Data Processing Agreement
This Data Processing Agreement (“DPA”) is part of the Terms of Service between Dumpling Software UG (haftungsbeschränkt), Kollwitzstrasse 76, 10435 Berlin, Germany (“Supadata”) and the customer (“Customer”). It applies whenever Supadata processes personal data on Customer’s behalf while providing the Supadata API (“Service”). It applies automatically.
1. Definitions
Terms such as “personal data”, “processing”, “controller”, “processor” and “personal data breach” have the meaning given in Regulation (EU) 2016/679 (“GDPR”).
“Customer Content” means URLs, files, prompts and other input Customer submits to the Service, and the transcripts, metadata and page content the Service returns.
2. Roles
2.1 For Customer Content, Customer is the controller and Supadata is the processor acting on Customer’s instructions.
2.2 For Customer’s account and billing data, Supadata is an independent controller; the Privacy Policy describes this processing.
2.3 Customer warrants that it has a legal basis for any personal data in Customer Content and that its instructions comply with data-protection law.
3. Processing details
Subject matter and purpose: retrieving publicly available video, audio and web content requested by Customer, transcribing it, extracting metadata and structured data, returning the results, and caching results for performance optimization. Duration: the term of the Terms plus the retention periods in section 9. Personal data: any personal data contained in the publicly available content Customer requests or in the files and prompts Customer supplies. Data subjects: persons whose personal data appears in that content. Special categories (Art. 9 GDPR): not intended. Customer must not submit such data without a legal basis under Art. 9(2) GDPR.
4. Instructions, confidentiality and no AI training
Supadata processes Customer Content only on Customer’s documented instructions, which consist of the Terms, this DPA and Customer’s use of the documented API features, unless EU or Member State law requires otherwise. Supadata will inform Customer if it believes an instruction infringes data-protection law. Persons authorised to process Customer Content are bound by confidentiality. Supadata does not use Customer Content to train, fine-tune or improve machine learning or artificial intelligence models.
5. Security
Supadata implements the technical and organisational measures in the Annex and maintains a level of security appropriate to the risk (Art. 32 GDPR). Supadata may update the Annex provided the overall level of security is not reduced.
6. Sub-processors
Customer authorises Supadata to engage the sub-processors listed at supadata.ai/legal/sub-processors. Supadata informs Customer of additions or replacements by updating that page. Customer may object on reasonable data-protection grounds within 14 days of the update; if no solution is found, Customer’s sole remedy is to terminate the affected Service. Supadata binds each sub-processor to obligations equivalent to this DPA and remains responsible for its performance.
7. International transfers
Some sub-processors process Customer Content outside the EEA, mainly in the United States. For those, Supadata relies on the EU Standard Contractual Clauses (Decision (EU) 2021/914, Module 3) or the sub-processor’s EU-US Data Privacy Framework certification.
8. Assistance, breaches and audits
8.1 Taking into account the nature of the processing and the information available to it, Supadata will assist Customer with data-subject requests and with Customer’s obligations under Art. 32 to 36 GDPR. Requests from data subjects that reach Supadata directly are forwarded to Customer. Customer bears the reasonable costs of assistance that goes beyond the features of the Service.
8.2 Supadata will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Content and will provide the information required by Art. 33(3) GDPR as it becomes available.
8.3 On reasonable request, Supadata will provide the information necessary to demonstrate compliance with Art. 28 GDPR, such as a description of its security measures. Where that information is insufficient and an audit is required by data-protection law or a supervisory authority, Customer or an independent auditor bound by confidentiality may audit Supadata’s relevant processing at Customer’s cost, at most once per year, on 30 days’ notice, during business hours and without disrupting Supadata’s operations.
9. Retention and deletion
Customer Content is processed transiently. Job results can be retrieved for 1 hour (single jobs) or 24 hours (batch jobs) and are then deleted; temporary media copies are deleted after processing; media files supplied through a direct file URL are not stored, though the URL and a failure marker may be cached briefly. Results of public content may be cached for performance optimization. Request logs containing metadata only (endpoint, status, timing, organisation ID) are kept for the duration of the customer relationship. Because Customer Content is not retained beyond these periods, no further return or deletion is required at termination, except where law requires storage.
10. General
Liability is governed by the Terms; nothing limits liability towards data subjects under Art. 82 GDPR. This DPA prevails over the Terms in matters of personal data, and the Standard Contractual Clauses prevail over this DPA. This DPA is governed by German law, venue Berlin-Mitte, and survives the Terms for as long as Supadata processes Customer Content.
Annex: Technical and organisational measures
- Encryption: TLS 1.2 or higher for all data in transit; encryption at rest by the infrastructure providers.
- Access control: production access limited to authorised staff with multi-factor authentication on a least-privilege basis; API keys that Customer can rotate or revoke at any time; single sign-on and two-factor authentication for the dashboard.
- Separation: Customer Content is separated by organisation; processing jobs are isolated and temporary files removed after completion.
- Logging: request metadata is logged for security, billing and abuse detection; request and response bodies are not stored in request logs.
- Availability: provider-managed redundancy and database backups; public status page at status.supadata.ai.
- Deletion: automatic expiry of job results; self-service account deletion in the dashboard.
- Sub-processors and incidents: sub-processors bound by written data-protection terms and listed publicly; incidents handled and notified as described in section 8.
Version 1.0 · Last updated: 5 August 2026