Draft: this document is currently under legal review and not yet in force.
Data processing agreement
Last updated:
This agreement under Art. 28 GDPR governs how we process personal data that you have processed in ShowBits Cloud. It forms part of the ShowBits contract and applies when that contract is concluded.
This English version is a translation for your convenience. Only the German version is legally binding.
1. Parties and subject matter
This agreement applies between the customer as controller (“customer”) and HBC Hohn Business Consulting UG (haftungsbeschränkt), Lerchenstraße 7, 14089 Berlin, as processor (“we”).
Its subject matter is the processing of personal data in providing ShowBits Cloud under the main contract (terms of service or enterprise contract). Its term corresponds to the term of the main contract.
For ShowBits OnPremise we do not process data on behalf of the customer as long as we have no access to the installation. If we are given access for support, this agreement applies accordingly.
2. Nature and purpose of processing
We process data to provide the contractual services: storing media, transcription and speaker detection, analysing and scoring passages, creating and editing clips, subtitles, copy and thumbnails, approval workflows, publishing on the customer's instruction, and support.
3. Types of data and data subjects
Types of data: account and usage data (name, email address, role, sign-in and log data), content data (audio and video recordings, images, voices, transcripts, names and statements of people appearing in the content) and metadata (titles, descriptions, dates, comments).
Data subjects: the customer's users and people who appear in the content, such as hosts, guests, interviewees and audiences.
If content contains special categories of personal data (Art. 9 GDPR), such as political opinions or health data, the customer is responsible for the lawfulness of that processing.
4. Instructions
We process data only on documented instructions from the customer. The instructions follow from the main contract, this agreement and the settings and features the customer uses in ShowBits. The customer gives further instructions in text form.
If we consider an instruction unlawful, we inform the customer without undue delay and may suspend its execution until it has been clarified.
5. No training on customer data
We do not use customer data to train or improve AI models, neither our own nor those of third parties. We agree corresponding obligations with subprocessors that provide AI services.
6. Confidentiality
Everyone at our company with access to customer data is bound by confidentiality or subject to a statutory duty of confidentiality.
7. Technical and organisational measures
We take the measures under Art. 32 GDPR described in Annex 1. We may develop them further as long as the level of protection is not reduced.
8. Subprocessors
The customer gives us general authorisation to engage subprocessors. The subprocessors currently engaged are listed in Annex 2.
We inform the customer of new or replaced subprocessors at least 30 days in advance. The customer may object for good reason under data protection law. If the parties find no solution, the customer may terminate the main contract effective on the date of the change.
We contractually bind subprocessors to an equivalent level of data protection. Services that the customer connects to ShowBits themselves, such as their own AI accounts, file storage or social media platforms, are not our subprocessors. The contractual relationship between the customer and the respective provider applies to them.
9. Place of processing
We process data in the European Union. Transfers to third countries take place only under the conditions of Art. 44 et seq. GDPR, for example on the basis of an adequacy decision or standard contractual clauses.
10. Assistance to the customer
We assist the customer with appropriate measures in responding to data subject requests (Art. 12 to 23 GDPR) and with their obligations under Art. 32 to 36 GDPR. If we receive a request from a data subject, we forward it to the customer.
11. Personal data breaches
We inform the customer without undue delay, at the latest within 48 hours after becoming aware of a breach affecting their personal data. The notification contains, as far as known, the information under Art. 33(3) GDPR. We take the necessary measures to remedy the breach and mitigate its consequences.
12. Deletion and return
During the term, the customer can export and delete their data at any time. After the contract ends, we delete the customer's data after 30 days and backups after 90 days at the latest, unless there is a statutory obligation to retain it. On request we confirm the deletion in text form.
13. Evidence and audits
We provide the customer with the information required to demonstrate compliance with this agreement. We publish current information on our security measures in the Trust Center.
The customer or an auditor appointed by them and bound to confidentiality may carry out audits. Audits must be announced with reasonable notice, take place during normal business hours and should not disrupt operations disproportionately. Evidence such as certificates or audit reports may replace an on-site audit.
14. Final provisions
In the event of conflicts between this agreement and the main contract, this agreement takes precedence on matters of data protection. Liability is governed by Art. 82 GDPR and otherwise by the main contract. German law applies. The German version is authoritative.
Annex 1: Technical and organisational measures
The following measures are in place. The status of further measures in progress or planned is published in the Trust Center.
Protecting unreleased content
Embargo protection
Episodes are only visible to the users and roles you assign until the release date.
File access log
Every view, download and export of a file is logged with user and time.
AI and your data
No training on customer content
Your uploads, transcripts and generated assets are never used to train or improve AI models, ours or third parties'.
Data protection
EU hosting
Cloud data is stored and processed exclusively in EU data centers.
Identity and access
Single sign-on
SAML 2.0 and OpenID Connect with your identity provider.
SCIM provisioning
Users and groups are created and removed automatically from your directory.
Roles and permissions
Fine-grained permissions per project, from viewer to approver to admin.
Audit logs
Traceable history of every login, permission change and approval.
Infrastructure and availability
Encryption in transit
TLS 1.3 for all connections.
Encryption at rest
AES-256 for stored media, transcripts and metadata.
Application security
Responsible disclosure
A clear channel for security researchers, with acknowledgement of valid reports.
Annex 2: Subprocessors
We engage the following subprocessors for ShowBits Cloud.
| Purpose | Provider | Location |
|---|---|---|
| Cloud hosting and storage | Published before launch | EU |
| AI inference (transcription, analysis) | Published before launch | EU |
| Transactional email | Published before launch | EU |
| Payments (Creator plan) | Published before launch | EU |
| Customer support | Published before launch | EU |