Spectra

Data Processing Agreement

Last updated: not yet published

Parties and roles

This agreement is between the customer, who is the controller, and Rahul Kumar, a sole proprietor established in India, who is the processor. It applies to personal data contained in session recordings made on the customer's websites. It forms part of the Terms of Service.

Subject matter and duration

We process recordings so that the customer can replay and analyse sessions on their own websites. Processing lasts for as long as the customer has an account, and each recording is kept for the retention window of the plan in force when it was made.

Nature and purpose of processing

Receiving recordings from the customer's websites, storing them, indexing them so they can be searched, serving them back to people the customer has authorised, and deleting them when their retention window ends or when the customer asks.

Categories of data subject

Visitors to the customer's websites, and the customer's own staff who use the dashboard.

Categories of personal data

Special category data is out of scope. The customer must not use the service to record health, biometric, financial account or other special category data, and must mask any field that would capture it.

Our obligations

Security measures

Sub-processors

The customer authorises the sub-processors described by category in the Privacy Policy. We name each of them, and what they do, to any customer on request: write to privacy@spectra-trace.com and we will send the current list.

We give 30 days' notice by email before a new sub-processor starts processing. A customer may object within that period on reasonable data protection grounds. If we cannot resolve the objection, the customer may terminate the affected part of the service and we refund the unused portion of what they have paid. We will not start the new sub-processor on that customer's data while an objection is open.

International transfers

Recordings are stored in France, inside the European Economic Area, and running the service does not move them out of it. The account database and transactional email are handled by providers who may process data outside the EEA under their own data processing terms.

We are established in India, which has no adequacy decision, and the service is administered from there. Where the customer is a controller in the EEA or the United Kingdom, that access is a restricted transfer and is made under the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two, controller to processor, and under the UK International Data Transfer Addendum where UK data is involved. Both are incorporated into this agreement by reference, and this agreement supplies the appendices they call for. We will send the executed clauses and the completed appendices to any customer who asks.

Alongside them we rely on the measures described above: data resides in the EEA rather than being exported, recordings are scoped to one workspace, nobody can open a recording without a time-limited grant that names the individual, and every grant is visible to the customer and revocable by them. We have never received a government request for customer data. If we receive one we will challenge it where there are grounds, and tell the customer unless the law forbids us from doing so.

Data subject requests

The customer can act on a request without contacting us: individual visitors' recordings can be deleted, a site and everything recorded under it can be deleted, and both remove the data wherever we hold it, including everywhere it is listed or searched. Where a request reaches us directly we pass it to the customer rather than acting on it ourselves.

Return and deletion

On termination, or on request, we delete the customer's recordings. Deletion is permanent and covers every copy we hold. Backups, where they exist, expire on their own schedule.

Deletion takes effect immediately wherever a recording is held, listed or searched, and there is no archived copy anywhere to outlive it, so for recordings immediate is the whole of it. Backups of account data roll off within 30 days, which is the longest a deleted record can persist anywhere. We do not restore a backup in order to recover data a customer has deleted.

Liability and precedence

Liability under this agreement is subject to the limit of liability in the Terms of Service, and the two form one aggregate cap rather than two separate ones, except where the law does not allow that. Where this agreement conflicts with the Terms of Service on the handling of personal data, this agreement prevails; on anything else, the Terms prevail. Where either conflicts with the Standard Contractual Clauses, the Clauses prevail.

Contact

privacy@spectra-trace.com