Skip to main content
← Legal

Data Processing Agreement

Effective date: April 28, 2026  ·  v1.4  ·  VidScore LLC

Previous versions available upon request.

Download PDF ↓
This Data Processing Agreement ("DPA") supplements the Enterprise Data Terms or other applicable service agreement ("Agreement") between VidScore™ LLC ("Processor") and the client ("Controller"). This DPA applies where VidScore processes personal data on behalf of the Controller in connection with the services.

1.Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person, as defined by GDPR Article 4(1).
  • "Processing" means any operation performed on Personal Data, including collection, storage, analysis, and deletion.
  • "Controller" means the entity that determines the purposes and means of processing Personal Data (the client).
  • "Processor" means the entity that processes Personal Data on behalf of the Controller (VidScore LLC).
  • "Sub-Processor" means a third party engaged by the Processor to process Personal Data on behalf of the Controller.
  • "Data Subject" means the individual whose Personal Data is being processed.
  • "Supervisory Authority" means an independent public authority responsible for monitoring GDPR application.

2.Scope and Purpose

This DPA applies to VidScore's processing of Personal Data in connection with the services described in the Agreement. The purpose of processing is to deliver analytical reports on publicly available YouTube video content as it relates to the Controller's brand, category, or competitive landscape.

VidScore processes Personal Data only as necessary to perform the services and in accordance with the Controller's documented instructions.


3.Details of Processing

Categories of Data Subjects

  • YouTube content creators whose public videos are analyzed
  • Public figures identified in or associated with analyzed video content
  • Controller's employees or representatives who interact with VidScore services

Categories of Personal Data

  • Names and public identifiers of content creators and public figures
  • Publicly available biographical information (from YouTube, Wikidata, Google Knowledge Graph)
  • Publicly available social media handles and profile URLs
  • Video transcripts (spoken words in publicly available videos)
  • Channel metadata (names, subscriber counts, descriptions)
  • Controller contact information (email, name) for account management
  • Team member identity data (work email, display name, role assignment, invited_at, joined_at, last_login_at, and invite tokens) for every person the Controller authorizes to access the Controller's enterprise portal
  • Portal activity records (actor, action, target, timestamp, request IP address, user agent, and action metadata) for every significant event that occurs within the Controller's organization scope in the portal
  • SSO configuration metadata (Scale tier only): registered email domain, selected identity provider, optional display name, requesting administrator email, request/activation timestamps, and the Supabase SAML provider identifier. Does not include SAML assertions, IdP secrets, or any metadata issued by the Controller's identity provider beyond the authenticated user identifier and email address

Nature of Processing

  • Collection of publicly available video content and metadata
  • AI-powered analysis of video transcripts using Google Cloud Vertex AI (Gemini models)
  • Identity enrichment using public knowledge bases (Wikidata, Google Knowledge Graph)
  • Storage of analysis results and derived structured data
  • Generation of analytical reports and deliverables

Duration

Processing continues for the duration of the Agreement plus the data retention period described in Section 11.


4.Processor Obligations

VidScore, as Processor, shall:

  • Process Personal Data only on documented instructions from the Controller, unless required by applicable law
  • Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk
  • Assist the Controller in fulfilling its obligations to respond to Data Subject rights requests
  • Assist the Controller in ensuring compliance with data breach notification, data protection impact assessments, and prior consultation obligations
  • Delete or return all Personal Data at the end of the services, at the Controller's choice
  • Make available all information necessary to demonstrate compliance with GDPR Article 28 obligations

5.Sub-Processors

The Controller provides general authorization for VidScore to engage sub-processors. VidScore maintains the current list of sub-processors on the Sub-processors page, which is the authoritative and current list and is referenced by, and forms part of, this DPA.

VidScore will publish any addition or replacement of a sub-processor on the Sub-processors page at least 30 days before the change takes effect. The Controller may review the Sub-processors page at any time. Customers who wish to receive email notifications when the Sub-processors page changes may subscribe by contacting [email protected]; VidScore maintains a manual notification list for customers who opt in and sends a change notice to every subscribed address at the time a change is published.

The Controller may object to the addition or replacement of a sub-processor by providing written notice to [email protected] within 30 days of publication on the Sub-processors page. If the Controller objects on reasonable data protection grounds and VidScore cannot accommodate the objection within 30 days, either party may terminate the affected services in accordance with the termination provisions of the applicable service agreement.

VidScore ensures that each sub-processor is bound by data protection obligations no less protective than those in this DPA.


6.Data Subject Rights

VidScore will assist the Controller in responding to Data Subject requests to exercise their rights under GDPR, including:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)

If VidScore receives a request directly from a Data Subject, VidScore will promptly notify the Controller and will not respond to the request without the Controller's instructions, unless legally required to do so.


7.Security Measures

VidScore implements appropriate technical and organizational measures including:

  • Encryption of data in transit (TLS 1.2+) and at rest
  • Access controls with role-based permissions and least-privilege principles
  • Authentication via secure token-based systems (Supabase Auth)
  • DDoS protection and web application firewall (Cloudflare)
  • Rate limiting on all API endpoints
  • Content Security Policy headers to prevent injection attacks
  • Regular security review of application code and dependencies
  • Logging and monitoring of access to systems containing Personal Data

VidScore's full technical and organizational measures are documented on the Technical and Organizational Measures page, which is referenced by, and forms part of, this DPA. The Controller should read this section together with that document.

VidScore regularly reviews and updates its security measures to address emerging threats and maintain a level of security appropriate to the nature of the data processed.


8.Data Breach Notification

VidScore will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Personal Data breach that affects Personal Data processed on behalf of the Controller.

The notification will include:

  • A description of the nature of the breach, including categories and approximate number of Data Subjects and records affected
  • The name and contact details of VidScore's point of contact for breach-related communication
  • A description of the likely consequences of the breach
  • A description of the measures taken or proposed to address the breach and mitigate its effects

VidScore will cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.


9.International Transfers

VidScore and its sub-processors are primarily based in the United States. For transfers of Personal Data from the EU/EEA to countries without an adequacy decision:

  • VidScore relies on Standard Contractual Clauses (SCCs) as adopted by the European Commission (Commission Implementing Decision 2021/914)
  • Where applicable, VidScore relies on the EU-US Data Privacy Framework for transfers to certified US organizations
  • Sub-processors maintain their own appropriate transfer mechanisms (SCCs, DPF certification, or binding corporate rules)

VidScore will inform the Controller of any changes to the transfer mechanisms used and will ensure that adequate safeguards are maintained at all times.


10.Audit Rights

VidScore will make available to the Controller all information necessary to demonstrate compliance with GDPR Article 28, and will allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller.

  • Audits require at least 30 days advance written notice
  • Audits will be conducted during normal business hours and will not unreasonably disrupt VidScore's operations
  • The Controller bears the costs of any audit unless the audit reveals material non-compliance by VidScore
  • Audit results are confidential and may not be disclosed to third parties without VidScore's written consent, except as required by law or a Supervisory Authority

Where multiple Controllers request audits, VidScore may satisfy audit obligations by providing the results of a recent independent third-party audit or certification, provided it addresses the relevant compliance concerns.


11.Termination and Data Return

Upon termination of the Agreement, VidScore will, at the Controller's choice:

  • Return all Personal Data to the Controller in a commonly used, machine-readable format; or
  • Delete all Personal Data and certify deletion in writing

The Controller must make its choice within 30 days of termination. If no instruction is received, VidScore will delete the Personal Data after a 90-day retention period.

VidScore may retain Personal Data to the extent required by applicable law, in which case VidScore will continue to protect such data in accordance with this DPA.


12.Contact

For questions about this DPA, to request a signed copy, or to exercise audit rights:

[email protected]

This standard DPA applies to all Enterprise Data subscriptions. No separate data processing agreement is required.

VidScore LLC
258 Harvard St, #355
Brookline, MA 02446

© 2026 VidScore LLC  ·  Data Processing Agreement  ·  v1.4