1. Parties and responsibilities
The customer is the organization identified in its accepted agreement receipt. The processor is the service operator identified in the supplier snapshot attached to that same receipt, trading as Scrub Metadata. This DPA forms part of the agreement for the Professional service and governs the personal data processed on the customer's behalf.
This DPA applies only to processing where ScrubMetadata acts on documented customer instructions as a processor. ScrubMetadata may act as a controller for separate account administration, security, billing-support, website, and direct-contact processing described in the Privacy Policy. The role follows the actual purpose and activity, not just the name of a data field.
Paddle is the merchant of record for the purchase. Its payment processing and independent-controller obligations do not replace the service operator's obligations under this DPA. Listing a provider does not, by itself, make it a subprocessor for every processing activity.
The customer determines its purposes, lawful grounds, notices and instructions, and authorizes its users and recipients. The customer remains responsible for its legal decisions, filings and notifications. ScrubMetadata provides the contracted processing and assistance and remains responsible for its own obligations. Software outputs are not legal advice or a determination of compliance.
2. Acceptance and your agreement copy
Once the complete agreement bundle is approved and published, an authorized representative of an approved customer accepts it during checkout. The accepted DPA and Terms take effect for the service when the first payment is verified and the subscription is activated. No separate email signature or repeated supplier approval is required. The executed receipt and its exact document versions are available in Billing. Viewing this page or opening checkout alone does not execute an agreement.
The receipt identifies the customer organization, accepting role, recorded authority confirmation, acceptance time, supplier snapshot, document versions and document hashes. Billing provides the accepted document copies separately from current policies. A later change to a public page does not amend the version already accepted by the customer.
This DPA takes precedence over conflicting service terms for customer-directed personal-data processing. Any applicable mandatory transfer terms take precedence over conflicting provisions of this DPA. Nothing in the agreement removes data-subject rights, supervisory powers or liability that applicable law does not permit the parties to exclude.
3. Documented instructions
ScrubMetadata will process customer data only for the agreed purposes and on documented customer instructions, including instructions about transfers. The accepted agreement, authorized workspace actions and recorded written directions from an authorized customer contact form those instructions. Access, changes, exports and final workflow actions remain subject to the customer's role and approval controls. Supplier admission approval does not replace the customer's own accountable decisions.
If Union or Member State law binding on the processor requires other processing, ScrubMetadata will inform the customer of that requirement before processing unless that law prohibits notice on important public-interest grounds. A demand from another jurisdiction is not treated as customer authorization or as a blanket exception to the agreed transfer protections.
ScrubMetadata will immediately tell the customer if, in its opinion, an instruction infringes the GDPR or other applicable Union or Member State data-protection law. It will suspend the affected instruction while the parties resolve it, protect the data during that suspension and explain what is needed to resume lawful processing.
4. Confidentiality and authorized access
ScrubMetadata will limit access to personnel who need it for the agreed service, support or security duties and ensure they are bound by confidentiality commitments or an appropriate statutory duty. Access must be appropriate to the assigned role, reviewed when responsibilities change and removed when no longer needed.
Customer-directed data will not be sold, used for advertising or used to train general-purpose models. Support and incident handling must use minimized references and redacted evidence rather than asking customers to send raw files or raw metadata.
5. Security and assistance
ScrubMetadata will maintain technical and organizational measures appropriate to the processing risks under Article 32, taking account of the state of the art, implementation costs, the processing and the risks to people. The security schedule below describes the service controls. ScrubMetadata will review their effectiveness and will not materially reduce the agreed protection without the customer's prior agreement.
Taking account of the processing and the information available to it, ScrubMetadata will assist the customer with Articles 32 to 36. Assistance includes relevant security-control and incident information, processing and provider details for DPIAs, and information needed for prior consultation with a supervisory authority. It does not transfer the customer's decision-making responsibility to the service operator.
6. People exercising their rights
ScrubMetadata will assist the customer, through appropriate technical and organizational measures where possible, with requests under GDPR Chapter III. Authorized customer users can use the available search, workflow, correction and export controls. Requests needing processor assistance can be sent to the privacy contact with the relevant organization and minimized case reference.
If ScrubMetadata receives a request concerning customer-directed data, it will promptly refer it to the customer. It will not decide the substance of the response without customer instructions unless the law requires it. ScrubMetadata will provide relevant information and action status in time to support the customer's applicable deadline, identifying any constraint promptly.
7. Subprocessors and changes
The customer authorizes only the subprocessors and processing activities identified as such in the Service Providers and Subprocessor Register version incorporated into its agreement. That register must identify the legal entity, service, purpose, location and relevant transfer arrangement for each authorized activity. Independent-controller services are identified separately.
ScrubMetadata will obtain the customer's prior written authorization before adding or replacing a subprocessor not covered by that authorization. It will provide the proposed provider details, processing, safeguards and intended start date so the customer can assess and object. It will not place the affected customer data with the new provider while authorization is unresolved. The parties will consider an alternative or the customer may end the affected service and exercise its return or deletion rights.
The request will go to the customer's designated privacy contact, with a proposed decision date that allows an informed assessment before the intended start. The parties must resolve a reasonable request for more information or time before use begins. Silence, an undelivered message or an expired response date is not authorization. ScrubMetadata will record the affirmative decision and versioned provider details, escalate failed delivery through an available contact route, and keep the affected processing suspended if no authorized alternative is available.
ScrubMetadata will bind each subprocessor by written obligations providing the data protection required for its assigned processing, including confidentiality, security, assistance, return or deletion and information needed for oversight. It will assess the provider's guarantees, remain fully responsible to the customer for the subprocessor's performance of those obligations and report relevant failures. It will provide relevant contractual and compliance information while protecting unrelated confidential information.
8. International access and transfers
International transfers, including relevant remote access, may occur only on documented instructions and with the safeguards required by GDPR Chapter V. The incorporated transfer schedule must identify the exporter, importer, countries, data, purposes, applicable mechanism and any supplementary measures. ScrubMetadata will not start an uncovered transfer merely because a hosting provider offers an EU region.
This DPA is not itself a transfer mechanism, an adequacy decision or an appointment of an EU representative. Payment through Paddle does not supply those safeguards for separate ScrubMetadata processing. If standard contractual clauses are relied on, the applicable clauses and completed annexes must be incorporated without changes that undermine their protection. A general link to a vendor policy is not an executed transfer instrument.
ScrubMetadata will inform the customer if it can no longer meet the agreed transfer safeguards and suspend the affected transfer until a lawful solution is in place. It will document the resolution or support return and deletion of the affected data.
9. Personal data breaches
When acting as a processor, ScrubMetadata will notify the customer controller without undue delay after becoming aware of a personal data breach. This duty follows the actual processing role and is not suspended by missing contract paperwork. The controller remains responsible for assessing and making any notification to a supervisory authority or data subject required by applicable law.
Notice will go to the customer's designated contact and describe, as information becomes available, the nature of the breach, affected people and records with approximate numbers, a contact for further information, likely consequences and measures taken or proposed to contain and remedy it. Missing details will follow in stages without delaying the initial notice. ScrubMetadata will preserve relevant evidence, record its investigation and cooperate with the customer on mitigation and required notifications.
The customer must keep its contact details current. ScrubMetadata will record notification attempts and escalate a failed delivery through the available contact route. An attempted or queued message is not represented as confirmed delivery. There is no contractual guarantee of a fixed incident response time or continuous staffed support in the standard Professional service.
10. Information, audits and inspections
ScrubMetadata will make available the information needed to demonstrate compliance with this DPA and allow and contribute to audits and inspections by the customer or its mandated auditor. Available evidence and remote review can be used first where sufficient. They do not replace an inspection that is reasonably necessary.
The parties will coordinate scope, timing, confidentiality and safe access to avoid unnecessary disruption and exposure of other customers' data. Coordination, a confidentiality agreement or discussion of reasonable costs must not frustrate mandatory audit rights, an urgent incident investigation or a supervisory authority's powers. Findings and necessary corrective actions will be documented and followed through.
11. Return, deletion and retained copies
When the processing service ends, ScrubMetadata will, at the customer's choice, return the customer-directed personal data in an available structured export and delete the remaining copies, or delete the data without return, unless Union or Member State law requires storage. Confidentiality and security duties continue until that work is complete.
Exit is operator-managed on request; the Professional service does not promise automated end-to-end deletion. The customer can retrieve available exports through its authorized workspace controls and record its return or deletion instruction. The operator then verifies authority, closes workspace access and carries out the documented deletion procedure. The proposed operational period for deletion from active customer-directed stores is 30 days after the service ends and the authorized instruction is recorded; this is a proposed operational timeframe, not a statutory claim. Provider retention follows provider terms. The dated confirmation identifies required retention exceptions and residual copies; when a provider expiry is not verified, it states “retained per provider terms; expiry not verified.” Subscription cancellation or workspace closure alone is not proof of deletion. A deletion or return instruction is tracked through the account and organization offboarding process, including any validated legal hold. ScrubMetadata will identify the affected records, applicable retention ground and completion status rather than issue an unsupported blanket erasure confirmation.
Residual backup copies must be isolated from ordinary use, protected and removed on the documented backup expiry schedule. If a backup is restored before expiry, the relevant deletion instructions must be reapplied before ordinary processing resumes. The incorporated retention schedule states the return window, proposed active-store timeframe, provider retention criteria and mandatory retention exceptions; it does not invent an unverified backup expiry. ScrubMetadata will provide confirmation when the agreed work is complete.
Separate records processed by ScrubMetadata as controller or by Paddle for its own obligations are governed by the applicable privacy information and law. That distinction is not permission to retain customer-directed workflow data for unrelated purposes.
This personal-data return clause does not limit any mandatory rights to switch data-processing services, export other eligible data or receive transition assistance. Where the EU Data Act applies, the service exit terms must separately meet its requirements. This DPA does not claim that those operational and contractual requirements have already been fulfilled.
12. When processing cannot continue safely
ScrubMetadata will promptly inform the customer if it cannot comply with this DPA. The customer may require suspension of the affected processing until compliance is restored, and may terminate the affected processing service for substantial or persistent breach or where a lawful and secure resolution cannot be achieved within a reasonable period. Return, deletion and continuing protection duties still apply.
If the affected service ends because we cannot remedy a substantial service or DPA breach, or cannot provide a lawful alternative after a subprocessor or transfer objection, we will record the termination date, request cancellation of future renewals through Paddle, and request a refund for the unused prepaid service period from that date. The request will identify the service amount and any applicable tax adjustment. This additional supplier remedy is separate from ordinary period-end cancellation and does not limit a greater mandatory remedy. We will track the Paddle outcome and explain any unresolved amount; neither a request nor an email is confirmation of cancellation or payment.
Neither routine self-service nor automatic subscription renewal authorizes a broader processing scope, a new transfer or the removal of an accountable customer approval. Material changes requiring customer agreement must be presented as such and recorded against the applicable agreement version.
Processing schedule
Supported raw file bytes and raw extracted metadata are processed locally and are not uploaded to ScrubMetadata. Minimized counts, categories, status, timestamps, and evidence hashes may be recorded when an authorized audit or compliance workflow is used.
- Service and purpose
- One Professional workspace for a single organization. Processing supports file-safety evidence, DSAR management, DPIAs, records of processing and provider oversight, incident management, and DPO advice, monitoring, tasks and management evidence.
- Processing operations
- Collection from authorized customer users, validation, organization-scoped storage, organization, retrieval, amendment, restricted disclosure, export and deletion of the permitted workflow records. Processing is continuous while the customer uses these functions, with event-driven notifications and scheduled operational checks.
- Duration
- From activation of the accepted service agreement until the customer data has been returned or deleted under the exit provisions below. Retention of a protected residual copy does not permit ordinary service use of that copy.
- People concerned
- Customer personnel and workspace users, people whose rights requests or incidents the customer manages, and contacts at customers, vendors, processors and other organizations represented in the permitted workflow records.
- Personal data
- Business contact and role details, DSAR subject and requester names and email addresses, request descriptions and case narratives, request and case references, assignments, dates, deadlines, decisions, status, approvals and audit events. Narratives must contain only the information needed to manage the workflow, not underlying case files or copied raw metadata. File-safety evidence is limited to permitted counts, categories, statuses, timestamps, redacted evidence and hashes. A hash or a case reference may still be personal data.
- Excluded content
- Original and processed file contents, raw extracted metadata values, full raw filenames and local paths are not transferred to ScrubMetadata through the supported local processing path. Do not paste or attach those values into a workflow, diagnostic message or support request. Keep underlying case material in the customer-controlled system and use a minimized reference here.
- Sensitive information
- The standard service does not authorize uploading special-category data, criminal-offence records or underlying DSAR and breach case files. Where a minimized workflow record itself reveals sensitive information, the customer must assess necessity, lawful grounds and safeguards before recording it. Processing outside the agreed scope requires an agreed amendment and suitable controls before it starts.
Security schedule
- File processing stays in the supported browser or local workflow. Only the canonical minimized evidence projection can be committed to the platform. The Professional offer does not include a supplier-operated raw-file processing service.
- Authenticated sessions, trusted-device checks, organization-scoped authorization and per-action permissions restrict customer operations. Reserved decisions and destructive actions retain separate authorization. Sign-in uses email magic links, not a promise of universal MFA or SSO.
- HTTPS protects application transport. Server records rely on managed database and hosting controls. Application-layer encryption is limited to explicitly wired sensitive-field and integration-credential paths, not every record.
- Rate limits, private response handling and idempotency controls protect sensitive routes. Canonical audit events record accountable changes. A recorded event or a hash does not establish external certification or prove that every risk has been removed.
- Operational monitoring filters credentials, message bodies, raw files, raw metadata, filenames and local paths. Optional browser error monitoring remains subject to the current consent controls.
- The operating process includes controlled source changes, testing, incident triage, notification tracking, documented restore and rollback procedures, and review of material security findings. Provider-specific storage, backup and recovery settings must be documented in the incorporated security and retention information.
- These measures are not a SOC 2 report, ISO certification, independent penetration-test opinion, guaranteed availability percentage or unconditional recovery-time promise. The customer assesses suitability for its own processing risks.