Try it Free

What to Ask a Video Vendor Before You Sign

Most vendor questionnaires for video tools ask the wrong things. They ask whether the vendor is “GDPR compliant” — a claim no vendor has ever answered “no” to — and whether data is “hosted in the EU”, which is a sentence with at least three meanings.

The questions below are the ones we would send. Every one of them has a factual answer that a vendor either has documented or has not. If a vendor cannot answer within a week, that is itself the answer.

1. Which data sits in which region, listed item by item

“EU hosting” usually describes where the video file lands. A video tool holds a lot more than video files: transcripts, AI summaries, comments, thumbnails, viewer analytics events, account records, session tokens, audit logs, email notification queues.

Ask for the in-scope and out-of-scope list. Good vendors publish it. Atlassian’s Loom documents the split explicitly: videos, comments, transcripts, AI summaries and workspace settings are pinned to your selected region, while user authentication and session data, user preferences, organisation membership and cross-workspace notifications stay global. That is a useful document precisely because it admits what is not covered.

Two follow-ups worth asking:

  • Does region selection happen once, at provisioning, or can it be changed later? Loom’s is set at provisioning and cannot be changed afterwards — and when Germany (Frankfurt) became available in May 2026, existing workspaces could not migrate into it. A team that already has a workspace is choosing between staying where it is and starting from an empty library.
  • Where do backups live? Backup replication to a second region is the most common quiet exception to a residency claim.

2. Where is it processed, not just where is it stored

Storage region and processing region are different questions. Transcription, AI summarisation, thumbnail generation, malware scanning and support access all touch the content, and any of them can happen somewhere else.

This is not pedantry. The EDPB’s Guidelines 05/2021 set out three cumulative criteria for a restricted transfer, and criterion two is satisfied by making data available — including remote access from a third country. A support engineer in Austin opening a ticket and viewing an EU-stored recording is a transfer under Chapter V. So is an AI feature that posts the audio to an API endpoint outside the EEA.

Ask specifically: which third-party APIs receive recording content or audio, and in which country do they run? Transcription and summarisation are the usual culprits, because they are the features most often bolted on via someone else’s model.

3. The sub-processor list, and what you can do about it

Under Article 28(2), a processor needs your prior specific or general written authorisation before engaging another processor. Under general authorisation, the vendor must inform you of intended changes and give you “the opportunity to object to such changes.”

That right is worthless if you find out by reading a web page you never visit. Ask:

  • Is the list versioned and dated, with a changelog?
  • Is there an email subscription for changes, and what is the notice period before a new sub-processor goes live?
  • What is your remedy if you object? In most standard DPAs the answer is “terminate” — which is fine, as long as you know that before you build a 4,000-video library on the platform.
  • Does the DPA flow the same obligations down to sub-processors, as Article 28(4) requires?

Count the list, too. A tool with fourteen sub-processors is not necessarily worse than one with three, but it is fourteen assessments instead of three, and fourteen chances for one of them to change.

4. Is there a DPA, and is it an actual Article 28 DPA

Two separate questions: does one exist, and is it available on the plan you intend to buy. Plenty of vendors offer a DPA on the enterprise tier only, which is a problem if your team is going to start on a self-serve plan and expense it.

When you have the document, check it against Article 28(3) rather than reading it front to back. The mandatory content is a checklist:

  • (a) processing only on documented instructions, “including with regard to transfers of personal data to a third country”
  • (b) confidentiality commitments from authorised personnel
  • (g) at your choice, deletion or return of all personal data after the end of the service, and deletion of existing copies
  • (h) making available all information necessary to demonstrate compliance, and allowing for and contributing to audits

Point (g) is the one to read twice, because it is also question five.

5. What happens on the day you cancel

Cancellation is where video tools differ most, and where almost nobody looks before signing.

  • Can you bulk-export every recording, in the original file format, without contacting support? A ZIP of MP4s is worth more than an API you have to write a script against on your last day of access.
  • Do transcripts, captions, comments and analytics come with the export, or just the video?
  • How long does the export window stay open after the subscription ends? Some tools lock the library at the end of the billing period.
  • Does deletion cover derived data — transcripts, AI summaries, embeddings, viewer event logs — or only the video file?
  • How long do deleted objects persist in backups, and is that number in the DPA or just in a support article?
  • What happens to links already embedded in your Notion, your help centre, your customer emails?

Ask for the deletion timeline in writing. “Immediately, with backup purge within 35 days” is a real answer. “We delete your data in accordance with our retention policy” is not.

6. Make them prove it

Every vendor claims encryption at rest, EU hosting and access controls. The point of this question is not to hear the claim again, it is to find the artefact behind it.

  • ISO 27001: ask for the certificate and read the scope statement. The scope line tells you which entity and which systems are covered. A certificate scoped to the corporate IT environment says nothing about the platform running your recordings.
  • SOC 2 Type II: ask for the report, not the logo, and check the observation period and any exceptions. If the period ended eight months ago, ask for a bridge letter.
  • EU Cloud Code of Conduct: an Article 40 code approved by the Belgian DPA in May 2021, monitored by SCOPE Europe, and designed to serve as a sufficient guarantee under Article 28(5). Adherence is verifiable in a public register, which is more than can be said for most trust-page claims.
  • A transparency report with numbers in it. Atlassian’s publishes counts by request type and country — 36 US government requests responded to in 2025, 25 international requests, zero national security requests, with the account figure for national security reported as a 0–250 band because US law does not permit more precision. Whatever you think of the numbers, a vendor publishing them is easier to evaluate than one publishing a paragraph about how seriously it takes your privacy.
  • Penetration test summary, dated, with the remediation status of the findings.
  • The source code, where it exists. This is the one we can speak to directly: SendRec is AGPLv3 and the whole server is on GitHub, so the answer to “what does it do with the audio” is a file you can read rather than a sentence we wrote. Open source is not a compliance certification and does not replace one — it just removes the need to take one specific class of claim on trust.

Article 28(3)(h) gives you audit rights. Most teams never use them. Asking what an audit would actually look like — remote questionnaire, on-site, third-party report only — tells you how the vendor thinks about the relationship.

7. Does anything in the product process faces or voices for identification?

Worth getting right, because it is widely overstated. A video recording of a colleague is personal data. It is not automatically biometric data.

Article 4(14) defines biometric data as personal data “resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person.” The EDPB’s Guidelines 3/2019 on video devices state the consequence plainly: video footage of an individual cannot in itself be considered biometric data if it has not been specifically technically processed in order to contribute to identifying that person.

So the question to the vendor is narrow and factual: does any feature perform facial recognition, face matching across videos, or voice-print speaker identification? Diarisation that labels “Speaker 1” and “Speaker 2” without matching them to known individuals is not identification. A “find every video this person appears in” feature is, and it drags you into Article 9 territory where processing is prohibited by default unless an exception applies.

Answering this correctly matters in both directions. Claiming Article 9 applies when it does not will make your legal team block a tool for no reason. Missing it when a face-matching feature ships in the next release is the worse failure.

8. Who owns the company, and who owns the servers

Two separate entities, two separate questions, and the second one is the one people ask. Where the hardware sits determines the storage region. Who controls the operating entity determines which legal system can compel disclosure. Those come apart constantly — a German data centre operated by a European subsidiary of a US parent is a different legal object from a German data centre operated by a company with no US presence.

That distinction is long enough to be its own post.


None of this requires a lawyer to ask. It requires a vendor willing to put specifics in an email: which data, which region, which sub-processors, which certificate, which deletion timeline. Send the list before the demo, not after the pilot — the answers arrive much faster when nobody has migrated anything yet.

Ask us the same questions and the answers are already written down: our sub-processors, with what each one receives and where it sits, and our DPA, which applies to every account including the free one. If either leaves something out, that is worth an email.