Data Processing Agreement

Last updated 27 September 2026

When your organisation uses Beviso, you are the controller of the personal data in your workspace and Beviso is your processor. Our Data Processing Agreement sets out the Article 28 GDPR terms that govern this.

What the DPA covers

  • Processing only on your documented instructions
  • Confidentiality obligations for everyone with access
  • Appropriate technical and organisational security measures (Art. 32)
  • Use of sub-processors only with notice and the right to object
  • Assistance with data subject requests, DPIAs and breach notifications
  • Notification of personal data breaches without undue delay
  • Deletion or return of data at the end of the service
  • Information and audit rights to demonstrate compliance

Categories of data and data subjects

Typically your employees, contractors and users of your connected tools: names, work email addresses, account identifiers, group memberships, device details and security-related activity records.

Sub-processors

ProviderPurpose
Vercel Inc.Application hosting, file storage, background jobs and AI model routing
MongoDB, Inc.Database hosting
ResendTransactional email, such as invitations and notifications
PostHog, Inc.Product analytics (EU instance)
Crisp IM SASSupport chat
Anthropic, PBCDrafting suggested answers to security questionnaires, when you use that feature

Requesting a signed DPA

Email contact@beviso.app with your organisation’s legal name and address and we will send you our DPA for signature.