Data Processing Addendum
Last updated September 2026. This addendum applies whenever TranscriptFetch processes personal data on your behalf. It forms part of the Terms and takes precedence over them on anything to do with personal data.
Need this signed, or need changes for your procurement process? Email us.
Terms
Who is who
You are the controller: you decide which videos to submit and why. TranscriptFetch is the processor: we act on your instructions and do not decide the purposes of the processing. Where we handle your own account data — your email, your API keys, your usage records — we act as a controller for that, and our Privacy Policy governs it instead.
Your API calls are the documented instructions. We process personal data only to provide the service, to bill you for it, and to keep it secure and available. We will tell you if we believe an instruction breaks data-protection law.
What is processed
Subject matter and durationRetrieving transcripts and listings for the media you submit, for as long as you hold an account.
Nature and purposeFetching published captions where they exist; where they do not, extracting the audio and transcribing it. Caching results so a repeat request does not refetch.
Types of personal dataWhatever appears in the media you submit. A transcript is speech, so it can contain names, opinions and anything else a person said on camera. We do not select or filter it. Plus the request metadata we need to run the service: the URL or id you sent, timestamps, credits spent, and your IP address.
Categories of data subjectsPeople appearing or speaking in the media you submit, and your own users to the extent their identifiers reach us.
Special category dataWe do not ask for it and we cannot detect it. If the media you submit contains it, you are responsible for having a lawful basis under Article 9.
Confidentiality and security
Everyone with access to personal data processed under this addendum is bound by confidentiality. The technical and organisational measures we actually operate are described in full on our security page, including API keys stored only as SHA-256 hashes, TLS in transit, encrypted managed Postgres at rest, and an origin that is not reachable from the public internet.
We are not SOC 2 or ISO 27001 certified and we say so plainly rather than implying otherwise. Our CAIQ v4 self-assessment is published on the Cloud Security Alliance STAR Registry, including the questions where the honest answer is that we do not do something yet.
Sub-processors
You authorise the sub-processors listed on our security page, which names each one, what it does, and what data reaches it. That list is the authoritative version and is kept current.
One deserves calling out rather than burying in a list: when media has no caption track, its audio leaves our infrastructure and is sent to our speech-recognition provider to be transcribed. If that matters for your use case, set mode: "captions" and the request will fail rather than transcribe.
We will give you notice before adding or replacing a sub-processor, and you may object on reasonable data-protection grounds. Each sub-processor is bound by obligations no less protective than these.
International transfers
TranscriptFetch operates from the United States. Where you are in the EEA, the UK or Switzerland, personal data is transferred outside your region, and the Standard Contractual Clauses adopted by the European Commission apply, with the UK Addendum where UK law governs. We are the data importer.
Helping you meet your own obligations
Data subject requestsIf a request reaches us that concerns your data, we forward it rather than answering it, and help you respond.
Personal data breachesWe notify you without undue delay after becoming aware of one, with what we know and what we are doing about it.
AssessmentsWe provide the information you reasonably need for a DPIA or a prior consultation with a supervisory authority.
Retention and deletion
Cached transcript results expire on the cache lifetime. Anonymous free-tool records are deleted automatically after 30 days. Deleting your account removes your associated data, other than records we must keep for legal and accounting purposes. On request at the end of the service we delete or return personal data processed on your behalf.
We do not sell personal data, and we do not train models on your requests.
Audit
We make available the information needed to demonstrate compliance with Article 28, and will answer a reasonable security questionnaire. Given the size of the operation we ask that audits be document-based and no more than once a year, unless a supervisory authority requires otherwise.
If your procurement process needs this countersigned, or needs changes, email us and we will tell you honestly what we can and cannot commit to.
This addendum is owner-authored from the service's actual data flows and has not yet been reviewed by qualified counsel. If your procurement process needs a counsel-reviewed or countersigned version, tell us and we will say honestly what we can commit to.