Data Processing Agreement
Last updated 17 August 2026.
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (“Customer”) and demobolt (“we”, “us”). It applies automatically wherever we process personal data on your behalf. No signature is required for it to be binding. If your procurement process needs a countersigned copy, ask us at hello@demobolt.io — the terms do not change.
Words like controller, processor, personal data, processing and data subject carry the meaning given to them in the GDPR. “Data Protection Laws” means the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and US state privacy laws, each as they apply to the processing.
1. Who is responsible for what
You are the controller. We are your processor. You decide what to capture, what to keep and what to publish. We store, transform and serve it on your instructions and for no other purpose.
Where you are yourself a processor acting for your own customer, we act as your sub-processor and the same terms apply. Under US state privacy laws we act as your service provider or processor: we will not sell or share the personal data, will not keep, use or disclose it for any purpose other than performing the Service, and will not combine it with data from anyone else.
Account and billing data about you as our customer — the names and contact details of your users, your plan, your payments — is different. We decide how to handle that, so for that data we are the controller and our Privacy Policy applies instead of this DPA.
2. Your responsibilities
You are solely responsible for the accuracy, quality and lawfulness of the personal data you put into the Service, for the means by which you obtained it, and for the instructions you give us. You confirm you have a lawful basis to provide it to us and to have us process it, that you have given any notices and obtained any consents required, and that your instructions will not put us in breach of Data Protection Laws.
Because of how the Service works, we do not monitor or control what you capture. The categories of personal data and the categories of data subjects processed through your account are therefore your choice alone, and yours to know. A captured page may incidentally contain personal data visible in your own systems — names, email addresses, customer records on screen. We do not choose that content and we cannot see it on your behalf. The Service gives you editing, replacement and blurring tools before you publish, and using them is your responsibility.
You must not put into the Service any protected health information subject to HIPAA, payment card data, government identification numbers, financial account credentials, biometric identifiers, special categories of personal data under Article 9 GDPR, personal data relating to criminal convictions, or personal data of children. The Service is not designed or certified for any of these.
You will indemnify us against all claims, losses and costs arising from personal data you provided in breach of this section, or from instructions that breach Data Protection Laws.
You also decide when a demo is published. Publishing makes the content reachable by anyone with the link, and any personal data still visible in it becomes visible to them. That disclosure is your processing decision, not ours.
3. What we will do
- Process personal data only on your documented instructions, including for transfers. Your use and configuration of the Service, together with the Terms and this DPA, are those instructions. If we are required by law to process it otherwise, we will tell you first unless the law forbids it.
- Tell you if, in our opinion, an instruction infringes Data Protection Laws — though assessing your own lawful basis stays your job.
- Keep anyone with access bound by confidentiality, and give access only to those who need it to run the Service.
- Keep the technical and organisational security measures set out in Annex 2, and not materially reduce them during your subscription.
- Keep records of the processing we carry out for you, and make available the information reasonably needed to show we meet our obligations under this DPA.
4. Sub-processors
You give us general authorisation to engage sub-processors. The current list is published at demobolt.io/subprocessors, which forms part of this DPA.
We will give at least 10 days’ notice before a new or replacement sub-processor starts processing your personal data, by updating that page and emailing the address on your account. Email is enough. You may object within that period on reasonable grounds relating to data protection, in writing. We will work with you in good faith to find a solution; if we cannot, you may terminate the affected part of the Service and we will refund the unused portion of what you prepaid for it. That is your sole remedy, and note that some sub-processors are essential — objecting to one may mean we cannot provide the Service to you at all.
Where we have to replace a sub-processor urgently — because of a security problem, an outage, or because the provider stops serving us — we may do it immediately and tell you as soon as we reasonably can. You keep the same right to object afterwards.
A sub-processor may engage its own sub-processors, on the same terms and with the same protections, and they are covered by the list and the notice above in the same way.
We bind every sub-processor in writing to obligations no less protective than those in this DPA, and we remain responsible to you for what they do as if we had done it ourselves.
5. Requests from individuals
The Service lets you view, correct and delete the personal data in your account, so you can answer most requests yourself. If you need a copy of it to hand to someone, ask us and we will send it to you.
If someone contacts us directly about data inside your account, we will not respond on your behalf beyond telling them to contact you, and we will pass the request on promptly. Where you cannot answer a request through the Service alone, we will give you reasonable assistance.
6. Help with your other obligations
Taking into account the nature of the processing and what is available to us, we will give you reasonable assistance with data protection impact assessments, prior consultations with a regulator, and your own security obligations. Where that assistance goes beyond what is straightforward, we may charge our reasonable costs, and we will agree them with you first.
7. Security incidents
We will notify you without undue delay once we have become aware of and confirmed a personal data breach affecting your personal data in our systems. This tracks Article 33(2) GDPR, which is the standard that applies to a processor. We do not commit to a fixed number of hours, because the 72-hour deadline in Article 33(1) is yours as controller, and a rigid clock on us would only mean handing you an incomplete picture in order to meet it.
The notice will describe what we actually know at the time: the nature of the incident, the categories and rough number of people and records involved, the likely consequences, what we are doing about it, and who to contact. We send information in stages as the investigation develops, and we will give you what you reasonably need to meet your own notification duties in time.
Only a confirmed breach counts. Unsuccessful attempts that do not compromise personal data — pings, port scans, failed log-ins, blocked attacks — are not security incidents and are not notified. Our notifying you is not an admission of fault or liability.
8. International transfers
We are established in, and run the Service from, the United States. Data you send us is processed there and by the sub-processors listed at demobolt.io/subprocessors.
Where you transfer personal data protected by EU, UK or Swiss law to us, the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914 are incorporated into this DPA by reference and apply automatically. By accepting this DPA both of us are treated as having signed them. They apply as follows:
- Module Two (controller to processor) applies, or Module Three (processor to sub-processor) where you are yourself a processor.
- You are the data exporter and we are the data importer. Clause 7, the docking clause, applies.
- In Clause 9, Option 2 (general written authorisation) applies, with the 30-day notice period in section 4 above.
- In Clause 11, the optional independent dispute resolution wording does not apply. In Clause 17, the governing law is that of Ireland, and in Clause 18 the forum is the courts of Ireland. Where you are established in an EU member state, that state’s law and courts apply instead.
- Annex I is filled in by Annex 1 below, Annex II by Annex 2 below, and Annex III by the sub-processor list.
- For the UK, the ICO’s International Data Transfer Addendum applies to the clauses above, with the tables completed by the same annexes. For Switzerland, references to the GDPR are read as references to the FADP and the Swiss Federal Data Protection and Information Commissioner is the supervisory authority.
demobolt is not certified under the EU-US Data Privacy Framework, so we do not rely on it for the transfer to us. Some of our sub-processors are certified, which is marked on the sub-processor list. If a transfer mechanism we rely on is invalidated, we will adopt a lawful alternative without undue delay rather than stop processing. If the Standard Contractual Clauses conflict with anything in this DPA, the Clauses win.
9. Deletion and return
You can delete your content at any time while your account is open, and ask us for a copy of it whenever you need one.
When the agreement ends, you choose whether we return the personal data to you or delete it. Tell us which within 30 days of the end. If you ask for it back, we will send you a copy in a commonly used format and delete it once you have it. If you ask us to delete it, or if you tell us nothing within those 30 days, we delete it on the timetable in the Privacy Policy. You can change your choice at any point before we act on it.
We delete existing copies too, unless the law requires us to keep them — in which case we tell you what we kept and why, and keep protecting it under this DPA. Copies in routine backups are overwritten in the ordinary course rather than picked out individually, and stay protected until they are. We confirm deletion in writing within 30 days of completing it if you ask.
10. Audits
On reasonable written notice, no more than once a year — and also after a confirmed security incident affecting you — we will give you the information reasonably necessary to demonstrate our compliance with this DPA, and answer a security questionnaire.
Where that is genuinely not enough to satisfy Data Protection Laws, we will allow an audit by an independent, reputable auditor you appoint, at your expense, at a time we agree, under confidentiality, and in a way that does not disrupt the Service or reveal other customers’ data.
11. Liability
Each party’s total liability arising out of or relating to this DPA, and to the Standard Contractual Clauses where they apply, is subject to the exclusions and the cap in the Terms of Service. This does not limit either party’s liability to a data subject under the third-party beneficiary rights in the Clauses.
If anything in this DPA conflicts with the Terms of Service, this DPA wins for matters of data protection.
Annex 1 — Details of the processing
- Subject matter — providing the demobolt service: capturing, storing, editing, hosting and serving interactive product demos.
- Duration — for as long as your account is open, plus the retention periods in the Privacy Policy.
- Nature and purpose — storage, hosting, transformation, compression, thumbnail generation, delivery over a content network, and publication where you choose to publish.
- Categories of data subjects — your users and staff; and any individuals whose personal data happens to appear in a page you capture, which is determined by you alone.
- Types of personal data — account identity and contact details; technical data such as IP address, browser and device information; and any personal data visible in the pages you capture, which may include names, email addresses, customer records and account identifiers shown in your own systems. Special categories of personal data are not permitted.
- Frequency — continuous, for as long as you use the Service.
- Competent supervisory authority — the Irish Data Protection Commission, or the authority of your own member state where you are established in the EU.
Annex 2 — Security measures
- Encryption in transit (TLS) and at rest.
- Each customer’s data separated at the database level and enforced by row-level security, so one account cannot read another’s.
- Access limited to those who need it, and reviewed when roles change.
- Passwords stored only as salted cryptographic hashes.
- Managed, patched infrastructure from established providers, with protection against network attacks and rate limiting on the API.
- Automated backups run by our database provider.
- Logging and error monitoring, with alerting on failures.
- Third-party advertising and analytics trackers stripped out of captures at publish, on a best-effort basis against a known list.
- Automated tests and static analysis run before changes reach production.
Annex 3 — Sub-processors
The current list is published at demobolt.io/subprocessors and forms part of this DPA.
Contact
Questions about this DPA, requests for a signed copy, and requests for our transfer documentation all go to hello@demobolt.io.