← Back to home

Data Processing Agreement (DPA)

Last updated: 2026-07-21. Summary of our standard processing terms. A signed, countersigned DPA is available to business customers on request — see “Executing this DPA” below.

1. Roles

For personal data your organisation submits to Beat Breeze (team member accounts, venue and zone names, uploaded content — brand assets, images, voiceovers — and usage records), you are the data controller and BMAsia Group (billing contracted through BMASIA LIMITED, Hong Kong) is the data processor. For our own billing and account records we act as a controller under our Privacy Policy.

2. Scope of processing

We process personal data only to provide the Beat Breeze service as described in the Terms of Service: operating accounts and team access, streaming and scheduling music, generating content you request, and producing usage and billing records. We do not sell personal data and do not process it for advertising.

3. Security measures

  • Encryption in transit (TLS) for all traffic; encrypted storage for content and databases.
  • Authentication is provided by Logto. We never store passwords.
  • Role-based access control enforced server-side, scoped per location and zone.
  • Production access restricted to authorised personnel; secrets managed via environment isolation.

4. Sub-processors

Logto (Silverhand Inc.) is listed for authentication, account identity, organisations, invitations, sessions, and MFA. The maintained list states each purpose and processing location at beatbreeze.io/legal/subprocessors. We update that page before engaging a new sub-processor; signed-DPA customers can request advance notice of changes.

5. Data-subject requests

We assist you in fulfilling data-subject rights requests (access, correction, deletion, export, objection) for data we process on your behalf. Requests can be routed through our privacy-requests channel or your account contact; we respond within 30 days as required by Thailand's PDPA.

6. Breach notification

If we become aware of a personal-data breach affecting your data, we notify your designated contact without undue delay and within 72 hours of confirmation, including the nature, scope, and remediation steps, consistent with PDPA notification duties.

7. International transfers

Hosting is primarily in Singapore. Logto processes identity data in the Beat Breeze production Logto Cloud EU tenant; Silverhand Inc. is a U.S. company. Other sub-processors may process data in the United States or other stated regions. Transfers are covered by contractual safeguards providing protection equivalent to Thai PDPA requirements (and GDPR standard contractual clauses where applicable).

8. Deletion on termination

When your account closes, we delete or anonymise personal data we process on your behalf within 30 days, except where retention is legally required (e.g. tax and billing records).

9. Executing this DPA

Enterprise and corporate-contract customers who need a signed DPA (including specific annexes for their compliance program) can request one via Contact → Sales or their account manager.