Data Processing Agreement
Last updated: September 21, 2026
What this is
When you record someone, or share a video with them, you decide why their data is collected and we carry it out. That makes you the controller and us the processor, and Article 28 of the GDPR requires a contract between us. This is that contract. It applies automatically to every account, forms part of our Terms of Service, and needs no signature to take effect. If your procurement process requires a signed copy on your paper or ours, write to privacy@sendrec.eu and we will sign one.
The parties are you, the account holder, and Neamtu Alexandru PFA, whose full details are on the imprint.
What we process, and why
Subject matter and purpose. We process personal data only to provide SendRec: to store and serve the videos you record, to show them to the people you share them with, to report who watched and what they said, and to keep your account working. We do not process it for our own purposes, and we never sell it or use it to train models.
Duration. For as long as your account exists, and then for the retention periods set out in our privacy policy.
Categories of data subject. You and anyone you invite to your workspace; anyone who opens a link you shared; anyone who appears or is heard in a recording you make.
Types of personal data. Account details such as name, email address and password hash. The content of recordings, which may include images of people, their voices and whatever is visible on a shared screen. Transcripts of that audio. Comments and the names or email addresses attached to them. For viewers of a shared link: browser, device, a bucketed referrer category, and an identifier derived from their IP address and user agent. Email addresses collected by the email gate when you switch it on. Billing identifiers for paid plans. Client IP addresses, which our request logs record for every call to the service.
Our obligations
We act on your instructions. We process personal data only as your use of SendRec directs, and as this agreement and the Terms set out. If a law we are subject to requires something else, we will tell you before doing it unless that law forbids the warning. If an instruction of yours appears to breach data protection law, we will say so.
Confidentiality. Everyone with access to personal data through SendRec is bound to keep it confidential.
Security. We maintain the measures Article 32 requires. In practice: traffic is encrypted in transit; passwords are hashed; share links carry unguessable tokens and can be password-protected or time-limited; video URLs are presigned and expire; access to production is restricted to the operator; backups are encrypted. SendRec is open source, so you can read how any of it works rather than accept a summary.
Breaches. If personal data we hold for you is breached, we will tell you without undue delay and in any event within 48 hours of becoming aware, with what we know about what happened, who is affected and what we are doing about it. That is sooner than the 72 hours you then have to notify your own authority.
Helping you meet your own duties. Access, correction, deletion, export and objection are built into the product, so most requests you receive you can answer yourself. Where a request needs us, we will help, at no charge. The same applies to data protection impact assessments and to prior consultation with a supervisory authority.
Deletion. When your account is closed, we delete the personal data we hold for you within the periods in the privacy policy, except where a law requires us to keep something, such as invoices. You can export your data before you go.
Audits. We will give you the information you need to verify this agreement is being met, and allow an audit on reasonable notice, no more than once a year unless an incident or an authority calls for another.
Sub-processors
You give us general authorisation to use sub-processors. The current ones are listed, with what each receives and where it sits, on our sub-processors page. Each is bound by terms no weaker than these.
We will update that page and notify account holders by email before a new sub-processor begins handling your data. If you object, tell us at privacy@sendrec.eu; if we cannot offer you an alternative, you may cancel your subscription before the change takes effect and we will refund the unused part of your term.
Where the data goes
Personal data is stored in the European Union and stays there. Every sub-processor that handles it is established in the EU, with two exceptions, neither in the path of your videos or your account data. Cloudflare, a United States company, answers DNS queries for our domain and routes inbound mail to our own addresses. jsDelivr, a public CDN we cannot tie to a single jurisdiction, serves the interface for our API reference to browsers that open it, and we intend to remove that dependency. Both are described on the sub-processors page. Where a transfer outside the EU or EEA occurs, it rests on Standard Contractual Clauses or another Chapter V safeguard.
Precedence
Where this agreement and the Terms of Service disagree about the processing of personal data, this agreement wins.
Contact
privacy@sendrec.eu. You may also complain to a supervisory authority; ours is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP).