Security and data handling

Your customers' data is your responsibility, and you are trusting us with part of it. This page sets out plainly where data lives, who can reach it, what our people are bound by, and how we handle GDPR when clients are in the EU and delivery is not.

If something here doesn't satisfy your security review, ask us. We would rather answer a hard question than have you assume.

Draft for your review

This page is written as an accurate-by-default draft: it describes how a managed outsourcing operation like Beacon normally works, and deliberately avoids claiming any certification, audit or compliance status. Every section carries a note listing the specifics you or your legal adviser need to verify or fill in. Nothing here should be published as a compliance commitment until you have checked it.

In particular: we have made no claim to ISO 27001, SOC 2, PCI DSS or any other certification, because we cannot verify one on your behalf.

How Beacon handles your data

Where your data lives

Beacon does not run its own copy of your customer database. Our team works inside the systems you already use — your helpdesk, CRM, inbox and accounting tools — under accounts you create and control. Your data stays in your systems, hosted wherever you have chosen to host them.

The information we do hold on our side is limited to what running the service requires: the written procedures for your account, our internal quality reviews and reports, and the operational notes your Beacon manager keeps. We keep this in our managed business systems, restricted to the people working on your account.

We do not copy production data into spreadsheets, personal drives or local machines for convenience, and we do not use your customer data to train any model.

To verify: Confirm the specific systems Beacon holds account documentation in, and their hosting region, before publishing.

Access controls

Access follows least privilege: each person on your account gets only the permissions their tasks require, in the tools you grant, and nothing beyond that. Where your tools support roles, we ask for the narrowest role that still allows the work.

Named individual accounts only. We do not share logins between team members, because shared accounts make it impossible to say who did what.

Access is granted when someone joins your account and revoked when they leave it or leave Beacon. Offboarding includes a check that every account, tool and credential has actually been removed, confirmed in writing to you.

You can revoke any access yourself, at any time, without asking us first.

To verify: Confirm your actual controls before publishing: password manager in use, whether multi-factor authentication is mandatory, and how often access reviews happen.

NDAs and confidentiality

Every Beacon employee signs a confidentiality agreement covering client and customer information as a condition of employment, and it survives the end of their employment.

Confidentiality and data handling are covered in induction training before anyone is given access to a client system, and specific rules for your account are written into its procedures.

We are happy to sign your own NDA or data processing agreement. Send it with your discovery call and we will review it with you rather than after the fact.

To verify: Confirm the exact scope and duration of the employee confidentiality clause with your legal adviser before publishing.

Device and network policy

Client work is done on equipment Beacon provides and manages, from our team members in Sri Lanka and Madagascar, over a secure network. This is a deliberate trade-off: it costs more than an unmanaged setup and it is far easier to control.

Personal devices are not used for client work. Where work outside the standard setup is genuinely necessary, it is agreed with you in advance and set up on managed equipment under the same rules.

Screens are positioned so that client information is not visible to others, and workspaces are cleared of client material at the end of a shift.

To verify: Confirm the technical specifics before publishing: disk encryption, endpoint protection, patching cadence, mobile phone policy on the floor, and any physical access controls at each site.

GDPR: EU clients, non-EU delivery

Most Beacon clients are established in the EU and our delivery teams sit in Sri Lanka and Madagascar. Neither country currently benefits from a European Commission adequacy decision, so a transfer mechanism is required — this is a normal, solvable situation, not a grey area, and it needs to be documented properly rather than glossed over.

In the usual arrangement, you are the controller of your customers' personal data and Beacon acts as a processor on your instructions. That relationship needs a written data processing agreement under Article 28, covering purpose, duration, security measures, sub-processors, assistance with data subject requests and what happens to data at the end of the contract.

For the transfer itself, the standard route is the European Commission's Standard Contractual Clauses together with a transfer impact assessment for the destination country. We will sign your SCCs and DPA, or provide ours for your review.

If your data involves special categories, children's data, health or financial records, tell us early. Some work is better kept in the EU, and we would rather say that than take it on.

To verify: This section must be reviewed by your data protection adviser before publishing. Confirm which SCC modules you use, whether a transfer impact assessment exists per location, your named sub-processors, your retention and deletion periods, and whether a DPO or EU representative is appointed.

Incidents and reporting

If we become aware of a security incident affecting your data, your named Beacon manager tells you directly and promptly, with what we know, what we don't yet know and what we are doing about it. As a processor, notifying regulators or affected individuals is your decision to make — our job is to give you the facts fast enough for you to make it, and to assist with the investigation.

After any incident we write up the cause and the change we made, and share it with you.

To verify: Confirm your committed notification window and internal escalation path before publishing.

Documents and questionnaires

We can complete your vendor security questionnaire and sign your data processing agreement and Standard Contractual Clauses as part of onboarding. Ask your Beacon contact, or raise it on the discovery call.

Privacy notice

How we handle personal data on our own website and in our own business.

Read the privacy notice

Terms

The contractual terms that sit behind a Beacon engagement.

Read the terms

Bring your security questions.

If your review process needs answers before a commercial conversation, we'll do it in that order.