Data Processing Agreement
Cytundeb Prosesu Data
Last updated: March 2026
Overview
This Data Processing Agreement (DPA) sets out the responsibilities of Capsiynau when processing personal data on behalf of customers.
For the purposes of UK GDPR: You (the customer) act as the Data Controller · Capsiynau acts as the Data Processor
Scope of Processing
Categories of data processed:
- Audio and video recordings submitted for transcription
- Generated transcripts and caption data
- Account and user information
- Usage and session data
Processing activities: speech-to-text transcription, caption generation and formatting, translation and language analysis, transcript storage and retrieval, user account management.
Security Measures
| Measure | Detail |
|---|---|
| Encryption in transit | TLS 1.2 / TLS 1.3 |
| Encryption at rest | AES-256 |
| Access control | Role-based, with row-level security |
| Infrastructure isolation | Logical separation between customer accounts |
| Authentication | Secure sign-in with session management |
| Monitoring | Automated security logging and alerting |
Sub-Processors
Capsiynau uses the following sub-processors to deliver the service. All sub-processors are required to meet security and compliance standards equivalent to those in this agreement.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication | EU / USA |
| Cloudflare R2 | File storage | EU / USA |
| Vercel | API and web hosting | Global edge |
| Railway | Background processing worker | USA |
| Upstash | Job queue (Redis) | EU / USA |
| OpenAI | Transcription and translation | USA |
| AssemblyAI | Speech transcription | USA |
| Anthropic | Language processing | USA |
| Google Cloud | Speech-to-Text (Chirp 2) | EU / USA |
| Resend | Transactional email | USA |
| Stripe | Billing and payments | USA |
Data Transfers
Capsiynau aims to process data within UK or European cloud regions wherever possible. Where data is transferred to providers outside the UK or EEA, appropriate safeguards are applied in accordance with UK GDPR, including Standard Contractual Clauses (SCCs) where required.
Data Breach Procedures
In the event of a personal data breach:
- Capsiynau will investigate immediately upon discovery
- Affected customers will be notified without undue delay and within 72 hours where required
- Appropriate mitigation actions will be taken
- Regulatory reporting to the ICO will occur if required under UK GDPR Article 33
Duration
This agreement applies for the duration of your use of the Capsiynau platform and terminates when your account is closed or the service agreement ends.
Contact
For DPA enquiries or to request a countersigned copy (Studio tier): privacy@capsiynau.com