Last updated: September 16, 2026

Data Processing Addendum

This Data Processing Addendum (DPA) supplements the Terms or other service agreement when Sneep Cut processes Customer Personal Data on behalf of a business customer. It is designed to address Article 28 GDPR requirements.

The customer accepting or signing the service agreement is “Customer.” GENESIS PROCUREMENT S.R.L., operator of Sneep Cut, is “Processor.” This DPA applies automatically where Customer is controller or processor of personal data and Sneep Cut processes that data on Customer’s documented instructions to provide the service.

If Customer acts as processor for another controller, Customer confirms it may appoint Sneep Cut as subprocessor and will communicate relevant controller instructions. A signed counterpart is available on request. If a negotiated signed DPA conflicts with this page, the signed DPA controls.

  • Subject matter and purpose: hosting, ingesting, transcribing, analyzing, transforming, editing, storing, exporting, scheduling, publishing, supporting, and securing media workflows requested by Customer.
  • Duration: the service term plus the limited deletion, backup, security, and legal-retention periods described in the agreement and Privacy Policy.
  • Data subjects: Customer users, personnel, contractors, clients, audience members, speakers, people depicted or heard in media, social-account contacts, and other people whose data Customer submits.
  • Data types: identifiers, contact and account data, images, video, voice, likeness, transcripts, captions, prompts, project metadata, social identifiers and tokens, publishing data, technical data, and any other personal data chosen by Customer.
  • Processing operations: collection from Customer, organization, storage, retrieval, consultation, automated analysis, alteration, transmission to Customer-selected destinations, restriction, export, and deletion.

The agreement, feature configuration, Customer actions, and written support directions are documented instructions. Processor will process Customer Personal Data only on those instructions unless Union or Member State law requires otherwise, in which case Processor will notify Customer before processing unless law prohibits notice.

Customer is responsible for the lawfulness, fairness, accuracy, transparency, and minimization of submitted data; required notices and consents; user authorization; and ensuring instructions comply with law. Processor will promptly inform Customer if, in its opinion, an instruction infringes applicable data-protection law and may pause the affected operation.

Processor limits access to personnel and contractors who need it for the service and binds them to confidentiality obligations that survive access. Access is reviewed and removed when no longer required.

Processor may update safeguards to reflect risk and technology, provided overall protection is not materially reduced. No control eliminates all risk.

  • Encrypted network transport and Secure/HTTP-only authentication cookies in production.
  • Password hashing, role and service access controls, restricted production access, and secrets separation.
  • Encryption of stored social credentials, short-lived OAuth state, signed media access, rate limiting, and account-scoped storage paths.
  • Upload validation and malware scanning, service and network isolation, monitoring, logging, and recovery procedures appropriate to the environment.
  • Deletion workflows that coordinate active jobs, billing cancellation, social credentials, database records, and account media before finalization.

Customer gives general authorization to use the providers listed on the Subprocessors page. Processor remains responsible for imposing data-protection obligations appropriate to the services supplied. Processor will post material additions before use where reasonably possible.

Customer may object promptly on reasonable data-protection grounds. The parties will try to resolve the concern, including by changing configuration where commercially and technically feasible. If no reasonable solution exists, either party may terminate the affected optional feature or service under the agreement.

Customer authorizes transfers needed for the listed providers and selected destinations. Processor will use a lawful transfer mechanism where required, including an adequacy decision or approved Standard Contractual Clauses with appropriate supplementary measures. If Standard Contractual Clauses must apply directly between Customer and Processor, the parties will complete and execute the appropriate module; Customer may request that document using the contact below.

Taking into account the nature of processing, Processor provides available self-service export, correction, disconnection, and deletion tools and reasonable assistance for Customer to answer rights requests. If Processor receives a request concerning Customer Personal Data, it will redirect the requester to Customer where feasible and will not respond substantively unless authorized or legally required.

Processor will provide reasonable information needed for Customer’s data-protection impact assessments, consultations, security obligations, and breach notifications, considering the service and information available to Processor.

Processor will notify Customer without undue delay after confirming a personal-data breach affecting Customer Personal Data. Notice will include available information about the nature, likely consequences, affected categories, measures taken, and contact point, and may be supplied in phases. Notification is not an admission of fault. Customer is responsible for notifications it is legally required to make as controller.

During the term, Customer may use available export tools. On account deletion or service termination, Processor will delete or return Customer Personal Data according to Customer’s choice where technically available, then remove remaining active copies, unless law requires retention. Protected backup remnants are isolated from ordinary use and removed or overwritten according to the applicable lifecycle. Customer-selected publications on third-party platforms must be managed separately.

Processor will make available information reasonably necessary to demonstrate Article 28 compliance. Customer should first use current documentation, independent reports if available, and written answers. If these are insufficient, Customer may request one proportionate audit per year by an independent, confidential, non-competitor auditor, with reasonable notice, during business hours, without accessing other customers’ data or disrupting security. Customer bears its audit costs unless a material breach by Processor is confirmed.

The agreement’s liability limits apply to this DPA to the extent permitted by data-protection law. This DPA controls over inconsistent agreement language about processing Customer Personal Data; otherwise the agreement remains unchanged. Romanian law governs, without displacing mandatory GDPR rights or the supervisory authority and court rights provided by GDPR.

Request a signed copy or send privacy instructions to admin@sneepcut.com