Data Processing Addendum
For teams and businesses.
If your organisation uses playbakk and we process personal data on your behalf, our Data Processing Addendum (DPA) sets out how. This page summarises it. The signed DPA is the binding document.
Request a signed copy
Email legal@playbakk.com with your organisation’s legal name, registered address, a signatory’s name and email, and the playbakk accounts it should cover. We will send the DPA for electronic signature. The DPA is being finalised with counsel and cannot be signed until the operating company is confirmed.
Parties and roles
The DPA is between your organisation (the controller) and [Operator legal entity — to be confirmed] (the processor). For account security, abuse prevention and billing, playbakk acts as an independent controller, as described in the privacy notice.
What we process — and what we do not
- Processed on our servers: account identifiers and display names of your users, authenticator configuration (encrypted), hashed recovery codes and session tokens, security activity, and consent request records (an opaque recording identifier, requested and granted modes, an optional guest name and a signed receipt).
- Not processed on our servers: recordings, clips, captions and transcripts. They are created and stored on your users’ devices. Cloud transcription and AI editing are currently switched off; if they are introduced, they will be opt-in and the DPA and sub-processor list will be updated first.
Summary of terms
- Instructions. We process personal data only on your documented instructions, including these terms and your use of the service.
- Confidentiality. Anyone authorised to process the data is bound by confidentiality.
- Security. We maintain the technical and organisational measures described in our trust centre and security page, including mandatory multi-factor authentication, encryption of authenticator secrets, hashing of recovery codes and session tokens, and HTTPS for all traffic.
- Sub-processors. You give general authorisation for the providers on our sub-processor list. We will tell you in advance about changes and you may object on reasonable grounds.
- International transfers. Covered by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where required.
- Assistance. We will help you respond to data-subject requests, carry out data-protection impact assessments and meet your security obligations, taking into account what we can see — which excludes your users’ local media.
- Personal data breaches. We will notify you without undue delay after becoming aware of a breach affecting your data. [Requires counsel review: fixed notification window, e.g. 48 or 72 hours]
- Deletion and return. When the service ends, we delete the server-side personal data we hold for you, unless law requires us to keep it. Local media remains on your users’ devices under their control.
- Audits. We will make available the information needed to demonstrate compliance and allow for reasonable audits. We do not currently hold third-party certifications such as ISO 27001 or SOC 2.
[Requires counsel review: full DPA text, liability cap interaction with the terms, governing law and UK GDPR / EU GDPR Article 28 mapping]