1. Roles
For personal data inside your demos, your viewer sessions and the leads your demos collect, you are the controller and Peutly is your processor. Peutly processes that data only to provide the Service, following your documented instructions, which are these Terms, this DPA and the way you configure and use the Service.
For the account, billing and product-usage data of the people in your workspace, Peutly is an independent controller, as described in our Privacy Policy.
2. What we process
- Data subjects: people whose data appears in the screens you capture; people who view your published demos; people who submit a form in one of your demos; people in your workspace.
- Categories of data: anything visible or typed on the pages you record (only password fields are masked at capture); webcam and microphone recordings you add; viewer IP address, browser user-agent, referrer and the steps they viewed; form fields a viewer submits (typically name, email, phone, company and country).
- Special categories: none intended. You agree not to capture special categories of personal data, government identifiers, payment card data or credentials in demos, and to use the editor's blur, hide and replace tools on anything sensitive before you publish.
- Duration: for as long as you use the Service, and until deletion under section 9.
3. Your responsibilities
- You have a lawful basis for the personal data you capture and for collecting data from viewers.
- You give viewers the information the law requires, and obtain consent where it is needed. This includes consent before analytics cookies are set when you connect Google Analytics, Segment or Heap to a demo, and a privacy notice on your lead forms.
- You are responsible for the endpoints you send webhooks to and for what happens to data after it reaches them.
4. Our obligations
- We process personal data only on your instructions, and tell you if we believe an instruction breaks data-protection law.
- Everyone at Peutly with access to customer data is bound by confidentiality.
- We apply the security measures in section 7.
- We help you respond to data-subject requests, carry out data-protection impact assessments and consult supervisory authorities, taking into account what we can reasonably do as your processor.
- We do not sell customer data and do not use it to train AI models.
5. Sub-processors
You give general authorisation for Peutly to use the sub-processors listed on our sub-processor page. Each is bound by written terms that protect personal data at least as well as this DPA. We remain responsible to you for their work. We give at least 30 days' notice before adding or replacing one, and you may object on reasonable data-protection grounds as described on that page.
6. International transfers
Peutly's application, storage and database run in the EU (Frankfurt). Some sub-processors are in, or have group companies in, the United States. For those transfers we rely on the EU-US Data Privacy Framework where the recipient is certified, and otherwise on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), which are incorporated into our agreements with them.
7. Security measures
- Encryption in transit with TLS 1.2 or higher on every public endpoint.
- Encryption at rest for file storage (AES-256) and for the managed database.
- Storage buckets are private and only reachable through our CDN; the network edge is protected by a web application firewall.
- No customer passwords: sign-in uses an email link or an identity provider. Short-lived access tokens, with the ability to revoke all sessions for a user.
- Password-protected demos store only a salted bcrypt hash of the password.
- Secrets for integrations are stored encrypted (AES-256-GCM).
- Production access is limited to the people who need it to run the Service.
- Automated backups of the database, managed by our database provider.
We review these measures as the Service changes. More detail is available on request at security@peutly.com.
8. Personal data breaches
We notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting your data. We tell you what we know about its nature, the data and people likely affected, the likely consequences and what we are doing about it, and we keep you updated as we learn more.
9. Deletion and return
You can export your demos as video or GIF and export leads from the dashboard at any time. When your subscription ends, or when you ask us to, we delete the personal data we process for you within 30 days, including recordings, assets, viewer sessions, engagement events and leads, unless the law requires us to keep it. Database backups roll over and are overwritten on the provider's schedule. To request deletion, email privacy@peutly.com. We confirm in writing when it is done.
10. Audits
We make available the information you reasonably need to show that we meet this DPA, including written answers to security questionnaires. Where that is not enough, you may audit us, or appoint an independent auditor bound by confidentiality, once a year with 30 days' notice, at your own cost and in a way that does not disrupt the Service or expose other customers' data.
11. Liability and term
Liability under this DPA is subject to the limitation of liability in the Terms. This DPA lasts as long as Peutly processes personal data for you. It is governed by Dutch law, and the courts named in the Terms have jurisdiction.