Data Processing Agreement
Version 3.0 · Effective 5 October 2026
This Data Processing Agreement ("DPA") forms part of the ScreenJournal Business Terms of Service (the "Terms") between Cyberinfra Limited, of 50 Athol Street, Douglas, Isle of Man IM1 1JB ("ScreenJournal", "we", "us"), and the Customer. It governs the personal data we process on the Customer's behalf. It is accepted with the Terms. In a conflict with the Terms concerning personal data, this DPA prevails. Capitalised terms not defined here have the meaning given in the Terms.
1. Definitions
- "Data Protection Law" means every law that applies to the processing of Customer Personal Data under this DPA, which may include the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules, India's Digital Personal Data Protection Act, 2023 and its rules, the Isle of Man Data Protection (Application of GDPR) Order 2018, the EU General Data Protection Regulation (the "EU GDPR"), the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws.
- "Customer Personal Data" means personal data in Customer Data that we process on the Customer's behalf as its processor.
- "Personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in Data Protection Law, and include their local equivalents (personal information controller and processor; data fiduciary, data processor and data principal).
- "Subprocessor" means a third party we engage to process Customer Personal Data, as listed in Annex 3.
- "Connected Tool" has the meaning given in the Terms.
2. Roles and instructions
2.1 Roles. The Customer is the controller of Customer Personal Data and decides the purposes and means of its processing. We are its processor.
2.2 Instructions. We process Customer Personal Data only on the Customer's documented instructions. Those instructions are: the Terms and this DPA; the Customer's configuration of the Services, including its capture modes, exclusion list, audio settings, retention settings and redaction settings; actions taken in the Services by its Members within the roles the Customer has given them; and any further written instruction consistent with these. Where the Customer allows Members or managers to redact a time range, each redaction is processed as the Customer's instruction to delete that range. We tell the Customer if we believe an instruction infringes Data Protection Law, and we may suspend the affected processing until it is resolved.
2.3 Processing required by law. If a law that applies to us requires other processing, we inform the Customer before processing unless that law prohibits it.
2.4 Our own data. We are a controller, not a processor, for account, billing, sign-in security, support, crash-report, website, email-delivery data and acceptance records, as described in our Privacy Policy.
2.5 Customer as processor. Where the Customer is itself a processor for a third-party controller (for example, an outsourcing provider monitoring agents for its client), we act as the Customer's subprocessor. The Customer warrants that its instructions, including its appointment of us, are authorised by that controller, and it remains our sole point of contact.
2.6 Affiliates. The Customer may let its affiliates use the Services under its organisation. It enters into this DPA for itself and for them, warrants that it may bind them, and remains responsible for their compliance. Rights under this DPA are exercised through the Customer only.
3. Customer obligations
3.1 The Customer warrants that, before the relevant processing starts, it has a lawful basis for it and has given every notice and obtained every consent Data Protection Law requires, including to Monitored Users and, where audio is enabled, to Third Party Participants.
3.2 A summary of the Workplace Monitoring Notice is shown to each Member at every desktop sign-in, and the Member's acknowledgment is recorded with its version and the time. It does not replace the notice the Customer owes, and the Services do not wait for it before monitoring. Where audio is enabled, the Customer must comply with the Call-Recording Addendum; the Services play no announcement on calls.
3.3 The Customer is responsible for the necessity and proportionality of its monitoring, for any impact assessment, for its decisions about people, and for dealing with its regulators, works councils and staff.
4. Our processing
4.1 Scope. We process the Customer Personal Data described in Annex 1, only to provide, secure and support the Services, and for no purpose of our own. We do not sell Customer Personal Data and do not use it to train AI models.
4.2 Personnel. We give access to Customer Personal Data only to personnel who need it for those purposes and who are bound by confidentiality obligations.
4.3 Staff access to accounts. Our platform staff may sign in to a Member's account to investigate a support issue. Each such session is marked as an impersonation in that Member's session list. We do not yet keep a central log of what staff view; the session-list marker is the record. Staff access is limited to support, security and legal purposes.
4.4 Minimisation in the Services. The following are built today. Applications and sites on the Customer's exclusion list are excluded before capture, and sensitive-category packs (banking, payroll, HR, health and adult content) are on by default; the Customer's administrators can change them. In the default capture mode, screen video is deleted after analysis, and any temporary copy is removed by a storage lifecycle rule we configure on the bucket. Before analysis output is stored, an automated filter removes private keys and access tokens, payment card numbers, US social security numbers and phone numbers from descriptions and window titles; names, email addresses and web addresses are kept. No biometric identification is performed. Where the Customer enables Record + Save or alert evidence clips, screen video is stored as Annex 1 describes.
5. Connected Tools chosen by the Customer
5.1 Any Member may connect a Connected Tool, which receives, read-only, the data that Member's role can see. Each such disclosure is made on the Customer's instruction to a recipient the Customer chooses. The provider of a Connected Tool is not our Subprocessor, and this DPA does not govern what it does with the data.
5.2 The Customer is responsible for deciding whether its Members may use Connected Tools, for the lawfulness of each disclosure, and for its own terms with each provider. Data a Connected Tool has received is outside our control and outside section 11. The Integration Terms apply.
6. Security
6.1 We implement the technical and organisational measures in Annex 2. Only the measures the Security page describes as built today are commitments; its list of items not yet built is not a promise. We may change measures, but not so as to reduce the overall level of protection below that in place when the Customer accepted this DPA.
6.2 Specifically: traffic is encrypted in transit with TLS; data in Amazon S3 and Google Cloud Storage is encrypted at rest by the providers' default server-side encryption; the disk of the server that holds our database is not encrypted at rest. Access inside an organisation follows the Customer's role model, and every query is scoped to the caller's organisation using its verified token.
7. Personal data breach
7.1 We notify the Customer without undue delay after we become aware of a personal data breach affecting Customer Personal Data, and in any event within 72 hours of confirming it. We do not yet operate detection tooling or an on-call rota; breaches usually come to our attention through errors we see and reports from customers and researchers, as our Security page explains.
7.2 The notice describes, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed, with a contact point. We supplement it as we learn more.
7.3 We reasonably assist the Customer with its own notifications to regulators and data subjects, including the Philippine National Privacy Commission and the Data Protection Board of India, and we aim to give the Customer what it needs in time for its own deadlines.
7.4 This section does not apply to unsuccessful attempts that do not compromise security, such as pings, port scans and failed sign-ins, or to incidents caused by the Customer or its Members. A notice is not an admission of fault.
8. Assistance
8.1 Requests from individuals. If a data subject contacts us about Customer Personal Data, we pass the request to the Customer without undue delay and do not answer it on the merits unless the law requires. Taking into account the nature of the processing, we help the Customer respond to requests to access, correct, erase, restrict or port data, to object, and to withdraw consent, and with grievances. Requests are handled by our staff by hand; there is no self-service export of all of a person's data.
8.2 Deletion and correction. We action a verified instruction from the Customer to delete or correct Customer Personal Data by the procedure in our Retention & Deletion Protocol, and we aim to complete it within thirty (30) days.
8.3 Assessments and consultation. We give the Customer reasonable help with data-protection impact assessments and prior consultation of a regulator about the Services, to the extent the Customer cannot obtain the information from this DPA, our Security page, our Automated Processing Statement or our other published documents.
9. International transfers
9.1 Where data is processed. We are established in the Isle of Man, which the European Union and the United Kingdom recognise as providing adequate protection for personal data. The core of the Services, including its database, runs on a server operated by Hetzner in Falkenstein, Germany. From there, Customer Personal Data is transferred onward: to India, where Amazon Web Services stores activity time-series data and older media in its Mumbai region; to Google, whose Cloud Storage holds newer media (region to be confirmed), whose Vertex AI service analyses screen recordings and audio through its global endpoint, and whose Gemini API serves report narratives, alert evaluation and the assistant, so AI processing may take place in any country where Google operates it; and to the United States and elsewhere for the services listed in Annex 3, including Cloudflare, Resend, Vercel and Sentry. Annex 3 states each Subprocessor's location.
9.2 Authorisation. The Customer authorises these transfers.
9.3 Customer to us. While the adequacy findings for the Isle of Man apply, a transfer from an EEA or UK Customer to us does not need standard contractual clauses. To the extent a transfer from the Customer to us requires a transfer mechanism under the EU GDPR, the UK GDPR or the Swiss Federal Act on Data Protection, the clauses in sections 9.6 to 9.8 apply.
9.4 Onward transfers. Our onward transfers to Subprocessors take place under each vendor's standard terms. We remain responsible for each Subprocessor under section 10. We have not yet recorded, for every Subprocessor, which transfer mechanism its terms provide; we will give the Customer the information we hold on request, and will add it to the Subprocessors page as it is confirmed.
9.5 Philippines and India. Under Philippine law the Customer, as personal information controller, remains accountable for personal information transferred abroad; we support it in meeting that duty through this DPA and the information we publish. India's law allows transfers outside India except to countries the central government restricts; if a country where Customer Personal Data is processed is restricted, the parties will cooperate to move or stop the affected processing.
9.6 EU standard contractual clauses. Where section 9.3 applies, the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 (the "SCCs") are incorporated into this DPA, and each party is deemed to have signed them on accepting it, with these elections: Module Two (controller to processor) where the Customer is a controller, and Module Three (processor to processor) where section 2.5 applies; Clause 7 (docking) applies; Clause 9(a) Option 2 (general written authorisation) applies, with the notice period in section 10.2; the optional language in Clause 11 does not apply; Clauses 17 and 18(b): the law and courts of Ireland; Annex I.A is completed by the Terms and this DPA, Annex I.B by Annex 1, Annex II by Annex 2 and Annex III by Annex 3; the competent supervisory authority is determined under Clause 13. As section 9.4 explains, our Subprocessors process under their standard terms, and we have not confirmed that each of those terms imposes the obligations Clause 9(b) of the SCCs describes; we remain liable to the Customer for each Subprocessor's performance as Clause 9(d) provides. Where the SCCs conflict with this DPA, the SCCs prevail.
9.7 UK. For transfers subject to the UK GDPR, the SCCs apply as amended by the UK International Data Transfer Addendum issued under section 119A of the Data Protection Act 2018. Table 1 is completed by the parties' details in the Terms; Tables 2 and 3 by section 9.6 and the Annexes; in Table 4, neither party may end the Addendum under its Section 19.
9.8 Switzerland. For transfers subject to the Swiss Federal Act on Data Protection, the SCCs apply with references to the EU GDPR read as references to that Act, and the Federal Data Protection and Information Commissioner as the competent authority.
9.9 Other mechanisms. If another lawful transfer mechanism becomes available for a transfer, we may rely on it, and the SCCs then apply only to the extent still required.
10. Subprocessors
10.1 Authorisation. The Customer gives general authorisation to the Subprocessors listed in Annex 3. Each Subprocessor processes under its standard terms (see section 9.4); we remain responsible to the Customer for its performance.
10.2 Changes. We post a new or replaced Subprocessor on the Legal page's change list at least thirty (30) days before it starts processing Customer Personal Data. The Customer can ask support@screenjournal.ai to add it to a notification list for these changes. The Customer may object on reasonable data-protection grounds within thirty (30) days of a posted change, by writing to support@screenjournal.ai. If we cannot resolve the objection, the Customer may terminate the affected Services and we refund fees it prepaid for the period after termination, notwithstanding the Refund & Cancellation Policy.
10.3 Past changes. Version 3.0 of the Subprocessors page records changes made before this DPA existed, including the move to Hetzner and the use of Google Cloud Storage and Vertex AI, for which advance notice was not given.
11. Return and deletion
11.1 Return. During the subscription term, the Customer can export reports as Excel workbooks (productivity, attendance, app usage, and a single Member's workbook) and timesheets as CSV files, and can download stored audio recordings one at a time. The Services do not export screen video, raw model outputs or a bulk copy of audio, and there is no machine-readable export of the whole organisation's data. If the Customer asks within thirty (30) days after the subscription ends, we give reasonable help to retrieve report exports where the data has not yet been deleted.
11.2 Deletion at termination. Within sixty (60) days after a subscription ends by cancellation or termination, or the Customer's organisation is deleted, we delete Customer Personal Data from the database, activity time-series storage and media storage, by the manual procedure in our Retention & Deletion Protocol, including stored screen video, alert evidence clips, audio and transcripts. We keep: data the law requires us to keep, until that requirement ends; records of each acceptance of the Terms and related documents, as evidence of their formation; and our support correspondence. Billing records are held by Paddle under its own obligations. Where a free trial ends without a subscription, the Terms (section 4.4) apply instead: the data is not deleted automatically and may be deleted after thirty (30) days.
11.3 What deletion does not reach. Copies outside our systems are not covered: recordings kept on a Member's device (which the desktop app removes after the period the Customer sets, up to three months), audio or exports a Member downloaded, and data a Connected Tool received.
11.4 Backups. We do not currently keep database backups. If we introduce them, we will state on the Retention & Deletion Protocol how long a deletion takes to reach backup copies.
11.5 During the term. We keep Customer Personal Data for the subscription term unless it is deleted earlier on a verified request, by the Customer or by a redaction the Customer allows. Automated expiry is not yet built; where the Customer sets a retention window for alert evidence clips, no process yet acts on it.
11.6 Confirmation. On request, we confirm in writing when deletion is complete.
12. Audit
12.1 We make available the information reasonably necessary to demonstrate compliance with this DPA, including our Security page, the Subprocessors page and answers to a reasonable written security questionnaire once a year at no charge. No SOC 2 report or ISO 27001 certificate has been issued.
12.2 Where that information is not enough and Data Protection Law requires an audit, the Customer may audit our processing of its data, once in any twelve months (unless a regulator requires more, or after a personal data breach affecting the Customer), through an independent auditor bound by confidentiality who is not our competitor, on at least thirty (30) days' written notice, during business hours, without access to other customers' data, without disrupting our operations, and at the Customer's cost. Audits under the SCCs are carried out under this section.
12.3 We keep an internal record of the processing we carry out for our customers. Annex 1 summarises it.
13. Requests from public authorities
If a public authority asks us for Customer Personal Data, we disclose it only where it presents valid legal process. Unless the law prohibits it, we refer the authority to the Customer and notify the Customer without undue delay so it can seek a remedy. We disclose only what is legally required, challenge a request we reasonably consider unlawful, and make no voluntary disclosure.
14. Liability, precedence and duration
14.1 Each party's liability under this DPA is subject to the limits and exclusions in the Terms, except where Data Protection Law does not allow such a limit. Liability is aggregated across the Customer and its affiliates.
14.2 This DPA is governed by the law that governs the Terms, except where the SCCs or mandatory Data Protection Law provide otherwise.
14.3 In a conflict, the following order applies, highest first: the SCCs and other transfer instruments in section 9; this DPA; the Terms; any other document.
14.4 This DPA lasts as long as we process Customer Personal Data. Obligations that by their nature continue, including sections 11 and 14, survive until performed.
14.5 We list every change to this DPA on the Legal page with its effective date and, where practicable, post material changes before they take effect. A new version that needs acceptance is accepted as the Terms describe.
Annex 1 — Details of processing
| Subject matter | Monitoring of work activity on devices the Customer manages, and the reports, assessments and tools built on it |
| Duration | The subscription term, then the deletion period in section 11 |
| Nature | Capture, upload, automated analysis by AI models, storage, retrieval, display, export and deletion |
| Purpose | Activity and productivity reporting to the Customer, timesheets and pay computation, alerts and review, the assistant, and support of the Services |
| Data subjects | The Customer's Monitored Users; its other Members (owners, administrators, managers, viewers and Members with the Billing role); Third Party Participants on recorded calls, meetings and webinars, including every presenter and attendee in listen mode; and people whose names, images or messages appear in screen content or are discussed with the assistant |
| Frequency | Continuous while a Monitored User is signed in and tracking is on, as the Customer configures |
| Special categories | Not sought. Screen content, audio, transcripts and free text may nevertheless contain special-category data (for example health information) where it appears on screen or is spoken. Sensitive-category packs exclude banking, payroll, HR, health and adult applications and sites by default |
| Profiling | Yes: activity scores, productivity percentages, weekly rankings, flags that activity may be simulated and alert evaluations about individual Monitored Users |
| Biometric data | None. Transcripts carry a model-assigned speaker label; voices are not matched against voiceprints |
| Processing operation | Personal data | Where it is held and who processes it | Retained for (true today) |
|---|---|---|---|
| Screen capture and timeline derivation, default mode | Short screen recordings with cursor and click markers (transient); application names, window titles, browser addresses and sites, descriptions, 1–5 activity scores, raw model answers, presence and idle signals | Google Cloud Storage and Vertex AI (analysis); Amazon S3, Mumbai (time-series); Hetzner, Germany | Video deleted after analysis, any temporary copy removed by a bucket lifecycle rule; timeline for the subscription term |
| Recordings on the Member's device | Screen recordings | The Member's device | The period the Customer sets, up to three months, then removed by the desktop app |
| Record + Save, where enabled | Screen video of every segment | Google Cloud Storage | Up to three months by policy; not enforced automatically |
| Alert evidence clips | Screen clip, alert message, decision and reply | Google Cloud Storage; Hetzner | Until deleted; a Customer-set window is not yet acted on; not removed by a Member's redaction |
| Audio and transcription, where enabled, including listen capture | Audio of calls, meetings and webinars including Third Party Participants; transcripts attributed to the member or the other party; a model-assigned speaker label; the member's display name sent with the audio | Vertex AI (transcription); Google Cloud Storage (audio, only where the Customer keeps audio); Amazon S3, Mumbai (transcripts) | Subscription term; where audio is not kept, any temporary copy is removed by a bucket lifecycle rule; downloaded copies are outside our control |
| Self-declared entries | Manual time entries, away reasons, declared off-screen work, alert explanations | Hetzner; Amazon S3, Mumbai | Subscription term; a Member can edit an entry's reason but not delete it |
| Automated inference and alerts | Scores, productivity percentages, weekly rankings, Review cases for possible simulated activity, alert matches and alert emails | Vertex AI (segment analysis); Gemini API (alert evaluation); Resend (alert emails); Amazon S3, Mumbai; Hetzner | Subscription term |
| Reports, timesheets and pay | Hours, pay rates and overrides entered by the Customer, computed pay, report narratives; weekly report emails | Gemini API (narratives); Hetzner (database and report cache); Google Workspace (report emails) | Subscription term |
| Assistant | Questions, answers, retrieved activity data, conversation history | Gemini API; Hetzner | Subscription term, unless the user deletes a conversation |
| Removing a Member | The Member's account | Hetzner | The account is deleted; the Member's monitoring data stays for the subscription term unless deleted on request |
| Sign-in jurisdiction | Country or region and timezone derived from the IP address at desktop sign-in, using a local database | Hetzner | Life of the account |
| Redaction | The redacted range, reason, actor and time | Hetzner; deletions in Amazon S3 and Google Cloud Storage | Content purged; the record of the redaction kept as evidence |
| Support access | Any data visible while staff are signed in to a Member's account | Hetzner | Session marked in the Member's session list; no central access log |
| Operational logs | Request metadata, user and organisation identifiers, IP addresses, error messages that may quote request content | Hetzner | No fixed window yet |
| Disclosure to Connected Tools (not subprocessing) | Timelines, summaries, transcripts and rankings within the connecting Member's role | The Connected Tool's provider, chosen by the Customer; access tokens on Hetzner | Tokens until revoked; data received is outside our control |
Annex 2 — Technical and organisational measures
The measures on our Security page, as built today, are incorporated into this DPA and complete Annex II of the SCCs. The page's list of items not yet built (its section 11) describes gaps and is not a commitment. Superseded versions are listed on the Legal page's archive where we have published them.
Annex 3 — Subprocessors
The list on our Subprocessors page is incorporated into this DPA and completes Annex III of the SCCs, as updated under section 10. Superseded versions are listed on the Legal page's archive where we have published them.
Annex 4 — US state privacy laws
This Annex applies only where Customer Personal Data is subject to a US state privacy law, such as the California Consumer Privacy Act as amended. For that data we act as a service provider or processor, and we:
- process it only for the limited and specified business purpose of providing the Services under the Terms;
- do not sell or share it, and do not receive it as consideration;
- do not retain, use or disclose it outside our direct business relationship with the Customer, except as that law permits;
- do not combine it with personal data from other sources, except as that law permits a service provider;
- tell the Customer if we can no longer meet these obligations, after which the Customer may take reasonable steps to stop and remediate unauthorised use;
- comply with that law and give the level of privacy protection it requires, and allow the Customer to take reasonable steps to ensure the data is used consistently with the Customer's obligations.
Where we de-identify data, we keep it de-identified and do not attempt to re-identify it.
Changes and previous versions
- 5 October 2026v3.0 first publication of the rebuilt Data Processing Agreement: Annex 1 rebuilt from the record of processing; transfers restated for hosting in Germany with onward transfers; connected AI tools as Customer-directed recipients; staff access; breach notice within 72 hours of confirmation; return formats and exclusions. Accepted at organisation creation.
Questions about this document: support@screenjournal.ai. Canonical URL: /legal/data-processing-agreement.