ScribeFlash

Legal

ScribeFlash data processing agreement

This Data Processing Agreement governs how ScribeFlash processes interview, transcript, research-evidence, and related personal data on a customer's behalf.

Effective
August 30, 2026
Last updated
August 30, 2026
  • This DPA applies only when ScribeFlash processes Customer Personal Data on a customer's behalf; the Privacy Policy covers data ScribeFlash controls for accounts, billing, security, and operations.
  • The customer is the controller or personal information handler and ScribeFlash is the processor or entrusted party acting only on documented instructions.
  • ScribeFlash may use bound subprocessors with notice, a reasonable objection process, and data-protection duties no less protective than this DPA.
  • At termination, ScribeFlash returns or deletes Customer Personal Data as selected by the customer, subject to limited legal-retention and isolated-backup exceptions.

1. Parties and formation

This Data Processing Agreement (“DPA”) is between the customer that orders or uses the ScribeFlash Service and determines the purposes and means of Customer Personal Data processing (“Customer”) and the operator providing ScribeFlash (“ScribeFlash”). It forms part of the accepted Terms, order, enterprise agreement, or other master services agreement (the “Main Agreement”).

Online acceptance of the Main Agreement includes this DPA. Enterprise customers may request an executable copy through the Contact page. Legal entity names, registered addresses, notice details, and signatures are those in the order, enterprise agreement, or signature page. This DPA alone does not grant Service access.

2. Scope and roles

This DPA covers processing on Customer's behalf to provide the Service, including upload, storage, transcoding, transcription, editing, retrieval, evidence coding, AI-assisted analysis, reporting, export, retention, and deletion. Annex I describes the processing.

Customer is the controller, personal information handler, or business and ScribeFlash is the processor, entrusted party, or service provider. Where Customer is itself a processor, ScribeFlash acts as its subprocessor and Customer confirms authority from the relevant controller.

ScribeFlash acts independently as a controller for account administration, Service security, fraud prevention, usage metering, billing, support, and its legal duties. Those activities fall under the Privacy Policy rather than this DPA.

3. Definitions and applicable law

“Customer Personal Data” means information relating to an identified or identifiable person that Customer submits to or generates through the Service and that ScribeFlash processes for Customer. It excludes irreversibly anonymized data.

“Applicable Data Protection Law” includes laws applicable to the processing, such as China's PIPL and Network Data Security Regulation, the EU GDPR, UK GDPR, and applicable US state privacy laws. Controller, processor, processing, data subject, personal data breach, and similar terms have the meanings in applicable law. Mandatory law controls over conflicting terminology.

4. Instructions and processing limits

ScribeFlash processes Customer Personal Data only on documented instructions in the Main Agreement, this DPA, product settings, administrator actions, API requests, support requests, and other written directions. Necessary international transfers are included.

ScribeFlash will not access, retain, use, combine, disclose, sell, or share Customer Personal Data beyond the agreed purposes, including for cross-context behavioral advertising. Unless Customer gives a lawful express written instruction, ScribeFlash does not use Customer Personal Data to train general-purpose generative AI models offered to the public.

ScribeFlash will notify Customer if it believes an instruction violates Applicable Data Protection Law and may pause it pending confirmation or correction. If law independently requires processing, ScribeFlash will notify Customer first unless prohibited for important public-interest reasons.

5. Customer obligations

Customer is responsible for a lawful, fair, necessary, and transparent basis for processing; required notices and consents; rights responses; retention decisions; access configuration; and evaluating whether transcription and AI functions suit its use case.

Customer will keep instructions lawful and data accurate, proportionate, and minimized. For recordings, children, health, financial, biometric, precise-location, or other sensitive data, Customer will obtain required separate or explicit consent and apply enhanced safeguards.

Customer is responsible for authorized users and credentials and confirms any upstream controller has authorized ScribeFlash's engagement.

6. Confidentiality and personnel

ScribeFlash ensures authorized personnel are bound by statutory or contractual confidentiality, access data only as needed for their duties, and receive role-appropriate privacy and security training.

Access is granted, reviewed, and revoked under least-privilege and need-to-know principles. ScribeFlash discloses Customer Personal Data only as Customer authorizes, this DPA permits, or law requires.

7. Security measures

Considering current technology, implementation cost, processing context, and risks to individuals, ScribeFlash maintains proportionate technical and organizational measures described in Annex II against unauthorized or unlawful access, use, disclosure, alteration, loss, or destruction.

Measures may evolve with technology and risk but will not materially reduce the Service's overall security during the Main Agreement. Customer remains responsible for member permissions, retention, sharing, exports, endpoints, and its own environment.

8. Subprocessors

Customer gives general written authorization for subprocessors that provide cloud infrastructure, object storage, transcription, AI models, email, monitoring, and support. ScribeFlash binds each subprocessor by written terms with materially equivalent privacy, security, confidentiality, deletion, and assistance duties and remains responsible for its processing obligations.

Current categories and confirmed providers appear in Annex III. ScribeFlash will give at least 15 days' notice through the product, account email, a subprocessor page, or an agreed channel before a material addition or replacement, except urgent security, availability, or legal changes notified as soon as reasonably possible.

Customer may object within 15 days on reasonable data-protection grounds. The parties will seek a commercially reasonable alternative. If unresolved, Customer may stop the affected function or, for a material risk increase without a reasonable alternative, terminate the affected order and receive a pro-rata refund for unused prepaid service.

9. International transfers

ScribeFlash transfers Customer Personal Data internationally only as instructed, necessary for the Service, and permitted by Applicable Data Protection Law, using adequacy decisions, certifications, standard clauses, approved contracts, or other valid safeguards.

For restricted EEA transfers where applicable, the parties incorporate the EU Commission Decision 2021/914 SCCs: Module 2 for controller-to-processor and Module 3 where Customer is a processor, with general written subprocessor authorization. The competent authority, Member State, and optional details follow Customer's principal establishment and order.

Recognized UK or Swiss addenda and modifications apply where required. For exports of personal information from China, the parties cooperate on applicable separate consent, impact assessments, standard contracts, certification, or security assessment; Customer determines and satisfies its exporter obligations and ScribeFlash provides reasonably necessary assistance.

10. Data-subject requests

Considering the nature of processing, ScribeFlash reasonably assists with access, copy, correction, supplementation, deletion, restriction, objection, portability, consent withdrawal, and automated-processing information. Product search, edit, export, retention, and deletion controls are part of that assistance.

ScribeFlash will forward a request received directly about Customer Personal Data and will not substantively respond for Customer unless legally required or authorized. Customer verifies identity, determines exceptions, and makes the final response. Extensive assistance beyond standard features may incur reasonable pre-disclosed fees.

11. Compliance and assessment assistance

Taking account of processing and available information, ScribeFlash reasonably assists with security duties, privacy or data-protection impact assessments, prior consultation, processing records, and regulator inquiries.

On reasonable request, ScribeFlash provides relevant security, architecture, data-flow, retention, subprocessor, and transfer information, subject to redaction and confidentiality for trade secrets, other customers, security-sensitive details, and third-party restrictions. Customer remains responsible for its compliance conclusions.

12. Personal data breaches

After confirming a breach affecting Customer Personal Data, ScribeFlash notifies Customer without undue delay and, where GDPR applies, aims to provide an initial notice within 48 hours of confirmation. Investigation and supplemental updates continue, and notice is not an admission of liability.

Where available and lawful, notice describes the nature of the event, affected data and people, likely consequences, mitigation, and a contact channel. Information may be provided in phases.

ScribeFlash will reasonably contain, investigate, remediate, document, and prevent recurrence and assist Customer's notification duties. It will not notify data subjects or regulators for Customer without written authorization unless law requires.

13. Government and third-party demands

Unless legally prohibited, ScribeFlash will notify Customer of a government, court, or law-enforcement demand and direct the requester to Customer. It discloses only what is legally binding and challenges demands that appear unlawful, overbroad, or disproportionate where reasonable grounds exist.

ScribeFlash documents basic request and disclosure details where lawful and applies minimization, secure transfer, and access restrictions.

14. Return, retention, and deletion

During the Service, Customer can export data, delete projects, and set media retention. At termination or a valid written request, ScribeFlash returns or deletes Customer Personal Data at Customer's choice and removes existing copies unless law requires retention. Without a selection, ScribeFlash may delete under its then-published retention rules.

Deletion disables production access before background cleanup of media, transcripts, evidence, reports, exports, and cache. Isolated disaster-recovery backups expire through normal rotation and are not restored for ordinary processing. Legally retained data is isolated, access-restricted, and deleted when the duty expires.

Customer must export needed data before termination or deletion. ScribeFlash can provide reasonable written confirmation of completion.

15. Information and audits

ScribeFlash provides information reasonably necessary to demonstrate compliance and permits audits by Customer or an independent, qualified, confidential auditor. Current third-party reports, certifications, questionnaires, and remote review should be used first.

Onsite audits are normally limited to once per 12 months, with 30 days' notice, during business hours, without operational disruption, other-customer access, or unnecessary security exposure. Confirmed material incidents, regulator demands, or reasonable evidence of serious breach are exceptions.

Customer pays routine audit costs. ScribeFlash bears reasonable remediation costs for a material breach it caused. Resource-intensive assistance beyond standard materials may be subject to agreed reasonable fees.

16. Liability, term, and precedence

This DPA starts when Customer becomes bound by the Main Agreement and continues until ScribeFlash no longer processes Customer Personal Data. Main Agreement liability limits apply except where Applicable Data Protection Law prohibits limitation.

Conflict priority is: applicable transfer SCCs; signed DPA or enterprise special terms; this DPA; order; Main Agreement; Privacy Policy. SCCs prevail only for covered transfers.

Main Agreement law and dispute terms apply, without limiting mandatory privacy law, regulator powers, or non-waivable data-subject rights.

Annex I: Processing details

Subject and duration: Customer Personal Data is processed to provide the ordered interview-research Service from upload, generation, or receipt until Customer deletion, termination and agreed cleanup, or a longer legal requirement.

Nature and purpose: receive, upload, transmit, host, organize, retrieve, transcode, transcribe, translate, edit, annotate, link evidence, perform AI-assisted analysis and summarization, generate findings and reports, display, export, back up, secure, support, retain, and delete solely to provide and protect the Service as instructed.

  • Data subjects: authorized users, employees, contractors, researchers, interview participants, customers or prospects, research subjects, and other people mentioned in Customer Content.
  • Data: names, email, role, company, account identifiers; voice, image, and recordings; IP and technical identifiers; interview answers, transcripts, speakers, timestamps; questions, tags, notes, evidence, findings, reports, and edit history.
  • Sensitive data: only if Customer uploads it, potentially health, disability, ethnicity, religion, political opinion, union status, sex life or orientation, finance, children, identity, and other protected data. The Service does not process biometric templates for unique identification.
  • Frequency: continuous or on demand, based on Customer use.
  • Retention: Customer settings, plan, order, and Section 14; current original-media choices can include delete after processing or 7, 30, 90, or 365 days.

Annex II: Technical and organizational measures

Controls vary by Service scope, deployment, and risk; implementation details may be provided confidentially:

  • Identity and access: server-side authentication, protected session cookies, role-based least privilege, administrator controls, session revocation, and access review.
  • Transmission and storage: production HTTPS/TLS, signed or short-lived upload URLs, controlled object storage, secrets separated from code, and appropriate encryption-at-rest capabilities.
  • Segregation and minimization: project- and account-scoped authorization, task-limited context, and no intentional tokens or full OAuth credentials in browser-accessible logs.
  • Secure development: review, dependency and configuration management, input and upload-host validation, authorization-boundary testing, and patch management.
  • Logging and monitoring: security and error events, sensitive-field redaction, anomaly monitoring, protected logs, and limited retention.
  • Availability and recovery: backup, restoration, continuity, queue-state management, fault isolation, and reasonable recovery testing.
  • Incident response: detection, triage, containment, investigation, remediation, notice, and post-incident review.
  • Lifecycle: media retention, project and account deletion, cleanup queues, cache and export removal, and isolated backup rotation.
  • Vendor and personnel: due diligence, contractual controls, minimum access, confidentiality, training, and joiner/mover/leaver procedures.

Annex III: Subprocessors and change notice

Current code and product configuration confirm Cloudflare R2 or equivalent Cloudflare infrastructure for object storage and media upload. It may process uploaded media, object keys, content type, and transfer metadata; actual region depends on deployment and account configuration.

Transcription, AI model, hosting, email, monitoring, and support providers can vary by deployment, customer region, or enterprise configuration. To avoid naming an incorrect legal entity in a public agreement, the binding register of legal names, locations, purposes, and notice subscriptions is supplied in the order, enterprise agreement, or current subprocessor list available on request. ScribeFlash must complete contractual and security review before enabling a new provider that processes Customer Personal Data.

Google sign-in and payment providers generally act as independent controllers for authentication or payment data they collect directly; they are subprocessors under this DPA only to the extent they process Customer Personal Data on ScribeFlash's behalf.

Use the Contact page to request an executable copy, the current subprocessor register, security materials, or applicable international-transfer terms.

Go to Contact
Research Data Processing Agreement | ScribeFlash