This Data Processing Addendum (the "DPA") is entered into between RyanTech LLC, a South Carolina limited liability company doing business as DemoPine ("DemoPine", "we", "us", "our"), and the Customer identified in Section 1.3.
DemoPine is the same entity the Terms of Service call "Demo Pine". The two spellings mean one company.
You do not need to sign this. Section 18.3 of the Terms incorporates this DPA into your agreement automatically, without signature, for all processing of Customer Content where you are subject to the GDPR, the UK GDPR, the Swiss FADP, or a US state privacy law. It is already in force. If your procurement process requires a countersigned PDF, email [email protected] and we will return one — but the protections below apply from the moment you accept the Terms, not from the moment we sign.
This DPA contains the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, a Swiss addendum, the full content required by Article 28(3) of the GDPR, and service-provider terms for US state privacy law. Annexes I, II and III at the end are populated and are part of it.
1. What this DPA is, and when it applies
1.1 Incorporation without signature. This DPA is incorporated into the Terms by Section 18.3 of the Terms and applies automatically, without signature, to all processing of Customer Content by DemoPine where you are subject to the GDPR, the UK GDPR, the Swiss FADP, or a US state privacy law. No separate execution, purchase order, or plan level is required. It applies on the Free plan as it does on Enterprise.
1.2 When it takes effect and how long it lasts. It takes effect on the date you accept the Terms (Section 1.1 of the Terms records that date and the version accepted) and continues for as long as we process Customer Personal Data on your behalf, including through the export window in Section 23.1 of the Terms and the retention periods in Section 23.3 of the Terms.
1.3 Who the Customer is. "Customer" has the meaning given in Section 1.2 of the Terms: the organization or individual that controls a Workspace and is responsible for its fees. Where you are the sole Member of your own Workspace, you are the Customer and the controller of the content in it, and you exercise the rights in this DPA yourself (Privacy Policy Section 1.4).
1.4 Affiliates and the docking clause. Clause 7 of the EU SCCs (the docking clause) is included. An Affiliate of the Customer that is subject to the GDPR, the UK GDPR, or the FADP may accede to this DPA and to the SCCs incorporated by it, as an additional data exporter, by written notice to [email protected] identifying the Affiliate and the Workspace concerned. No further agreement is required. An acceding Affiliate takes the rights and obligations of the Customer under this DPA for the Workspaces it controls.
1.5 What this DPA does not cover. This DPA governs the personal data we process as your processor. It does not govern the personal data for which DemoPine is itself the controller — your account record, your name and email address, sign-in session records including the IP address and browser user agent, billing contact details, our diagnostic logs, and visits to demopine.com. That data is governed by our Privacy Policy, Sections 2, 7, 11, 12 and 13, and you exercise your rights over it directly with us. Section 3 below draws the line precisely.
2. Definitions
Capitalised terms not defined here have the meaning given in Section 2 of the Terms — including Customer Content, Demo, Member, Share Link, Sub-processor, Term, and Workspace.
| Term | Meaning |
|---|---|
| Customer Personal Data | Personal data contained in Customer Content, and the other personal data described in Annex I, that DemoPine processes on the Customer's behalf under the Terms. |
| Data Protection Law | All laws applicable to the processing of Customer Personal Data under this DPA, including the GDPR, the UK GDPR, the Swiss FADP, and US State Privacy Law. |
| EU SCCs | The standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (controller to processor). |
| FADP | The Swiss Federal Act on Data Protection of 25 September 2020, and its implementing ordinance. |
| GDPR | Regulation (EU) 2016/679. |
| Personal Data Breach | A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data. |
| UK Addendum | The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0, in force 21 March 2022. |
| UK GDPR | The GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018. |
| US State Privacy Law | The California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the "CCPA/CPRA") and comparable comprehensive state privacy laws, including those of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Maryland, Minnesota, Tennessee, Indiana, Kentucky, Rhode Island, and Washington. |
| controller, processor, data subject, processing, supervisory authority | As defined in the GDPR. "Business", "service provider", "sell", "share", and "sensitive personal information" have the meanings given in the CCPA/CPRA. |
3. Roles of the parties
3.1 The split. This restates Section 18.2 of the Terms; it does not change it.
| Data | Role |
|---|---|
| Customer Content and the personal data inside it — captured screenshots, screen recordings, tab audio, HTML page captures, step and overlay text, brand kits, uploaded files, imported bundles | You are the controller. DemoPine is your processor. |
| Demo viewer analytics generated when someone plays a published Demo | You are the controller. DemoPine is your processor. |
| Lead-capture form submissions | You are the controller. DemoPine is your processor. |
| Member directory records pushed to us by your identity provider or directory (SSO and SCIM) | You are the controller. DemoPine is your processor. |
| Workspace invitations you send, including the invited person's email address, which we transmit at your direction as your service provider (Terms Section 5.6) | You are the controller. DemoPine is your processor. |
| Account records, authentication and sign-in session records (including IP address and user agent), billing contact and payment records, our diagnostic and security logs, marketing-site visits | DemoPine is the controller. Governed by the Privacy Policy, not by this DPA. |
3.2 Independent controllers. Stripe, Inc. acts as our processor for the transaction records we instruct it to keep and as an independent controller for fraud prevention, financial-crime compliance, and its own regulatory obligations. Google LLC acts as an independent controller where a user chooses Google sign-in or where a Google-hosted profile image is loaded. We cannot instruct either of them in respect of that processing, and requests about it must go to them. See Privacy Policy Section 8.2.
3.3 Your identity provider. If you connect SAML SSO or a SCIM directory, that provider is your vendor and your sub-processor, not ours (Terms Section 16.5). You are responsible for what it sends us.
3.4 No sale, no sharing, no training. We do not sell Customer Personal Data, do not share it for cross-context behavioural advertising, do not use it for our own purposes, and do not use it to train AI models (Terms Section 13.5). Our agreement with our AI Sub-processor prohibits that provider from training on inputs or outputs submitted through its commercial API, and we will not engage an AI Sub-processor that does not make an equivalent commitment.
4. Subject matter, duration, nature, and purpose
This Section, with Annex I, is the description required by Article 28(3) of the GDPR and by Annex I.B of the EU SCCs.
4.1 Subject matter. DemoPine's processing of Customer Personal Data in order to provide the Service — an interactive product-demo tool that captures, stores, edits, publishes, and measures screen recordings and screenshots — as described in the Terms and any order form.
4.2 Duration. For the Term, plus the 30-day export window in Section 23.1 of the Terms, plus the retention periods published in Section 23.3 of the Terms and Section 11.1 of the Privacy Policy, and reproduced in Annex I.B below. Records we are required or entitled to keep under Section 23.4 of the Terms survive that period.
4.3 Nature of the processing. Collection at your direction through the Capture extension and the app; upload; storage; structural and format conversion, including re-encoding, resizing, thumbnail extraction, and remuxing of recorded video; organisation and indexing; retrieval and display to Members; publication to a public Share Link when you publish a Demo; embedding of media bytes into a published payload; computation and aggregation of playback analytics; receipt and storage of lead-form submissions; transmission of invitation emails at your instruction; transmission of prompt text and, for screenshot steps, the current screenshot to our AI Sub-processor when a user invokes an AI writing feature; metering of that use; export; erasure; and support and troubleshooting at your request.
4.4 Purpose. Solely to provide, secure, maintain, troubleshoot, and support the Service for you under the Terms, and to comply with law. Nothing else.
4.5 Types of personal data and categories of data subjects. Set out in Annex I.B.
4.6 We do not inspect what you capture. We do not pre-screen, moderate, validate, or inspect Customer Content, and we apply no automated content-moderation tooling to it (Terms Section 9.4). We therefore have no practical means of knowing whether a particular capture contains personal data, or which categories. Annex I.B describes what the Service is capable of holding, because you — not we — decide what actually goes into it.
5. Processing only on documented instructions
5.1 Documented instructions. We process Customer Personal Data only on your documented instructions, including for transfers to a third country, unless required to do so by law to which we are subject — in which case we will inform you of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
5.2 What counts as your instructions. Your complete and final instructions are: (a) this DPA; (b) the Terms and the Privacy Policy; (c) any order form or MSA signed by both parties; (d) the configuration choices and actions you and your Members take in the Service — publishing a Demo, sending an invitation, enabling a lead-capture form, connecting SSO or SCIM, invoking an AI writing feature, exporting, or deleting; and (e) any further written instruction you give us at [email protected] that we accept in writing.
5.3 Instructions we may charge for or decline. If an instruction goes beyond the Service as documented, we may decline it, or agree it separately and charge a reasonable fee for the work. We will tell you which.
5.4 If we think an instruction is unlawful. We will inform you immediately if, in our opinion, an instruction infringes Data Protection Law, and may suspend performance of that instruction until you confirm, withdraw, or amend it. We are not obliged to give you legal advice, and this is not a warranty that instructions we do not object to are lawful.
5.5 Aggregated and de-identified statistics. You instruct us, as part of your documented instructions, to generate aggregated and de-identified usage statistics as described in Section 21.4 of the Terms — counts of Demos published, playback rates, feature adoption. We generate them only where the aggregation is applied to the exclusion of any personal data, will not attempt to re-identify them, will bind any recipient to the same, and do not derive statistics from the contents of your screen captures, HTML captures, audio, or lead submissions.
6. Confidentiality
6.1 Personnel. We ensure that every person authorised to process Customer Personal Data — employees, officers, and contractors — is bound by a written obligation of confidentiality that survives the end of their engagement, or is under an appropriate statutory obligation of confidentiality. Section 19 of the Terms binds us in respect of your Customer Content, which is your Confidential Information; those obligations survive for three years after termination and indefinitely for trade secrets.
6.2 Need to know. Access to production systems holding Customer Personal Data is limited to personnel who need it to operate, secure, or support the Service. See Annex II for what that control does and does not consist of — in particular, we disclose there that we do not currently maintain a general-purpose access audit log.
7. Security of processing
7.1 Article 32 measures. Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to individuals, we implement and maintain the technical and organisational measures set out in Annex II. Annex II is the measures list required by Article 32 of the GDPR and by Annex II of the EU SCCs.
7.2 We maintain a written information security program and review it at least annually (Terms Section 18.6).
7.3 Changes. We may update the measures in Annex II, provided the updates do not materially reduce the overall level of security. Material changes are published in this document.
7.4 What we do not have. Annex II states plainly which measures we lack. We hold no SOC 2, ISO 27001, HIPAA, or PCI DSS certification or attestation, we do not claim compliance with those frameworks, we run no formal penetration-testing or bug-bounty programme, we operate no automated intrusion-detection system, and we keep no general-purpose security or access audit log. We say so here rather than in a footnote, because it is material to your own Article 32 and DPIA assessment.
7.5 The Service is not designed for regulated data. Sections 3.5 and 11.3 of the Terms prohibit putting protected health information, consumer health data, cardholder data, financial account numbers, government identifiers, biometric or genetic data, precise geolocation of identifiable individuals, GDPR Article 9 special-category data, children's personal data, or classified or export-controlled information into the Service, absent a signed writing from us. Our measures are calibrated to that prohibition.
8. Sub-processors
8.1 General written authorisation. You give us general written authorisation to engage Sub-processors. Clause 9 of the EU SCCs is agreed with OPTION 2 — GENERAL WRITTEN AUTHORISATION, with the notice period in Section 8.3.
8.2 Current list. Our current Sub-processors, the function each performs, the categories of data each receives, and its primary processing location are maintained at https://demopine.com/subprocessors and in Section 8.1 of the Privacy Policy. Annex III incorporates that list by reference. It is the authoritative list; the summary in Annex III is a convenience.
8.3 Notice of changes. We will give at least 30 days' notice before adding or replacing a Sub-processor that processes Customer Personal Data, by email to Workspace owners at the address we hold for them and by updating the sub-processor page, which explains how to be added to our sub-processor notification list by email.
8.4 Your right to object, and your exit. If you reasonably object on data-protection grounds within that 30-day period, we will work with you in good faith to offer an alternative. If we cannot, you may terminate the affected subscription and we will refund the prepaid fees allocable to the remainder of your then-current term, calculated on a straight-line daily basis (Terms Sections 16.4 and 6.11.1(4)). This is a deliberate exception to our otherwise non-refundable fee policy.
8.5 Flow-down and responsibility. We impose on each Sub-processor, by written contract, data-protection obligations that are no less protective than those in this DPA, including the obligations required of a processor by Article 28(3) and, where the Sub-processor is outside the EEA, UK, or Switzerland, an appropriate transfer mechanism. We remain fully liable to you for a Sub-processor's performance of our obligations under this DPA.
8.6 Copies of sub-processor agreements. On request to [email protected], we will provide a copy of the data-protection terms of our agreement with a Sub-processor, with commercial terms redacted, as Clause 9(c) of the EU SCCs requires.
9. Assistance with data subject requests
9.1 We refer, we do not act unilaterally. If a demo viewer, a lead submitter, a person whose personal data appears in a capture, or any other individual asks us to access, correct, delete, restrict, port, or object to the processing of data held inside your Workspace, we will, where lawful, tell them promptly that we act only as your processor, identify you where we are permitted to, forward the request to you, and assist you in responding. We will not alter or delete your data on a third party's instruction except where the law requires it. This restates Section 18.5 of the Terms and Section 13.6 of the Privacy Policy.
9.2 The tools we provide. Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to data subject requests. In practice:
| You need to | How |
|---|---|
| Find and remove a person from a capture | Delete or edit the step, or delete the Demo, in the app. Deleting a Demo removes it, its media, its analytics, and its leads, and revokes every Share Link minted from it in the same transaction |
| Take a published Demo down | Unpublish or delete it. The link dies immediately and permanently; the published payload is purged |
| Delete lead records | Delete the Demo, or reset the Demo's analytics (admin only), which erases every analytics event and every lead for that Demo. There is no per-record lead deletion in the app today — ask us and we will do it |
| Export a person's data for a portability or access request | Per-Demo export bundle containing the Demo and all of its media; CSV export of analytics events and lead records on plans that include CSV export. There is no single "download everything" archive; for anything the app cannot export, we assemble it manually |
| Anything the app cannot do | Email [email protected]. Where this DPA or the Terms says "ask us", we complete the action within 30 days of a verified request and confirm in writing (Privacy Policy Section 11.3) |
9.3 No charge for reasonable assistance. We do not charge for assistance of the kind described above. We may charge a reasonable fee for assistance that is manifestly unfounded, excessive, or that requires engineering work beyond the documented functionality of the Service, and we will tell you before incurring it.
9.4 Deadlines are yours. Statutory response deadlines run against you as controller. Our doing part of the work by hand does not extend them, and we resource these requests accordingly.
10. Assistance with Articles 32 to 36
Taking into account the nature of the processing and the information available to us, we will assist you in ensuring compliance with your obligations under Articles 32 to 36 of the GDPR, and their equivalents under the UK GDPR and the FADP:
- Article 32 — security of processing. By implementing and maintaining Annex II, by describing it honestly including its gaps, and by answering reasonable written security questionnaires under Section 13.
- Articles 33 and 34 — breach notification. As set out in Section 11 below.
- Article 35 — data protection impact assessments. By providing the information in this DPA, its Annexes, the Privacy Policy, and our transfer impact assessments, and by answering reasonable questions in writing. Sections 4, 10.2, 12.1 and 12.5 of the Terms, and Sections 4 and 12 of the Privacy Policy, are written to give you the facts a DPIA needs — including the ones that do not flatter us.
- Article 36 — prior consultation. By providing information reasonably required for a consultation with a supervisory authority about processing we carry out for you.
We will provide this assistance at no charge where it is proportionate to the Service you buy from us; where it is not, we will agree scope and a reasonable fee with you first.
11. Personal data breaches
11.1 72 hours. If we become aware of a Personal Data Breach, we will notify the affected Workspace's owner and admins without undue delay and in any event within 72 hours of becoming aware. This is the same commitment made in Section 18.7 of the Terms and Section 12 of the Privacy Policy. It is a maximum, not a target.
11.2 What the notice contains. The nature of the incident, including where possible the categories and approximate number of data subjects and records concerned; the likely consequences; the measures we have taken or propose to take, including to mitigate its adverse effects; and a contact point for further information. Where we cannot provide all of it at once, we will provide it in phases without further undue delay.
11.3 We will not wait for a complete investigation. We will not delay notice because an investigation is incomplete, and our notice is not an admission of fault or liability.
11.4 Assistance. We will provide reasonable assistance, information, and cooperation so that you can meet your own notification obligations to supervisory authorities and to data subjects, and will cooperate with you and your regulators in investigating and remediating the incident.
11.5 Who notifies whom. As processor, we notify you. Notifying a supervisory authority and, where required, the affected individuals is your obligation as controller. Where DemoPine is the controller (Section 3.1), that processing sits outside this DPA (Section 1.5) and is governed by Section 12 of the Privacy Policy.
11.6 Records. We maintain a record of Personal Data Breaches affecting Customer Personal Data, including the facts, effects, and remedial action taken, and will make it available to you on request.
12. Deletion or return at the end of the term
12.1 Your choice. At the end of the provision of services relating to processing, we will, at your choice, delete or return all Customer Personal Data to you, and delete existing copies, unless a law to which we are subject requires storage of the personal data. Your default choice, absent a written instruction to the contrary, is deletion.
12.2 The export window. After a paid subscription ends or is terminated for any reason, we keep your Customer Content available for export for 30 days (Terms Section 23.1). We provide that window even where we terminated for cause, except where doing so would violate law, a court order, or sanctions obligations, or where the content is itself unlawful. If we suspended your access before termination, we restore export-only access for that period on request.
12.3 How to get it out. Per-Demo export bundles containing the Demo and all of its media, and CSV export of analytics events and lead records on plans that include CSV export. There is no single "download everything about my account" archive today. For anything the app cannot export, contact [email protected] and we will assemble it manually within a reasonable time — and, for customers covered by Section 29.3 of the Terms (EU switching and egress under the Data Act), within the timescales that Section requires, at no charge, with a 30-day transitional period extendable once.
12.4 The retention schedule runs independently. Categories on the published retention schedule are deleted when they reach their period whether or not you have exported them. The schedule is in Section 23.3 of the Terms, Section 11.1 of the Privacy Policy, and Annex I.B below.
⚠️ The retention sweeper currently ships in dry-run mode. It runs daily at 03:20 UTC, counts what it would remove, reports that to our application logs, and deletes nothing. Until we switch it out of dry-run, read the periods in Annex I.B as our commitment about what we will delete and when — not as a description of deletions that have already happened — and note that deletions in those categories are performed on request in the meantime. We disclose this rather than describe a finished state, and we will not remove this note until the sweeper is live.
12.5 What survives. Notwithstanding Section 12.1, we retain records we are required or entitled to keep under Section 23.4 of the Terms — billing and tax records, invoices, payment records, raw payment-processor event records, and records needed to establish, exercise, or defend legal claims. Those are DemoPine controller records, not Customer Personal Data processed on your behalf. Where you exercise an erasure right, we satisfy it by deleting or de-identifying the personal data we hold about you, not by destroying business records we are obliged to keep.
12.6 Backups. Deletion from the live Service is immediate in our production systems, but residual copies may persist in our database provider's encrypted backups and point-in-time restore history for up to 1 day before they are overwritten in the ordinary rotation. We do not restore deleted personal data from backup except to recover from a system failure, and if we do, we re-apply pending deletions immediately afterwards. Deleted data may also persist for a limited period in providers' logs until those are overwritten in the ordinary course.
12.7 Anonymous Share Links. A Share Link created without an account is attached to no Workspace and is not reachable by account or Workspace deletion, unless it was minted from a Demo you later delete from a Workspace — in which case the deletion revokes it. It is otherwise bounded by the 180-day cap in Annex I.B, subject to the dry-run disclosure above, and by our removing it on request. Email [email protected] or [email protected] with the full /s/<code> URL and we will remove it within one business day.
12.8 Certification. On written request following deletion, we will certify in writing that deletion has been carried out, as Clause 8.5 of the EU SCCs requires.
13. Audit and information rights
13.1 Information. We make available to you all information reasonably necessary to demonstrate compliance with Article 28 and with this DPA. In the first instance that means this DPA and its Annexes, the Privacy Policy, the sub-processor page, our transfer impact assessments, and written answers to a reasonable security questionnaire. We aim to respond to a questionnaire within 30 days.
13.2 Audits and inspections. You may audit our compliance with this DPA, including by inspection, and we will contribute to those audits. Because we hold no third-party audit report to offer you in place of one:
- an audit may be conducted once in any 12-month period, on at least 30 days' written notice, during our normal business hours, without unreasonably disrupting our operations;
- it may be carried out by you or by an independent auditor you appoint who is not a competitor of ours and who is bound by confidentiality obligations at least as protective as Section 19 of the Terms;
- its scope is limited to systems, records, and premises used to process Customer Personal Data, and it must not access another customer's data, our other customers' Confidential Information, or anything that would put us in breach of a legal or contractual obligation;
- you bear your own and the auditor's costs; we bear ours;
- we will make personnel available to answer questions and will share the results with you.
13.3 More frequent audits. The once-per-year limit does not apply where a supervisory authority requires an audit, where you have reasonable grounds to suspect a Personal Data Breach affecting your Customer Personal Data, or where an audit is required following such a breach.
13.4 Supervisory authorities. We will submit to audits and inspections by a competent supervisory authority, and will make our premises and records available to it, as Clause 8.9 of the EU SCCs requires.
13.5 Remediation. Where an audit identifies a deficiency in our compliance with this DPA, we will remediate it at our own cost within a reasonable period agreed with you.
14. International transfers: the EU Standard Contractual Clauses
14.1 Where the data goes. DemoPine is operated from the United States and our infrastructure is hosted in the United States. If you are outside the United States, Customer Personal Data will be transferred to and processed in the United States. Privacy Policy Section 9 sets this out.
14.2 Incorporation. Where you are established in the EEA, or are otherwise subject to the GDPR, and Customer Personal Data is transferred from the EEA to DemoPine in the United States, the EU SCCs — Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor) — are hereby incorporated into this DPA by reference and form part of it, with you as data exporter and RyanTech LLC as data importer. They apply automatically, without signature, from the date in Section 1.2.
14.3 The selections we have made. The optional and variable provisions of the EU SCCs are completed as follows.
| Provision | Selection |
|---|---|
| Modules | Module Two (controller to processor) applies. Modules One, Three, and Four are deleted and do not apply. |
| Clause 7 — Docking clause | Included. See Section 1.4 above for how an Affiliate accedes. |
| Clause 9(a) — Use of sub-processors | OPTION 2 — GENERAL WRITTEN AUTHORISATION. The agreed notice period for the addition or replacement of a sub-processor is 30 days. The current sub-processor list is at https://demopine.com/subprocessors and in Annex III. |
| Clause 11(a) — Redress | The optional paragraph is omitted. DemoPine has not appointed an independent dispute resolution body. This does not affect a data subject's right to lodge a complaint with a supervisory authority or to seek a judicial remedy. |
| Clause 13(a) — Competent supervisory authority | As identified in Annex I.C below. |
| Clause 17 — Governing law | OPTION 1. The EU SCCs are governed by the law of Ireland. |
| Clause 18(b) — Choice of forum and jurisdiction | The courts of Ireland. |
| Annexes I, II and III to the EU SCCs | Populated by Annex I, Annex II, and Annex III to this DPA. |
| Signature and date (Annex I.A) | The EU SCCs are entered into on the date the Customer accepted the Terms, recorded by us under Section 1.1 of the Terms. No signature is required (Terms Section 18.3). A countersigned copy is available on request to [email protected]. |
14.4 Conflicts. In the event of a conflict between the EU SCCs and any other part of this DPA, the Terms, the Privacy Policy, or any order form, the EU SCCs prevail to the extent of the conflict, as Clause 5 of the EU SCCs requires.
14.5 Government access — Clauses 14 and 15. We carry out transfer impact assessments for our Sub-processors and will share them with you on request from [email protected]. As required by Clause 15 and as stated in Section 18.8 of the Terms and Section 10.3 of the Privacy Policy: we require valid legal process before disclosing Customer Personal Data; we notify the affected Workspace owner before disclosing and give you a reasonable opportunity to seek protective relief, unless legally prohibited or where there is a risk of death or serious physical harm; where prohibited, we seek a waiver and notify you as soon as we lawfully can; we disclose only the narrowest responsive set; and we challenge demands we reasonably consider unlawful, overbroad, or inconsistent with the GDPR or the EU SCCs. As of the last-updated date of this DPA, DemoPine has never received a national-security request, a FISA order, or a national-security letter, and has never disclosed customer content to any government body. We will update this statement if that changes, to the extent we are legally permitted to.
14.6 Alternative mechanisms. If the European Commission adopts a replacement or successor to the EU SCCs, or if an adequacy decision or another lawful transfer mechanism becomes available and applicable, we may adopt it on written notice to you, and it will replace the EU SCCs to the extent it applies.
15. International transfers: the UK Addendum
15.1 Incorporation. Where Customer Personal Data is transferred from the United Kingdom and the transfer is subject to the UK GDPR, the UK Addendum (version B1.0) is incorporated into this DPA by reference and forms part of it, appended to the EU SCCs incorporated by Section 14, and applies automatically without signature. Part 2 of the UK Addendum (the Mandatory Clauses) applies in full.
15.2 Table 1: Parties.
| Start date | Parties' details | Key contact | |
|---|---|---|---|
| Exporter | The date the Customer accepted the Terms (Terms Section 1.1) | The Customer, as defined in Section 1.3 of this DPA: the organisation or individual that controls the Workspace. Full name, trading name, and main address are those held in the Customer's DemoPine account and billing record | The Workspace owner, at the account email address held for them. Job title: as held in the Customer's own records |
| Importer | The same date | RyanTech LLC, a South Carolina limited liability company, trading as DemoPine / Demo Pine. 2764 Pleasant Road, Suite A #599, Fort Mill, SC 29708, USA | Data protection contact, [email protected]; legal notices, [email protected] |
Signatures are not required. Entry into this DPA is effected by acceptance of the Terms under Section 18.3 of the Terms, and both parties are treated as having signed the UK Addendum on the start date above.
15.3 Table 2: Selected SCCs, Modules and Selected Clauses.
| Item | Selection |
|---|---|
| Addendum EU SCCs | The Approved EU SCCs — Commission Implementing Decision (EU) 2021/914 — as incorporated by Section 14 of this DPA, including the Appendix Information set out in Table 3 |
| Reference (if any) | DemoPine Data Processing Addendum, last updated August 1, 2026 |
| Other identifier (if any) | Published at https://demopine.com/dpa |
| Are the Approved EU SCCs, including the Appendix Information, set out in an attached agreement? | Yes — in Sections 14 and 21 to 23 of this DPA |
| Module in operation | Module Two (controller to processor) |
| Clause 7 (Docking clause) | Used |
| Clause 11 (Option) | Not used — the optional independent-dispute-resolution-body paragraph is omitted |
| Clause 9a (Prior authorisation or general authorisation) | General authorisation |
| Clause 9a (Time period) | 30 days |
| Is personal data received from the Importer combined with personal data collected by the Exporter? | No |
15.4 Table 3: Appendix Information.
| Appendix element | Where it is set out |
|---|---|
| Annex 1A: List of Parties | Annex I.A of this DPA, and Table 1 above |
| Annex 1B: Description of Transfer | Annex I.B of this DPA |
| Annex II: Technical and organisational measures including technical and organisational measures to ensure the security of the data | Annex II of this DPA |
| Annex III: List of Sub processors (Module Two only) | Annex III of this DPA, and https://demopine.com/subprocessors |
15.5 Table 4: Ending this Addendum when the Approved Addendum changes.
| Ending this Addendum when the Approved Addendum changes | Selection |
|---|---|
| Which Parties may end this Addendum as set out in Section 19 of the Mandatory Clauses | Exporter (the Customer) |
15.6 UK interpretation. For UK transfers, references in the EU SCCs to the GDPR are read as references to the UK GDPR; references to EU or Member State law are read as references to UK law; the competent supervisory authority is the Information Commissioner's Office; and the governing law and forum under Clauses 17 and 18 are the laws of England and Wales and the courts of England and Wales, in each case as required by the Mandatory Clauses of the UK Addendum. Where the UK Addendum and any other part of this DPA conflict, the UK Addendum prevails for UK transfers.
16. International transfers: Switzerland
16.1 Incorporation. Where Customer Personal Data is transferred from Switzerland and the transfer is subject to the FADP, the EU SCCs incorporated by Section 14 apply, with the adaptations recognised by the Swiss Federal Data Protection and Information Commissioner (the "FDPIC") set out in this Section. These adaptations together are the "Swiss addendum" referred to in Section 18.3 of the Terms.
16.2 The adaptations.
| Point | Adaptation for Swiss transfers |
|---|---|
| Competent supervisory authority (Clause 13 and Annex I.C) | The FDPIC. Where a transfer is subject to both the FADP and the GDPR, the FDPIC is competent for the FADP-governed part and the authority identified in Annex I.C is competent for the GDPR-governed part |
| References to legislation | References to the GDPR are read as references to the FADP in respect of data transfers governed exclusively by the FADP. References to EU or Member State law are read as references to Swiss law |
| Legal entities | The term "personal data" includes data relating to identified or identifiable legal entities, where and for so long as Swiss law affords such data protection equivalent to that afforded to natural persons |
| Clause 18(c) — data subject rights | The term "Member State" must not be interpreted so as to exclude data subjects in Switzerland from suing for their rights in their place of habitual residence |
| Governing law and forum (Clauses 17 and 18(b)) | For transfers governed exclusively by the FADP, the EU SCCs are governed by the law of Switzerland and the forum is the courts of Switzerland. For transfers governed by both the FADP and the GDPR, Section 14.3 applies to the GDPR-governed part |
| Breach notification | Our 72-hour commitment in Section 11 applies. It is set so that a Swiss controller can meet its own obligation to notify the FDPIC as soon as possible |
16.3 Onward transfers. Where a Sub-processor is certified under the Swiss-US Data Privacy Framework, we may rely on that certification for the relevant transfer in place of or in addition to the adaptations above (Privacy Policy Section 9).
17. US state privacy law: service provider and processor terms
This Section restates and expands Section 18.4 of the Terms. It applies to personal information subject to the CCPA/CPRA or comparable US State Privacy Law. You are the business or controller. DemoPine is the service provider or processor.
17.1 Our undertakings under the CCPA/CPRA. We will:
- process personal information only to perform the services specified in the Terms, this DPA, and your order, and for no other purpose;
- not sell personal information and not share personal information for cross-context behavioural advertising, as those terms are defined by the CCPA/CPRA. We have never done so, including in the twelve months before the date of this DPA;
- not retain, use, or disclose personal information outside the direct business relationship with you, or for any commercial purpose other than the business purposes specified in the Terms and this DPA, including in the context of a merger or similar transaction except as permitted by the CCPA/CPRA;
- not combine personal information we receive from you with personal information we receive from another source, except as permitted by Cal. Civ. Code § 1798.140(ag)(1) and its implementing regulations;
- comply with the obligations applicable to service providers under the CCPA/CPRA and provide the same level of privacy protection as the CCPA/CPRA requires of you;
- notify you promptly, and in any event without undue delay, if we determine we can no longer meet these obligations;
- permit you to take reasonable and appropriate steps to stop and remediate unauthorised use of personal information, including through the information and audit rights in Section 13;
- permit you to monitor our compliance, through Section 13;
- impose the same restrictions on any Sub-processor engaged to assist in providing the services, by written contract, as Section 8.5 requires;
- assist you in responding to verifiable consumer requests to know, access, correct, delete, opt out, and limit the use of sensitive personal information, through Section 9;
- not use, retain, or disclose sensitive personal information for any purpose other than those permitted by Cal. Civ. Code § 1798.121(d) — providing the service you requested, security, and fraud prevention — and never to infer characteristics about an individual.
We certify that we understand the restrictions in this Section 17 and will comply with them. We do not sell or share personal information.
17.2 Other US state laws. For personal data subject to a comparable US State Privacy Law, we additionally: process personal data only on your documented instructions; ensure that persons processing it are subject to a duty of confidentiality; delete or return personal data at your direction at the end of the provision of services, subject to Section 12.5; make available the information necessary to demonstrate compliance and allow and contribute to reasonable assessments and audits under Section 13; engage sub-processors only under a written contract imposing equivalent obligations and after giving you the notice and objection right in Section 8; and assist you with security, breach notification, and data protection assessments through Sections 10 and 11.
17.3 De-identified data. Where we generate aggregated or de-identified data under Section 5.5, we will take reasonable measures to ensure it cannot be associated with an individual or household, will publicly commit to maintain and use it only in de-identified form, will not attempt to re-identify it, and will contractually obligate any recipient to the same.
17.4 Consumer health data. We do not knowingly collect consumer health data as defined by the Washington My Health My Data Act, Nevada SB 370, or comparable law. Section 11.3 of the Terms prohibits you from putting it into the Service. If you believe such data has been published through DemoPine, email [email protected] and we will act.
18. Your obligations as controller
18.1 Lawfulness. You warrant that you have a lawful basis for the processing you instruct us to carry out; that you have given every notice and obtained every consent that Data Protection Law requires, including from people whose screens, records, or details are captured, from viewers of your Demos, and from people who fill in a lead-capture form; and that your instructions to us will not put us in breach of Data Protection Law. Sections 10.1 to 10.5 of the Terms set this out in full and are material to our agreement to provide the Service.
18.2 What you capture. The Capture extension records the visible contents of the tab you record — screenshots on each click, optional video and tab audio, a copy of the page's HTML, and structured details of the elements you interact with, including the values held in form fields. Nothing is automatically redacted, masked, or blurred. Blur is non-destructive in the editor — the stored original is unchanged — but destructive on export: every blur rectangle on a screenshot step is burned into the pixels of the published payload and of any export bundle, and the rectangle is dropped from that copy. Blur on video and HTML-capture steps is NOT baked and remains presentation-only. Use synthetic or scrubbed data. Do not capture what you cannot afford to disclose.
18.3 Publishing is your act. A Share Link is a public URL with no password, no email gate, no domain restriction, and no view limit, and Share pages are not currently blocked from search engines. Publishing is an act of publication by you (Terms Section 12.3).
18.4 Who can see what, inside a Workspace. Access is scoped to the Workspace, not to the author. Any Member — including a read-only viewer on plans where that role exists — can see every Demo and its captured media, download a full export bundle, read the member list with names and email addresses, view billing history, and, on plans with full analytics, read and export lead names, email addresses, and companies. Choose Members accordingly; this is a control you hold and we do not.
18.5 Prohibited data. You will not put into the Service any category of data prohibited by Sections 3.5 and 11.3 of the Terms. Capturing such data is a breach of the Terms and is outside the scope of the processing described in Annex I.
18.6 Email verification. We do not currently require email-address verification for password sign-ups (Terms Section 4.2), and accounts created through SSO or SCIM are marked verified on your identity provider's assertion rather than on our own verification. Confirm out of band that the person who accepted an invitation is the person you meant to invite before putting sensitive captures into a shared Workspace.
18.7 Your own trackers. Our viewer analytics set no cookies and store no persistent or cross-demo identifier on a viewer's device. If you add your own tracking, embed our player in a page that sets cookies, or enable a lead-capture form, you are responsible for any notice and consent those viewers are owed.
19. Liability, precedence, and general terms
19.1 Order of precedence. Section 28.4 of the Terms governs, and ranks this DPA above the Terms on the subject matter it covers. From highest to lowest: (1) a signed order form, MSA, or enterprise agreement; (2) a signed data processing addendum, on the subject matter it covers; (3) this DPA, on the subject matter it covers; (4) the Terms; (5) the Privacy Policy; (6) any other Documentation, help content, or marketing material. Within this DPA, the EU SCCs prevail over everything else for transfers they cover (Section 14.4), and the UK Addendum prevails for UK transfers (Section 15.6).
19.2 Liability. Each party's liability arising out of or relating to this DPA is subject to the exclusions and limitations in Sections 25 and 26 of the Terms, to the maximum extent permitted by law. Nothing in this Section 19.2 limits or excludes either party's liability to a data subject under the EU SCCs or the UK Addendum, liability that cannot be limited under Data Protection Law, or any right of a data subject to compensation under Article 82 of the GDPR. The EU SCCs' own liability and indemnity provisions (Clauses 12 and 14) apply as written for the transfers they govern.
19.3 Governing law of this DPA. Except where the EU SCCs, the UK Addendum, or the Swiss addendum provide otherwise for the transfers they govern — in which case those provisions control — this DPA is governed by the law of the State of South Carolina, USA, and Sections 30 and 31 of the Terms apply to disputes under it. The arbitration agreement in Section 30 of the Terms does not restrict a data subject's rights under Clause 11 or Clause 18 of the EU SCCs, or the equivalent provisions of the UK Addendum.
19.4 Changes to this DPA. We may update this DPA. For a change that materially and adversely affects your rights, Section 32 of the Terms applies — at least 30 days' notice, and your right to reject the change. Changes required to keep a transfer mechanism lawful, or to reflect a new or replacement set of standard clauses, take effect as required by the relevant decision or law.
19.5 Severability and survival. If any provision of this DPA is held unenforceable, it is modified to the minimum extent necessary or severed, and the rest remains in force. Sections 6, 11, 12, 13, 17, and 19 survive the end of the Term.
19.6 Language. This DPA is written in English. Any translation is for convenience only; the English version controls.
20. How to contact us
RyanTech LLC (d/b/a DemoPine)
A South Carolina limited liability company
2764 Pleasant Road, Suite A #599
Fort Mill, SC 29708 USA
| What you need | Where to write |
|---|---|
| Data-protection questions, DPA queries, sub-processor questions, transfer impact assessments, data subject requests | [email protected] |
| A countersigned copy of this DPA, an Affiliate accession under Section 1.4, or any legal notice | [email protected] |
| Security vulnerability reports | [email protected] |
| Takedowns, anonymous-share removal, export assistance | [email protected] |
EU and UK representative. DemoPine has no establishment in the European Union or the United Kingdom and has not appointed an Article 27 representative, because the Service is directed to the United States and DemoPine does not target data subjects in the EEA or the UK. That is a statement about DemoPine's own obligations under Article 3(2). It does not narrow this DPA: where you are subject to the GDPR, UK GDPR, or Swiss FADP, this DPA and the transfer clauses in Sections 14 to 16 apply in full, and DemoPine performs every processor obligation in them. The same reasoning applies to the representative requirement in Article 14 of the Swiss FADP, and DemoPine has not appointed a Swiss representative; this does not affect the Swiss adaptations in Section 16, which continue to apply to transfers from Switzerland for customers subject to the FADP. If DemoPine begins marketing the Service in those markets it will appoint representatives and name them here first.
Data Processing Addendum: https://demopine.com/dpa · Terms of Service: https://demopine.com/terms · Privacy Policy: https://demopine.com/privacy · Sub-processors: https://demopine.com/subprocessors
21. Annex I — Description of the processing
This Annex is Annex I to the EU SCCs and Annex 1 to the UK Addendum.
21.1 Annex I.A — List of parties
| Data exporter | Data importer | |
|---|---|---|
| Name | The Customer — the organisation or individual that controls the Workspace, as defined in Section 1.2 of the Terms. Name, trading name, and address are those held in the Customer's DemoPine account and billing record | RyanTech LLC, a South Carolina limited liability company, doing business as DemoPine and Demo Pine |
| Address | As held in the Customer's account and billing record | 2764 Pleasant Road, Suite A #599, Fort Mill, SC 29708, USA |
| Contact person | The Workspace owner, at the account email address held for them | Data protection contact, [email protected]; legal notices, [email protected] |
| Activities relevant to the data transferred | Use of the DemoPine Service to capture, build, store, publish, and measure interactive product demos, and to administer the Customer's Workspace and its Members | Provision of the DemoPine Service, as described in the Terms and in Section 4 of this DPA |
| Role | Controller | Processor |
| Signature and date | Not required. The parties enter into these clauses on the date the Customer accepts the Terms, recorded by DemoPine under Section 1.1 of the Terms. Terms Section 18.3 provides that this DPA applies automatically, without signature | As for the exporter |
21.2 Annex I.B — Description of transfer
Categories of data subjects.
| Category | Notes |
|---|---|
| The Customer's Members — owners, admins, editors, and viewers of a Workspace | Including accounts created for them by the Customer's SSO or SCIM directory |
| People the Customer invites to a Workspace | An invitee may have no DemoPine account and may never create one |
| Individuals whose personal data appears in captured content | The Customer's own end users, customers, employees, counterparties, or any other person whose data was rendered on a screen the Customer recorded. These people have typically never heard of DemoPine and have no relationship with us |
| Viewers of a published Demo | People who open a Share Link and press play |
| People who submit a lead-capture form on a Demo |
Categories of personal data.
| Category | What it consists of |
|---|---|
| Captured screen content | Full screenshots of the recorded browser tab (JPEG as captured; PNG where a redaction has been applied on export); video recordings of the tab and, where enabled, the tab's audio; a verbatim copy of the page's HTML with only scripts, <noscript> blocks, and iframes removed; the URL and title of the page; click coordinates; structured details of the element clicked, including its visible text, accessible label, form label, placeholder, and — where the element is an input — the value it held; and the original filename of any uploaded file. Any personal data visible or present in those artefacts |
| Demo authoring content | Step names, overlay and callout text, calls to action, chapter names, branching configuration, and brand-kit values (colours, logo URLs, and scanned palette and logo candidates) |
| Directory and identity records | Email address and display name received in a signed SAML assertion at first SSO sign-in; email address, display name, and the directory's external identifier received over SCIM; Workspace role and active status. Every other attribute an identity provider or directory sends is ignored, and the raw SAML assertion is not retained |
| Invitation records | The invited person's email address, the role assigned, who invited them, and the invitation's timestamps |
| Viewer analytics | Event type (view, step viewed, hotspot clicked, demo completed, lead submitted); a playback session identifier minted in the viewer's browser memory per playback; step and hotspot identifiers; share code and Demo identifier; device class (mobile, tablet, desktop) derived from the user-agent string, which is itself discarded; the hostname only of the referring page; a two-letter country code supplied by our CDN; and a timestamp. No IP address, no cookie, and no cross-demo or cross-visit identifier |
| Lead-capture submissions | Name, work email, and company — or any subset the Customer asks for — each truncated to 320 characters. Anything else submitted is discarded. Stored with the playback session identifier and share code |
| AI feature inputs | The instruction text, the text being worked on, and — for a screenshot step only — the current screenshot (images over 5 MB are not sent; no image is sent for video, page-capture, or audio steps). Transmitted to our AI Sub-processor at the moment a user invokes the feature. Not retained by DemoPine: we keep only the feature used, the model, credits consumed, and input and output token counts, attributed to a Workspace and user |
Sensitive data.
The Service is a general-purpose product-demo tool and is not designed, marketed, or certified for special-category or otherwise regulated data. Sections 3.5 and 11.3 of the Terms prohibit the Customer from putting into the Service any protected health information, consumer health data, cardholder data, financial account numbers, government identifiers, biometric or genetic data, precise geolocation of identifiable individuals, GDPR Article 9 special-category data, personal data of children below the applicable age of digital consent, or classified or export-controlled information.
Restrictions and safeguards applied to sensitive data: the contractual prohibition above; the blur tool, which is destructive for screenshot steps on export (burned into the pixels, rectangle dropped) but remains presentation-only on video and HTML-capture steps; and the general measures in Annex II. DemoPine applies no technical detection or filtering of sensitive data, because we do not inspect Customer Content (Section 4.6). Captures containing prohibited categories are a breach of the Terms.
Frequency of the transfer. Continuous, on an ongoing basis, for the duration of the Term.
Nature of the processing. As set out in Section 4.3.
Purpose of the transfer and further processing. As set out in Section 4.4: to provide, secure, maintain, troubleshoot, and support the Service for the Customer under the Terms, and to comply with law.
Period for which the personal data will be retained. Customer Personal Data is retained for as long as the Customer's Workspace holds it — until the Customer or a Workspace admin deletes it, or the account or Workspace is deleted — subject to the published retention schedule below and to the export window in Section 12.2. This table reproduces the processor-scope rows of Section 23.3 of the Terms and Section 11.1 of the Privacy Policy; those Sections govern.
| Category | Period | Measured from | Enabled |
|---|---|---|---|
| Closed Workspace invitations (accepted, revoked, or expired), including the invited person's email address | 90 days | the date it closed | On |
| Revoked or expired Share Link records, kept as tombstones so a retired code is never reissued | 90 days | revocation or expiry | On |
| Share Links created without an account, and their stored payloads | 180 days | creation | On |
| Orphaned published-share payloads | 7 days | last modified | On |
| Orphaned media objects | 7 days | last modified | On |
| Demo analytics events | 400 days (13 months) | the event | On |
| Lead-capture submissions | 730 days (24 months) | the submission | On |
| AI usage events — user identifier removed (pseudonymised) | 90 days | the event | On |
| AI usage events — deleted | 400 days (13 months) | the event | On |
| AI usage metering periods | 400 days (13 months) | period end | On |
| Empty Workspaces (no members, no demos, no billing history) | 90 days | last change | Off |
⚠️ Read with Section 12.4. The sweeper that enforces this schedule currently runs in dry-run mode: it reports what it would delete and deletes nothing. The periods above are our published commitment; until the sweeper is live, deletions in these categories are performed on request. Rows marked "Off" ship disabled and delete nothing at all today.
Transfers to sub-processors. Subject matter, nature, and duration of the processing carried out by each Sub-processor are as set out in Annex III and at https://demopine.com/subprocessors. Each Sub-processor processes for the duration of our agreement with it and only for the function identified there.
21.3 Annex I.C — Competent supervisory authority
| Situation | Competent authority |
|---|---|
| The data exporter is established in an EEA Member State | The supervisory authority of that Member State, responsible for ensuring the exporter's compliance with the GDPR |
| The data exporter is not established in the EEA but is subject to the GDPR under Article 3(2) and has appointed a representative under Article 27 | The supervisory authority of the Member State in which that representative is established |
| The data exporter is not established in the EEA, is subject to the GDPR under Article 3(2), and is not required to appoint an Article 27 representative | The supervisory authority of the Member State in which the data subjects whose personal data is transferred are located |
| The transfer is subject to the FADP | The Swiss Federal Data Protection and Information Commissioner (Section 16.2) |
| The transfer is subject to the UK GDPR | The Information Commissioner's Office (Section 15.6) |
DemoPine has no establishment in the European Union or the United Kingdom, so no single lead supervisory authority applies to DemoPine itself, and DemoPine has not appointed an Article 27 representative (Section 20). The competent authority is determined by reference to you, the data exporter, as set out in the table above.
22. Annex II — Technical and organisational measures
This Annex is Annex II to the EU SCCs and Annex II to the UK Addendum. It is written to describe only measures we actually have, and to name the ones we do not. We make no claim to any certification. Where a measure is provided by a platform rather than by us, we say so.
22.1 Measures we implement
| Area | Measures |
|---|---|
| Pseudonymisation and encryption | All traffic to demopine.com and app.demopine.com is served over HTTPS; plain HTTP is redirected. Passwords are stored only as salted scrypt hashes; we never store, log, or can recover a plaintext password. SCIM bearer tokens are stored only as SHA-256 hashes with a short display prefix; the plaintext is shown once at creation and never again, and comparison is constant-time. Invitation tokens are likewise stored only as SHA-256 hashes. Data at rest is encrypted by our managed database and object-storage platforms as part of their services; we rely on their published commitments for that and do not operate our own key management. AI usage records are pseudonymised at 90 days by removing the user identifier |
| Confidentiality — access control | Access control is enforced server-side on every request and is scoped to the Workspace. The workspace-selection cookie only selects a Workspace and confers no permissions of its own; permissions are re-checked against membership on every request. Roles are owner, admin, editor, and viewer (role selection requires the Team plan or above). Card data never reaches our servers — payment details are entered directly into Stripe's hosted or embedded checkout |
| Confidentiality — stored media | Captured media is held in a private object-storage bucket. Every read goes through a URL we sign for the requester, which stops working one hour after issue; the app refreshes URLs before they lapse. Stored objects are marked private; API responses carrying signed URLs are returned cache-control: private, no-store. A published Demo never fetches the bucket at all — publishing embeds the media bytes into the published payload, so a viewer never receives a storage URL |
| Integrity | Deleting or unpublishing a Demo revokes every Share Link minted from it in the same database transaction, and the published payload is then purged. Revocation is checked on the read path, before any stored copy is read, so a revoked, expired, or unknown code is dead even if a cleanup failed. A database trigger applies the same rule to every other route by which a Demo can disappear, including Workspace and account deletion. Retired codes are kept as tombstones so a code is never reissued. Cross-site request forgery is blocked using request headers rather than a CSRF cookie. Presigned uploads pin the content type, so a presigned URL cannot be reused to upload a different MIME type |
| Authentication | Password sign-in requires a minimum of 12 characters and a zxcvbn strength score of at least 3, enforced on both client and server, with passwords resembling the user's name or email rejected. Session tokens are opaque and cryptographically signed, delivered in HttpOnly, Secure, SameSite=Lax cookies that JavaScript cannot read, with a 7-day lifetime refreshed while the user stays active. Resetting a password revokes every other active session. Google sign-in is available as an alternative. SAML assertions must be signed, are checked against a pinned audience, are tied to email domains the Customer has claimed, and the raw assertion is not retained |
| Availability and resilience | The application, database, and object storage run on managed platforms (see Annex III). Our database provider maintains automated backups and point-in-time restore history. Backups are encrypted at rest, are not accessible to customers, and are not used for ordinary operations |
| Data minimisation | Viewer analytics store no IP address, no cookie, and no cross-demo identifier; the user-agent string is reduced to a device class and discarded; the referrer is reduced to a hostname; the viewer's IP is used transiently in memory only as a rate-limiting key and is never written to the analytics store. Lead forms keep only name, work email, and company, each truncated to 320 characters, and discard anything else submitted. SCIM attributes beyond email, display name, and external identifier are ignored. AI prompts, screenshots, and generated output are not retained |
| Limited retention | A published retention schedule (Annex I.B) enforced by a dedicated sweeper that runs daily at 03:20 UTC, works in small batches, and writes an audit record of every run once it is out of dry-run. If any single category would touch more than a quarter of its own table, that category is skipped and reported rather than executed — a safeguard against a mistaken period or a misconfigured connection. The check is not applied to tables with fewer than 1,000 rows. See the dry-run disclosure in 22.2 |
| Abuse limitation | Rate limiting is applied to public endpoints, including the analytics ingestion endpoint and the share paths. Invitations from a Workspace generating complaints may be rate-limited or disabled |
| Personnel | Everyone with access to production systems is bound by written confidentiality obligations that survive the end of their engagement (Terms Section 19). Access is limited to personnel who need it to operate, secure, or support the Service |
| Governance | A written information security program, reviewed at least annually (Terms Section 18.6). A published vulnerability disclosure route at [email protected], with a commitment not to pursue civil action or refer to law enforcement researchers who act in good faith under the policy in Section 12 of the Privacy Policy |
| Transfers to Sub-processors | Each Sub-processor is engaged under a written agreement limiting it to processing on our documented instructions, with obligations no less protective than this DPA and an appropriate transfer mechanism. Transfer impact assessments are carried out and shared with customers on request. 30 days' advance notice of any addition or replacement, with an objection right and a refund-backed exit (Section 8) |
| Assisting the controller | The measures in Sections 9, 10, 11, 12 and 13 of this DPA — in-app deletion, unpublishing, analytics reset, per-Demo and CSV export, manual assistance where the app cannot do it, and 72-hour breach notification |
22.2 Measures we do not have
We state these because they are material to your Article 32 assessment, your DPIA, and your vendor review. Do not infer any of them from the table above.
| Gap | What it means for you |
|---|---|
| No SOC 2, ISO 27001, HIPAA, or PCI DSS certification or attestation | There is no third-party report we can send you in place of an audit. Section 13 gives you a direct audit right instead |
| No formal penetration-testing programme and no bug-bounty programme | Our security posture is not externally validated on a schedule |
| No general-purpose security or access audit log | We cannot today produce a record of which person accessed which Customer Content and when. We do retain a billing webhook audit trail, a last-used timestamp for SCIM directory access tokens, and — once the retention sweeper is live — an audit record of every sweeper run |
| No automated intrusion-detection system | Detection of anomalous activity is not automated |
| The retention sweeper runs in dry-run mode | It reports what it would delete and deletes nothing today. The periods in Annex I.B are a commitment, not a description of completed deletions; deletions in those categories are performed on request until it is enabled |
| The old public media domain has not yet been detached | Media URLs handed out under media.demopine.com before the change to signed URLs remain public and non-expiring until we detach that domain at our content-delivery provider. That is an operational step we still owe. Treat any media URL already in circulation from that period as permanently live |
| No email-address verification at sign-up | A person can create an account with an email address they do not control, and a Workspace invitation can be accepted by any signed-in account whose address matches. Confirm invitees out of band (Section 18.6) |
| DemoPine offers no multi-factor authentication of its own | Where you require MFA, enforce it at your SAML identity provider or on the Google account used for Google sign-in |
| No data-residency choice and no customer-managed encryption keys | All processing is in the United States (Section 14.1) |
| Blur is destructive only on screenshots | Blur on screenshot steps is burned into the pixels of any published payload or export bundle, and the rectangle is dropped from that copy. Blur on video and HTML-capture steps is not baked and remains presentation-only — we cannot re-encode video in the browser, and an HTML capture has no pixels to burn |
| No content inspection or moderation | We do not pre-screen, validate, or moderate Customer Content, and apply no automated content-moderation tooling to it. We act on notices and on our own detection of Acceptable Use Policy violations |
| Rate limiting is per application instance | It is in-memory and per-process, not a shared distributed limiter |
| No availability commitment | We do not commit to any level of uptime or performance and offer no service-level agreement or service credits, except where an Enterprise order form or MSA signed by both parties expressly provides one (Terms Section 25.2) |
| We do not currently run formal personnel background checks or a formal recurring security-training programme | RyanTech LLC is a small company. Confidentiality obligations and need-to-know access are the controls in place; a background-check and training programme is not |
22.3 A note on residual risk
Two facts follow from what the Service is, not from any measure we could add. First, a signed media URL is a bearer token for its one hour of life: anyone who obtains one within that window — from a browser's network tab, a HAR file, a proxy log, an extension, or a shared screen — can fetch that one file until it lapses. Second, a live Share Link is public, and revoking it stops us serving the Demo but does not retrieve copies anyone already downloaded. Access controls reduce exposure; they do not undo a capture. Assess the data you put into the Service on that basis.
23. Annex III — Sub-processors
This Annex is Annex III to the EU SCCs and Annex III to the UK Addendum.
The authoritative, current list of Sub-processors — including the function each performs, the categories of Customer Personal Data each receives, and its primary processing location — is published at https://demopine.com/subprocessors and in Section 8.1 of the Privacy Policy, and is incorporated into this Annex by reference. It is maintained there rather than reproduced here so that one page changes when a Sub-processor does, and so that the 30-day notice in Section 8.3 always points at a current document.
As at the last-updated date of this DPA, the Sub-processors approved under the general written authorisation in Section 8.1 are:
| Sub-processor | Function |
|---|---|
| Fly.io, Inc. | Application hosting for app.demopine.com |
| Neon, Inc. | Managed PostgreSQL database |
| Cloudflare, Inc. | Object storage (R2) for captured media and published-demo payloads; content delivery; hosting for demopine.com |
| Anthropic PBC | AI text generation for the built-in writing assistant |
| Zoho Corporation (ZeptoMail) | Transactional email — password resets and Workspace invitations only |
All of them process in the United States. Consult the sub-processor page for each one's data categories and precise processing location before relying on this summary.
Not Sub-processors. Stripe, Inc. (and Stripe Payments Europe Ltd for EU customers) and Google LLC act in part as independent controllers and are described in Section 3.2 and in Section 8.2 of the Privacy Policy. Your own identity provider or directory, if you connect one, is your sub-processor, not ours (Section 3.3).
Adding or replacing one. Section 8.3 and Section 8.4 govern: 30 days' notice, a reasoned objection right, and a refund-backed exit if we cannot offer an alternative.
_This Data Processing Addendum is published at https://demopine.com/dpa and is incorporated into the Terms of Service by Section 18.3 of those Terms. Last updated: August 1, 2026._