Data Processing Agreement
Effective: July 13, 2026
1. Scope & Roles
This Data Processing Agreement ("DPA") forms part of the PgBeam Terms of Service and governs the processing of personal data by PgBeam on behalf of the Customer.
Controller: The Customer is the Controller for all personal data contained in database queries routed through PgBeam. PgBeam is also a Controller for account data (name, email, billing information) collected directly from users.
Processor: PgBeam acts as a Processor for database traffic (queries, results, and connection metadata) that passes through the PgBeam proxy infrastructure.
2. Processing Details
Nature of processing: PostgreSQL wire protocol proxying with policy enforcement (read-only checks, table allowlists, PII masking, query budgets), audit logging of statements and decisions, connection pooling, query routing, and transient in-memory caching of query results.
Purpose: To provide the PgBeam service as described in the Terms of Service: safe, policy-enforced PostgreSQL access for applications and AI agents, with connection pooling and query caching.
Duration: For the duration of the Customer's use of the PgBeam service, plus any applicable retention periods.
Categories of data subjects: The Customer's end users and any individuals whose personal data is stored in the Customer's database and queried through PgBeam.
Types of personal data: Any personal data contained in the Customer's database queries and results. PgBeam does not inspect, parse, or classify query content. Data flows through the proxy transparently.
3. Processor Obligations
PgBeam shall:
Documented instructions: Process personal data only on documented instructions from the Customer, unless required by applicable law.
Confidentiality: Ensure that persons authorized to process personal data are subject to confidentiality obligations.
Security measures: Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk (see Section 5).
Sub-processor management: Not engage another processor without prior written authorization from the Customer. Current sub-processors are listed in Section 4.
Data subject requests: Assist the Customer in responding to data subject access, rectification, erasure, and portability requests.
Deletion on termination: Upon termination of the service, delete all personal data processed on behalf of the Customer within 90 days, unless retention is required by applicable law.
4. Sub-Processors
The following sub-processors are authorized to process personal data on behalf of the Customer:
Fly.io, Inc.: Hosting for the globally distributed database proxy (data plane). Processing includes routing, connection pooling, policy enforcement, and transient in-memory caching of the database traffic that passes through the PgBeam proxy. The data plane spans multiple metros worldwide and routes each connection to the nearest one via global anycast.
Amazon Web Services (AWS): Control plane hosting (United States). Processing includes compute, DNS, and secrets management.
Vercel: Dashboard and marketing site hosting (United States).
PlanetScale: Managed PostgreSQL database for PgBeam's control plane data.
Stripe: Payment processing and subscription management.
PostHog: Product analytics for the dashboard and website (hosted in the European Union). This processes account identifiers and product usage data, not the Customer's database traffic.
BetterStack: Uptime monitoring and log management.
Google LLC: Transactional email delivery via Google Workspace and Gmail SMTP, such as account and billing notifications (currently our email provider, United States).
GitHub: Source code hosting and container image registry.
5. Security Measures
PgBeam implements the following technical and organizational security measures:
Encryption in transit: All connections use TLS 1.2 or higher. Client-to-proxy and proxy-to-upstream connections are encrypted using PostgreSQL-native SSL negotiation.
Encryption at rest: Database credentials are encrypted using AES-256-GCM.
Network isolation: Data plane proxies communicate over a private encrypted mesh network. Inter-region traffic does not traverse the public internet.
Authentication: JWT-based authentication via JWKS verification. API key authentication for programmatic access. Two-factor authentication support.
Access control: Role-based access control via organization membership. Per-project resource isolation (connection limits, rate limits, cache namespaces).
Credential passthrough: PgBeam does not store or log plaintext database credentials. Client credentials are passed through transparently to the upstream database.
6. International Transfers
Where personal data is transferred outside the European Economic Area (EEA) to a sub-processor, PgBeam relies on the European Commission's Standard Contractual Clauses (SCCs) adopted on June 4, 2021, incorporating the module appropriate to the transfer. For transfers to United States-hosted sub-processors (for example AWS, Vercel, and Google LLC for transactional email), the SCCs are the primary transfer mechanism; where a sub-processor maintains an active EU-US Data Privacy Framework (DPF) certification, PgBeam may also rely on that certification for the relevant transfer.
For transfers subject to United Kingdom data protection law, the SCCs are supplemented by the UK International Data Transfer Addendum (or, where used, the UK International Data Transfer Agreement). For transfers subject to Swiss data protection law, the SCCs apply with the adaptations recognized by the Swiss Federal Data Protection and Information Commissioner (FDPIC).
PgBeam applies supplementary technical and organizational measures that support these transfers, including encryption in transit and at rest and access controls (see Section 5). The data plane spans multiple metros worldwide and routes each connection to the nearest one via global anycast. Product analytics data processed by PostHog is hosted in the European Union and is not transferred outside the EEA on that leg.
7. Breach Notification
PgBeam shall notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach. The notification shall include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.
Contact
Questions about this DPA? Contact us at privacy@pgbeam.com.