Terms of Service

Effective date: May 25, 2026

These Terms of Service (the “Terms”) govern access to and use of the Beacon BCMS platform (the “Service”) provided by Outamation (“Beacon,” “we,” “us,” or “our”). By accessing or using the Service, the customer organization (the “Customer”) and its authorized users agree to these Terms.

1. Accounts and access

Beacon is an invitation-only platform. Tenant accounts are provisioned exclusively by Beacon platform administrators. Individual user accounts within a tenant are provisioned by the tenant’s COMPANY_ADMIN or by Beacon staff. There is no self-service signup.

Each user is responsible for maintaining the confidentiality of their credentials and for all activity that occurs under their account. Platform administrators authenticate using a password and time-based one-time password (TOTP); all other roles authenticate exclusively via Microsoft Entra ID SSO. Users must not share their credentials or authentication tokens with any other person.

Customer administrators are responsible for managing their users’ access, including promptly deactivating accounts for users who should no longer have access to the Service.

2. Acceptable use

The Customer and its authorized users agree not to:

  • Use the Service for any unlawful purpose or in violation of any applicable law or regulation.
  • Attempt to access, view, or modify data belonging to any other tenant or any user for whom you are not authorized.
  • Probe, scan, or test the security or availability of the Service, or attempt to circumvent any security control, authentication mechanism, or rate limit.
  • Use automated scripts, bots, or crawlers to scrape data from the Service.
  • Transmit unlawful, harmful, defamatory, or otherwise objectionable content through the Service’s notification or messaging features.
  • Introduce malicious code, viruses, or any software intended to damage or disrupt the Service or its infrastructure.
  • Misuse the in-app Help assistant by submitting personal data, security credentials, or confidential information not related to Beacon platform questions (see Section 5).

Beacon may suspend or terminate access where misuse is reasonably suspected, without prior notice where immediate action is required to protect the integrity of the platform or the data of other customers.

3. Third-party services

The Service is delivered in part through the following third-party providers. By using the Service, users acknowledge that their data may be processed by these providers in accordance with their respective terms and privacy policies:

  • Twilio - WhatsApp business messaging for emergency notifications, drill announcements, and alerts. Terms: twilio.com/legal/tos.
  • Amazon Web Services (AWS) - SMS delivery via AWS End User Messaging (PinpointSMSVoiceV2) and application hosting infrastructure. Terms: aws.amazon.com/service-terms.
  • Google Gemini AI - powers the in-app Help assistant. Questions submitted to the chatbot are processed by Google. Terms: ai.google.dev/gemini-api/terms.
  • Microsoft Azure / Microsoft Entra ID - SSO authentication for all non-platform-administrator users. Terms: azure.microsoft.com/support/legal.
  • SMTP email provider - transactional email delivery. The specific provider is configured per deployment (examples: Office 365, Exchange, Amazon SES).

Beacon is not responsible for the availability, accuracy, or compliance practices of third-party services. Outages or failures in third-party services (including Twilio, AWS, or Microsoft) may affect notification delivery and platform availability without constituting a breach by Beacon.

4. Emergency notifications and mobile number consent

By providing a mobile number in the platform and enabling SMS or WhatsApp opt-in, users and Contacts expressly consent to receive emergency alert messages, drill-related notifications, and incident communications related to their organization’s registered locations and business continuity activities.

Standard carrier message and data rates may apply. Beacon is not responsible for carrier charges incurred by message recipients.

SMS delivery uses AWS End User Messaging with a toll-free origination number for US/Canadian recipients and an alphanumeric Sender ID for international recipients. WhatsApp delivery uses Twilio with Meta-approved Content templates. Production WhatsApp messages are business-initiated and must comply with Meta’s messaging policies.

Email opt-out requests require administrator approval before taking effect, given the role of email in life-safety and emergency communications. WhatsApp opt-out is fully self-service. SMS opt-out requests also require administrator approval. Emergency alert messages are dispatched with category-preference bypass (“bypassCategoryPref”) to ensure life-safety notifications reach recipients even when non-emergency notification categories are muted.

5. AI Help assistant

The in-app Help chatbot is powered by Google Gemini AI and is provided as a convenience for answering questions about the Beacon platform’s features and workflows.

  • Do not submit personal or confidential informationin chatbot questions. Questions are forwarded to Google’s Gemini API. Beacon filters known sensitive patterns before transmission, but users are responsible for the content of their questions.
  • AI responses are informational only and do not constitute legal, compliance, regulatory, or professional advice. The chatbot answers questions about Beacon product features; it cannot advise on whether a specific BCP plan meets any particular regulatory requirement.
  • All chatbot interactions (questions and answers) are logged in Beacon’s own database for cost tracking and quality review purposes.
  • The chatbot is rate-limited to 15 questions per user per minute.

6. Customer data and data processing

The Customer retains ownership of all data it submits to the Service. Beacon processes that data solely to provide the Service as described in these Terms and in the Privacy Policy.

Beacon acts as a data processor on behalf of the Customer, which is the data controller for personal data entered into the Service. A Data Processing Agreement (DPA) governing the processing of personal data in accordance with applicable data protection law (including GDPR where applicable) is available upon request at info@outamation.com.

The Customer is responsible for ensuring it has an appropriate legal basis for providing personal data (including employee and Contact mobile numbers, email addresses, and other personal information) to the Service, and for complying with applicable data protection obligations as data controller.

7. Subscription, fees, and access

Paid plans are billed in advance per the pricing communicated at the time of order. Fees, billing cycles, and usage limits are governed by the applicable order form or subscription agreement between the Customer and Beacon. Access to the Service is contingent on the subscription remaining in good standing.

8. Service availability and SLA

Beacon targets 99.5% monthly uptime for the core platform. Planned maintenance will be announced to customer administrators in advance. Unplanned outages will be communicated through available channels as promptly as possible.

Beacon is not liable for interruptions or degradation of service caused by third-party providers (including AWS, Twilio, Microsoft, or Google), force majeure events, or actions taken by the Customer or its users that affect platform integrity.

Where a separate Service Level Agreement (SLA) is agreed in writing, its terms govern over this section.

9. Disclaimers and limitation of liability

The Service supports business continuity planning, drill execution, and incident coordination. It does not replace the Customer’s own judgment, professional advice, emergency services, or regulatory compliance obligations.

The Service is provided “as is” and “as available.” To the maximum extent permitted by applicable law, Beacon disclaims all implied warranties, including fitness for a particular purpose and merchantability. Beacon’s total liability to the Customer arising out of or related to these Terms is limited to the fees paid by the Customer in the twelve months preceding the claim.

Beacon is not liable for: (a) notification delivery failures caused by third-party carriers, SMS providers, or WhatsApp platform restrictions; (b) emergency alert mismatches caused by inaccurate location data (coordinates, area codes) entered by the Customer; or (c) any harm resulting from reliance on AI chatbot responses.

10. Termination

Either party may terminate a subscription as set out in the applicable order form or subscription agreement. On termination, the Customer may request an export of its operational data within 30 days before it is removed from the platform. Audit log data is retained by Beacon as required for its own compliance and security obligations.

Beacon may terminate or suspend access immediately for material breach of these Terms, including but not limited to unauthorized access attempts, misuse of notification features, or non-payment.

11. Changes to these Terms

Beacon may update these Terms from time to time. Material changes will be communicated to customer administrators at least 30 days before taking effect, except where immediate changes are required by law or to address a security risk. Continued use of the Service after the effective date of updated Terms constitutes acceptance of the revised Terms.

12. Governing law

These Terms are governed by the laws of the jurisdiction in which Outamation is incorporated, without regard to conflict of law principles. Any disputes arising out of these Terms will be subject to the exclusive jurisdiction of the courts of that jurisdiction, unless a separate agreement specifies otherwise.

13. Contact

Questions about these Terms, requests for a Data Processing Agreement, or notices of breach should be directed to: info@outamation.com.