Data Processing Agreement
Our standard DPA, incorporated by reference into the Terms for customers subject to GDPR, UK GDPR or similar laws.
Last updated July 1, 2026
In plain English
When we process data on your behalf, you are in charge and we follow your instructions. We keep it secure, tell you quickly if something goes wrong, use only the subprocessors on our published list, and delete everything when you ask.
1. Roles and scope
This Agreement applies where DemoRiff processes Personal Data on behalf of Customer in providing the Service. Customer is the Controller; DemoRiff is the Processor. Where Customer is itself a processor, DemoRiff is a sub-processor and the same obligations apply.
2. Processing details
| Item | Detail |
|---|---|
| Subject matter | Provision of the DemoRiff video and documentation platform |
| Duration | The term of the Agreement, plus the deletion period |
| Nature and purpose | Hosting, transcription, synthesis, rendering, translation, hosting and analytics |
| Types of Personal Data | Identifiers and content appearing in Customer Content; viewer analytics data; end-user account data |
| Categories of data subject | Customer's personnel, Customer's customers appearing in recordings, and viewers of published assets |
3. Instructions
DemoRiff processes Personal Data only on documented instructions from Customer, including with regard to international transfers, unless required by law — in which case DemoRiff informs Customer before processing unless that law prohibits it. Use of the Service constitutes an instruction to process as described in the Documentation.
4. No model training
DemoRiff will not use Customer Personal Data or Customer Content to train, fine-tune, evaluate or otherwise develop machine learning models, and requires the same of every sub-processor providing inference services. This obligation survives termination.
5. Confidentiality and security
Personnel with access are bound by confidentiality obligations. DemoRiff implements the technical and organisational measures described in Annex II and at /security, including encryption in transit and at rest, access control, logging, resilience testing and a documented incident response plan.
6. Sub-processors
Customer provides general authorisation for the sub-processors listed at /legal/subprocessors. DemoRiff gives at least thirty days' notice before adding or replacing a sub-processor. Customer may object on reasonable data protection grounds, in which case the parties will work in good faith to resolve it; failing resolution, Customer may terminate the affected Service without penalty.
7. Data subject rights and assistance
DemoRiff provides functionality enabling Customer to access, correct, export and delete Personal Data. Where a data subject contacts DemoRiff directly, DemoRiff refers them to Customer. DemoRiff assists Customer with data protection impact assessments and prior consultations, taking into account the nature of processing.
8. Personal data breach
DemoRiff notifies Customer without undue delay and in any case within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data, with the information available at that time and updates as the investigation progresses.
9. Deletion and return
On termination, Customer may export Personal Data for 90 days. Thereafter DemoRiff deletes it from production, replicas and backups on a documented schedule, and will issue a signed certificate of deletion on request.
10. Audit
DemoRiff makes available its SOC 2 Type II report and ISO 27001 certificate, and responds to reasonable security questionnaires. Where a Controller requires an on-site audit, the parties will agree scope and timing, no more than once annually except following a Personal Data Breach.
11. International transfers
The Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Modules Two and Three as applicable, together with the UK International Data Transfer Addendum, are incorporated by reference and apply to transfers from the EEA, UK and Switzerland.