Data Processing Agreement
Last updated 28 September 2026
This Data Processing Agreement (“DPA”) is part of the agreement between Muvero (“Muvero”, “we”, “us”) and the customer that uses the Muvero service (“you”), made up of our Terms of Service and this DPA. It applies whenever we process personal data on your behalf while providing the service, and it meets the requirements of Article 28 of the EU General Data Protection Regulation (“GDPR”) and the UK GDPR.
It applies automatically to every workspace. Customers on the Business and Enterprise plans can also ask for a copy signed by both sides at privacy@muvero.app; the signed copy has the same content.
1. Roles
- You are the controller of the personal data in your content: the recordings, links and text you put into Muvero and everything made from them. You decide why and how it is processed.
- We are the processor. We process that data only to provide the service to you.
- For our own account, billing and security records we are a controller ourselves; our Privacy Policy covers that data, not this DPA.
2. What we process
The subject matter, nature, purpose and duration of the processing, the types of personal data and the categories of people concerned are described in Annex 1.
3. Our obligations
Instructions. We process personal data only on your documented instructions. Your instructions are this DPA, the Terms, and what you or your members do in the app (for example starting a job, sharing a link or deleting a project). If we believe an instruction breaks data protection law, we tell you. If the law requires us to process data in another way, we tell you first, unless the law forbids that.
Confidentiality. Everyone at Muvero who can access your personal data is bound by a duty of confidentiality and accesses it only when that is needed to run or support the service.
Security. We apply the technical and organisational measures in Annex 2 and keep them appropriate to the risk. We may improve them over time, but not in a way that lowers the overall level of protection.
No other use. We do not sell your content, we do not use it to train AI models, and we do not use it for our own purposes.
Helping you with requests. The app lets you find, correct, export and delete content yourself. Where you need more, we help you answer requests from people exercising their rights (access, correction, deletion, restriction, portability, objection). If a person contacts us directly about your content, we pass the request on to you and do not answer it ourselves.
Helping you with compliance. Taking into account what information we have, we help you with security, breach notification, data protection impact assessments and prior consultation with a supervisory authority (GDPR Articles 32 to 36).
4. Personal data breaches
If we become aware of a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to your personal data, we notify you without undue delay and in any case within 48 hours. We send the notice to the workspace owner’s email address and tell you, as far as we know them at the time: what happened, the categories and approximate number of people and records affected, the likely consequences, and what we have done or propose to do. We add information as we learn more. Notifying you is not an admission of fault.
5. Sub-processors
You authorise us to use the sub-processors listed in Annex 3. We give each of them data protection obligations that are at least as protective as this DPA, and we remain responsible to you for their work.
Before we add or replace a sub-processor, we tell the workspace owner by email at least 30 days in advance. If you have a reasonable data protection objection, tell us within that period. We will try to find a solution with you; if we cannot, you may cancel the affected plan before the change applies and we refund the part of the current period you have paid for and not used.
6. International transfers
Muvero and some of its sub-processors are located outside the European Economic Area and the United Kingdom. Where personal data is transferred to a country without an adequacy decision, the transfer is covered by:
- the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), Module Two (controller to processor) between you and us, which are incorporated into this DPA by reference, with the details in the Annexes filled in by Annexes 1 to 3 below;
- for UK data, the UK International Data Transfer Addendum to those clauses; and
- between us and our sub-processors, Module Three of the same clauses or another safeguard recognised under GDPR Article 46, or the EU–US Data Privacy Framework where the sub-processor is certified.
If this DPA and the Standard Contractual Clauses conflict, the clauses prevail.
7. Deletion and return
You can export your content (transcripts, subtitles, articles, projects) and delete it in the app at any time. When the agreement ends, or when you ask us to close your workspace, we delete your content within 30 days, unless the law requires us to keep it. Copies in backups are deleted when those backups expire.
8. Audits
We make available the information you need to show that we meet this DPA. Once a year, or after a personal data breach, you may audit our compliance, yourself or through an independent auditor bound by confidentiality. Give us at least 30 days’ written notice; audits take place during business hours, avoid disrupting the service and other customers’ data, and are at your cost. We first answer written questions, which is often enough.
9. Liability and order of precedence
Each party’s liability under this DPA is subject to the limits in the Terms, except where the law does not allow such a limit. On data protection matters this DPA prevails over the Terms. This DPA lasts as long as we process personal data for you.
Annex 1: Details of the processing
- Subject matter and purpose: providing the Muvero service: storing recordings and text, transcribing and detecting speakers, translating, summarising, extracting topics and sentiment, writing articles, making subtitles, video exports and reels, generating voice from text, and sharing results through links you create.
- Nature of the processing: collection, storage, analysis by automated speech and language models, transformation, retrieval, disclosure through links you share, and deletion.
- Duration: while you use the service, then until deletion under section 7.
- People concerned: people who can be heard or are mentioned in your recordings and texts (for example speakers, interviewees, guests, callers, athletes, officials), and your workspace members.
- Types of personal data: voices and what is said, names and other details mentioned in the content, images of people in videos, and members’ names and email addresses. Your content may contain special categories of data (for example health, political opinions or religious beliefs) if you put it there; you decide whether you have a lawful basis for that.
- Frequency: continuous, while the service is used.
Annex 2: Security measures
- In transit: all traffic between browsers, apps, our servers and our providers is encrypted with TLS.
- At rest: media files are stored with a provider that encrypts stored objects at rest. Passwords are stored only as salted hashes.
- Access control in the app: every workspace is separated from the others; within a workspace, roles (user, editor, admin) limit who can invite members, change billing and remove people. Sign-in attempts are rate-limited.
- Staff access: access to customer data through our owner console is limited to staff who need it, protected by two-factor authentication, and recorded in an audit log.
- Secrets: API keys and credentials are kept in the hosting environment’s secret store, not in source code.
- Sharing: content leaves the workspace only when a member shares a link to it, which can be turned off again, or publishes it.
- Deletion: deleted projects go to the workspace trash and can then be removed for good; failed uploads are deleted after 30 days.
- Payments: card details are handled only by our payment provider; we never see or store the full card number.
- AI providers: we send content to AI providers only to run the job you started, under terms that do not allow them to train their models on it.
Annex 3: Sub-processors
| Sub-processor | What it does for Muvero | Data it handles | Location |
|---|---|---|---|
| Railway Corporation | Hosting of the app, the API, the database and background workers | All service data | United States |
| Cloudflare, Inc. | File storage (R2), content delivery and DNS | Recordings, videos, transcripts and other files | United States |
| RunPod, Inc. | GPU servers for speech recognition and speaker detection | Audio of recordings | United States |
| OpenAI, L.L.C. | Summaries, translation, articles, topics and text clean-up | Transcript text | United States |
| Google LLC | Voice generation from text | Text sent for voice generation | United States |
| Resend, Inc. | Service emails (sign-in codes, invites, billing notices) | Names and email addresses of members | European Union (Ireland), company in the United States |
| Stripe, Inc. and Stripe Payments Europe, Ltd. | Payments | Billing contact details and payment data (not your content) | United States and Ireland |
Contact
Data protection questions and requests: privacy@muvero.app.