Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the agreement between Aptbyte Ventures, a business registered in Delhi, India ("Rewind", "we", "us", the "Processor") and the customer that has subscribed to a Team or Enterprise plan, sponsors a cohort, or administers Kiosk/Exam mode (the "Customer", the "Controller") under our Terms of Service (the "Agreement"). It applies where and to the extent Rewind processes Personal Data on the Customer's behalf and the GDPR, UK GDPR, or similar data-protection law applies to that processing. If this DPA conflicts with the Agreement on the subject of Personal Data processing, this DPA controls.
"GDPR", "Personal Data", "processing", "controller", "processor", "data subject", "supervisory authority", and "personal data breach" have the meanings given in Regulation (EU) 2016/679 (and, for UK Customers, the UK GDPR). "SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914 (and, for the UK, the ICO's International Data Transfer Addendum to those clauses).
1. Roles of the parties
- The Customer is the controller of the Personal Data described in Section 3 (or, where the Customer is itself a processor for another controller, the Customer warrants that it has the controller's authorization for this DPA and its instructions).
- Aptbyte Ventures is the processor, processing that Personal Data only on the Customer's behalf and documented instructions as described in this DPA.
- For clarity: Rewind acts as an independent controller (not the Customer's processor) for its own account administration, billing, and service telemetry as described in the Privacy Policy; that processing is outside the scope of this DPA.
2. Subject-matter, duration, nature, and purpose of processing
| Subject-matter | Provision of the Rewind service to the Customer's organization: seat and member management, licence validation, Kiosk/Exam-mode submission delivery, and opt-in bug-report handling. |
|---|---|
| Duration | The term of the Agreement, plus the deletion period in Section 10. |
| Nature | Collection (only for the limited categories below), storage, transmission,
retrieval, and deletion. Rewind's design is local-first: spreadsheet session recordings
(.rewind files) are built and stored on end users' devices and are
not transmitted to Rewind, except the two upload paths in Section
3. |
| Purpose | Operating the service for the Customer as described in the Agreement — no other purpose. Rewind does not use Customer Personal Data for advertising or to train machine-learning models. |
3. Categories of data and data subjects
3.1 Data subjects
- The Customer's members and seat holders (employees, contractors, students, exam participants) who use Rewind under the Customer's plan.
- The Customer's administrators.
3.2 Categories of Personal Data
| Category | Details |
|---|---|
| Account identifiers | Email address; organization membership, role, and seat assignment; subscription tier. |
| Usage metadata | Event counts, durations, boolean flags, and short feature labels — schema-constrained at the database; never spreadsheet cell contents, note text, or file names. |
| Kiosk/Exam submissions | Session recordings uploaded when the Customer runs an exam: cell-edit timeline, notes, and where enabled by the Customer, audio/video and a workbook snapshot. Uploaded solely for delivery to and review by the Customer. |
| Bug-report attachments | Optional, per-report, opt-in uploads of a
.rewind file and/or workbook by an individual user, solely to investigate the
reported issue. |
No special categories of data (Art. 9 GDPR) are required by the service. If the Customer's exam recordings incidentally capture such data (e.g., in audio/video), the Customer is responsible for its instructions and lawful basis for that content.
4. Processor obligations (Art. 28(3) GDPR)
Rewind will:
- Documented instructions. Process Personal Data only on the Customer's documented instructions (including this DPA, the Agreement, and the Customer's use of administrative controls in the product), including with regard to international transfers, unless required to do otherwise by law to which Rewind is subject — in which case Rewind will inform the Customer of that legal requirement before processing, unless the law prohibits it. Rewind will inform the Customer if, in its opinion, an instruction infringes the GDPR.
- Confidentiality. Ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Security. Implement the technical and organizational measures in Section 5 (Art. 32 GDPR).
- Sub-processors. Engage sub-processors only as permitted by Section 6.
- Data-subject requests. Assist the Customer as described in Section 7.
- Breach notification, DPIA assistance. Assist the Customer as described in Sections 8 and 9 (Arts. 32–36 GDPR), taking into account the nature of the processing and the information available to Rewind.
- Deletion or return. At the Customer's choice, delete or return Personal Data at the end of the engagement as described in Section 10.
- Audit. Make available the information necessary to demonstrate compliance, and allow for and contribute to audits, as described in Section 11.
5. Security measures (Art. 32 GDPR)
Technical and organizational measures actually implemented in the service:
- Local-first architecture / data minimization by design. Session recordings are built and stored on the end user's device; there is no ingest endpoint for ordinary session content. Only the two upload paths in Section 3 transmit recording content to Rewind's systems.
- Encryption in transit. All communication between clients and Rewind's systems uses TLS (HTTPS).
- Zero-knowledge encryption at rest for session files (Team/Enterprise).
Where enabled,
.rewindfiles are encrypted client-side with AES-256-GCM using keys controlled by the Customer or its users; Rewind cannot decrypt, recover, or reset them. - Row-level security and least privilege. Database access is governed by row-level security policies scoping each user and organization to its own data; privileged administrative functions are execution-restricted.
- Schema-bounded telemetry. Usage metadata is constrained at the database to an allowed event vocabulary and size cap, preventing spreadsheet content from entering telemetry.
- Operable erasure. Account deletion is implemented as a single
transactional routine (
user_delete()) that removes the user's rows across all user-keyed tables and the authentication record. - Payment data delegation. Card data is handled by Stripe's hosted checkout; Rewind never receives full card numbers.
Rewind may update these measures from time to time provided the updates do not materially reduce the overall level of protection.
6. Sub-processors
The Customer grants Rewind general written authorization to engage the sub-processors listed below.
| Sub-processor | Purpose | Location / notes |
|---|---|---|
| Supabase, Inc. | Database, authentication, file storage, serverless functions | [PLACEHOLDER — hosting region; verify project region in the Supabase dashboard] |
| Cloudflare, Inc. | Web hosting and content delivery | Global edge network (United States company) |
| Resend, Inc. | Transactional email (sign-in codes, service notices) | United States [PLACEHOLDER — confirm whether EU-region sending is enabled] |
| Stripe, Inc. | Payment processing | United States; Stripe acts largely as an independent controller for payment data under its own terms |
| Razorpay Software Pvt. Ltd. (planned) | Payment processing for customers in India | India — not yet engaged; will be added to this list with notice under this Section before use |
- Change notification. Rewind will notify the Customer (by email to the organization administrator, or by updating this page with an in-product or email notice) at least 30 days before adding or replacing a sub-processor.
- Right to object. The Customer may object on reasonable data-protection grounds within that notice period. If the objection cannot be resolved, the Customer may terminate the affected services and receive a pro-rata refund of prepaid fees for the unused period.
- Flow-down. Rewind will impose data-protection obligations on each sub-processor materially equivalent to those in this DPA, and remains liable to the Customer for its sub-processors' performance.
7. Data-subject requests
- Taking into account the nature of the processing, Rewind will assist the Customer with appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer's obligation to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection — Arts. 12–23 GDPR).
- Much of this is self-serve: administrators can manage members and seats in the team
console, and erasure of an individual account is available via the account console or on
request (implemented by the
user_delete()routine described in Section 5). - If a data subject contacts Rewind directly about processing under this DPA, Rewind will promptly forward the request to the Customer and will not respond substantively except as instructed by the Customer or required by law.
8. Personal data breach notification
- Rewind will notify the Customer without undue delay after becoming aware of a personal data breach affecting Personal Data processed under this DPA, and in any event within [PLACEHOLDER — contractual notice window, e.g. 72 hours; align with the incident-response runbook in OPS.md] of becoming aware.
- The notification will describe, to the extent then known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information may be provided in phases as the investigation progresses.
- Rewind will document breaches and cooperate with the Customer's own notification obligations to supervisory authorities and data subjects (Arts. 33–34 GDPR). Rewind's notification is not an admission of fault.
9. DPIA and prior-consultation assistance
Rewind will provide reasonable assistance to the Customer with data protection impact assessments and prior consultation with supervisory authorities (Arts. 35–36 GDPR), to the extent the assistance relates to processing by Rewind and the information is available to Rewind. This page, the Privacy Policy, and Rewind's security documentation are intended to satisfy most such requests.
10. Deletion and return on termination
- On termination or expiry of the Agreement, at the Customer's choice, Rewind will delete or return all Personal Data processed under this DPA, and delete existing copies, unless law requires longer storage.
- Deletion of individual accounts is implemented by the transactional
user_delete()routine (Section 5), which removes the user's data across all service tables. Kiosk/Exam submissions and bug-report attachments held in storage are deleted on request and in any event per the retention periods stated in the Privacy Policy. - Session files stored locally on end users' devices are outside Rewind's possession and control and are unaffected by termination; the Customer is responsible for its own devices and files.
- Where zero-knowledge encryption is in use, destroying the Customer-held keys renders the corresponding files permanently unreadable, which the parties agree is an acceptable deletion method for those files.
11. Audits
- Rewind will make available to the Customer information reasonably necessary to demonstrate compliance with Art. 28 GDPR, including this DPA, its sub-processor list, security documentation, and summaries of any third-party assessments Rewind holds.
- Where that information is insufficient to meet a legal requirement, the Customer (or an independent auditor mandated by it, not a competitor of Rewind) may conduct an audit of Rewind's relevant processing, no more than once per 12 months (except after a personal data breach or where required by a supervisory authority), on at least 30 days' written notice, during business hours, without disrupting the service, under confidentiality, and at the Customer's expense.
- Audits of sub-processor infrastructure (e.g., Supabase, Cloudflare data centres) are satisfied by the audit reports and certifications those providers make available.
12. International transfers
- India, where Aptbyte Ventures is established, is not the subject of a European Commission adequacy decision. Where Personal Data subject to the GDPR or UK GDPR is transferred to Rewind in India, or onward to a sub-processor in a country without an adequacy decision, the parties rely on the SCCs as the transfer mechanism: Module Two (controller-to-processor) between the Customer and Rewind, and Module Three (processor-to-processor) between Rewind and its sub-processors, which are incorporated by reference into this DPA. For UK transfers, the ICO's International Data Transfer Addendum applies. Rewind does not claim certification under the EU–U.S. Data Privacy Framework.
- Annex I of the SCCs is completed by Sections 2, 3, and 6 of this DPA; Annex II by Section 5. [PLACEHOLDER — counsel to confirm SCC module selection, optional clauses (docking, governing law of the SCCs), and the competent supervisory authority.]
- Sub-processors that are U.S. companies (Section 6) execute their own SCC-based transfer terms as part of their standard DPAs, which Rewind maintains on file.
13. Liability
Each party's liability arising out of or related to this DPA is subject to the exclusions and limitations of liability in the Terms of Service (Section 12 of the Terms), except to the extent liability cannot be limited under applicable data-protection law (including Art. 82 GDPR as between the parties and data subjects).
14. Representative, contact, and general
- EU representative (Art. 27 GDPR): [PLACEHOLDER — name and contact details of the appointed EU representative; a UK representative may additionally be required under UK GDPR Art. 27].
- Privacy contact: [email protected].
- Governing law and forum: as set out in the Terms of Service [PLACEHOLDER — dispute-resolution seat; Delhi, India per the Terms — counsel to confirm interaction with the SCCs' governing-law clause, which must be the law of an EU member state for transfers they govern].
- If any provision of this DPA is found unenforceable, the remainder stays in effect. This DPA terminates automatically when Rewind ceases all processing of the Customer's Personal Data.
Rewind is an independent product and is not affiliated with, endorsed by, or sponsored by Microsoft Corporation or Google LLC. Microsoft and Excel are trademarks of the Microsoft group of companies. Google Sheets and Google Workspace are trademarks of Google LLC. General contact: [email protected].