July 21, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Terms") between BEEM Technologies Inc. ("BEEM") and the customer identified in the Quotation ("Customer") and applies to the extent BEEM processes Personal Information on behalf of Customer in connection with the Services. Capitalized terms not defined herein have the meaning set out in the Terms.
2.1 As between the parties, Customer is the controller (or, under Law 25 and PIPEDA, the person or organization with control of the Personal Information) and BEEM is the service provider / processor. Under the CCPA, BEEM is a "service provider" and certifies that it understands and will comply with the restrictions applicable to service providers.
2.2 BEEM processes Personal Information solely (i) to provide, secure, maintain and improve the Services in accordance with the Terms; (ii) as documented in Customer's written instructions, including the configuration choices Customer makes in the Platform; and (iii) as required by applicable Law, in which case BEEM informs Customer of that legal requirement before processing, unless prohibited by Law. BEEM will inform Customer without undue delay if, in BEEM's opinion, an instruction infringes Applicable Data Protection Laws.
2.3 The subject matter, duration, nature and purposes of the processing, and the categories of Personal Information and of data subjects, are described in Annex A.
2.4 BEEM shall not sell or share Personal Information (as those terms are defined under the CCPA), nor retain, use or disclose it other than to provide the Services, or combine it with Personal Information obtained from other sources except as permitted for the provision of the Services.
2.5 BEEM will notify Customer if it determines that it can no longer meet its obligations as a service provider under the CCPA. Upon receiving such notice, Customer may take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Information, and may verify BEEM's compliance in accordance with Section 9.
BEEM ensures that persons authorized to process Personal Information (including the ADS Team, as defined in the Professional Services (ADS) Terms & Conditions) are bound by appropriate confidentiality obligations and process Personal Information only as needed to provide the Services.
4.1 BEEM implements and maintains industry-standard technical and organizational measures designed to protect the confidentiality, availability and integrity of Personal Information, as described in Annex B. BEEM's information security program follows SOC 2-aligned processes.
4.2 Customer Data is hosted in a dedicated cloud environment, in the AWS region corresponding to Customer's location or preference (for example, AWS Canada ca-central-1 for Canadian customers, or a U.S. AWS region for U.S. customers), as confirmed at deployment. The Platform's AI features operate within that environment; Personal Information processed by AI features is not transmitted to third-party AI model providers outside of it and is not used to train artificial-intelligence models.
4.3 Customer is responsible for configuring and using the Services in a manner consistent with its own obligations under Applicable Data Protection Laws, including access management, sharing controls and the activation of integrations.
5.1 Customer provides general authorization for BEEM to engage the Subprocessors listed in Section C.1 of Annex C. BEEM imposes on each Subprocessor data protection obligations materially equivalent to those in this DPA.
5.2 BEEM will give Customer at least 30 days' prior written notice (which may be by email to the Notification Email Address) of the addition or replacement of a Subprocessor processing Personal Information. Customer may object on reasonable, documented data-protection grounds within that period; the parties will then cooperate in good faith to find a solution and, failing one, Customer may terminate the affected Services in accordance with the Terms.
5.3 BEEM remains responsible for the performance of its Subprocessors' obligations under this DPA.
6.1 Taking into account the nature of the processing, BEEM provides Customer with commercially reasonable assistance to respond to requests from individuals exercising their rights under Applicable Data Protection Laws (access, rectification, deletion, portability, withdrawal of consent). If BEEM receives such a request directly, it will redirect the individual to Customer without undue delay.
6.2 BEEM provides commercially reasonable assistance to Customer with data protection impact assessments, Law 25 privacy impact assessments relating to the Services, and consultations with supervisory authorities, to the extent the required information is available to BEEM.
6.3 Taking into account the nature of the processing and the information available to BEEM, BEEM provides Customer with reasonable assistance in meeting Customer's obligations relating to the security of processing and to the notification of Security Incidents to authorities and affected individuals (Articles 32 to 36 of the GDPR and the equivalent provisions of Law 25 and PIPEDA).
7.1 BEEM notifies Customer without undue delay and in any event within 72 hours after becoming aware of a Security Incident, through the Notification Email Address, and provides information reasonably available to BEEM regarding the nature of the incident, the categories and approximate number of individuals and records concerned, the likely consequences, and the measures taken or proposed. BEEM thereafter provides Customer with updates as further information becomes available.
7.2 BEEM maintains a register of Security Incidents as required by Law 25. As between the parties, Customer is responsible for notifications to individuals and authorities required of a controller; BEEM is responsible for those required of a processor.
8.1 Personal Information is processed in Canada and the United States, as reflected in Annex C. Before communicating Personal Information subject to Law 25 outside Québec, BEEM conducts and documents, before such communication, the assessment of the factors set out in Law 25, and that contractual safeguards in this DPA support the conclusion that the information receives adequate protection.
8.2 Where BEEM processes Personal Information originating from the EEA or the UK outside those territories, the parties incorporate the Standard Contractual Clauses (controller-to-processor module) or the applicable UK addendum by reference, as set out in Annex D; in case of conflict between the Standard Contractual Clauses and this DPA, the Standard Contractual Clauses prevail.
9.1 Upon written request, no more than once per 12-month period, BEEM makes available information reasonably necessary to demonstrate compliance with this DPA, including a description of its information security program, completed security questionnaires and available third-party attestations or audit summaries.
9.2 Customer (or an independent auditor mandated by Customer and bound to confidentiality) may audit BEEM's compliance with this DPA, upon at least 30 days' prior written notice, no more than once per 12-month period (except following a Security Incident or a demonstrated non-compliance with this DPA), during business hours, and without access to other customers' data or to information protected by law or confidentiality obligations. Audits are conducted remotely and on a documentation basis wherever possible. The costs of Customer's auditor are borne by Customer, and if an audit requires more than one business day of BEEM personnel time, Customer reimburses BEEM's reasonable costs for the additional time at BEEM's then-current ADS rates.
Upon termination of the Terms, BEEM returns or deletes Personal Information in accordance with Section 19(c) of the Terms (30-day instruction window, transfer or copy on request, deletion thereafter), unless retention is required by applicable Law, in which case BEEM continues to protect the retained information under this DPA and deletes it as soon as legally permitted. Upon Customer's written request, BEEM certifies the deletion in writing. Personal Information residing in encrypted backups is deleted in accordance with BEEM's normal backup rotation cycles and remains protected under this DPA until overwritten.
The liability of each party under this DPA is subject to the limitations and exclusions set out in the Terms. In case of conflict between this DPA and the Terms with respect to the processing of Personal Information, this DPA prevails; the Standard Contractual Clauses, where applicable, prevail over both.
Maintained under BEEM's Information Security Program (full descriptions available to Customer on request):
The providers in Section C.1 are Subprocessors that process Customer Personal Information on behalf of Customer under this DPA; the providers in Section C.2 process account, billing and communications data for BEEM's own purposes, with BEEM acting as controller, and are therefore not Subprocessors under this DPA.
| Subprocessor | Location | Purpose |
|---|---|---|
| Amazon Web Services (AWS) | Canada, USA or other available AWS regions per Customer's request | Cloud infrastructure hosting |
| Fivetran | USA | Data connector / extraction services |
| Sentry | USA | Error monitoring |
| Atlassian (Jira) | USA | Professional services delivery management (ADS engagements only) |
| Service provider | Location | Purpose |
|---|---|---|
| Stripe | USA | Credit card payment processing |
| GoCardless | USA/UK | Preauthorized debit processing |
| HubSpot | USA | CRM, communications, quoting |
| Mixpanel | USA | Product usage analytics |
| Zoho | USA | Invoicing (ADS engagements only) |
Note: third-party AI model providers are not Subprocessors - models are deployed within Customer's dedicated cloud environment and Customer Data is not transmitted to model providers.
Where the transfer of Personal Information originating from the EEA requires a transfer mechanism under the GDPR, the Standard Contractual Clauses adopted by the European Commission under Decision (EU) 2021/914 (the "SCCs"), Module Two (controller to processor), are deemed entered into between Customer (as data exporter) and BEEM (as data importer) and are incorporated into this DPA by reference, completed as follows:
For transfers subject to UK data protection law, the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner (in its version in force) applies mutatis mutandis, completed with the information above. For transfers subject to the Swiss Federal Act on Data Protection (FADP), the SCCs apply as adapted to the FADP, including as to the competent Swiss supervisory authority and applicable Swiss law where required.
Companies that trust us





