LAST UPDATED: AUGUST 16, 2026

Data Processing Addendum

1. Parties and scope

The customer is “Controller” or “Business,” and BestEstateLLC, an Illinois company operating under the BeeCNC trade name, is “Processor” or “Service Provider” for personal data BeeCNC handles on the customer’s behalf. Each party remains independently responsible for personal data it controls for its own purposes. This DPA applies while BeeCNC processes covered data under the agreement.

2. Documented instructions

BeeCNC will process covered data only to provide, secure, support, and improve the contracted service; comply with documented customer instructions; or satisfy applicable law. The agreement, product configuration, support requests, and lawful written directions constitute instructions. BeeCNC will notify the customer if an instruction appears unlawful unless prohibited.

3. Customer responsibilities

The customer will provide required notices, establish a lawful basis, collect valid marketing consent when required, respond to individuals, configure appropriate retention, and ensure submitted data and instructions are lawful. The customer will not submit scraped, purchased, sensitive, children’s, health, financial-account, government-identifier, or other high-risk data unless expressly agreed in writing after appropriate review.

4. Confidentiality and security

BeeCNC will ensure authorized personnel are bound by confidentiality and will maintain measures appropriate to risk. Current measures include managed cloud infrastructure, access controls, tenant-scoped authorization, encrypted transport, validated inputs, rate limiting, audit records, webhook verification, dependency review, security testing, minimized analytics, and incident response.

5. Subprocessors

The customer gives general authorization for the providers on the Subprocessor List. BeeCNC will impose appropriate data-protection obligations and remains responsible for subprocessor performance as required by law. The customer may object to a material addition on reasonable data-protection grounds; the parties will attempt a commercially reasonable resolution.

6. Individual requests

Taking account of the processing, BeeCNC will provide reasonable technical and organizational assistance for access, correction, deletion, restriction, portability, objection, opt-out, consent, and appeal requests. BeeCNC may direct a requester to the customer and will not independently fulfill a client-workspace request unless authorized or legally required.

7. Incidents and compliance assistance

BeeCNC will notify the customer without undue delay after confirming a personal-data breach affecting covered data and will provide available information reasonably needed for notices, risk assessments, and mitigation. BeeCNC will reasonably assist with security obligations, impact assessments, regulator consultations, and documented compliance inquiries, considering the nature of processing and available information.

8. Return and deletion

At the customer’s choice and subject to product capabilities, BeeCNC will return or delete covered data after service termination, unless law requires retention. Residual backup copies will remain protected, unavailable for ordinary use, and deleted through the normal backup cycle.

9. Audits

BeeCNC will make reasonably necessary compliance information available. Where that is insufficient, the customer may request an audit no more than annually, during business hours, with reasonable notice, confidentiality protections, scope limitations, and responsibility for its costs, unless a regulator or confirmed incident reasonably requires otherwise.

10. U.S. state terms

BeeCNC will not sell covered data, share it for cross-context behavioral advertising, retain/use/disclose it outside the direct business relationship except as permitted by law, or combine it with unrelated personal data except as legally permitted. BeeCNC will assist the customer with applicable consumer requests and assessments. The parties agree this DPA is a binding processing contract where required by U.S. state law.

11. UK terms and transfers

For UK restricted transfers, the parties will use an applicable adequacy regulation or execute the then-current UK International Data Transfer Agreement or UK Addendum as necessary. The customer is exporter and BeeCNC is importer unless the transfer facts require otherwise. The parties will complete required tables and supplementary measures before a restricted transfer.

Appendix A — processing details

Appendix B — instructions and contacts

Controller contact: the customer account owner or designated privacy contact. Processor: BestEstateLLC d/b/a BeeCNC, 7705 New England Ave, Burbank, Illinois 60459, USA. Privacy contact: privacy@beecnc.com. Security reports: security@beecnc.com. Commercial support: legal@beecnc.com.