Privacy Policy

What personal data we collect, why, and the rights you have over it.

Last updated July 1, 2026

In plain English

We collect the minimum we need to run the product and bill you. We never sell your data, never use your recordings to train models, and you can export or delete everything on request.

1. Who we are

DemoRiff, Inc. is the controller of personal data processed through our website and accounts. Where we process Customer Content on behalf of a business customer, that customer is the controller and we are the processor, governed by our Data Processing Agreement.

2. What we collect

CategoryExamplesPurposeBasis
AccountName, work email, role, organisationProvide the Service, authenticateContract
BillingBilling contact, address, tax ID, last four digits of cardProcess payment, meet tax obligationsContract, legal obligation
UsageFeature interactions, render counts, error reportsOperate, secure and improve the ServiceLegitimate interests
Customer ContentRecordings, audio, transcripts, generated assetsProvide the ServiceContract (as processor)
Viewer analyticsWatch depth, device type, truncated IPProvide analytics to our customersProcessor, per customer instruction
MarketingEmail, engagement with our emailsSend material you asked forConsent

Full card details are handled by our payment processor and never reach our systems.

3. What we do not do

  • We do not sell personal data, and we do not share it for cross-context behavioural advertising.
  • We do not use Customer Content to train machine learning models, in any form, on any plan.
  • We do not permit our model subprocessors to retain Customer Content after inference.
  • We do not read Customer Content except for support you request, an investigation of suspected abuse, or a legal requirement.

4. Retention

Account and billing records are kept for the life of the account plus seven years where tax law requires. Customer Content is kept until you delete it or 90 days after account termination. Usage logs are kept for 24 months. Audit logs follow your workspace's configured retention, up to seven years.

5. International transfers

We operate processing regions in the United States, the European Union and Australia. Where personal data is transferred out of the EEA or UK, we rely on Standard Contractual Clauses and the UK Addendum, together with supplementary technical measures including encryption in transit and at rest.

6. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, and to data portability. Exercise them at privacy@demoriff.com; we respond within thirty days. You may also lodge a complaint with your supervisory authority.

If your data is held by a business customer of ours, direct your request to them; we will assist them in fulfilling it.

7. Cookies

Our website uses strictly necessary cookies for authentication and, with your consent, analytics cookies. Share pages support a cookieless analytics mode that our customers can enable, which produces aggregate retention data without persisting an identifier.

8. Security

AES-256 encryption at rest, TLS 1.3 in transit, per-workspace key scoping, least-privilege internal access with hardware-key MFA and quarterly review, annual third-party penetration testing, and SOC 2 Type II and ISO 27001 certification. Details at /security.

9. Children

The Service is not directed to anyone under 16 and we do not knowingly collect their personal data.

10. Changes and contact

Material changes are notified by email at least thirty days in advance. Contact our Data Protection Officer at privacy@demoriff.com.