Screen Browser

Data Processing Addendum

The addendum under which Screen Browser processes personal data on behalf of customer organisations, covering sub-processors, security measures, data subject rights, international transfers and audits.

Last updated: 2026-09-21 — Version v1.2

1. Parties and how it applies

This Data Processing Addendum ("DPA") is between MiCCA OÜ, a private limited company registered in Estonia, registry code 11509095, registered address Tartu, Tartu County, Estonia, VAT number EE101555946 ("MiCCA"), and the customer organisation that has accepted the Terms of Service ("Customer").

This DPA is part of the Terms of Service and applies to every Customer from the moment its account is created, without a separate signature. The app records who accepted the Terms, when, and the version accepted; the person accepting confirms that they may bind the Customer. Requests for a countersigned copy go to [email protected].

2. Roles

The Customer confirms that it has a lawful basis to record its target applications and to have MiCCA process the personal data in them, and that it has made the attestation described in the Acceptable Use Policy.

3. Subject matter, duration, nature and purpose

MiCCA processes Customer Data for as long as the Customer has an account, to provide the Service: signing in to the Customer's application with the credentials it supplies, recording a browser session in a short-lived, isolated recording environment, generating narration and captions, and storing and delivering the resulting videos and reports. Details are in Annex 1.

4. Instructions

MiCCA processes Customer Data only on the Customer's documented instructions: the Terms, this DPA, and the Customer's use of the app and API (creating projects, starting runs, choosing retention settings, deleting data). MiCCA will tell the Customer if it believes an instruction breaches data protection law. MiCCA may process Customer Data where EU or Member State law requires it, and then informs the Customer unless the law forbids it.

5. Confidentiality

MiCCA restricts access to Customer Data to people who need it to provide the Service and who are bound by confidentiality obligations. MiCCA does not look at the Customer's recordings except to provide support the Customer asked for, to investigate abuse or a security incident, or where the law requires it.

6. Security measures

MiCCA maintains technical and organisational measures appropriate to the risk, including:

MiCCA may improve these measures and will not reduce the overall level of protection during the term.

7. Sub-processors

The Customer gives general authorisation for MiCCA to use the sub-processors listed in Annex 2. MiCCA imposes data protection obligations on each sub-processor that are no less protective than this DPA, and remains responsible to the Customer for their performance.

MiCCA will notify the Customer by email at least 30 days before adding or replacing a sub-processor. The Customer may object within that period on reasonable data protection grounds. If the parties cannot resolve the objection, the Customer may terminate the affected subscription.

8. International transfers

MiCCA's application and storage run in the European Union. Daytona, Google, ElevenLabs, Stripe and Resend are based in the United States, and Cloudflare operates in the EU and the US. Where Customer Data leaves the European Economic Area, MiCCA relies on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) with any supplementary measures required, or on an adequacy decision of the European Commission where one applies. The Customer may request a copy of the applicable clauses.

9. Data subject requests

If a data subject contacts MiCCA about Customer Data, MiCCA forwards the request to the Customer without undue delay and does not answer it directly unless the Customer asks it to. MiCCA assists the Customer with reasonable technical and organisational measures in responding to requests for access, rectification, erasure, portability, restriction and objection. The Customer can locate and delete runs, videos and projects in the app itself; MiCCA helps with what the app does not offer.

10. Personal data breaches

MiCCA notifies the Customer without undue delay, and within 72 hours, after becoming aware of a personal data breach affecting Customer Data. The notification describes what happened, the data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact; details may follow in phases as they become known. MiCCA assists the Customer with its own notifications to supervisory authorities and data subjects.

11. Further assistance

MiCCA assists the Customer with data protection impact assessments and prior consultations with supervisory authorities that concern the Service, and makes available the information needed to demonstrate compliance with GDPR Article 28.

12. Deletion and return

The Customer can export videos, reports and guides from the app at any time. When the Customer deletes a run, a project or its account, MiCCA deletes the associated Customer Data within 30 days; copies in backups expire within a further 30 days as the backups rotate. On request to [email protected], MiCCA confirms deletion in writing. MiCCA may keep data that EU or Member State law requires it to keep, for as long as that law requires.

13. Audits

On reasonable notice of at least 30 days, and no more than once in twelve months unless a supervisory authority requires otherwise or a breach has occurred, the Customer or an independent auditor bound by confidentiality may audit MiCCA's compliance with this DPA. MiCCA first provides documentation and answers written questions; an inspection takes place only where that is not sufficient, during business hours, without exposing other customers' data. Each party bears its own costs.

14. Liability and precedence

The liability limits in the Terms of Service apply to this DPA. On the processing of personal data this DPA prevails over the Terms, and the Standard Contractual Clauses prevail over both. Estonian law governs this DPA; disputes go to Tartu County Court, Estonia.

15. Contact

Data protection enquiries: [email protected]. Legal notices: [email protected].

Annex 1 — Details of processing

Annex 2 — Sub-processors

Sub-processor Purpose Location
Hetzner Online GmbH application hosting Germany
Cloudflare, Inc. network, security and file storage EU / US
Daytona compute for recordings United States
Google LLC AI language services; never credentials United States
Google LLC (Google Analytics) visit and conversion statistics, only with consent United States
ElevenLabs, Inc. AI speech services United States
Stripe, Inc. payments United States
Resend, Inc. transactional email United States
Sentry error monitoring United States

Last updated 2026-09-21