Data Processing Agreement
Last updated: 2026-09-18. This is a working draft pending legal review before public launch.
This agreement applies where you are a controller of personal data under GDPR, UK GDPR or a similar law, and we process that data on your behalf.
Roles
You are the controller. We are the processor. You decide what files to send and why; we process them only on your documented instructions, which are the API calls you make.
Scope
Subject matter. File processing: compression, optimization and format conversion.
Duration. For as long as your account is active.
Data types. Whatever personal data happens to be inside the files you submit. We do not inspect or categorize it.
Data subjects. Determined entirely by you.
Our obligations
We process only on your instructions. We keep personnel with access under confidentiality obligations. We apply the technical and organizational measures described below. We assist you with data subject requests, breach notification and impact assessments. We delete files according to the retention schedule in our Privacy Policy.
Security measures
Encryption in transit and at rest. Row-level access control in our database. Multi-factor authentication on production access. Isolated, sandboxed processing with no persistent storage on compute workers. Hashed API key storage. Audit logging of privileged actions.
Subprocessors
You give general authorization for the subprocessors listed at subprocessors. We give 30 days' notice before adding one, and you may object; if we cannot resolve the objection you may terminate without penalty and receive a refund of unused credits.
International transfers
Processing happens in the United States. Transfers from the EEA, UK or Switzerland rely on the Standard Contractual Clauses, incorporated here by reference.
Deletion and return
Files are deleted automatically on the schedule described in the Privacy Policy. On account closure we delete or anonymize personal data within 60 days, retaining only what accounting law requires.
Audit
We will provide the information reasonably needed to demonstrate compliance. On-site audits require 30 days' notice, happen no more than once a year unless a regulator requires otherwise, and are at your cost.