Skip to content

Updated 2026-09-01

Privacy policy

Beams AB processes personal data when you use our platform and when your guests follow a broadcast. This policy describes what we collect, why, how long we keep it and the rights you have under the GDPR.

Controller and processor

Beams AB, reg. no. 559xxx-xxxx, Stockholm, is the controller for data about our customers and visitors to beams.se.

When you broadcast an event through Beams you are the controller for your attendees and Beams is your processor. A data processing agreement forms part of the contract and governs what we may do with attendee data.

Data about you as a customer

When you create an account we process your name, email address, a hashed password, your chosen language and the organisation you belong to. The legal basis is performance of a contract.

  • Account details: name, email, language, role in the organisation
  • Company details: legal name, registration number, billing and address details
  • Audit log: who published a broadcast, revealed a stream key or muted an attendee

Data about broadcast attendees

What is collected depends on how the organiser configured their Beam. At minimum only an anonymous session identifier is stored.

  • Display name and email address when the organiser asks for them
  • Questions and votes the attendee submits
  • Technical data: pseudonymised IP address (HMAC-SHA-256), browser user agent and approximate country
  • Watch time and connection timestamps, aggregated per minute for analytics

Why we process the data

The data is used to deliver the broadcast, moderate questions, prevent abuse, produce analytics for the organiser and invoice the volume actually delivered.

We never sell personal data and do not use it for profiling or advertising.

Retention

Account data is kept for the duration of the contract and then for 24 months for accounting and support reasons. Accounting records are kept for seven years as required by Swedish law.

Attendee data and recordings are deleted according to the retention period in the chosen plan, by default 30 to 365 days. The organiser can request earlier deletion.

Where data is processed

The database, application and realtime layer run inside the EU. Email is sent through Postmark.

The video feed is received in the Cloudflare data centre nearest the studio and then delivered over Cloudflare's global network. Cloudflare Stream is not covered by Cloudflare's Regional Services, which means we cannot guarantee that video data is processed or stored exclusively inside the EU. Transfers outside the EU/EEA take place under the European Commission standard contractual clauses and Cloudflare's data processing agreement.

If your organisation requires a binding commitment to EU-only processing, contact us before signing so we can go through the available options.

Sub-processors

We use the following sub-processors to deliver the service:

  • Cloudflare, Inc. — video ingest, transcoding and delivery
  • Postmark (ActiveCampaign, LLC) — transactional email
  • Anthropic PBC — brand analysis of a customer public website, on request only
  • Google LLC — Google Analytics on beams.se, only after consent

Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and to object to processing. Contact us at dataskydd@beams.se.

You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection, imy.se.

Security

Passwords are stored hashed. Stream keys and restream keys are encrypted at rest with AES-256-GCM and can only be read by users with explicit permission — every such reveal is logged. All traffic runs over TLS.