Legal
Data Processing Agreement.
Last updated: 25 September 2026
This Data Processing Agreement (the DPA) forms part of the agreement between BrainBoxIT Limited trading as BeckonDesk (the processor), a company registered in England and Wales, company number 11703272, and the customer (the controller) for the provision of the BeckonDesk visitor and contractor management platform.
It reflects the requirements of the UK GDPR, the EU GDPR where applicable, the UK Data Protection Act 2018, and applicable US state privacy laws. Where a customer has signed a negotiated agreement that addresses data processing, that agreement takes precedence over this document.
1. Roles
The customer is the data controller for personal data processed within their tenant, including the visitor, contractor and employee records they collect. BrainBoxIT Limited is the data processor and processes that personal data only on the customer's documented instructions.
2. Subject matter and duration
- Subject matter. Provision of the BeckonDesk visitor and contractor access management platform, including sign-in, sanctions and watchlist screening, badge issue, host notification and evacuation roll call.
- Duration. The term of the underlying agreement, plus a 30-day grace period for data export, after which customer data is deleted.
- Categories of data subject. The customer's visitors, contractors, delivery drivers, employees and hosts.
- Categories of personal data. Name, employer, contact details, host and visit purpose, arrival and departure times, badge records, signatures where the customer collects them, photographs where the customer enables them, insurance and certification documents uploaded by contractors, and sanctions screening results.
- Special category data. BeckonDesk does not use facial recognition and does not store biometric identifiers. Government-ID documents are not scanned or stored.
3. Sub-processors
The customer authorises BeckonDesk to engage the following sub-processors. BeckonDesk will give the customer at least 30 days' notice before adding or replacing a sub-processor, during which the customer may object on reasonable data protection grounds.
- Microsoft Azure. Hosting, database, storage and identity. United States.
- Microsoft Entra External ID. Customer authentication. United States.
- Microsoft Azure OpenAI Service. Sanctions match adjudication and delivery label extraction. East US.
Two flows send personal data to the Azure OpenAI Service: sanctions adjudication sends the visitor's name and company together with the matched sanctions entries, and delivery label scanning sends the parcel label image, which typically contains a recipient name and address. Microsoft does not use Azure OpenAI Service customer data to train or improve its models, and content is not retained for model improvement.
Sanctions and watchlist screening runs against published government lists, including UK OFSI, UN, EU, OFAC SDN and the US Consolidated Screening List. Screening is performed inside the BeckonDesk environment. Visitor data is not sent to a third-party screening provider.
4. Security measures
- Encryption in transit and at rest.
- Per-tenant data isolation, so one customer's records are not reachable from another tenant.
- The database endpoint is restricted by firewall to Azure services only and is not open to general internet traffic. Credentials are held in Azure Key Vault and never in source code.
- Role-based access control, with staff access limited to what a support request requires.
- Automated daily backup with a 7-day point-in-time restore window.
- Retention controls that purge visitor records on the schedule the customer configures.
BeckonDesk will notify the controller without undue delay, and in any case within 48 hours of becoming aware, of a personal data breach affecting their data. The controller's own obligation to notify its supervisory authority runs to 72 hours, so this commitment is set shorter to leave the controller time to act.
5. Hosting location and international transfers
Customer data is hosted in Microsoft Azure regions in the United States. The application runs in East US and the database is located in Central US. Data is not replicated outside the United States without the controller's written instruction.
Where the controller is established in the United Kingdom or the European Economic Area, or otherwise processes personal data subject to UK or EU GDPR, transfers to the United States are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or under the EU Standard Contractual Clauses, as applicable. Those clauses are incorporated into this DPA by reference and take precedence over any conflicting term.
6. Data subject rights
The platform provides the controller with tools to search, export, correct and delete records within their tenant, which covers most access, rectification, portability and erasure requests. Where a request cannot be fulfilled through the platform, BeckonDesk will assist the controller on request and within a timeframe that allows the controller to meet its statutory deadline.
7. Audit
The controller may audit BeckonDesk's compliance with this DPA. That right is satisfied in the first instance by documentation: BeckonDesk will provide its security documentation and complete the controller's security questionnaire, under NDA where BeckonDesk asks for one.
Where the documentation is not sufficient to demonstrate compliance, the controller may carry out an on-site or live audit once per 12 months, on 30 days' written notice, during business hours, and subject to confidentiality. Each party bears its own costs; the controller bears BeckonDesk's reasonable costs for work beyond a standard documentation response.
Independent audit reports for the underlying platform layer, including ISO 27001 and SOC 2, are published by Microsoft Azure and are not BeckonDesk certifications.
8. Return and deletion
On termination the controller may export their data for 30 days. After that period BeckonDesk deletes customer data from the live platform. Backups are retained for a 7-day point-in-time restore window and are deleted when that window expires. BeckonDesk will confirm deletion in writing on request.
Contact
Data protection enquiries: [email protected]. How BeckonDesk handles personal data collected through this website is set out separately in the privacy notice.