Skip to content

Draft, pending legal review. This document is a working draft and is not yet in effect. Last updated October 5, 2026.

Paperbeam, Inc.

Data Processing Addendum

Last updated · Draft
This DPA forms part of the Terms of Service and applies whenever Paperbeam processes personal data on a customer’s behalf. A countersigned copy is available from legal@paperbeam.ai.

1. Definitions

“Customer Personal Data” means personal data within Customer Data that Paperbeam processes on behalf of the Customer. “Data Protection Laws” means the GDPR, the UK GDPR, the Swiss FADP, the CCPA/CPRA and other laws that apply to that processing. Other terms have the meanings given in those laws or in the Terms.

2. Roles and instructions

The Customer is the controller and Paperbeam is the processor (or, for CCPA purposes, the service provider) of Customer Personal Data. Paperbeam will process it only on the Customer’s documented instructions, which are the Terms, this DPA and the Customer’s configuration of the Service, unless required otherwise by law, in which case we will tell the Customer first where permitted.

3. Scope of processing

  • Subject matter: producing and delivering internal company newspapers and archives.
  • Duration: the subscription term plus the deletion period in Section 9.
  • Data subjects: the Customer’s employees, contractors, customers, prospects and others who appear in connected Sources.
  • Categories of data: names, work contact details, job titles, and business content such as call transcripts, CRM records, messages and tickets. The Customer should not connect Sources containing special-category data without a lawful basis.

4. Paperbeam’s obligations

  • Ensure personnel with access are bound by confidentiality.
  • Maintain the technical and organizational measures in Annex II, including encryption in transit (TLS 1.2+) and at rest (AES-256), tenant isolation through row-level security, least-privilege access and audit logging.
  • Not use Customer Personal Data to train AI models, or for any purpose other than providing the Service.
  • Not sell or share Customer Personal Data as those terms are defined under the CCPA.
  • Assist the Customer with data subject requests, impact assessments and consultations with regulators.

5. Subprocessors

The Customer authorizes Paperbeam to engage the subprocessors listed on our subprocessors page. Paperbeam imposes data protection terms on each subprocessor at least as protective as this DPA and remains responsible for their performance. We will give at least 30 days’ notice before adding or replacing a subprocessor. The Customer may object on reasonable data protection grounds; if we cannot address the objection, the Customer may terminate the affected Service and receive a pro-rata refund of prepaid fees.

6. International transfers

Where Customer Personal Data is transferred from the EEA, UK or Switzerland to a country without an adequacy decision, the parties agree to the EU Standard Contractual Clauses (Module Two, controller to processor, and Module Three where applicable), with the UK Addendum and Swiss amendments as required. The Annexes to the SCCs are completed by Sections 3 and 4 of this DPA and Annex II.

7. Personal data breaches

Paperbeam will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe the nature of the breach, the likely consequences, and the measures taken or proposed, with updates as more is known.

8. Audits

On request, Paperbeam will make available information reasonably necessary to demonstrate compliance, including third-party audit reports once available. Our SOC 2 Type I audit is in progress. The Customer may conduct an audit no more than once a year, on 30 days’ notice, at its own cost, if those materials are not sufficient.

9. Return and deletion

On cancellation, Customer Data remains available for export for 30 days. Paperbeam then deletes Customer Personal Data from production systems, and from backups within their normal rotation, unless retention is required by law. During the subscription, raw source content is deleted on a short rolling schedule and the Customer may configure further retention limits.

10. Annex II: security measures (summary)

  • Encryption in transit and at rest; KMS envelope encryption for tokens and keys, decrypted only at use.
  • A workspace_id on every record and Postgres row-level security on every tenant table.
  • Zero-data-retention AI endpoints by default; models receive no write access to customer systems.
  • SSO for all users; SAML SSO, SCIM and audit logs available on Business plans.
  • Error monitoring with content scrubbing; secrets never written to logs.
  • Annual independent penetration testing, beginning before public launch.

11. Contact

Data protection questions: privacy@paperbeam.ai. Security incidents and vulnerability reports: security@paperbeam.ai.