Supademo Data Processing Agreement
Version 2.0 · Updated July 24, 2026
How this DPA applies
This Data Processing Agreement (this "DPA") is entered into between Supademo, Inc., a Delaware corporation with offices at 651 N Broad St., Suite 201, Middletown, Delaware 19709, United States ("Supademo"), and the customer that has entered into the Agreement with Supademo ("Customer").
This DPA is incorporated into and forms part of the Agreement. It applies automatically, and is effective as of the effective date of the Agreement, wherever Supademo processes Personal Data on Customer's behalf in providing the Services. No signature is required for this DPA to be binding on the parties. Customers whose procurement processes require an executed copy may request a countersignature version at privacy@supademo.com; an executed copy does not change these terms.
"Agreement" means the agreement between Supademo and Customer governing Customer's use of the Services: the Supademo Master Subscription Agreement together with its Order Forms, where the parties have signed one, and otherwise the Supademo Terms of Service. "Services" has the meaning given in the Agreement.
If this DPA conflicts with the Agreement with respect to the Processing of Personal Data, this DPA controls for that subject matter. If the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses control.
1. Definitions
"CCPA" means the California Consumer Privacy Act, as amended (including by the California Privacy Rights Act), and its implementing regulations.
"Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Supervisory Authority" have the meanings given to them (or to their nearest equivalents) in applicable Data Protection Laws.
"Customer Personal Data" means Personal Data that Supademo Processes on Customer's behalf in providing the Services.
"Data Protection Laws" means all data protection and privacy laws applicable to the Processing of Customer Personal Data under the Agreement, including, where applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the CCPA, and other applicable US state privacy laws.
"Security Incident" means a confirmed breach of security leading to unauthorized access to or acquisition of Customer Personal Data within Supademo's systems that materially compromises the confidentiality, integrity, or availability of Customer Personal Data. Unsuccessful attempts or events that do not compromise Customer Personal Data (such as pings, port scans, or failed log-in attempts) are not Security Incidents.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.
"Subprocessor" means a third party engaged by Supademo to Process Customer Personal Data.
"UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner's Office.
2. Roles and scope of Processing
2.1 Roles. Customer is the Controller of Customer Personal Data or, where Customer acts on behalf of its own customers, a Processor. Supademo Processes Customer Personal Data as Customer's Processor or, where Customer is a Processor, as its Subprocessor. Each party will comply with its own obligations under Data Protection Laws.
2.2 Details of Processing. The subject matter, duration, nature and purpose of Processing, and the categories of Personal Data and Data Subjects are described in Annex 1.
2.3 Sensitive data. Customer will not submit to the Services protected health information subject to HIPAA, payment card data, government identification numbers, biometric identifiers, special categories of personal data, or other highly regulated sensitive information, unless the applicable Order Form expressly permits such Processing and the parties have entered into any required addendum.
3. Processing instructions
Supademo will Process Customer Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required otherwise by applicable law (in which case Supademo will inform Customer of that legal requirement before Processing, unless the law prohibits it). The Agreement, this DPA, and Customer's use and configuration of the Services constitute Customer's complete documented instructions; additional instructions require the parties' written agreement. Supademo will inform Customer if, in its opinion, an instruction infringes Data Protection Laws, without any obligation to monitor Customer's legal compliance.
4. Confidentiality of Processing
Supademo will ensure that all personnel authorized to Process Customer Personal Data are bound by written confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
5. Security
Supademo will implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, as described in Annex 2, including encryption of Customer Personal Data in transit and at rest, access controls and authentication, security monitoring, vulnerability assessments, incident response procedures, and security training for personnel. Supademo maintains SOC 2 Type II attestation, with current security information available at security.supademo.com. Supademo may update its measures from time to time, provided the updates do not materially reduce the overall protection of Customer Personal Data during a paid Subscription Term.
6. Subprocessors
6.1 General authorization. Customer provides general authorization for Supademo to engage Subprocessors. Supademo's current Subprocessor list is available at supademo.com/privacy-policy/subprocessors, where Customer may also subscribe to change notifications.
6.2 Notice and objection. Supademo will provide notice at least thirty (30) days before a new or replacement Subprocessor Processes Customer Personal Data. Customer may object within the notice period on reasonable grounds relating to data protection. The parties will work in good faith to resolve the objection; if they cannot, Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees for the unused portion of the terminated Services, as Customer's sole remedy.
6.3 Flow-down and responsibility. Supademo will bind each Subprocessor to written data protection obligations no less protective than those in this DPA, will review Subprocessors' security certifications and audit reports, and remains responsible for its Subprocessors' performance to the same extent as for its own.
7. Data Subject requests
Supademo will promptly forward to Customer any request it receives directly from a Data Subject relating to Customer Personal Data, and, taking into account the nature of the Processing, will assist Customer through available Service functionality and other reasonable assistance in fulfilling Customer's obligations to respond. Customer is responsible for responding to Data Subject requests.
8. Assistance to Customer
Taking into account the nature of the Processing and the information available to Supademo, Supademo will provide reasonable assistance with Customer's obligations regarding security, Security Incident notifications, data protection impact assessments, and prior consultations with Supervisory Authorities.
9. Security Incident notification
Supademo will notify Customer without undue delay, and in any event within seventy-two (72) hours, after confirming a Security Incident. To the extent available, the notification will describe the nature of the Security Incident, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point; Supademo may provide information in phases as its investigation proceeds. Supademo will take reasonable steps to contain, investigate, and remediate the Security Incident and will reasonably cooperate with Customer's obligations to notify authorities and Data Subjects. Supademo's notification of a Security Incident is not an acknowledgment of fault or liability.
10. International transfers
10.1 Locations. Customer Personal Data is hosted in the United States by default, with European Union data residency available where selected on an applicable Order Form, and may be Processed in other locations where Supademo's authorized personnel and Subprocessors operate, subject to this Section.
10.2 EEA transfers. Where Customer Personal Data protected by the GDPR is transferred to a country without an adequacy decision, the SCCs are incorporated into this DPA and apply as follows: Module Two (controller to processor) applies where Customer is a Controller and Module Three (processor to processor) applies where Customer is a Processor; Clause 7 (docking) is not included; under Clause 9(a), Option 2 (general written authorization) applies with the notice period in Section 6.2; the optional language in Clause 11(a) is not included; under Clause 17, Option 1 applies and the SCCs are governed by the laws of Ireland; under Clause 18(b), disputes will be resolved by the courts of Ireland; and Annexes I, II, and III of the SCCs are completed by Annexes 1, 2, and 3 of this DPA. By entering into the Agreement, the parties are deemed to have signed the SCCs, including their Annexes, as of the effective date of the Agreement.
10.3 UK and Swiss transfers. For transfers subject to the UK GDPR, the UK Addendum is incorporated, with Tables 1 through 3 completed by the information in this DPA and its Annexes, and for Table 4, either party may end the UK Addendum as set out in its Section 19. For transfers subject to Swiss law, the SCCs apply with the adaptations required by Swiss law, including that the Swiss Federal Data Protection and Information Commissioner is the competent authority and references to EU member state law include Swiss law where applicable.
10.4 Alternative mechanisms. If a transfer mechanism relied on under this Section is invalidated or superseded, the parties will cooperate in good faith to implement a lawful alternative.
11. Audits
Supademo will make available information reasonably necessary to demonstrate compliance with this DPA. Customer's audit and information requests will first be satisfied by Supademo's then-current SOC 2 Type II report, security certifications, and security documentation, supplemented by written responses to a reasonable security questionnaire no more than once per twelve (12) months. Where that information is insufficient to demonstrate compliance, or where required by Data Protection Laws or a Supervisory Authority, Customer may conduct an audit of Supademo's relevant Processing activities no more than once per twelve (12) months, on at least thirty (30) days' written notice, during business hours, with scope agreed in advance, without unreasonable disruption to Supademo's operations, at Customer's expense, and subject to the confidentiality obligations in the Agreement. Audit rights with respect to Subprocessors are satisfied by Supademo providing available certifications, SOC reports, audit summaries, or equivalent evidence.
12. CCPA and US state privacy laws
Where the CCPA or another US state privacy law applies, Supademo acts as Customer's "service provider" or "processor". Supademo will not sell or share Customer Personal Data; will not retain, use, or disclose Customer Personal Data for any purpose other than providing the Services under the Agreement or as otherwise permitted by law; and will not combine Customer Personal Data with Personal Data from other sources except as permitted for service providers. Supademo certifies that it understands and will comply with these restrictions, will notify Customer if it determines it can no longer meet its obligations, and, upon such notice, Customer may take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data.
13. Deletion and return
During the Subscription Term, Customer may export Customer Personal Data using available Service functionality. Following expiration or termination of the Agreement, Supademo will make Customer Personal Data available for export as provided in the Agreement and will thereafter delete Customer Personal Data, unless retention is required by applicable law, with copies in routine backups deleted or overwritten in the ordinary course and remaining protected under this DPA until deletion. Upon written request, Supademo will confirm deletion in writing.
14. Liability
To the greatest extent permitted by law, each party's and its affiliates' total liability arising out of or relating to this DPA, and, where they apply, the SCCs and UK Addendum, is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this Section limits any Data Subject's rights under Data Protection Laws or any liability that cannot be limited under Data Protection Laws.
15. General
15.1 Term. This DPA remains in effect for the duration of the Agreement and any additional period during which Supademo Processes Customer Personal Data.
15.2 Updates. Supademo may update this DPA to reflect changes in Data Protection Laws or the Services. Supademo will provide at least thirty (30) days' notice of material changes through the Services or by email, and no update will materially reduce the protection of Customer Personal Data during a paid Subscription Term. An Order Form may fix the version of this DPA that applies to that Order Form.
15.3 Governing law. This DPA is governed by the same law, and subject to the same venue, as the Agreement, except where the SCCs, the UK Addendum, or Data Protection Laws require otherwise.
15.4 Severability. If any provision of this DPA is held invalid or unenforceable, the remainder will remain in full force and effect.
Annex 1 — Details of Processing
A. Parties. Data exporter: Customer, as identified in the Agreement or Customer's account, acting as Controller (or Processor, per Section 2.1); contact details as provided in the Agreement or account. Data importer: Supademo, Inc., 651 N Broad St., Suite 201, Middletown, Delaware 19709, United States, acting as Processor (or Subprocessor); contact: privacy@supademo.com.
B. Description of Processing.
Categories of Data Subjects: Customer's employees and other authorized users; end users and viewers who interact with Customer's demos; Customer's leads and prospects.
Categories of Personal Data: contact and identification data (such as names, email addresses, and phone numbers) where Customer uses features like surveys, forms, or trackable links; account credentials and authentication data; demo content submitted by or for Customer, including screenshots and recordings that may incidentally contain Personal Data visible in Customer's source systems; usage and interaction data; device and browser information; IP addresses and approximate location.
Special categories of data: none; Customer agrees not to submit them (Section 2.3).
Frequency: continuous, for the duration of the Agreement.
Nature and purpose: hosting, creating, displaying, and sharing interactive product demos; engagement and performance analytics; customer support; account and authentication management; as further described in the Agreement.
Duration and retention: the Subscription Term plus the export and deletion period described in Section 13 and the Agreement, and longer only where required by applicable law.
Transfers to Subprocessors: as described in Annex 3, for the purposes above.
C. Competent Supervisory Authority. Determined in accordance with Clause 13 of the SCCs.
Annex 2 — Technical and organizational measures
Supademo maintains a written information security program aligned with its SOC 2 Type II attestation, including: encryption of Customer Personal Data in transit and at rest; access controls based on least privilege, with authentication controls including multi-factor authentication for Supademo personnel; logging and security monitoring; vulnerability management and periodic security assessments; secure software development practices; a documented incident response plan; backup and business continuity procedures; personnel security training and confidentiality commitments; Subprocessor and vendor security review; and physical and environmental safeguards provided through Supademo's cloud infrastructure providers. Current details are published at security.supademo.com.
Annex 3 — Subprocessors
Supademo's current Subprocessors, and the mechanism to subscribe to change notifications, are listed at supademo.com/privacy-policy/subprocessors. New Subprocessors are engaged in accordance with Section 6.