Data Processing Agreement
Last updated 27 September 2026
When your organisation uses Beviso, you are the controller of the personal data in your workspace and Beviso is your processor. Our Data Processing Agreement sets out the Article 28 GDPR terms that govern this.
What the DPA covers
- Processing only on your documented instructions
- Confidentiality obligations for everyone with access
- Appropriate technical and organisational security measures (Art. 32)
- Use of sub-processors only with notice and the right to object
- Assistance with data subject requests, DPIAs and breach notifications
- Notification of personal data breaches without undue delay
- Deletion or return of data at the end of the service
- Information and audit rights to demonstrate compliance
Categories of data and data subjects
Typically your employees, contractors and users of your connected tools: names, work email addresses, account identifiers, group memberships, device details and security-related activity records.
Sub-processors
| Provider | Purpose |
|---|---|
| Vercel Inc. | Application hosting, file storage, background jobs and AI model routing |
| MongoDB, Inc. | Database hosting |
| Resend | Transactional email, such as invitations and notifications |
| PostHog, Inc. | Product analytics (EU instance) |
| Crisp IM SAS | Support chat |
| Anthropic, PBC | Drafting suggested answers to security questionnaires, when you use that feature |
Requesting a signed DPA
Email contact@beviso.app with your organisation’s legal name and address and we will send you our DPA for signature.