Data Processing Agreement

Article 28 GDPR terms governing the prospect data BeReach processes on your behalf

PublishedJune 5, 2026UpdatedJuly 13, 2026

Summarize with AI

This Data Processing Agreement ("DPA") governs the prospect data you source and process through the Service, for which you are the controller and BeReach is the processor. It does not cover BeReach's own customer, account and billing data, for which BeReach is the controller (see our Privacy Policy).

1. Parties and scope

This DPA forms part of the Terms of Service between BEREACH SAS ("Processor", "BeReach") and the customer ("Controller", "you"). It applies to the processing of personal data carried out by BeReach on your behalf in providing the Service.

Where terms are capitalised but not defined here, they have the meaning given in the Terms of Service or in the GDPR (Regulation (EU) 2016/679).

2. Roles

You are the Controller of the prospect data processed through the Service. You determine the purposes and means of that processing: which data you source, whom you contact and why. BeReach is the Processor and processes that data only to provide the Service, on your documented instructions.

You are responsible for having a valid legal basis for the processing and for providing any information required to the data subjects, as set out in the Terms and the Privacy Policy.

3. Details of processing

  • Subject matter: provision of the BeReach Service.
  • Duration: for the term of your subscription.
  • Nature and purpose: processing in transit to enable sourcing from third-party public-data providers and to route outreach through your own connected account. BeReach does not store prospect data or your access credentials.
  • Type of personal data: professional contact data (for example name, professional email, job title, company). No special-category data is processed.
  • Categories of data subjects: the prospects you choose to target.

4. Processor obligations

BeReach will:

  • a. Instructions. Process the personal data only on your documented instructions, including for transfers, unless required otherwise by law (in which case we will inform you where permitted).
  • b. Confidentiality. Ensure that persons authorised to process the data are bound by confidentiality.
  • c. Security. Implement appropriate technical and organisational measures under Article 32 GDPR, taking into account that BeReach does not retain the data (see Annex 2).
  • d. Sub-processors. Engage sub-processors only under the conditions in clause 5.
  • e. Data subject rights. Taking into account the nature of the processing, assist you by appropriate measures to respond to requests from data subjects. Because BeReach does not store the data, most such requests are handled directly by you as Controller.
  • f. Assistance. Assist you in ensuring compliance with your obligations under Articles 32 to 36 GDPR, taking into account the information available to us.
  • g. Deletion or return. On termination, as BeReach does not retain prospect data, there is no stored prospect data to return or delete. Any incidental data is deleted.
  • h. Records and audit. Make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, subject to reasonable notice and confidentiality.
  • i. Breach. Notify you without undue delay after becoming aware of a personal data breach affecting your data.

5. Sub-processors

You give general authorisation for BeReach to engage sub-processors to provide the Service. Current sub-processors include Stripe (billing), Vercel (hosting and infrastructure), Resend (email and communication), and third-party public-data providers (the source of public prospect data). A current and complete list of sub-processors is available on our Sub-processors page.

We will inform you of intended changes and give you the opportunity to object. BeReach imposes on each sub-processor data-protection obligations equivalent to those in this DPA.

6. International transfers

Where processing involves a transfer of personal data outside the EEA, the parties will rely on an appropriate transfer mechanism, such as the EU Standard Contractual Clauses, which are incorporated by reference where applicable.

7. Liability, term and miscellaneous

This DPA is subject to the liability provisions of the Terms of Service. It takes effect when you accept the Terms and remains in force while BeReach processes personal data on your behalf. In case of conflict between this DPA and the Terms on data-protection matters, this DPA prevails. This DPA is governed by French law.

Annex 1: Details of processing

The details of processing (subject matter, duration, nature and purpose, types of personal data and categories of data subjects) are set out in clause 3.

Annex 2: Technical and organisational measures

BeReach maintains appropriate technical and organisational measures for the processing under this DPA, including: encryption of data in transit (TLS); access controls and authentication for its systems; processing in transit with no persistent storage of prospect data or access credentials; audit logging; and the security safeguards provided by its sub-processors. These measures reflect the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing.