Last updated: 2026-09-21 — Version v1.2
1. Parties and how it applies
This Data Processing Addendum ("DPA") is between MiCCA OÜ, a private limited company registered in Estonia, registry code 11509095, registered address Tartu, Tartu County, Estonia, VAT number EE101555946 ("MiCCA"), and the customer organisation that has accepted the Terms of Service ("Customer").
This DPA is part of the Terms of Service and applies to every Customer from the moment its account is created, without a separate signature. The app records who accepted the Terms, when, and the version accepted; the person accepting confirms that they may bind the Customer. Requests for a countersigned copy go to [email protected].
2. Roles
- MiCCA as processor. Personal data in the Customer's target applications that appears in recordings, run reports, logs and derived artifacts, and any personal data in the Customer's guides ("Customer Data"). The Customer is the controller, or a processor for its own client, and MiCCA processes Customer Data on its instructions under this DPA.
- MiCCA as controller. Account data of the Customer's users (names, email addresses, roles, usage logs) and billing data, governed by the Privacy Policy, not by this DPA.
The Customer confirms that it has a lawful basis to record its target applications and to have MiCCA process the personal data in them, and that it has made the attestation described in the Acceptable Use Policy.
3. Subject matter, duration, nature and purpose
MiCCA processes Customer Data for as long as the Customer has an account, to provide the Service: signing in to the Customer's application with the credentials it supplies, recording a browser session in a short-lived, isolated recording environment, generating narration and captions, and storing and delivering the resulting videos and reports. Details are in Annex 1.
4. Instructions
MiCCA processes Customer Data only on the Customer's documented instructions: the Terms, this DPA, and the Customer's use of the app and API (creating projects, starting runs, choosing retention settings, deleting data). MiCCA will tell the Customer if it believes an instruction breaches data protection law. MiCCA may process Customer Data where EU or Member State law requires it, and then informs the Customer unless the law forbids it.
5. Confidentiality
MiCCA restricts access to Customer Data to people who need it to provide the Service and who are bound by confidentiality obligations. MiCCA does not look at the Customer's recordings except to provide support the Customer asked for, to investigate abuse or a security incident, or where the law requires it.
6. Security measures
MiCCA maintains technical and organisational measures appropriate to the risk, including:
- Encryption of Customer Data in transit (TLS) and at rest, including object storage and backups.
- Credential protection: target-application credentials are encrypted at rest, decrypted only inside the recording environment for the duration of a run, never sent to any AI provider and never written to logs.
- Isolated recording environments: every run gets a fresh, isolated recording environment whose network reaches only the hosts the Customer allowed; it is destroyed after the run.
- Access control: production access is limited to authorised staff, uses individual accounts and strong authentication, and follows least privilege.
- Audit logging of administrative actions and access to production systems.
- Tenant separation in the application and storage.
- Backups encrypted and rotated on a 30-day window.
- Incident response procedures, including the notifications in section 10.
MiCCA may improve these measures and will not reduce the overall level of protection during the term.
7. Sub-processors
The Customer gives general authorisation for MiCCA to use the sub-processors listed in Annex 2. MiCCA imposes data protection obligations on each sub-processor that are no less protective than this DPA, and remains responsible to the Customer for their performance.
MiCCA will notify the Customer by email at least 30 days before adding or replacing a sub-processor. The Customer may object within that period on reasonable data protection grounds. If the parties cannot resolve the objection, the Customer may terminate the affected subscription.
8. International transfers
MiCCA's application and storage run in the European Union. Daytona, Google, ElevenLabs, Stripe and Resend are based in the United States, and Cloudflare operates in the EU and the US. Where Customer Data leaves the European Economic Area, MiCCA relies on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) with any supplementary measures required, or on an adequacy decision of the European Commission where one applies. The Customer may request a copy of the applicable clauses.
9. Data subject requests
If a data subject contacts MiCCA about Customer Data, MiCCA forwards the request to the Customer without undue delay and does not answer it directly unless the Customer asks it to. MiCCA assists the Customer with reasonable technical and organisational measures in responding to requests for access, rectification, erasure, portability, restriction and objection. The Customer can locate and delete runs, videos and projects in the app itself; MiCCA helps with what the app does not offer.
10. Personal data breaches
MiCCA notifies the Customer without undue delay, and within 72 hours, after becoming aware of a personal data breach affecting Customer Data. The notification describes what happened, the data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact; details may follow in phases as they become known. MiCCA assists the Customer with its own notifications to supervisory authorities and data subjects.
11. Further assistance
MiCCA assists the Customer with data protection impact assessments and prior consultations with supervisory authorities that concern the Service, and makes available the information needed to demonstrate compliance with GDPR Article 28.
12. Deletion and return
The Customer can export videos, reports and guides from the app at any time. When the Customer deletes a run, a project or its account, MiCCA deletes the associated Customer Data within 30 days; copies in backups expire within a further 30 days as the backups rotate. On request to [email protected], MiCCA confirms deletion in writing. MiCCA may keep data that EU or Member State law requires it to keep, for as long as that law requires.
13. Audits
On reasonable notice of at least 30 days, and no more than once in twelve months unless a supervisory authority requires otherwise or a breach has occurred, the Customer or an independent auditor bound by confidentiality may audit MiCCA's compliance with this DPA. MiCCA first provides documentation and answers written questions; an inspection takes place only where that is not sufficient, during business hours, without exposing other customers' data. Each party bears its own costs.
14. Liability and precedence
The liability limits in the Terms of Service apply to this DPA. On the processing of personal data this DPA prevails over the Terms, and the Standard Contractual Clauses prevail over both. Estonian law governs this DPA; disputes go to Tartu County Court, Estonia.
15. Contact
Data protection enquiries: [email protected]. Legal notices: [email protected].
Annex 1 — Details of processing
- Data subjects: the Customer's staff who use the Service; users, customers and other people whose personal data appears in the Customer's target application, guides or recordings.
- Categories of data: names, email addresses, usernames and other data shown on the recorded pages; credentials the Customer supplies for its own application; text of guides; run logs. No special categories of data are intended to be processed.
- Processing operations: storage, encryption, signing in to the Customer's application, screen recording, narration and captions, video production, delivery, backup and deletion.
- Duration: the term of the Customer's account, plus the deletion periods in section 12.
Annex 2 — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | application hosting | Germany |
| Cloudflare, Inc. | network, security and file storage | EU / US |
| Daytona | compute for recordings | United States |
| Google LLC | AI language services; never credentials | United States |
| Google LLC (Google Analytics) | visit and conversion statistics, only with consent | United States |
| ElevenLabs, Inc. | AI speech services | United States |
| Stripe, Inc. | payments | United States |
| Resend, Inc. | transactional email | United States |
| Sentry | error monitoring | United States |