Data Processing Addendum
Last updated: June 26, 2026 · Version 1.1
How to execute this DPA
This Data Processing Addendum (“DPA”) is incorporated by reference into the Recordable Master Subscription Agreement or order form between Recordable and the customer (“Customer”) and takes effect on the date the Customer first uses the Service. If your procurement process requires a counter-signed copy, or if your DPO needs negotiated changes (e.g. additional security controls, jurisdiction-specific clauses), email privacy@recordable.ai and we will return a signed PDF within five business days.
This document is provided in English; the English version controls. Translations may be made available for convenience but are not legally binding.
1. Definitions
Capitalized terms used but not defined in this DPA have the meanings given to them in the Master Subscription Agreement. The following definitions apply:
- “GDPR” means Regulation (EU) 2016/679 (the General Data Protection Regulation), as amended or replaced from time to time, together with any UK-equivalent enacted by reference (UK GDPR).
- “Customer Personal Data”means any personal data that Recordable processes on behalf of the Customer in providing the Service. For the avoidance of doubt, it includes recordings, screenshots, click event metadata, typed-text metadata, end-user account data of the Customer’s users, and any personal data captured incidentally within recordings.
- “Sub-processor” means a third party engaged by Recordable to process Customer Personal Data in connection with the Service.
- “SCCs” means the Standard Contractual Clauses approved by European Commission Decision (EU) 2021/914 of 4 June 2021, including the Module Two (controller-to-processor) clauses, as updated from time to time.
- “Data Subject”, “Controller”, “Processor”, and “Personal Data Breach” have the meanings given in Art. 4 GDPR.
2. Roles of the Parties
For the purposes of Customer Personal Data, the Customer is the Controller and Recordable is the Processor. Where the Customer acts as a Processor for an upstream Controller (e.g. the Customer is itself processing personal data on behalf of its own customers), Recordable acts as a Sub-processor and the obligations in this DPA flow accordingly.
Each party is responsible for its own compliance with the GDPR and other applicable data protection law in respect of its role.
3. Subject Matter, Nature, Purpose, and Duration
Subject matter: the processing of Customer Personal Data for the purpose of providing the Service described in the Master Subscription Agreement, namely the recording, redaction, AI-assisted documentation, storage, sharing, and translation of workflow recordings.
Nature of the processing: collection, transmission, storage, organisation, alteration (including AI-generated step descriptions and translations), retrieval, consultation, disclosure to Sub-processors, and erasure.
Purpose: to enable the Customer to capture, document, share, and govern workflows within its organisation.
Duration: for the term of the Master Subscription Agreement plus any retention period required by §10 of this DPA.
4. Categories of Data Subjects and Personal Data
Categories of Data Subjects:the Customer’s employees, contractors, and authorised users; and any natural persons whose personal data appears within recordings the Customer chooses to capture (e.g. colleagues, customers visible on screen).
Categories of Personal Data:
- Identification and account data: name, email, language preference, authentication tokens.
- Workflow content: redacted screenshots, step descriptions, click coordinates, action types, text typed into form fields during recording, video recordings, drawing and blur layers.
- Usage and audit data: feature events, IP address (transient, for security and rate limiting), audit log entries.
- Special categories of personal data: not intentionally collected. The Customer acknowledges that screenshots may contain incidental personal data and is responsible for instructing its users to redact such data using the in-product review step before upload.
5. Customer Instructions
Recordable will process Customer Personal Data only on documented instructions from the Customer, including with regard to transfers to third countries. The Master Subscription Agreement, this DPA, the Service’s in-product configuration (workspace settings, visibility, retention controls), and reasonable written instructions submitted by the Customer are deemed documented instructions.
Recordable will inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
6. Confidentiality
Recordable will ensure that personnel authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to Customer Personal Data is granted on a need-to-know basis and is reviewed on personnel changes.
Recordable personnel access the content of a Customer workspace only where the Customer has explicitly enabled support access for that workspace. Such access is read-only, time-limited, used solely to resolve a support request, recorded in the workspace’s audit log, and may be revoked by the Customer at any time in workspace settings. Enabling support access constitutes a documented instruction under Section 5.
7. Security Measures (Art. 32 GDPR)
Recordable implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of Customer Personal Data in transit (TLS 1.2+).
- Encryption of Customer Personal Data at rest within the object storage layer (Cloudflare R2) and database layer (Neon).
- Logical separation of Customer data via per-workspace scoping enforced at the application layer and reinforced by row-level filters in the database.
- Access controls: SSO/Clerk-managed authentication for Recordable personnel, principle of least privilege for production access, mandatory MFA.
- Audit logging of administrative actions on Customer workspaces, with logs retained for at least 12 months.
- A documented incident response procedure with defined roles, escalation paths, and the 72-hour notification commitment in §11.
- Regular review of Sub-processor security posture and at least annual review of cryptographic configurations and key rotations.
Recordable will, on the Customer’s reasonable request and subject to applicable confidentiality obligations, make available a current summary of these measures.
8. Sub-processors
The Customer authorises Recordable to engage Sub-processors to process Customer Personal Data, subject to the conditions in this section. The current list of Sub-processors, together with their processing region and applicable transfer mechanism, is published in the “Third-Party Processors” and “International Transfers” sections of the Privacy Policy and is incorporated into this DPA by reference.
Recordable will: (a) impose on each Sub-processor data protection obligations no less protective than those in this DPA; (b) remain responsible for the acts and omissions of Sub-processors as if they were its own; and (c) provide at least 30 days’ prior notice of any material change to the Sub-processor list (e.g. adding a new AI provider). The Customer may object on reasonable data-protection grounds within that period; if the parties cannot agree on a remedy, the Customer may terminate the affected portion of the Service for convenience without penalty.
Customers who require advance written notice rather than the published list may subscribe to sub-processor change notifications.
9. International Transfers
Where Customer Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, the parties agree that the SCCs apply and are incorporated into this DPA by reference, with the following choices:
- Module Two (controller-to-processor) applies between the Customer and Recordable.
- Module Three (processor-to-processor) applies where the Customer is itself a Processor and Recordable is the Sub-processor.
- The optional docking clause (Clause 7) is included.
- For Clause 9 (Use of sub-processors), Option 2 (general written authorisation) is selected, with the 30-day notice period in §8 above.
- The supervisory authority is the lead authority for the Customer’s establishment in the EEA, or the Belgian Data Protection Authority (APD/GBA) where the Customer has no EEA establishment.
- The governing law is the law of Belgium; disputes are subject to the courts of Brussels.
- Annex I (parties, processing description) and Annex II (technical and organisational measures) are completed by reference to §3, §4, and §7 of this DPA.
- Annex III (Sub-processors) is completed by reference to the Privacy Policy.
For transfers from the United Kingdom, the parties incorporate the UK International Data Transfer Addendum to the SCCs (issued by the UK ICO under s.119A Data Protection Act 2018).
Where a Sub-processor is certified under the EU-US Data Privacy Framework, transfers to that Sub-processor may rely on that certification in lieu of the SCCs while the certification remains valid.
10. Retention, Deletion, and Return
On termination or expiry of the Master Subscription Agreement, and at the Customer’s option, Recordable will return all Customer Personal Data to the Customer (via the in-product export described in the “Your Rights” section of the Privacy Policy) or delete it. Unless the Customer specifies otherwise in writing within 30 days of termination, deletion is the default.
Deletion takes effect within 30 days, save for: (a) data retained on encrypted backup media pending the next backup rotation cycle (rotated at least every 90 days), and (b) data Recordable is required by law to retain (e.g. tax records).
11. Personal Data Breach Notification
Recordable will notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of any Personal Data Breach affecting Customer Personal Data. The notification will include, to the extent then known:
- The nature of the breach, including the categories and approximate number of Data Subjects and records affected.
- The likely consequences of the breach.
- Measures taken or proposed to address the breach and mitigate its possible adverse effects.
- The contact point at Recordable for further information.
Recordable will provide reasonable assistance to the Customer in complying with its own Art. 33 and 34 GDPR obligations. Notification by Recordable is not an acknowledgment of fault or liability.
12. Assistance with Data Subject Requests
Taking into account the nature of the processing, Recordable will assist the Customer by appropriate technical and organisational measures, insofar as possible, to fulfil the Customer’s obligation to respond to requests from Data Subjects exercising their rights under Articles 15 to 22 GDPR. The Service includes self-service data export and account-deletion endpoints; for requests that cannot be fulfilled through those endpoints, Recordable will respond to written requests from the Customer within ten business days.
13. DPIA and Prior Consultation
Recordable will provide reasonable assistance to the Customer in carrying out Data Protection Impact Assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR, where such assessments relate to the Service. Recordable maintains a current DPIA covering its own processing of Customer Personal Data and will share a redacted summary on request.
14. Audits
Recordable will make available to the Customer all information necessary to demonstrate compliance with the obligations in Article 28 GDPR. The Customer may, no more than once per twelve-month period, conduct an audit of Recordable’s data-protection practices, subject to:
- 30 days’ prior written notice (except in the event of a Personal Data Breach, where notice may be shorter).
- Reasonable scope, duration, and confidentiality protections.
- Conduct in a manner that does not unreasonably interfere with Recordable’s business operations.
- The Customer bearing its own costs and the reasonable costs of Recordable’s personnel time.
Where Recordable holds an independent third-party assessment (e.g. SOC 2 Type II, ISO 27001), the Customer agrees to accept that assessment in lieu of an on-site audit, except where applicable law requires otherwise or where a Personal Data Breach has occurred.
15. Liability
The liability of each party arising out of or in connection with this DPA, whether in contract, tort (including negligence), or any other basis of liability, is subject to the limitations and exclusions of liability set out in the Master Subscription Agreement. Nothing in this DPA limits or excludes either party’s liability for the rights of Data Subjects under Clause 12 of the SCCs or where such limitation is prohibited by applicable law.
16. Term, Conflict, and Order of Precedence
This DPA is effective from the date the Customer first uses the Service and continues for so long as Recordable processes Customer Personal Data. In the event of any conflict between this DPA, the Master Subscription Agreement, and the SCCs, the order of precedence is: (1) the SCCs (where transfer scenarios apply); (2) this DPA; (3) the Master Subscription Agreement.
17. Contact
For all matters arising under this DPA, including data subject requests routed via the Customer, audit requests, sub-processor objections, and breach notifications: