1. Scope and roles
The Customer is the controller of personal data contained in Customer Content and in its organization’s user records; PlayableDesk processes it as processor. Details of the processing are in Annex 1.
2. Instructions
We process personal data only on the Customer’s documented instructions — these Terms, this DPA and the Customer’s use of the Platform’s features — unless the law requires otherwise, in which case we inform the Customer first where legally allowed. We tell the Customer if we believe an instruction breaks data protection law.
3. Confidentiality
Everyone at PlayableDesk who can access personal data is bound by confidentiality and accesses it only as needed. Our studio team accesses a Customer’s organization only while the Customer allows “PlayableDesk Studio” access, which the Customer can switch off at any time.
4. Security
We implement the technical and organisational measures in Annex 2 and keep them appropriate to the risk. We may improve them over time without reducing the overall level of protection.
5. Subprocessors
The Customer authorises the subprocessors in Annex 3. We impose data-protection terms on each that are at least as protective as this DPA and remain responsible for them. We give at least 30 days’ notice of a new subprocessor by updating this page and emailing account owners; the Customer may object on reasonable data-protection grounds, and if we cannot address the objection the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees.
6. Assistance
Taking into account the nature of the processing, we help the Customer respond to data-subject requests (most can be handled directly in the Platform), and with security, breach notification, data protection impact assessments and prior consultation, to the extent required by law.
7. Personal data breaches
We notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Customer’s data, with the information the Customer reasonably needs to meet its own obligations, and we take reasonable steps to contain it.
8. Return and deletion
When the subscription ends, the Customer can export its content during a 30-day read-only period. We then delete Customer personal data within 90 days, including from active systems, unless the law requires us to keep it; backups expire on their normal cycle.
9. Audits
We make available the information reasonably needed to demonstrate compliance with this DPA, including written answers to security questionnaires. Where that is not enough, the Customer may carry out an audit (itself or via an independent auditor bound by confidentiality) once per year with 30 days’ notice, during business hours and at its own cost.
10. International transfers
Where personal data is transferred outside the EEA, the UK or Switzerland to a country without an adequacy decision, the Standard Contractual Clauses adopted by Commission Decision (EU) 2021/914 (Module 2 or 3 as applicable) and, for the UK, the International Data Transfer Addendum, are incorporated by reference, together with any supplementary measures needed.
11. General
If this DPA conflicts with the Terms, this DPA prevails for data protection matters. Liability under this DPA is subject to the limits in the Terms, except where the law does not allow it.
Annex 1 — Details of processing
| Subject matter | Providing the PlayableDesk platform and, under Studio plans, producing playable ads. |
|---|---|
| Duration | The subscription term plus the deletion period in section 8. |
| Nature and purpose | Hosting, storage, editing, rendering and exporting of projects; AI-assisted editing at users’ request; support; sending account emails. |
| Data subjects | The Customer’s users; any people appearing in assets or content the Customer uploads. |
| Categories of data | Names, work emails, job titles, usage and activity records; any personal data the Customer chooses to include in projects, assets, briefs, prompts or comments. |
| Special categories | None intended. The Customer should not upload special-category data. |
Annex 2 — Security measures
- Encryption: TLS for all traffic; data encrypted at rest by our database and storage provider.
- Tenant isolation: every table is protected by row-level security in the database so one organization cannot read another’s data; server-side checks repeat these rules.
- Access control: invitation-only accounts, passwords of at least 12 characters stored hashed, role-based permissions (owner, admin, editor, viewer), optional allowed email domains, sign-out of all sessions.
- Least privilege for our team: staff roles in our back-office; studio access to a customer only while the customer allows it.
- Accountability: an activity log of membership, access, plan, billing and AI-control changes visible to customer admins.
- Isolation of ad content: playables run in a sandboxed iframe in the editor and previews.
- Resilience: managed infrastructure with backups [confirm backup frequency and retention for the production plan].
- Secure development: code review, automated tests (including access-control tests) before release, and secrets kept server-side.
- Vulnerability reports: security@playabledesk.com.
Annex 3 — Authorised subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database, authentication and file storage for the platform | [Region of the Supabase project, e.g. EU (Frankfurt)] |
| Netlify, Inc. | Hosting and content delivery for the website and the platform | United States / global CDN |
| Anthropic, PBC | AI models for the in-editor agent (only content sent to the agent) | United States |
| OpenAI, L.L.C. | AI models for the in-editor agent (only content sent to the agent) | United States |
| Resend, Inc. | Transactional email (invitations, password resets) | United States |