This Data Processing Addendum ("DPA") applies whenever Glitter AI, Inc. ("Glitter") processes personal data on behalf of a customer ("Customer") in providing the Glitter services. It contains the terms required by Article 28 GDPR and equivalent laws and incorporates the 2021 EU Standard Contractual Clauses, the UK Addendum and the Swiss adjustments for transfers to Glitter in the United States.
Plain-English Summary
Heads up: This is just a summary for your convenience. The legal terms below are what actually govern our agreement.
- Your content, your instructions: You are the controller (or a processor for your own clients) of what you record and create in Glitter. Glitter is your processor and uses it only to provide the service.
- Never used for AI training: not by Glitter and not by the AI providers Glitter uses.
- Sub-processors: listed at glitter.io/legal/sub-processors, with advance notice of changes and a right to object.
- Transfers: EEA, UK and Swiss data transferred to the United States is covered by the 2021 EU Standard Contractual Clauses, the UK Addendum and the Swiss adjustments built into this DPA.
- Security and incidents: a SOC 2 Type II audited security program (Annex II), and notice within 72 hours if a breach affects your data.
- Deletion and return: delete your content at any time; when the service ends, ask Glitter to return it or have it deleted. Every copy, including backups, is gone within 30 days of deletion.
How this DPA applies
This DPA forms part of the agreement that governs Customer's use of the Services, whether the Glitter Subscription Terms & Conditions, the Glitter Terms of Use, or a separately signed agreement, in each case including its Order Forms (the "Agreement"), unless the Agreement expressly excludes it. Where an individual accepts the Agreement on behalf of an organization, that organization is the Customer and the individual represents that they have authority to bind it. By accepting the Agreement, each party is deemed to have accepted and signed this DPA, including the Standard Contractual Clauses and their Annexes. Customer enters into this DPA on behalf of itself and its Affiliates that use the Services, is responsible for their compliance, and exercises their rights under it on their behalf.
For the processing of Customer Personal Data, the order of precedence in case of conflict is: (1) the Standard Contractual Clauses, UK Addendum and Swiss Addendum; (2) the BAA, for PHI only; (3) this DPA; (4) the remainder of the Agreement. Nothing in the Agreement contradicts the Standard Contractual Clauses or prejudices the rights of data subjects.
1. Definitions
Capitalized terms not defined here have the meaning given in the Agreement. "Controller", "processor", "data subject", "personal data", "personal data breach", "processing", "special categories of personal data" and "supervisory authority" have the meanings given in the GDPR, and the equivalent terms under other Data Protection Laws (including "business", "service provider", "consumer" and "personal information" under US State Privacy Laws) are read accordingly.
1.1. "Account Data" means personal data relating to Customer's relationship with Glitter, such as the names, email addresses and roles of Authorized Users, billing contacts, support communications and account settings.
1.2. "Affiliate" means an entity that controls, is controlled by or is under common control with a party, where control means ownership of more than fifty percent (50%) of the voting interests.
1.3. "Authorized User" means an individual whom Customer permits to use the Services under the Agreement.
1.4. "BAA" means a HIPAA business associate agreement executed between Customer and Glitter, and "PHI" has the meaning given in 45 C.F.R. § 160.103.
1.5. "Customer Content" means the screen recordings, screenshots, audio, video, transcripts, interaction data, uploaded files, text and other content that Customer or its Authorized Users record, upload or generate with the Services, including outputs the Services generate from that content.
1.6. "Customer Personal Data" means personal data in Customer Content and any other personal data Glitter processes on Customer's behalf in providing the Services. It excludes Account Data and Usage Data.
1.7. "Data Protection Laws" means the laws applicable to the processing of personal data under the Agreement, including, to the extent applicable: Regulation (EU) 2016/679 (the "GDPR"); the GDPR as it forms part of UK law under the European Union (Withdrawal) Act 2018 (the "UK GDPR") and the UK Data Protection Act 2018; the Swiss Federal Act on Data Protection of 25 September 2020 (the "FADP"); and US State Privacy Laws, each as amended or replaced.
1.8. "EU SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced.
1.9. "Restricted Transfer" means a transfer of Customer Personal Data to Glitter, or onward to a Sub-processor, that Data Protection Laws would prohibit absent an appropriate transfer mechanism, including a transfer from the EEA, the United Kingdom or Switzerland to a country without an applicable adequacy decision.
1.10. "Security Incident" means a personal data breach affecting Customer Personal Data in the possession or control of Glitter or a Sub-processor. It excludes unsuccessful attempts and events that do not compromise the security of Customer Personal Data, such as failed log-in attempts, pings, port scans and denial of service attacks.
1.11. "Sub-processor" means a third party (including a Glitter Affiliate) engaged by Glitter to process Customer Personal Data in connection with the Services, and "Sub-processor Page" means https://www.glitter.io/legal/sub-processors or a successor page notified to Customer.
1.12. "Supervisory Authority" means a public authority responsible for monitoring the application of Data Protection Laws, including the EEA supervisory authorities, the UK Information Commissioner and the Swiss Federal Data Protection and Information Commissioner.
1.13. "Swiss Addendum" means the adjustments in Section 11.5, and "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0, in force from 21 March 2022, as amended or replaced.
1.14. "US State Privacy Laws" means the US state laws governing the processing of personal information that apply to the parties, including the California Consumer Privacy Act of 2018, as amended, and its regulations (the "CCPA"), and comparable laws of other states.
1.15. "Usage Data" means data about the use and performance of the Services that Glitter collects or generates in operating them, such as event logs, feature usage, device and browser information and diagnostic data, excluding Customer Content.
2. Roles and scope
2.1. For Customer Personal Data, Customer is the controller (or, where it acts for its own clients, a processor) and Glitter is a processor (or sub-processor). Glitter processes Customer Personal Data only on Customer's behalf in accordance with this DPA and the Instructions. The subject matter, duration, nature and purpose of processing, the types of personal data and the categories of data subjects are set out in Annex I.
2.2. Where Customer is a processor for a third-party controller, Customer warrants that its Instructions and its appointment of Glitter are authorized by that controller and is Glitter's sole point of contact. Glitter is not required to interact with, or take instructions from, that controller.
2.3. Glitter processes Account Data and Usage Data as an independent controller to operate, secure, support, bill for and improve the Services, to communicate with Customer and Authorized Users, to comply with law, and as described in the Privacy Policy. Glitter does not process Customer Content as a controller, does not use it to train or improve artificial intelligence or machine learning models, and does not permit any third party to do so. Glitter may create and use aggregated, de-identified data derived from Customer Content that cannot reasonably identify Customer, an Authorized User or any other individual; such data is not Customer Personal Data.
3. Instructions and Customer responsibilities
3.1. Instructions. Customer instructs Glitter to process Customer Personal Data (a) to provide, maintain, secure and support the Services, including as initiated by Authorized Users through the Services' features (such as recording, transcribing, generating, editing, redacting, translating, answering questions about, storing, sharing and exporting guides); (b) as specified in the Agreement and this DPA; and (c) per other documented instructions that Glitter agrees to (together, the "Instructions"). Glitter will not process Customer Personal Data for any other purpose, including transfers to a third country or international organization, unless required by law to which Glitter is subject, in which case Glitter will inform Customer before processing unless the law prohibits it on important grounds of public interest. Glitter will inform Customer if, in its opinion, an Instruction infringes Data Protection Laws, and may suspend that Instruction until Customer confirms or modifies it. Glitter is not obliged to review Customer's processing for legal compliance.
3.2. Customer responsibilities. Customer is solely responsible for: (a) the accuracy, quality and legality of Customer Personal Data and how Customer obtained it; (b) a lawful basis for the processing and any notices and consents Data Protection Laws require; (c) its Instructions; (d) deciding whether the Services are appropriate for the data it processes, and configuring and using them accordingly, including sharing and access settings, the redaction features, and its Authorized Users' credentials and permissions; and (e) not making guides containing Customer Personal Data public without a lawful basis. Customer will not submit PHI unless a BAA is in effect and the HIPAA setting is enabled for its organization, and is responsible for a lawful basis under Article 9 GDPR (or equivalent) for any other special categories of personal data it chooses to process. Customer will indemnify Glitter against claims, fines and losses arising from Customer's breach of this Section 3.2.
4. Confidentiality
Glitter ensures that persons authorized to process Customer Personal Data are bound by written or statutory confidentiality obligations and access it only as needed to perform the Services.
5. Security
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risks for the rights and freedoms of natural persons, Glitter implements the technical and organizational measures in Annex II. Customer has reviewed Annex II and agrees that those measures are appropriate for the Customer Personal Data it chooses to process. Glitter may update them provided the overall level of protection is not materially reduced during the term. Customer is responsible for the security measures within its control described in Section 3.2(d).
6. Sub-processors
6.1. Customer gives general written authorization for Glitter to engage the Sub-processors listed on the Sub-processor Page (Annex III) and additional or replacement Sub-processors under this Section.
6.2. Glitter gives at least ten (10) days' prior written notice of a new or replacement Sub-processor by updating the Sub-processor Page and emailing the address(es) Customer registers for that purpose by writing to privacy@glitter.io with the subject "Subscribe to sub-processor updates". Where a replacement is needed urgently to maintain the security or availability of the Services, Glitter may give shorter notice.
6.3. Customer may object within the notice period on reasonable data protection grounds, stated in writing. The parties will discuss in good faith; if Glitter cannot reasonably accommodate the objection, either party may terminate the affected Services on written notice, without refund of prepaid fees, as Customer's sole and exclusive remedy. Customer acknowledges that certain Sub-processors, such as cloud infrastructure and AI providers, are essential to the Services. Absent a timely objection, the Sub-processor is deemed authorized.
6.4. Glitter binds each Sub-processor by written terms imposing data protection obligations no less protective than those in this DPA, to the extent applicable to its services, including transfer safeguards where required, and remains liable for the Sub-processor's performance of those obligations. On request, Glitter provides the data protection terms of a Sub-processor agreement, with commercial and unrelated information redacted.
7. Assistance
7.1. Glitter will, to the extent legally permitted, promptly notify Customer of any request from a data subject relating to Customer Personal Data and will not respond except to direct the data subject to Customer or as required by law. Customer is responsible for responding to such requests. Taking into account the nature of the processing, Glitter will assist Customer by appropriate measures, insofar as possible. Customer will use the Services' own access, correction and deletion features where they suffice, and may request from Glitter a copy of Customer Personal Data it cannot obtain through the Services.
7.2. Taking into account the nature of the processing and the information available to it, Glitter will provide reasonable assistance with Customer's obligations under Articles 32 to 36 GDPR (security, breach notification, impact assessments and prior consultation) and their equivalents, where Customer lacks the relevant information.
7.3. Assistance is free where it can be provided through the Services' standard features or generally available documentation. Otherwise, to the extent permitted by law, Glitter may charge reasonable fees.
8. Security Incidents
8.1. Glitter will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident, describing, as known, its nature, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed, and may provide this in phases. Glitter will take reasonable steps to contain and mitigate the Security Incident and will give Customer the cooperation reasonably necessary for Customer's own notification obligations.
8.2. Notification is not an admission of fault or liability. Customer is responsible for Security Incidents caused by its or its Authorized Users' acts or omissions, including compromised credentials.
9. Return and deletion
9.1. Customer may access and delete Customer Content through the Services during the term. Deletion through the Services is permanent, and Glitter has no obligation to restore deleted Customer Content. Content Customer deletes, and prior versions of screenshots Customer redacts, are removed from Glitter's systems, including backups, within thirty (30) days. Export features, where included in Customer's plan, are described in the Documentation, and Customer may request a copy of its Customer Content by contacting Glitter.
9.2. After termination or expiry of the Agreement, at Customer's election made in writing before or within thirty (30) days after the end of the term, Glitter will either return Customer Personal Data by providing a copy of Customer Content in a commonly used, machine-readable format within a reasonable period, and then delete it, or delete it. Absent an election, Glitter deletes Customer Personal Data within ninety (90) days after the end of the term. All remaining copies held by Glitter, including in backups, are deleted or overwritten within thirty (30) days after that deletion and remain subject to this DPA until then. Glitter may retain data that applicable law requires it to keep, isolated and protected from further processing. Glitter certifies deletion in writing on request (including under Clause 8.5 of the EU SCCs).
10. Records, information and audits
10.1. Glitter maintains the records required by Article 30(2) GDPR and makes available the information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR. No more than once in any twelve (12) month period, unless a Supervisory Authority requires otherwise, Glitter will on written request provide its current SOC 2 Type II report and other third-party audit reports it makes generally available, under reasonable confidentiality terms, and written responses to Customer's reasonable security questionnaires. Security documentation is also available at https://trust.glitter.io/.
10.2. If that information is not reasonably sufficient, or where a Supervisory Authority or Data Protection Laws require it, Customer or an independent auditor mandated by Customer (bound by confidentiality and not a Glitter competitor) may audit Glitter's compliance with this DPA, no more than once in any twelve (12) month period unless a Supervisory Authority requires otherwise, on at least thirty (30) days' written notice with a scope agreed in good faith, during business hours, without unreasonable disruption or risk to other customers' data, at Customer's cost including Glitter's reasonable time and expenses for on-site audits. Audit findings are Glitter's Confidential Information and are shared with Glitter promptly. Audits under Clause 8.9 of the EU SCCs follow this Section, without prejudice to Supervisory Authority rights under the EU SCCs.
11. International transfers
11.1. Glitter and its Sub-processors process Customer Personal Data in the United States and the locations on the Sub-processor Page, and Customer authorizes those transfers subject to this Section. Restricted Transfers are made under the EU SCCs, the UK Addendum and the Swiss Addendum. If Glitter later adopts another valid transfer mechanism, it may rely on it in addition to the EU SCCs.
11.2. EU SCCs. For Restricted Transfers subject to the GDPR, the EU SCCs are incorporated by reference and entered into between Customer (and each covered Affiliate) as data exporter and Glitter as data importer, completed as follows:
- Modules: Module Two (controller to processor) where Customer is a controller; Module Three (processor to processor) where Customer is a processor, in which case references to the controller are to Customer's third-party controller and Customer warrants it has that controller's authorization.
- Clause 7 (docking clause): applies.
- Clause 9: Option 2 (general written authorization), with the notice period in Section 6.2.
- Clause 11(a): the optional language does not apply.
- Clause 13: the competent supervisory authority is identified in Annex I, Part C.
- Clause 17: Option 1, the laws of Ireland.
- Clause 18: the courts of Ireland.
- Annexes I, II and III of the EU SCCs are Annexes I, II and III of this DPA.
11.3. UK Addendum. For Restricted Transfers subject to the UK GDPR, the EU SCCs as completed above apply as amended by the UK Addendum, incorporated by reference and completed as follows: Table 1 with the information in Annex I, Part A; Table 2 with the EU SCCs as completed in Section 11.2; Table 3 with Annexes I, II and III of this DPA; and in Table 4, the Importer may end the UK Addendum as set out in its Section 19.
11.4. Swiss Addendum. For Restricted Transfers subject to the FADP, the EU SCCs as completed above apply with these adjustments: references to the GDPR are read as references to the FADP; references to the EU, Union, Member State and Member State law include Switzerland and Swiss law; the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority under Clause 13; data subjects habitually resident in Switzerland may bring claims in Switzerland under Clause 18(c); and where a transfer is subject to both the GDPR and the FADP, the EU SCCs are interpreted to comply with both.
11.5. Assessments and government requests. On request, Glitter will provide the information reasonably necessary for Customer's transfer impact assessment under Clause 14 of the EU SCCs. The safeguards for US signals intelligence under Executive Order 14086 and the Data Protection Review Court apply to transfers to the United States regardless of the mechanism used. Glitter will handle legally binding requests from public authorities for Customer Personal Data in accordance with Clause 15 of the EU SCCs (notification unless prohibited, review and challenge where there are reasonable grounds, minimum disclosure, and documentation available to Customer on request) and will not voluntarily disclose Customer Personal Data to a public authority.
11.6. If a transfer mechanism in this Section ceases to be valid, the parties will cooperate in good faith to implement an alternative without undue delay, and Glitter may suspend the affected Restricted Transfers in the meantime to the extent Data Protection Laws require.
12. US State Privacy Laws
To the extent US State Privacy Laws apply, Glitter is a "service provider", "contractor" or "processor" and Customer is a "business" or "controller", and Customer discloses Customer Personal Data to Glitter only for the limited and specified business purposes of providing the Services under the Agreement and Annex I. Glitter will not (a) sell or share Customer Personal Data; (b) retain, use or disclose it for any purpose other than those business purposes or outside the direct business relationship with Customer; or (c) combine it with personal information from other sources, except as those laws permit. Glitter will comply with the obligations applicable to service providers and processors, provide the level of privacy protection those laws require, notify Customer if it can no longer meet them, and allow Customer to take reasonable and appropriate steps under Section 10 to ensure compliance and to stop and remediate unauthorized use. Sub-processor notice and flow-down follow Section 6 and consumer request assistance follows Section 7. Glitter certifies that it understands and will comply with these restrictions.
13. HIPAA
Where a BAA is in effect, it governs PHI and prevails over this DPA for PHI. This DPA does not create a business associate relationship in the absence of a BAA.
14. Liability
Each party's and its Affiliates' total aggregate liability arising out of or related to this DPA is subject to the exclusions and limitations of liability in the Agreement, which apply to the Agreement and this DPA together. This does not limit either party's liability to data subjects under Clause 12 of the EU SCCs (or its UK and Swiss equivalents) or any liability that cannot be limited under Data Protection Laws.
15. General
15.1. This DPA takes effect when the Agreement is accepted and remains in effect until Glitter has deleted all Customer Personal Data under Section 9.
15.2. Glitter may update this DPA. Updates required by Data Protection Laws, or that only increase protection, take effect on posting; other updates take effect at Customer's next renewal or on Customer's earlier acceptance.
15.3. This DPA is governed by the law governing the Agreement, except that the EU SCCs, UK Addendum and Swiss Addendum are governed as set out in Section 11 and except where Data Protection Laws require otherwise. If any provision is unenforceable, the remainder stays in force. Except for data subjects' rights under the EU SCCs, the UK Addendum and the Swiss Addendum, this DPA has no third-party beneficiaries.
15.4. Notices to Glitter under this DPA go to privacy@glitter.io; notices to Customer go to the administrator email address(es) on Customer's account and any address registered under Section 6.2.
ANNEX I: Description of the processing and transfer
A. List of parties
Data exporter: Customer, as identified in the Agreement or Order Form, with its covered Affiliates. Contact: the administrator contact(s) on Customer's Glitter account. Activities: use of the Services to create, edit, host and share process documentation. Role: controller (Module Two) or processor (Module Three).
Data importer: Glitter AI, Inc., 1111B S Governors Ave STE 7606, Dover, DE 19904, United States. Contact: privacy@glitter.io. Activities: provision of the Services. Role: processor.
Acceptance of the Agreement constitutes each party's signature of this Annex and of the EU SCCs, UK Addendum and Swiss Addendum.
B. Description of the transfer
Categories of data subjects: Authorized Users (Customer's employees, contractors and agents); individuals whose personal data appears in Customer Content, such as Customer's employees, customers, end users and suppliers whose information is visible on screen, spoken in a narration or contained in uploaded files (and, where a BAA is in effect, patients); and individuals who view guides Customer shares, to the extent the Services record their access.
Categories of personal data: identity and contact data of Authorized Users and viewers (name, email address, profile picture, organization, role, authentication identifiers); Customer Content, including screen recordings and screenshots that may show any personal data on the recording user's screen, microphone audio and transcripts, interaction metadata (click positions, page URLs, window and application titles), uploaded files, and generated guide text, annotations, comments and translations; associated technical and engagement data (IP address, device and browser information, timestamps, view events); and support communications.
Sensitive data and restrictions: the Services are not designed to process special categories of personal data or PHI, but Customer Content may include them depending on what Customer records. Safeguards: the Customer obligations in Section 3.2; on-device redaction before capture and cloud redaction that replaces the stored screenshot, with prior versions and backup copies purged within thirty (30) days; guides private to the organization by default; and, where a BAA is in effect and the HIPAA setting is enabled, transcription and AI processing only on BAA-covered infrastructure, automatic screening of transcripts for personal identifiers, public sharing disabled, access-controlled embeds only, and session replay disabled.
Frequency: continuous during the Agreement. Nature: collection, recording, storage, transcription, automated analysis, question answering and text generation, redaction, translation, organization, retrieval, display, sharing at Customer's direction, export and deletion. Purpose: providing the Services (creation, editing, hosting and sharing of process documentation) and related support. Retention: the term of the Agreement plus the period in Section 9, or shorter where Customer deletes content. Sub-processor transfers: as described in Annex III, for the purposes on the Sub-processor Page; Sub-processors are contractually prohibited from using Customer Personal Data to train or improve AI models.
C. Competent supervisory authority
Where the data exporter is established in an EEA member state, that state's supervisory authority; where it is not but has an Article 27 GDPR representative, the authority of the representative's member state; otherwise, the authority of the member state where the data subjects are located. For UK GDPR transfers, the UK Information Commissioner; for FADP transfers, the Swiss Federal Data Protection and Information Commissioner.
ANNEX II: Technical and organizational measures
Glitter's security program is audited annually by an independent auditor against the SOC 2 Type II criteria (report available on request via https://trust.glitter.io/) and includes:
- Governance: written security policies with defined ownership, periodic risk assessments, vendor assessment and written data protection terms (and BAAs where PHI is involved) for Sub-processors, and change management for production systems.
- Encryption: TLS in transit and AES-256 at rest.
- Access control: personnel access to production systems and Customer Personal Data restricted to authorized staff on a need-to-know basis, individually authenticated and logged; Customer Content logically segregated by organization with database-level row security; customer-managed roles and sharing permissions; SAML 2.0 single sign-on on eligible plans.
- Privacy controls: guides private to the organization by default; on-device redaction before capture; cloud redaction that replaces the stored screenshot, with prior versions and backup copies purged within 30 days; platform-enforced HIPAA restrictions for organizations with a BAA.
- Monitoring: application audit logging, access monitoring, error monitoring and availability monitoring.
- Vulnerability management: periodic application penetration testing, dynamic application security testing, dependency and patch management, and a responsible disclosure process.
- Incident response: a documented process for detection, containment, investigation, notification under Section 8 and post-incident review.
- Resilience: automated backups retained for no more than 30 days, cloud provider redundancy, and a business continuity and disaster recovery plan.
- Personnel: written confidentiality obligations, security awareness training and endpoint security controls.
- Physical security: data centers of the cloud providers on the Sub-processor Page, audited under recognized industry standards.
- Deletion: customer-initiated deletion through the Services at any time; end-of-term deletion under Section 9; certificates of destruction on request.
ANNEX III: List of sub-processors
Customer has authorized the Sub-processors listed on the Sub-processor Page at https://www.glitter.io/legal/sub-processors, as updated under Section 6. The page identifies each Sub-processor, its service, the categories of Customer Personal Data it processes and its processing location.
Last updated: September 19, 2026