Data Processing Agreement
Last updated: 20 July 2026
This agreement covers the personal data you put into RecapYear — the rows of your CSV. Under UK GDPR you are the controller of that data and we are your processor. Article 28 requires those terms to be in writing, so here they are.
It forms part of our Terms and applies automatically when you use RecapYear — there is nothing to sign. For everything else (our own site, your account, your payment) see the Privacy Policy, where we are the controller.
1. The basics
- Subject matter: generating year-in-review recap cards and share links from data you supply.
- Duration: the length of a single request. We are not a store — see section 6.
- Nature and purpose: reading your file, computing highlights, rendering cards, encoding share links.
- Type of personal data: whatever you choose to upload. The product needs only a name or handle plus numbers.
- Categories of data subjects: your customers, users, members or staff — whoever your rows describe.
- Controller / processor: you / us. We are not a joint controller and we never become the controller of your rows.
Do not upload special category data(health, biometrics, race, religion, politics, sex life), criminal offence data, children’s data, or financial account details. RecapYear is not built for it and you must not send it.
2. We act only on your instructions
We process your rows only to give you what you asked for, and only as instructed by you through the product. We will not use your data for our own purposes. In particular we do not:
- add your rows to our own marketing lists or contact anyone in them;
- train models on your data;
- sell, rent, share or enrich it;
- profile the individuals in it, or combine your data with another customer’s;
- keep it after your request is served.
If the law ever required us to process your data otherwise, we would tell you first unless that law forbids it. If we think an instruction of yours breaches data protection law, we will say so.
3. Confidentiality
Access is limited to the people who need it to run the service — today that is one person — under a duty of confidentiality.
4. Security
Measures appropriate to the risk (Article 32). The most important one is architectural rather than a promise:
- In the free flow your CSV never leaves your browser. It is read and processed on your own machine and never reaches our servers.
- In the Pro batch export the file is sent over HTTPS, held in memory only for as long as the request takes, and returned to you. It is not written to a database or to disk.
- Encryption in transit (TLS); hosting on Google Cloud; access to the deployment restricted to the operator.
- Data we never hold cannot leak — retention is the control we rely on most.
5. Sub-processors
You give general authorisation for the sub-processors below. We stay responsible for what they do with your data, and we will give you notice of any addition or replacement with a reasonable opportunity to object.
- Google Cloud — hosting and compute. This is where the request runs, so it is the only provider that handles your data on our behalf.
That is the whole list — one sub-processor. It is short because there is very little to process: your rows exist only in memory for the length of a single request.
We deliberately do not list Polar, Plausible or Microsoft 365 here. They never receive your data, and they are not engaged by us to process it on your behalf: Polar is the Merchant of Record and acts as an independent controller of the payment relationship with the buyer; Plausiblemeasures aggregate traffic on our own site; Microsoft 365 carries our email. Those are providers of our own business, where we are the controller — a different role, described in our Privacy Policy. Naming them as sub-processors here would wrongly suggest your file travels to them.
Where a sub-processor operates outside the UK, transfers rely on appropriate safeguards (UK adequacy, the UK IDTA or the Addendum to the EU SCCs).
6. Deletion and return
There is nothing to return at the end of the contract, because we keep nothing. Your rows are discarded as soon as your cards or export are produced, and we hold no database of recaps: the content of a share link lives inside the link itself, which you control and can simply stop sharing. Technical logs never contain the contents of your file.
7. Helping you meet your obligations
- Data subject requests: if one of your people contacts us, we will not respond on your behalf — we will pass it to you promptly and help where we can. In practice we hold nothing to erase or export.
- Personal data breaches: we will notify you without undue delay after becoming aware of one affecting your data, with the detail you need for your own reporting.
- DPIAs and consultations: we will give you the information about our processing that you reasonably need.
8. Audit
On reasonable written request we will provide the information needed to demonstrate compliance with this agreement, and allow an audit or inspection — at a mutually agreed time, no more than once a year unless a breach or a regulator requires otherwise, and subject to confidentiality.
9. Liability and general
The liability provisions of our Terms apply to this agreement. If any term here conflicts with the Terms on the handling of your rows, this agreement wins. It is governed by the law of England and Wales.
10. Contact
The processor under this agreement is Luis Cristian Aurrecoechea Di Giacomo, 6 Southgate Drive, Towcester, Northamptonshire, NN12 6JQ, United Kingdom. Questions, notices, or a request under this agreement: hello@recapyear.com. You can also complain to the UK ICO (ico.org.uk).