Data Processing Addendum
This Data Processing Addendum ("DPA") supplements the Terms of Service between RenderMac ("Processor") and the customer identified in the applicable order or account ("Customer," acting as "Controller") whenever Customer's Job Content includes personal data for which Customer determines the purposes and means of processing. Where this DPA conflicts with the Terms of Service on data-protection matters, this DPA controls.
1.Definitions
"Personal Data," "Controller," "Processor," and "Data Subject" have the meanings given in applicable data protection law (e.g. GDPR Article 4, CCPA/CPRA §1798.140), to the extent such law applies to the personal data in question. "Job Content" has the meaning given in the Terms of Service.
2.Roles of the parties
Customer is the Controller of any personal data contained in its Job Content (for example, footage of identifiable people submitted for stitching, transcoding, or Remotion rendering). RenderMac is a Processor with respect to that personal data, processing it solely to perform the Service as instructed by Customer through the API, and does not determine the purposes or means of processing Customer's personal data beyond what is necessary to operate the Service as documented in the API/OpenAPI contract.
3.Processing instructions
RenderMac will process Job Content only: (a) to perform the requested named service (e.g. ffmpeg.stitch_export.v1) and its mandatory verification (byte count, SHA-256, container/media-format check, and any configured probabilistic re-render sampling per verification_policies), (b) as necessary to operate billing, support, and security functions described in the Privacy Policy, or (c) as required by law. Customer's API calls, job input schemas, and webhook configuration constitute Customer's documented processing instructions for purposes of this DPA.
4.Confidentiality of personnel
RenderMac limits access to Job Content and personal data to personnel and systems that need it to operate the Service, and requires personnel with such access to be bound by confidentiality obligations. Named admin roles (superadmin, ops, support_buyer, support_provider, finance, readonly) further restrict which internal capabilities an individual admin has, rather than granting every support/operations hire the same unrestricted access a shared token historically implied.
5.Security measures
RenderMac maintains technical and organizational measures appropriate to the risk, including at minimum: encryption of secrets at rest (AES-256-GCM for webhook signing secrets and BYOB storage credentials; salted SHA-256 hashing for API keys, admin tokens, and device credentials, never stored in recoverable plaintext); encryption in transit (TLS for all API, webhook, and provider WebSocket traffic); role-based access control for administrative functions; an append-only, tamper-resistant audit log for every consequential admin action; and mandatory dual-admin approval, enforced at the database layer, before any real-money provider payout executes.
6.Subprocessors
Customer authorizes RenderMac's use of the following subprocessors, and any others added to the equivalent list in the Privacy Policy, which RenderMac will keep current:
| Subprocessor | Function | Location |
|---|---|---|
| Stripe, Inc. | Payment processing and Connect payouts | United States |
| Cloudflare, Inc. | Edge network, Workers/Pages hosting, R2 object storage | Global edge, primary control plane in the United States |
| Neon, Inc. | Managed Postgres database hosting | United States (aws-us-east-1) |
RenderMac will provide reasonable advance notice before adding a new subprocessor that will process Customer's Job Content, via the contact on file for Customer's organization, so Customer may object on reasonable data-protection grounds.
7.Assistance with data subject requests
RenderMac will provide reasonable assistance to Customer in responding to a verified Data Subject request (access, correction, deletion, or portability) concerning personal data in Job Content, to the extent RenderMac can identify and act on that data using the job/organization identifiers Customer provides. Customer remains responsible for determining whether and how to respond to the underlying request as Controller.
8.Breach notification
RenderMac will notify Customer without undue delay, and in any case within 72 hours of becoming aware, of any confirmed unauthorized access to or disclosure of Customer's Job Content or account data, and will provide the information reasonably available at the time (nature of the incident, categories/approximate volume of data affected, and remediation steps taken or planned), updating that notification as more information becomes available.
9.International transfers
RenderMac's infrastructure is US-region by default (see the Privacy Policy). If Customer's Job Content includes personal data originating outside the United States, Customer acknowledges that data will be transferred to and processed in the United States. As noted in the counsel-review notice above, this DPA does not yet attach Standard Contractual Clauses or another recognized transfer mechanism; Customer should not rely on this DPA alone as sufficient for EU/UK personal data until that gap is closed.
10.Deletion or return of data
On termination of the Terms of Service, RenderMac will, at Customer's election made within 30 days of termination, delete or return Customer's Job Content and associated personal data, except where RenderMac is required to retain specific records (e.g. append-only ledger/audit entries) for legal, tax, or accounting purposes as described in the Privacy Policy.
11.Audit rights
On reasonable written notice and no more than once per 12-month period (absent a specific security incident), RenderMac will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, which may take the form of documentation review, a questionnaire response, or a summary of relevant audit-log evidence, rather than an on-site audit of RenderMac's infrastructure, unless otherwise agreed in writing.
12.Term & liability
This DPA remains in effect for as long as RenderMac processes personal data on Customer's behalf under the Terms of Service. Liability under this DPA is subject to the limitations of liability in the Terms of Service unless a separately negotiated agreement says otherwise.