description of Processing.** Schedule 1 describes the subject matter, duration, nature, purpose, and categories of Processing.

**2.4 Excluded data.** This DPA does not apply to Personal Data that Beam Processes as a Controller, such as Customer's account, billing, and usage information, which is described in the [Privacy Policy](/v2/security/privacy-policy).

## 3. Customer instructions and responsibilities

**3.1 Instructions.** Beam will Process Customer Personal Data only on Customer's documented instructions, which consist of (a) the Agreement and this DPA; (b) Customer's use and configuration of the Service, including the workloads Customer deploys and the features it enables; and (c) other written instructions that Customer gives and Beam acknowledges. Beam will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, but Beam is not obliged to monitor for infringements or to give legal advice.

**3.2 Customer responsibilities.** Customer is responsible for the lawfulness of its Processing, including having a lawful basis, giving required notices, obtaining required consents, and responding to Data Subjects. Customer will not submit to the Service (a) special categories of Personal Data under Article 9 GDPR or sensitive data under US State Privacy Laws, unless Customer has determined that the Service's controls are adequate for that data and Applicable Data Protection Law permits it; or (b) protected health information under HIPAA, unless a Business Associate Agreement with Beam is in place.

**3.3 Compliance.** Each party will comply with Applicable Data Protection Law in performing this DPA.

## 4. Beam's obligations

**4.1 Confidentiality.** Beam will ensure that personnel authorized to Process Customer Personal Data are bound by confidentiality obligations and receive appropriate training.

**4.2 Security.** Beam will implement and maintain the technical and organizational measures described in Schedule 2. Beam may update those measures, provided the updates do not materially reduce the overall level of protection.

**4.3 Assistance.** Taking into account the nature of the Processing and the information available to Beam, Beam will assist Customer, by appropriate technical and organizational measures and at Customer's reasonable request, in meeting Customer's obligations regarding Data Subject requests (Section 7), security (Section 4.2), Personal Data Breach notification (Section 6), data protection impact assessments, and prior consultations with Supervisory Authorities. Beam may charge reasonable fees for assistance that goes beyond the standard features of the Service.

**4.4 Legal requests.** If Beam receives a request from a government authority or other third party for Customer Personal Data, Beam will, unless legally prohibited, notify Customer promptly and direct the requester to Customer. Beam will disclose Customer Personal Data only to the extent legally required and will use reasonable efforts to limit the disclosure.

**4.5 US State Privacy Laws.** Beam will not (a) Sell or Share Customer Personal Data; (b) retain, use, or disclose it for any purpose other than the business purposes specified in the Agreement or as permitted by law; (c) retain, use, or disclose it outside the direct business relationship between Beam and Customer; or (d) combine it with Personal Data that Beam receives from other sources, except as permitted for Service Providers. Beam certifies that it understands these restrictions and will comply with them. Beam will notify Customer if it determines that it can no longer meet its obligations under US State Privacy Laws, and Customer may take reasonable steps to stop and remediate unauthorized use of Customer Personal Data.

## 5. Subprocessors

**5.1 Authorization.** Customer gives Beam general authorization to engage Subprocessors. The Subprocessors engaged on the effective date are listed in the Subprocessor List.

**5.2 Changes.** Beam will update the Subprocessor List at least 30 days before a new Subprocessor begins Processing Customer Personal Data, except where a Subprocessor must be replaced urgently for security or continuity reasons, in which case Beam will update the list and notify Customer as soon as practicable. Customers who want to receive change notices by email can subscribe by emailing [legal@beam.cloud](mailto:legal@beam.cloud).

**5.3 Objection.** Customer may object to a new Subprocessor on reasonable, documented data protection grounds within 30 days of the update. The parties will discuss the objection in good faith. If Beam cannot offer a reasonable alternative within 30 days, Customer may terminate the affected part of the Service on written notice, and Beam will refund any prepaid Fees for the period after termination.

**5.4 Flow-down.** Beam will impose on each Subprocessor data protection obligations no less protective than those in this DPA, to the extent applicable to the services the Subprocessor provides, and will remain liable for the Subprocessor's performance.

## 6. Personal Data Breach

**6.1 Notification.** Beam will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notice will be sent to the email address of Customer's account owner and to any security contact Customer has registered.

**6.2 Content.** The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach. Beam may provide information in phases as it becomes available.

**6.3 Cooperation.** Beam will take reasonable steps to contain, investigate, and mitigate the breach and will cooperate with Customer's reasonable requests for information needed to meet Customer's own notification obligations. Beam's notification is not an admission of fault or liability.

## 7. Data Subject requests

**7.1 Referral.** If Beam receives a request from a Data Subject relating to Customer Personal Data, Beam will not respond except to acknowledge receipt and refer the Data Subject to Customer, unless required by law, and will notify Customer promptly where the request identifies Customer.

**7.2 Assistance.** Beam will assist Customer in responding to Data Subject requests through the features of the Service, including the ability to retrieve, modify, and delete Customer Data using the dashboard, CLI, and API, and, where those features are insufficient, through reasonable additional assistance under Section 4.3.

## 8. Audits and information

**8.1 Reports.** On request, and subject to confidentiality obligations, Beam will provide Customer with its most recent SOC 2 Type II report and other summaries of its security controls, and will answer reasonable written security questionnaires, no more than once per year.

**8.2 Audits.** If the information in Section 8.1 is insufficient to demonstrate compliance with this DPA, or an audit is required by a Supervisory Authority or Applicable Data Protection Law, Customer or an independent auditor bound by confidentiality may audit Beam's compliance: no more than once in any 12-month period, unless a Personal Data Breach or a Supervisory Authority requires otherwise; on at least 30 days' written notice; during business hours; in a manner that does not unreasonably disrupt Beam's operations or compromise the security of other customers; and at Customer's expense. Beam may require the auditor to sign a non-disclosure agreement. Audits do not extend to the facilities of Beam's cloud hosting providers, for which Beam will make available those providers' third-party certifications and audit reports.

## 9. Return and deletion

**9.1 During the term.** Customer can retrieve and delete Customer Data at any time using the Service.

**9.2 After termination.** After the Agreement ends, Beam will make Customer Data available for retrieval for 30 days and will then delete it from active systems within 60 days and from backups within 90 days, as described in the Agreement, unless Applicable Data Protection Law requires retention, in which case Beam will continue to protect the data and Process it only as required by law. On request, Beam will confirm deletion in writing.

## 10. International transfers

**10.1 Locations.** Beam Processes Customer Personal Data in the United States and in the other locations listed in the Subprocessor List.

**10.2 EEA transfers.** For Restricted Transfers subject to the GDPR, the parties enter into the EU SCCs, which are incorporated into this DPA by reference, completed as follows: (a) Module Two (controller to processor) applies where Customer is a Controller, and Module Three (processor to processor) applies where Customer is a Processor; (b) Clause 7 (docking clause) does not apply; (c) in Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 5.2; (d) in Clause 11, the optional language does not apply; (e) in Clause 13, the competent Supervisory Authority is determined by the Member State in which Customer or its Controller is established or, if not established in the EEA, in which its representative is appointed or the Data Subjects are located; (f) in Clause 17, the governing law is the law of Ireland; (g) in Clause 18, the forum is the courts of Ireland; and (h) Annexes I, II, and III are completed by Schedules 1, 2, and 3 of this DPA.

**10.3 UK transfers.** For Restricted Transfers subject to the UK GDPR, the EU SCCs as completed in Section 10.2 apply as amended by the UK Addendum, with Tables 1 to 3 completed by the information in this DPA and its Schedules, and with the option in Table 4 that either party may end the UK Addendum as set out in Section 19 of the UK Addendum.

**10.4 Swiss transfers.** For Restricted Transfers subject to the FADP, the EU SCCs apply with these adaptations: references to the GDPR are read as references to the FADP; the competent Supervisory Authority is the Federal Data Protection and Information Commissioner; the term "Member State" is not read so as to exclude Data Subjects in Switzerland from enforcing their rights in Switzerland; and the EU SCCs also protect the data of legal entities until the FADP no longer does so.

**10.5 Alternative mechanisms.** If Beam adopts an additional lawful transfer mechanism, such as certification under the EU-U.S. Data Privacy Framework, Beam may rely on it in place of or in addition to the mechanisms above and will update this DPA accordingly. If a mechanism relied on is invalidated, the parties will cooperate in good faith to implement a replacement.

**10.6 Conflict.** If there is a conflict between this DPA and the EU SCCs or the UK Addendum, the EU SCCs or UK Addendum prevail for the transfers they govern.

## 11. Liability

Each party's liability arising out of or relating to this DPA, including the EU SCCs and the UK Addendum, is subject to the exclusions and limitations of liability in the Agreement. Liability under this DPA counts toward, and does not add to, the cap in the Agreement, except to the extent Applicable Data Protection Law or the EU SCCs do not permit that limitation with respect to Data Subjects.

## 12. General

**12.1 Duration.** This DPA lasts for as long as Beam Processes Customer Personal Data.

**12.2 Precedence.** For the Processing of Customer Personal Data, this DPA prevails over conflicting terms of the Agreement.

**12.3 Changes.** Beam may update this DPA where required by Applicable Data Protection Law or to reflect a new transfer mechanism, and otherwise as described in the Agreement's provisions on changes to the Terms. Updates will not reduce the level of protection for Customer Personal Data without Customer's agreement.

**12.4 Governing law.** This DPA is governed by the law that governs the Agreement, except where the EU SCCs, the UK Addendum, or Applicable Data Protection Law require otherwise.

## Schedule 1: Description of Processing

**Parties.** Data exporter: Customer, whose contact details are those associated with its Beam account; role: Controller (Module Two) or Processor (Module Three). Data importer: Smartshare, Inc. d/b/a Beam, 1 Broadway, 14th Floor, Cambridge, MA 02142, United States, [privacy@beam.cloud](mailto:privacy@beam.cloud); role: Processor.

**Subject matter.** Beam's provision of the Service, a serverless platform for deploying and running compute workloads with associated storage and networking, under the Agreement.

**Duration.** The term of the Agreement plus the retrieval and deletion periods in Section 9.

**Nature and purpose.** Hosting, storing, transmitting, executing, and otherwise Processing Customer Data as necessary to run the workloads Customer deploys, provide storage and networking, provide support, secure the Service, and meter and bill usage, as instructed by Customer under Section 3.1.

**Categories of Data Subjects.** Determined by Customer. Typically Customer's employees, contractors, and Users, and Customer's end users, customers, or other individuals whose data Customer includes in Customer Data.

**Categories of Personal Data.** Determined by Customer. May include any Personal Data that Customer chooses to include in code, datasets, model inputs and outputs, files, logs, or other Customer Data.

**Special categories of data.** None intended. Customer will not submit special-category or sensitive data except as permitted by Section 3.2, and protected health information only under a Business Associate Agreement.

**Frequency.** Continuous, for as long as Customer uses the Service.

**Retention.** As described in Section 9 and the Agreement.

**Processing by Subprocessors.** The subject matter, nature, and duration of Processing by Subprocessors are described in the Subprocessor List.

**Competent Supervisory Authority.** Determined under Section 10.2(e).

## Schedule 2: Technical and organizational measures

Beam maintains the measures below. The [Security overview](/v2/security/security) describes them in more detail.

| Area                           | Measures                                                                                                                                                                                                                                         |
| ------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Assurance                      | SOC 2 Type II audit of Beam's controls by an independent auditor; annual review of the security program                                                                                                                                          |
| Encryption                     | TLS for data in transit between customers and the Service and between Service components; encryption at rest for Customer Data, including volumes, images, and secrets                                                                           |
| Access control                 | Single sign-on and multi-factor authentication for Beam personnel; role-based, least-privilege access to production systems; access reviewed quarterly and revoked on role change or departure; customer access through per-workspace API tokens |
| Workload isolation             | Customer workloads run in isolated, non-root containers with network isolation between customers                                                                                                                                                 |
| Logging and monitoring         | Centralized logging of authentication, administrative, and system events; error and performance monitoring; alerting on anomalous activity                                                                                                       |
| Vulnerability management       | Dependency and container image scanning; patching prioritized by severity; coordinated vulnerability disclosure through [security@beam.cloud](mailto:security@beam.cloud)                                                                        |
| Incident response              | Documented incident response process with defined roles and severity levels; customer notification under Section 6; post-incident reviews                                                                                                        |
| Business continuity            | Infrastructure hosted across multiple availability zones of Beam's cloud providers; regular backups of control-plane data; documented recovery procedures                                                                                        |
| Personnel                      | Confidentiality agreements; security and privacy training on hire and annually                                                                                                                                                                   |
| Vendor management              | Security and privacy review of Subprocessors before engagement and periodically thereafter; contractual flow-down under Section 5.4                                                                                                              |
| Physical security              | Beam does not operate its own data centers; physical security is provided by Beam's cloud hosting providers under their own SOC 2 and ISO 27001 programs                                                                                         |
| Data minimization and deletion | Customer controls the data it submits; deletion tooling in the dashboard, CLI, and API; deletion on termination under Section 9                                                                                                                  |

## Schedule 3: Subprocessors

Beam's current Subprocessors, with their purpose, the categories of data they Process, and their location, are listed in the [Subprocessor list](/v2/security/subprocessor-list), which is incorporated into this Schedule.

## Version History

* **September 14, 2026:** First published version. Replaces the previous process of requesting a data processing addendum by email.
