These terms form part of the terms of service between you, the landlord or agent who holds a Beamwise account (“you”), and Oxus Technologies Limited (“we”). They apply whenever we process personal data on your behalf, and they meet the requirements of Article 28 of the EU GDPR and of the UK GDPR. You accept them when you accept the terms of service.
1. Roles
For personal data about your tenants, the tradespeople you add and any other people whose details you put into Beamwise, you are the controller and we are your processor. For the data of account holders and for billing, we are a controller in our own right, as described in our privacy notice, and these terms do not apply to that data.
2. What we process for you
- Subject matter and purpose: providing Beamwise to you: tracking compliance for your properties, storing documents, sending reminders, certificate copies, invitations and signing requests, running tenant and tradesperson portals, and keeping the audit trail.
- Nature of processing: storage, organisation, retrieval, display, transmission by email, and deletion.
- People concerned: tenants, prospective tenants, tradespeople and your own staff or agents.
- Types of data: names, email addresses, phone numbers, tenancy details, rent and deposit amounts, qualifications and registration numbers, the content of certificates, agreements and other documents, repair requests, electronic signature records (typed name, time, IP address, browser details) and portal sign-in details. Beamwise is not designed for special category data, such as health information; please do not upload it unless it is genuinely necessary.
- Duration: for as long as your account is open, and then as set out in section 9.
3. Your instructions
We process the data only on your documented instructions, which are these terms and what you do in Beamwise (for example, choosing to email a tenant their certificate). We will not use it for our own purposes, and we will not sell it. If we are required by EU, Member State or UK law to process it in another way, we will tell you first unless that law forbids it. If we believe an instruction breaks data protection law, we will tell you.
As controller, you are responsible for having a lawful basis for the data you put into Beamwise and for giving the people concerned the information the law requires about how you use it.
4. Confidentiality
Everyone we authorise to access the data is bound by a duty of confidentiality. Access by our staff is limited to what is needed to run and support the service, and is recorded in the audit trail.
5. Security
We take appropriate technical and organisational measures under Article 32, including: encryption in transit and at rest; private document storage reachable only through links that expire within minutes; strict separation so that each account, tenancy and tradesperson sees only their own data; role-based access; single-use, expiring invitation and signing links; an audit trail of access and changes; and hosting with providers that hold recognised security certifications.
6. Sub-processors
You give us general authorisation to use the following sub-processors:
- Supabase Inc.: database, sign-in and document storage (EU, Ireland).
- Vercel Inc.: application hosting (EU, Ireland).
- Resend: email delivery (EU, Ireland).
Each is bound by a written contract that imposes data protection obligations equivalent to these. We remain responsible to you for their work. We will give you at least 30 days’ notice by email before adding or replacing a sub-processor, and you may object on reasonable data protection grounds. If we cannot address your objection, you may end your subscription without charge before the change takes effect.
7. International transfers
The data is hosted and processed in the EU. Where a sub-processor may access it from outside the EU or UK, the transfer is covered by an adequacy decision (including the EU-US Data Privacy Framework and its UK extension, where the provider is certified) or by the European Commission’s standard contractual clauses with the UK addendum.
8. Helping you meet your obligations
- Requests from individuals: if a tenant or tradesperson contacts us to use their rights, we will pass the request to you promptly and not answer it ourselves unless you ask us to. Beamwise lets you view and correct their details, and we will carry out anything you cannot do yourself, such as erasing a person’s data, when you ask.
- Personal data breaches: we will tell you without undue delay, and in any case within 48 hours of becoming aware of a breach affecting your data, with what we know about it, so that you can meet your own 72-hour deadline to inform the regulator.
- Security, impact assessments and regulators: we will give you reasonable help with your obligations under Articles 32 to 36, taking into account the information available to us.
9. At the end
When your account closes, you may ask for a copy of the data within 30 days (see section 11 of the terms of service). After that we delete it, including from our providers’ systems within their normal backup cycles, unless the law requires us to keep it.
10. Audits
We will make available the information you reasonably need to show that these obligations are met, and answer your written questions about our data protection measures. Where that is not enough, we will allow an audit by you or an auditor you appoint who is bound by confidentiality, on reasonable notice, at your cost, and no more than once a year unless a regulator requires it or there has been a breach.
11. Contact
Questions about these terms: info@beamwise.co.uk.