1. Introduction
This Data Processing Addendum ("DPA") forms part of the Terms of Service between helpful bits GmbH ("CrispDemo", "we", "us", or "Processor") and you ("Customer" or "Controller") for the provision of CrispDemo services applicable to United States users.
This DPA reflects the parties' agreement with regard to the processing of Personal Data in accordance with the requirements of applicable data protection laws.
2. Definitions
2.1 Personal Data
"Personal Data" means any information relating to an identified or identifiable natural person that is processed by CrispDemo in the course of providing the Services.
2.2 Processing
"Processing" means any operation or set of operations performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, transmission, or deletion.
2.3 Services
"Services" means the CrispDemo desktop application (CrispDemo Studio), which turns screen recordings and screenshots into videos, and the related server features provided to Customer, including AI requests made through CrispDemo's servers.
3. Scope and Roles
3.1 Scope of Processing
CrispDemo will process Personal Data as necessary to provide the Services in accordance with Customer's instructions as set forth in the Terms of Service and this DPA.
3.2 Controller and Processor
Customer is the Controller of Personal Data, and CrispDemo is the Processor. Each party will comply with the obligations that apply to it under applicable data protection laws.
3.3 Nature and Purpose
The nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are described below:
- Nature: Forwarding narration, music, and video review requests to Google (Gemini, Gemini text-to-speech, and Lyria) through CrispDemo's servers, holding the narration text or music brief until each request finishes, generated audio for up to 7 days, and a video sent for review only while it is forwarded; and keeping account, balance, usage, and audit records
- Purpose: To narrate, score, and review the videos Customer creates from screen recordings and screenshots
- Types of Personal Data: Finished videos sent for review, which can show parts of Customer's screen recordings and screenshots and any personal data visible in them, with their scene titles and narration text; narration text; music briefs; account data; and request and usage records
- Categories of Data Subjects: Customer and authorized users of the Services
- Not processed by CrispDemo: Frames from screen recordings and screenshots that Customer's own coding agent (for example Claude Code, Codex, or OpenCode) reads on Customer's computer and sends to its provider under Customer's account with that provider. CrispDemo does not receive or transmit them
4. Processor's Obligations
4.1 Instructions
CrispDemo will process Personal Data only in accordance with Customer's documented instructions, unless required to do so by applicable law.
4.2 Confidentiality
CrispDemo will ensure that persons authorized to process Personal Data are subject to appropriate confidentiality obligations.
4.3 Security
CrispDemo will implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of Personal Data in transit, and of sign-in refresh tokens at rest
- Measures to ensure ongoing confidentiality, integrity, availability, and resilience
- Regular testing and evaluation of security measures
- Procedures for regular backup and recovery of Personal Data
4.4 Sub-processors
Customer authorizes CrispDemo to engage Sub-processors to process Personal Data. CrispDemo will:
- Enter into a written agreement with each Sub-processor imposing data protection obligations substantially similar to those in this DPA
- Maintain a list of Sub-processors at crispdemo.com/legal/us/subprocessors
- Provide at least 30 days' notice of any new Sub-processor
- Remain liable for Sub-processor performance
4.5 Data Subject Rights
CrispDemo will, to the extent legally permitted, promptly notify Customer if it receives a request from a Data Subject to exercise their rights. CrispDemo will assist Customer in responding to such requests.
4.6 Deletion and Return
Upon termination or expiration of the Services, CrispDemo will delete or return all Personal Data to Customer, unless applicable law requires continued storage.
5. Security Measures
CrispDemo implements the following categories of technical and organizational measures:
5.1 Physical Security
Our infrastructure providers maintain SOC 2 Type II certified data centers with physical access controls, surveillance, and environmental controls.
5.2 System Security
- TLS 1.2+ encryption for data in transit
- AES-256 encryption for sign-in refresh tokens stored on our servers
- Regular security patches and updates
- Intrusion detection and prevention systems
- Firewall protection and network segmentation
5.3 Access Control
- Role-based access control (RBAC)
- Multi-factor authentication for administrative access
- Principle of least privilege
- Regular access reviews and revocation
5.4 Organizational Security
- Security awareness training for employees
- Incident response procedures
- Business continuity and disaster recovery plans
- Regular security assessments and audits
6. Data Breach Notification
6.1 Notification Obligation
CrispDemo will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer's data. Notification will be provided to Customer's designated contact within 72 hours of discovery where feasible.
6.2 Breach Information
The notification will include, to the extent available:
- The nature of the breach
- The categories and approximate number of Data Subjects affected
- The likely consequences of the breach
- The measures taken or proposed to address the breach
7. Audit Rights
7.1 Compliance Verification
CrispDemo will make available to Customer information necessary to demonstrate compliance with this DPA and allow for audits, including inspections conducted by Customer or an independent auditor.
7.2 Audit Process
Audits will be conducted upon reasonable notice, during business hours, no more than once per year unless required by a Supervisory Authority or in response to a suspected breach. Customer will bear the costs of audits unless they reveal material non-compliance.
8. Liability and Indemnification
8.1 Liability
Each party's liability under this DPA is subject to the limitations and exclusions set forth in the Terms of Service.
8.2 Indemnification
CrispDemo will indemnify and hold harmless Customer from any claims, damages, or losses resulting from CrispDemo's breach of this DPA, subject to the limitations in the Terms of Service.
9. Term and Termination
This DPA will remain in effect for as long as CrispDemo processes Personal Data on behalf of Customer. Upon termination, CrispDemo will delete or return all Personal Data as described in Section 4.6.
10. Contact
For questions about this DPA or our data processing practices, please contact our Data Protection Officer at dpo [at] crispdemo.com.
Last Updated: September 25, 2026
Version: 1.2