# legal
Data Processing Agreement
The GDPR Article 28 terms under which mdreel processes personal data contained in the content you upload. This DPA is incorporated by reference into the Terms of Service and you accept it by using the Service.
1. Roles of the parties
This Data Processing Agreement (“DPA”) applies where Royalcode Robert Sztygowski (“mdreel”, the processor) processes personal data contained in Customer Content on behalf of the Customer (the controller) in providing the Service. It forms part of, and is governed by, the Terms of Service. Where this DPA and the Terms conflict on the processing of personal data, this DPA prevails.
2. Scope and documented instructions (Art. 28(3)(a))
mdreel processes personal data only on the Customer's documented instructions, including as set out in the Terms, this DPA, the product documentation, and the configuration choices the Customer makes in the Service. The subject-matter, duration, nature, purpose, data types and categories of data subject are described in Annex A. mdreel will inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law, and is not obliged to follow an instruction that would do so.
3. Confidentiality (Art. 28(3)(b))
mdreel ensures that persons authorised to process the personal data are bound by an appropriate duty of confidentiality and process the data only as instructed.
4. Security of processing (Art. 28(3)(c), Art. 32)
mdreel implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of the state of the art and the nature of the processing. A summary of those measures is in Annex B.
5. Subprocessors (Art. 28(2), (3)(d), (4))
The Customer gives general authorisation for mdreel to engage subprocessors to provide the Service. The current subprocessors are listed, with their role and location, on the Subprocessors page. mdreel imposes on each subprocessor data-protection obligations equivalent to those in this DPA (flow-down) and remains fully liable to the Customer for a subprocessor's performance.
mdreel will give at least 30 days' notice of any intended addition or replacement of a subprocessor (via the Subprocessors page and, on request, by email). The Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, the Customer may terminate the affected part of the Service.
6. Assistance with data-subject rights and compliance (Art. 28(3)(e), (f))
Taking into account the nature of the processing, mdreel assists the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under Chapter III GDPR (Arts. 15–22). mdreel also assists the Customer in ensuring compliance with its obligations under Arts. 32–36 (security, breach notification, data-protection impact assessments and prior consultation), taking into account the information available to mdreel.
7. Personal data breach (Art. 33)
mdreel notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Content, and provides the information the Customer reasonably needs to meet its own notification obligations.
8. Return and deletion (Art. 28(3)(g))
At the Customer's choice, mdreel deletes or returns all personal data in Customer Content after the end of the provision of the Service, and deletes existing copies, unless storage is required by EU or Member-State law. By design, uploaded source recordings are deleted after processing, and outputs are deleted when the Customer deletes them or closes the account. The Service also provides a deletion endpoint for individual jobs.
9. Information and audits (Art. 28(3)(h))
mdreel makes available to the Customer the information necessary to demonstrate compliance with Art. 28, and allows for and contributes to audits, including inspections, conducted by the Customer or a mandated auditor, subject to reasonable notice, confidentiality, and frequency limits, and primarily by providing documentation of its measures.
10. No transfers outside the EEA
By design, all processing under this DPA takes place within the European Economic Area. No personal data is transferred to a third country as part of the Service, so no Chapter V transfer mechanism (such as Standard Contractual Clauses) is required. If mdreel ever needs to process outside the EEA, it will notify the Customer and put an appropriate Chapter V safeguard in place beforehand.
Annex A — Details of processing
Subject-matter: processing of personal data contained in Customer Content to provide the mdreel video/audio-to-Markdown Service.
Duration: for the term of the Terms of Service and until deletion or return of the data as described in section 8.
Nature and purpose: upload, storage, automated AI analysis of video and audio, generation of timestamped Markdown and structured output, delivery to the Customer, and deletion.
Categories of personal data: any personal data present in the recordings the Customer uploads — for example the voices, images and statements of speakers and other individuals appearing in or referenced by the recording, and text shown on screen. mdreel does not require or solicit special-category data; the Customer must not upload such data without an appropriate lawful basis.
Categories of data subjects: individuals appearing, speaking, mentioned or shown in Customer Content — which may include the Customer's staff, its customers, and third parties, as determined by the Customer.
Controller / processor: the Customer is the controller; mdreel is the processor.
Annex B — Technical and organisational measures (Art. 32)
- EU-region processing: all compute, storage and AI processing pinned to EU regions.
- Encryption: data encrypted in transit (TLS) and at rest.
- Access control: least-privilege access, no long-lived exported credentials, and centrally managed secrets.
- Data minimisation & retention: source recordings deleted after processing by default; per-job deletion; storage-lifecycle backstop.
- No model training: Customer Content is not used to train AI models; the AI provider operates under no-training terms.
- Integrity & auditability: signed webhooks, audit logging of data access and deletion, and scale-to-zero infrastructure.
- Resilience: managed, backed-up EU database and object storage.
Published by Royalcode Robert Sztygowski, ul. Józefa Wybickiego 2/9, 05-820 Piastów, Poland · VAT PL 8222319203 · hello@mdreel.com. Version 1.0, effective 2026-07-18.