This policy explains what personal data Beacon MSP collects, why, how long we keep it, and what rights you have over it.
Effective date: 10 June 2026 · Controller: Beacon MSP · Contact: hello@beaconmsp.io
Beacon MSP ("Beacon", "we", "our") operates the Beacon compliance monitoring platform accessible at beaconmsp.io. We are the data controller for personal data processed in connection with operating the platform and our subscriber relationships. Our contact address for privacy matters is hello@beaconmsp.io.
We collect the minimum data necessary to deliver the service and meet our legal obligations.
When an MSP organisation signs up, we collect:
Purpose: Authentication, account management, service communication.
Legal basis (GDPR): Art. 6(1)(b) — performance of the contract.
To connect your managed client tenants, subscribers provide:
These credentials are sensitive business data, not personal data about individuals. Decrypted values exist only in memory for the duration of a compliance scan and are never included in exports, logs, API responses, or support sessions.
Purpose: Performing automated Azure security compliance scans on behalf of the subscriber.
Legal basis (GDPR): Art. 6(1)(b) — performance of the contract.
We store the output of each scan run: compliance check results, risk scores, finding details, and historical trend data scoped to the subscriber's organisation. This data belongs to the subscriber and is exported or deleted on request.
Legal basis: Art. 6(1)(b) — performance of the contract.
Every administrative action performed by platform users is recorded in a tamper-evident audit log, including: login and logout events, user invitations, role changes, client additions, credential updates, and webhook configurations. Each entry captures actor user ID, timestamp, source IP address, and action detail.
Purpose: Security accountability, fraud prevention, incident investigation.
Legal basis: Art. 6(1)(f) — legitimate interests (platform security and integrity).
Subscription payments are processed by Stripe. We do not store card numbers, bank details, or full payment instrument data. Stripe provides us with a token, last-four digits, card brand, and expiry date for display purposes. We store transaction IDs and subscription status records needed to manage your account.
Legal basis: Art. 6(1)(b) — contract performance; Art. 6(1)(c) — legal obligation (financial record-keeping).
We collect standard server-side request logs (IP address, endpoint, HTTP status, response time) for performance monitoring, abuse detection, and error diagnosis via Sentry. We do not use client-side analytics cookies or tracking pixels.
Legal basis: Art. 6(1)(f) — legitimate interests (service reliability and security).
We use session cookies only. A single HTTP-only, Secure, SameSite=Strict session cookie is set on login to maintain your authenticated session. It is deleted when you log out or when the session expires. We do not use advertising cookies, cross-site tracking cookies, or any third-party analytics cookies. No cookie consent banner is required for session-only cookies under ePrivacy rules.
| Data type | Retention period |
|---|---|
| Account and user data | For the duration of the active subscription plus 30 days after termination (to allow data export), then deleted. |
| Azure credential data | Same as account data. Deleted immediately on manual credential removal or on account termination. |
| Compliance scan results | For the duration of the active subscription plus 30 days, then deleted. |
| Audit logs | 12 months from the date of the log entry, then deleted. |
| Billing records | 7 years from the transaction date, as required by financial regulations. |
| Server/request logs | 30 days rolling, then purged automatically. |
We engage the following sub-processors to deliver the platform. Each is bound by a data processing agreement and appropriate safeguards for international transfers.
| Sub-processor | Role | Location |
|---|---|---|
| Railway | Application hosting and PostgreSQL database | EU and US regions |
| Vercel | CDN and static asset delivery | US (global CDN) |
| Stripe | Payment processing and subscription billing | US (EU entity available) |
| Resend | Transactional email delivery (account notifications, alerts) | US |
| Sentry | Error tracking and application performance monitoring | US |
| Microsoft Azure | API connectivity for Azure compliance scanning (outbound calls only) | Global (Microsoft data centres) |
We do not sell your data to any third party. We do not share personal data with advertisers or data brokers.
Several sub-processors listed above are based in the United States or process data globally. Where personal data is transferred from the European Economic Area (EEA) to a third country, we rely on the European Commission's Standard Contractual Clauses (SCCs) as the legal transfer mechanism. We verify that each sub-processor either holds an adequacy decision, operates under SCCs, or participates in an equivalent approved framework. You may request a copy of the applicable transfer safeguards by emailing hello@beaconmsp.io.
If you are located in the EEA or UK, you have the following rights regarding your personal data:
To exercise any of these rights, email hello@beaconmsp.io. We will respond within 30 days. If you believe we have not handled your data lawfully, you have the right to lodge a complaint with your local supervisory authority (e.g., the Dutch Autoriteit Persoonsgegevens, the ICO in the UK, or the relevant authority in your EU member state).
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or destruction. Key controls include:
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware, and affected data subjects without undue delay where required by law.
We may update this Privacy Policy from time to time. For material changes — those that significantly affect how we process your data or your rights — we will provide at least 30 days' notice by email to the account holder before the changes take effect. The updated policy will also be posted at this URL with a revised effective date. Continued use of the service after the effective date constitutes acceptance of the updated policy.
For any privacy-related questions, requests, or complaints, contact us at: