Data Processing Agreement

Our standard DPA, incorporated by reference into the Terms for customers subject to GDPR, UK GDPR or similar laws.

Last updated July 1, 2026

In plain English

When we process data on your behalf, you are in charge and we follow your instructions. We keep it secure, tell you quickly if something goes wrong, use only the subprocessors on our published list, and delete everything when you ask.

1. Roles and scope

This Agreement applies where DemoRiff processes Personal Data on behalf of Customer in providing the Service. Customer is the Controller; DemoRiff is the Processor. Where Customer is itself a processor, DemoRiff is a sub-processor and the same obligations apply.

2. Processing details

ItemDetail
Subject matterProvision of the DemoRiff video and documentation platform
DurationThe term of the Agreement, plus the deletion period
Nature and purposeHosting, transcription, synthesis, rendering, translation, hosting and analytics
Types of Personal DataIdentifiers and content appearing in Customer Content; viewer analytics data; end-user account data
Categories of data subjectCustomer's personnel, Customer's customers appearing in recordings, and viewers of published assets

3. Instructions

DemoRiff processes Personal Data only on documented instructions from Customer, including with regard to international transfers, unless required by law — in which case DemoRiff informs Customer before processing unless that law prohibits it. Use of the Service constitutes an instruction to process as described in the Documentation.

4. No model training

DemoRiff will not use Customer Personal Data or Customer Content to train, fine-tune, evaluate or otherwise develop machine learning models, and requires the same of every sub-processor providing inference services. This obligation survives termination.

5. Confidentiality and security

Personnel with access are bound by confidentiality obligations. DemoRiff implements the technical and organisational measures described in Annex II and at /security, including encryption in transit and at rest, access control, logging, resilience testing and a documented incident response plan.

6. Sub-processors

Customer provides general authorisation for the sub-processors listed at /legal/subprocessors. DemoRiff gives at least thirty days' notice before adding or replacing a sub-processor. Customer may object on reasonable data protection grounds, in which case the parties will work in good faith to resolve it; failing resolution, Customer may terminate the affected Service without penalty.

7. Data subject rights and assistance

DemoRiff provides functionality enabling Customer to access, correct, export and delete Personal Data. Where a data subject contacts DemoRiff directly, DemoRiff refers them to Customer. DemoRiff assists Customer with data protection impact assessments and prior consultations, taking into account the nature of processing.

8. Personal data breach

DemoRiff notifies Customer without undue delay and in any case within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data, with the information available at that time and updates as the investigation progresses.

9. Deletion and return

On termination, Customer may export Personal Data for 90 days. Thereafter DemoRiff deletes it from production, replicas and backups on a documented schedule, and will issue a signed certificate of deletion on request.

10. Audit

DemoRiff makes available its SOC 2 Type II report and ISO 27001 certificate, and responds to reasonable security questionnaires. Where a Controller requires an on-site audit, the parties will agree scope and timing, no more than once annually except following a Personal Data Breach.

11. International transfers

The Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Modules Two and Three as applicable, together with the UK International Data Transfer Addendum, are incorporated by reference and apply to transfers from the EEA, UK and Switzerland.