Data processing addendum
Last updated 13 August 2026
For customers who need GDPR or UK GDPR terms in writing. This forms part of the terms of service and applies whenever we process personal data on your behalf.
1. Roles
You are the controller of the personal data contained in captures your application creates. We are the processor. We process that data only on your documented instructions — which, in practice, are the settings on your project and the calls your SDK makes.
For your own account data (your email, billing details) we are the controller, and the privacy policy governs it.
2. Subject matter and duration
We process personal data for as long as you hold an account, plus your configured retention window. Processing ends when you delete the data, the retention window expires, or the agreement terminates — whichever is first.
3. Nature and purpose
Storing rendered captures, generating expiring signed URLs for them, delivering those URLs to endpoints you nominate, and showing them back to you in the dashboard.
4. Categories of data and data subjects
Data subjects: your end users, and any individual whose personal data happens to be visible on a captured screen.
Categories: whatever was on screen at the moment of capture, plus the page URL and title, viewport dimensions, user agent, country derived from IP, and any params and caption you attach.
We have no way to know in advance what a capture will contain. If your screens can show special-category data — health, financial, biometric — configure redact or exclude so it is destroyed in the browser before encoding, and never reaches us at all.
5. Our obligations
- Process personal data only on your documented instructions, unless the law requires otherwise — in which case we will tell you first, if we are allowed to.
- Ensure everyone we authorise to process it is under a duty of confidentiality.
- Apply the security measures in section 7.
- Help you respond to data subject requests, and with DPIAs and regulator consultations, so far as is reasonable.
- Delete or return personal data at the end of the agreement.
- Make available the information you need to demonstrate compliance.
6. Sub-processors
You authorise the sub-processors listed at screen2api.com/subprocessors, which forms part of this addendum. At the date above they are Supabase Inc. (database, authentication and object storage), Vercel Inc. (hosting and edge network), Functional Software, Inc. trading as Sentry (error tracking), and Sendinblue SAS trading as Brevo (transactional and list email).
That page is maintained as the single list so this clause and the privacy policy cannot drift apart; where they differ, that page is current.
We will give you 30 days’ notice before adding or replacing one. If you reasonably object on data-protection grounds, you may terminate the affected service without penalty. Each sub-processor is bound by terms no less protective than these.
7. Security
- Encryption in transit (TLS) and at rest.
- Files held in a private bucket, reachable only via signed URLs that expire — never later than the capture, which is deleted after three days by default and seven at the outside.
- Row-level security in the database, so one organisation cannot read another’s rows even if application code is wrong.
- Secret API keys stored only as SHA-256 hashes and shown exactly once.
- Webhook payloads signed with HMAC-SHA256 over a timestamped body, so recipients can detect tampering and replay.
- Redaction applied in the browser before encoding, so redacted pixels are never transmitted.
- Access to production limited to staff who need it.
8. Breach notification
We will notify you without undue delay, and in any case within 72 hours, of becoming aware of a personal data breach affecting your data — with what we know about its nature, likely consequences, and what we are doing about it.
9. International transfers
Where personal data leaves the EEA or UK, the transfer relies on the European Commission’s Standard Contractual Clauses, together with the UK Addendum where applicable, which are incorporated here by reference. Storage is in the EU for every account; data residency elsewhere is available on the Business plan on request.
10. Audits
On reasonable written notice, no more than once a year, we will provide the information needed to demonstrate compliance with this addendum. Where available we will offer third-party audit reports in place of an on-site audit.
11. Deletion
You can delete captures from the dashboard at any time. On termination we delete your personal data within 30 days, except where the law requires us to keep it — in which case we keep it only for as long as required, and only for that purpose.
12. Signing this
Accepting the terms of service accepts this addendum. If your procurement process needs a countersigned copy, email legal@screen2api.com and we will arrange it.