Skip to main content
Legal

Customer Data Processing Agreement

Last updated: July 21, 2026

This Data Processing Agreement ("DPA") implements Article 28 GDPR for Customer Personal Data processed through streamrunnr. It is version 2026-07-21-v11 and forms part of the Terms of Service where the scope in section 1 applies. Annexes 1 to 3 are integral parts of this DPA.

1. Parties, Scope, and Priority

The "Customer" is any natural person, legal person, or organisation that has entered into the streamrunnr agreement and acts as controller or processor for Customer Personal Data. The "Processor" is LL Platforms UG (haftungsbeschränkt), Wuhlestraße 7 a, 12683 Berlin, Germany, email: support@streamrunnr.com. If Customer processes personal data for another controller, Customer acts as processor and streamrunnr as its subprocessor; Customer confirms that the controller has authorised the engagement and the instructions given under this DPA.

This DPA applies only where Processor processes personal data contained in Customer content, configurations, or service instructions on Customer's behalf ("Customer Personal Data"). It does not apply to processing for which Processor or Paddle acts as an independent controller, including account contracting, billing, fraud prevention, security, legal compliance, and Processor's own service administration; those activities are described in the Privacy Policy.

This DPA, version 2026-07-21-v11, is concluded electronically when Customer or an authorised Customer representative accepts the Terms or otherwise enters into a service agreement that incorporates it. It remains available at https://streamrunnr.com/dpa. If this DPA conflicts with the Terms regarding processing of Customer Personal Data, this DPA prevails. Mandatory data-protection law always prevails.

2. Documented Instructions and Customer Responsibilities

Processor will process Customer Personal Data only on Customer's documented instructions, including the Terms, this DPA, Customer's use and configuration of the service, destinations and schedules selected by Customer, and documented support requests. These instructions cover the operations in Annex 1 and transfers necessary to use the approved subprocessors in Annex 3.

Selecting YouTube, Twitch, or a custom RTMP/RTMPS destination instructs Processor to transmit the chosen content and destination credential to that recipient. Customer — not Processor — selects that independent recipient and is responsible for its lawfulness, terms, privacy information, and any transfer mechanism required for the destination. A destination selected by Customer is not Processor's subprocessor merely because Processor transmits data to it.

If EU or Member-State law requires processing beyond Customer's instructions, Processor will inform Customer of that legal requirement before processing unless the law prohibits notice. Processor will promptly inform Customer if, in its opinion, an instruction infringes the GDPR or other applicable Union or Member-State data-protection law and may suspend the affected instruction while the parties resolve it.

Customer is responsible for the lawfulness, accuracy, and transparency of its instructions and Customer Personal Data; for providing required notices and establishing a legal basis; for responding as controller to data subjects; and for using the service consistently with the Terms. Customer will not submit special-category data, criminal-offence data, or data concerning children unless that processing is necessary, lawful, proportionate, covered by appropriate safeguards, and permitted by the Terms.

3. Processor Duties and Confidentiality

  • Processor will ensure that persons authorised to process Customer Personal Data are bound by confidentiality or an appropriate statutory duty and receive access only as necessary for their role.
  • Processor will not sell Customer Personal Data, use it for advertising, or determine an unrelated purpose for it. Processor may create genuinely anonymous service statistics that no longer constitute personal data.
  • Processor will keep the records and compliance information required of it under applicable data-protection law and make the information needed to demonstrate Article 28 compliance available under section 8.
  • Processor will notify Customer if it can no longer meet a material obligation under this DPA and will take reasonable steps to remediate the issue.

4. Security and Personal Data Breaches

Taking account of the state of the art, implementation costs, and the nature, scope, context, purposes, and risks of the processing, Processor will maintain appropriate technical and organisational measures under Article 32 GDPR. The current measure categories are described in Annex 2. Processor may update individual measures where the overall protection is not materially reduced.

Processor will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Notices will be sent to Customer's account contact or another security contact supplied to support@streamrunnr.com. As information becomes available, Processor will describe the nature of the breach, affected data and data subjects where known, likely consequences, measures taken or proposed, and a contact point. Processor may provide information in phases and will reasonably assist Customer's investigation, mitigation, documentation, and legally required notifications.

5. Data-Subject, DPIA, and Authority Assistance

Taking account of the nature of the processing, Processor will assist Customer through appropriate technical and organisational measures, insofar as possible, with requests under Chapter III GDPR. If Processor receives a request relating identifiable Customer Personal Data, it will direct the requester to Customer or notify Customer and will not respond on Customer's behalf unless instructed or legally required.

Considering the information available to Processor, Processor will reasonably assist Customer with security obligations, breach notifications, data-protection impact assessments, and prior consultation under Articles 32 to 36 GDPR. Ordinary assistance is included in the service. The parties will agree in advance on any reasonable fee for unusually extensive, repetitive, or customer-specific work not caused by Processor's breach of this DPA.

6. Subprocessors and International Transfers

Customer grants general written authorisation for the subprocessors listed in Annex 3. Processor will impose data-protection obligations that provide materially equivalent protection for the relevant processing and remains responsible to Customer for each subprocessor's performance to the extent required by Article 28 GDPR.

Processor will give at least 30 days' advance notice by service email or a prominent in-app notice before adding or replacing a subprocessor that will process Customer Personal Data. Customer may object within 14 days on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable alternative; if none is available, Customer may terminate the affected service without penalty before the change takes effect. Processor may make an urgent replacement sooner where necessary for security, availability, or legal compliance and will notify Customer as soon as reasonably possible.

Processor will not transfer Customer Personal Data to a country outside the EEA without a lawful transfer mechanism. Depending on the recipient and current legal status, that mechanism may be an adequacy decision, certification under the EU-U.S. Data Privacy Framework only while the relevant recipient is validly certified, or the European Commission's Standard Contractual Clauses with supplementary measures where required. No certification is represented merely by naming it here. Customer may request information about the currently documented mechanism for a listed subprocessor.

7. Return and Deletion

During the agreement, Customer can delete individual videos, playlists, and stream profiles through the service and should retrieve any content it wishes to retain before deletion. Before account deletion or other irreversible termination, Customer may ask Processor to provide or facilitate a reasonable return of available Customer Personal Data in a commonly used form, taking account of the service's technical capabilities.

Ending only the paid subscription does not end the account agreement or this DPA while account configuration remains stored. After subscription expiry, the video rows and associated video objects — source files, converted variants, derivatives, and thumbnails — are retained for the 30-day grace period and then deleted from active storage; references to those videos are removed from playlists. Empty playlists, stream profiles, schedules, and encrypted destination credentials remain until Customer deletes the relevant item or instructs account deletion.

At the end of the processing services, Processor will, at Customer's choice, return then delete or directly delete Customer Personal Data, unless Union or Member-State law requires retention. An account-deletion request is a documented deletion instruction. Processor's retryable workflow stops active processing and streams, removes content and configuration from primary systems, and then removes the identity. Residual copies in protected provider backups remain isolated from ordinary use and are deleted on the provider's applicable backup cycle; if restored for disaster recovery, the protections and deletion instruction continue to apply.

Independent-controller records — for example paid-contract, tax, fraud-prevention, statutory declaration, or legal-claims evidence — are not Customer Personal Data under this DPA and follow the retention rules in the Privacy Policy.

8. Information and Audits

Processor will make information reasonably necessary to demonstrate compliance with this DPA available to Customer. Customer should first use current documentation, questionnaires, summaries, and independent reports that Processor can lawfully provide. No certification or audit report is promised unless Processor actually holds and identifies it.

If that information is insufficient, Customer or an independent auditor bound by confidentiality may conduct one audit per year on at least 30 days' written notice, during normal business hours, and without accessing another customer's data or weakening security. Additional audits are permitted after a relevant personal data breach, a reasonable indication of material non-compliance, or a competent authority's requirement. Customer bears its audit costs unless the audit identifies Processor's material breach; the parties will coordinate scope and safeguards in advance.

9. Term, Liability, and Contact

This DPA begins when incorporated into the agreement and continues until Processor has deleted or returned Customer Personal Data as required above. The governing-law, jurisdiction, and liability provisions of the Terms apply, without limiting mandatory rights or responsibilities under the GDPR. Termination does not affect provisions that by their nature must continue, including confidentiality, deletion, audit cooperation, and liability.

Customer may send documented instructions, data-protection requests, security notices, or requests for a signed copy of this DPA to support@streamrunnr.com, clearly marked "Data Processing". Operational instructions made through authenticated service controls remain valid documented instructions.

Annex 1 — Description of Processing

Subject matter and purpose

Hosting, organising, securing, converting, scheduling, and transmitting Customer-provided video content so Customer can operate continuous or scheduled live streams to destinations selected by Customer, plus related support, troubleshooting, security, and deletion on Customer's behalf.

Duration

For the duration of the account agreement and afterwards only for the return, grace-period, deletion, backup-expiry, or legally required periods described in section 7.

Nature of operations

  • Collection from Customer; upload; recording; organisation; storage; retrieval; consultation; encryption and decryption of destination credentials; access control; and deletion.
  • Automated technical analysis, format validation, transcoding, generation of variants, thumbnails, and media metadata, and temporary processing on streaming infrastructure.
  • Combination into playlists; association with profiles and schedules; transmission to Customer-selected RTMP/RTMPS destinations; technical logging; support and incident investigation.

Categories of data subjects

  • Customer's authorised users, staff, contractors, representatives, and support contacts.
  • Persons whose image, voice, name, online identifier, performance, or other information appears in Customer-provided videos, audio, metadata, playlists, schedules, or support material.
  • Minors or other vulnerable persons only where Customer's processing is lawful and permitted by the Terms.

Types of personal data

  • Names, business contact and account-related identifiers where supplied as Customer data.
  • Video, still images, voice, audio, captions, text, filenames, descriptions, thumbnails, and associated technical metadata.
  • Playlist and schedule information, stream-profile metadata, destination URLs, encrypted stream keys or tokens, IP addresses, device and service-event data, and support material.
  • Special-category, criminal-offence, or children's data only if Customer lawfully submits it under section 2; Processor does not require or intentionally solicit such data for the service.

Annex 2 — Technical and Organisational Measures

  • Governance and confidentiality: documented access responsibilities, least-privilege access, confidentiality obligations, security maintenance, and incident procedures.
  • Identity and access: tenant-bound application access, server-only privileged roles, strong authentication controls, short-lived access sessions, protected refresh sessions, re-authentication for high-risk account actions, and rate limiting.
  • Cryptography and secrets: TLS for web and storage connections; salted password hashes; purpose-bound HMAC values for one-time codes; Secure HttpOnly session cookies; application-level authenticated AES-256-GCM encryption and versioned key management for stream keys. Delivery to Customer destinations uses RTMPS where supported and otherwise may use unencrypted RTMP, as selected by Customer.
  • Isolation and minimisation: account ownership checks, service-role restrictions for privileged tables, object-key ownership validation, removal of stream keys from ordinary API responses and logs, bounded logs, and purpose-limited operational data.
  • Integrity and secure operation: input and media-type validation, protocol and format allowlists, private/reserved-network protections for destinations, bounded processing resources, dependency and change review, testing, and fail-closed destructive workflows.
  • Availability and recovery: monitored services, durable retry queues for critical lifecycle work, controlled stream restarts, provider resilience, backup and recovery procedures appropriate to the hosted component, and deletion instructions that continue to apply after recovery.
  • Deletion and lifecycle: user-level deletion controls, automated 30-day video-library expiry after subscription end, tenant-scoped object deletion, account teardown that stops active workloads before primary-data deletion, and provider backup expiry.
  • Review: periodic review and improvement of measures based on material product, threat, provider, and legal changes. These descriptions state control categories and do not claim an external certification.

Annex 3 — Authorised Subprocessors and Transfer Information

The following providers are authorised only for the stated service functions. Before live processing of Customer Personal Data, Processor will maintain an Article 28 agreement with each provider used in a processor role and will document the applicable transfer mechanism. Locations describe the expected geographic scope and may be narrowed by the live account configuration.

  • Supabase, Inc. — authentication and hosted database for accounts, content metadata, profiles, playlists, schedules, and legal/service records. Expected locations: EEA project infrastructure and potentially the United States for provider operations or support. Transfer safeguard where required: applicable adequacy decision or the European Commission Standard Contractual Clauses in the provider agreement, with supplementary measures as necessary.
  • Cloudflare, Inc. — application delivery/Workers, security edge services, and R2 object storage for uploaded video objects. Expected locations: global network, including the EEA and United States; object placement follows the live Cloudflare configuration. Transfer safeguard where required: applicable adequacy decision or Standard Contractual Clauses in the provider agreement, with supplementary measures as necessary.
  • Hetzner Online GmbH — EEA-hosted servers for temporary video conversion, thumbnails, and live-stream execution. Expected location: EEA production data centres selected by Processor. No third-country transfer is intended for this processing; any future non-EEA location requires section 6 notice and a lawful transfer mechanism.
  • Resend, Inc. — transactional email delivery where Customer Personal Data is included in a service or support message. Expected locations: United States and other locations disclosed under the provider agreement. Transfer safeguard where required: applicable adequacy decision or Standard Contractual Clauses, with supplementary measures as necessary.
  • The Google contracting entity identified in Processor's Workspace agreement — operator support and abuse mailbox where Customer includes Customer Personal Data in correspondence. Expected locations: EEA, United States, and Google's global support infrastructure according to the live Workspace configuration. Transfer safeguard where required: applicable adequacy decision or Standard Contractual Clauses in the provider agreement, with supplementary measures as necessary.

Paddle and Customer-selected streaming destinations are not subprocessors for the processing described here: Paddle acts independently for purchase and billing data, while Customer instructs transmission to its selected destination. Google sign-in is also treated as an independent recipient for the account-holder relationship as described in the Privacy Policy.