October 1, 2026
This Data Processing Addendum (“DPA”) is entered into between the Host, as defined in the Agreement (“Customer”) and Bending Spoons US Inc. (“Bending Spoons” or “Processor”). The Customer and the Processor may be referred to herein individually as the “Party” and collectively as the “Parties”.
Whereas:
- The Customer and Bending Spoons Operations S.p.A. entered into an agreement (the “Agreement”), according to which the latter will provide services to the Customer (“Services”).
- To provide the Services, Bending Spoons will process certain personal data in the capacity of a data processor on behalf of the Customer. Bending Spoons Operations S.p.A., in turn, will act as a sub-processor, processing personal data under the instructions of Bending Spoons and for the sole purpose of executing the Agreement.
The Parties agree that Sections 2 to 10 of this DPA apply to any processing of Personal Data carried out by Bending Spoons as data processor. The processing activities and personal data processed by the Processor on behalf of the Customer are described in Annex I of this DPA (“Description of Processing”).
- The Parties agree that Section 11 of this DPA applies for the processing operations carried out by Bending Spoons in its role as autonomous controller and for its own purposes (as better described in Section 11 of this DPA).
- The Parties enter into this DPA, which is hereby incorporated into the Agreement, in order to ensure that they comply with Applicable Privacy Law and establish safeguards and procedures for the lawful processing of personal data.
Therefore, the Parties agree as follows:
- Definitions
When used in this DPA, the following terms have the following meanings.
- “Adequacy Decision” means a legally binding decision issued by the European Commission, allowing the transfer of Personal Data from the EEA to a third country that has been considered adequate in terms of data protection safeguards.
- “Agreement” as defined in recital A.
- “Applicable Privacy Law” means all applicable data protection laws and regulations, including but not limited to Regulation (EU) 2016/679 (“GDPR”) and the California Consumer Privacy Act at Cal. Civ. Code § 1798.100 et seq., as amended, and its implementing regulations (“CCPA”).
- “Data Subject” means an identified or identifiable natural person to which the Personal Data pertains.
- “Data Subjects’ Rights” means the rights which Data Subjects are entitled to under the Applicable Privacy Law, including but not limited to the right to request access to, rectification or erasure of Personal Data, to request the restriction of Processing concerning the Data Subject or to object to Processing, as well as the right to data portability.
- “EEA” means the European Economic Area.
- “Personal Data” means personal data that the Processor processes on behalf of the Customer to provide the Services.
- “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
- “Processing” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- “Services” means the services and activities regulated by the Agreement.
- “Standard Contractual Clauses” means the standard contractual clauses adopted by the European Commission under Commission Implementing Decision (EU) 2021/914 of 4 June 2021, on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, and available at the following link: https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32021D0914&from=EN.
- “Sub-processor” means an entity engaged by the Processor to assist it in (or who undertakes any) processing of Personal Data in the performance of the Processor’s obligations pursuant to the DPA.
- “Transfer Mechanisms” means an Adequacy Decision issued by the European Commission allowing the transfer of personal data from the EEA to a third country whose domestic law provides an adequate level of protection of personal data. Where such Adequacy Decision is not available or effective, this definition means the Standard Contractual Clauses, as well as binding corporate rules (BCRs) approved by a competent Supervisory Authority.
-
Obligations of the Customer
- The Customer agrees that in order for the Processor to provide the Service, the Customer shall provide the Processor with Personal Data.
- The Customer is responsible for assessing and ensuring that the processing of Personal Data is legitimate and in compliance with Applicable Privacy Law.
- The Customer represents and warrants that it has an appropriate legal basis to process and disclose Personal Data to the Processor.
- The Customer represents and warrants it fully complies with Applicable Privacy Law, indemnifying the Processor against all damages, costs and losses incurred as a result of any breach by the Customer of the provisions of Applicable Privacy Law.
- It’s the Customer’s responsibility to provide written instructions to the Processor. The Customer warrants that any instructions it provides are in accordance with the Applicable Privacy Law. Verbal instructions issued by the Customer to the Processor must be confirmed in writing without delay, but in any case no later than five (5) working days after providing the verbal instructions.
- Obligations of the Processor
The Processor agrees to:
- Ensure the confidentiality of the Personal Data that it learns or becomes aware of in the performance of the Services or the Agreement and to comply with the instructions given by the Customer.
- Process Personal Data only in accordance with the instructions of the Customer, unless required by law to do otherwise.
- Except as otherwise expressly permitted by Applicable Privacy Law, not retain, use, disclose, or otherwise process Personal Data for any purpose other than those specified in the Agreement or this DPA.
- Limit Personal Data collection, use, retention, and disclosure to activities reasonably necessary and proportionate to achieve the processing set out in this DPA and the Agreement and not process the Personal Data in a manner incompatible with those purposes.
- To the extent the CCPA applies to the processing of Personal Data, unless otherwise permitted by Applicable Privacy Law, the Processor shall not: (i) “sell” or “share” Personal Data within the meaning of the CCPA; and (ii) retain, use, or disclose Personal Data (a) for any purpose other than to perform, support, and improve the Service, or (b) outside of the direct business relationship between the Processor and the Customer. The Processor shall notify the Customer if the Processor determines that it can no longer meet its obligations under the CCPA.
- In accordance with Applicable Privacy Law, implement adequate operational, technical and organisational measures to ensure the confidentiality, integrity, and availability of Personal Data and to eliminate or, in any case, to minimize any risk of destruction or loss of data, whether or not accidental, and of unauthorized or non-compliant processing, taking into account (1) the current state of the art and technical progress, (2) the risks associated with the data processed, and (3) the nature of the data. The Processor has adopted at least the measures described in the Security Overview page, available at the following link: https://support.streamyard.com/hc/en-us/articles/18795807558164-Security-Overview-Technical-and-Organizational-Measures.
- Cooperate with and assist the Customer in ensuring its compliance with its obligations under Applicable Privacy Law, including but not limited to assisting with data protection impact assessments, audits, and consultations with regulatory bodies, taking into account the nature of the processing and the information available to the Processor.
- Identify in writing the personnel authorized to process Personal Data and to provide them with instructions on the operations to perform in compliance with Processor’s obligations under this DPA, ensuring that the instructions given are duly observed, and the authorized personnel are under an appropriate obligation of confidentiality.
- Cooperate in good faith with the Customer to ensure compliance with this DPA, assist the Customer in complying with its obligations under the Applicable Privacy Law, and make available to the Customer all information necessary to demonstrate compliance with the Applicable Privacy Law.
- Notify the Customer, unless legally prohibited from doing so, after having become aware of any communication with the relevant Supervisory Authority, courts, law enforcement authorities, or other public authorities in relation to the processing of Personal Data regulated by this DPA.
- Immediately inform the Customer when, in the Processor’s opinion, an instruction received from the Customer violates the Applicable Privacy Law.
- Assist the Customer with appropriate technical and organizational measures to comply with all Data Subjects’ Rights requests that the Customer may receive, pursuant to Section 6 of this DPA.
- Appoint a data protection officer, where required by the Applicable Privacy Law.
-
Authorization for Sub-processing
- The Customer acknowledges, agrees and consents that, for the sole and exclusive purpose of providing the Services and subject always to compliance with the terms of this DPA, Personal Data may be processed by the Processor and its Sub-processors.
- The Customer hereby authorizes the Processor to engage Sub-processors subject to the conditions that the Processor:
- enters into a written agreement with the Sub-processor containing the same obligations as set out in this DPA or, in any case, ensures that the Sub-processor offers no fewer guarantees than those offered by the Processor in this DPA;
- assesses the Sub-processor and remains liable for the actions or omissions of the Sub-processor with regard to its obligations under this DPA.
- The Processors maintains a list of the Sub-processors in its Subprocessors page available at the following link: https://support.streamyard.com/hc/en-us/articles/52721830281236-Subprocessors. The Customer may subscribe to receive update when changes are made to the Sub-processors list.
- The Customer may reasonably object to the use of a new Sub-processor on legitimate grounds, subject to the termination and liability clauses of the Agreement. The Customer acknowledges that the Sub-processors are essential for the provision of the Services and that objecting to the use of a Sub-processor may prevent the Processor from offering the Services to the Customer.
-
Transfers of Personal Data
- Where the Customer is located in the EEA and the provision of the Services entails the transfer of Personal Data from the EEA, the Parties agree that the Standard Contractual Clauses are incorporated into this DPA by reference and will apply to those transfers.
- To the extent that the Standard Contractual Clauses apply between the Customer and the Processor, the Parties agree upon the following:
- only the clauses of the Standard Contractual Clauses under MODULE TWO will apply;
- Clause 7 of the Standard Contractual Clauses is not applicable;
- under Clause 9(a) of the Standard Contractual Clauses, Option 2 is applicable, under the terms of Section 4 of this DPA;
- the optional clause under Clause 11(a) of the Standard Contractual Clauses is not applicable;
- under Clause 17 of the Standard Contractual Clauses, Option 1 is applicable. The laws of Italy will apply;
- under Clause 18(b) of the Standard Contractual Clauses, the courts of Milan, Italy will apply;
- Annex 1 of the Standard Contractual Clauses shall be deemed completed with the information included in Annex 1 of this DPA;
- Annex 2 of the Standard Contractual Clauses shall be deemed completed with the information included in Clause 3.6 of this DPA;
- Annex 3 of the Standard Contractual Clauses shall be deemed completed with the information included in Clause 4.3 of this DPA.
- Where the Processor carries out a transfer of Personal Data to a third country, including in cases where the Processor engages a Sub-processor located outside the EEA, the Processor shall ensure that an appropriate Transfer Mechanism is implemented, including, where applicable, an Adequacy Decision or the Standard Contractual Clauses.
-
Data Subjects’ Rights
- Taking into account the nature of the processing, the Processor will assist the Customer in the fulfilment of Customer’s obligations, under Applicable Privacy Law, to respond to requests to exercise Data Subjects’ Rights, by means of appropriate technical and organizational measures.
- The Processor will cooperate with and assist the Customer in responding to Data Subjects’ Rights requests in a timely and lawful manner, and provide such information as may reasonably be required to respond to Data Subjects’ Rights, or otherwise to enable the Customer to comply with its duties related to Data Subjects' Rights under Applicable Privacy Law.
- In the event the Processor receives a request directly from a Data Subject relating to Personal Data, the Processor will immediately notify the Customer, and at the Customer’s direction, act on behalf of the Customer in accordance with the Customer’s instructions for responding to such requests.
-
Right to audit
- At the Customer’s written request, the Processor will provide the Customer with all the relevant and reasonable information in the form of documentation to demonstrate Processor’s compliance with its obligations set forth in this DPA.
- Should the Customer show that the documents and information provided do not sufficiently demonstrate Processor’s compliance, Processor will allow for and contribute to an audit conducted by the Customer by making available to the Customer additional documents and information reasonably requested that demonstrates Processor’s compliance with its obligations set forth in this DPA.
- An audit shall be performed during Processor’s normal working days and normal working hours, no more than once per year or if requested by a relevant authority, subject to notice given thirty (30) days in advance. The Customer shall ensure minimal disruption to the business of the Processor. Upon the Processor's request, the Customer shall provide a copy of the audit report to the Processor.
- Any information gathered on Processor’s activities will be subject to a specific confidentiality agreement between the Parties.
- The Customer shall bear the full costs of any audit that is requested, including any costs in time and resources made by the Processor due to the request.
- The Customer shall ensure that the auditor is bound by confidentiality obligations, and that the audit is conducted in a manner that does not compromise the security or confidentiality of the personal data of the Processor or of its other customers.
-
Personal Data Breach
- Upon receiving knowledge of a Personal Data breach of Customer’s Personal Data, the Processor will notify Customer without undue delay.
- With respect to each Personal Data breach, the Processor shall provide all assistance to the Customer that can reasonably be expected by the Processor, including the provision of adequate information regarding the breach, inquiries from authorities, limiting the impact of the breach and Customer’s damage as a result of the breach.
- The Processor shall promptly adopt adequate corrective measures to remedy a Personal Data breach and shall cooperate with the Customer to develop and implement an action plan to address the Personal Data breach in accordance with Applicable Privacy Law.
-
Liability and Indemnity
- In the event of a breach of this DPA by the Processor, the Customer will be entitled to withdraw from the Agreement at no cost and without penalties, unless the Processor adopts the corrective measures required by the Customer within thirty (30) days from receipt of a notice to that effect.
- The liability of each Party under this DPA shall be subject to, and shall not exceed, the limitations and exclusions of liability set out in the Agreement.
- The Customer shall defend, indemnify and hold harmless the Processor (including its employees and affiliates) from and against any claims, incidents, liabilities, procedures, damages, losses and expenses (including legal fees), arising out of or in any way connected with Customer’s access to or use of the Services or Customer’s breach of this DPA.
-
Return and Deletion of Personal Data
- The Processor will retain audio-visual content according to conditions mentioned in the plan selected by the Customer, as detailed at this link, except to the extent that the Agreement or applicable laws state otherwise.
- Save for previous Section 10.1, three years after the last use of the Services or the expiration of the subscription, as defined in the Agreement, whichever occurs later, the Processor shall delete the Personal Data, except to the extent that the Agreement or applicable laws state otherwise. Upon the Customer's request, the Processor shall offer a means for the Customer to retrieve the Personal Data prior to such deletion.
- The Customer shall reimburse the Processor for any additional costs arising from the return of the Personal Data.
- Further processing carried out by Bending Spoons as Autonomous Data Controller
11.1. The Customer authorizes Bending Spoons to process Personal Data involved in the Services for the following autonomous further purposes: (1) establish, exercise, or defend rights of Bending Spoons and its affiliates, including proving the correct execution of the Service, (2) comply with legal or regulatory obligations applicable to the processing and retention of data to which Bending Spoons is subject, (3) ensure and improve the quality and the proper functioning of the Service, including by analyzing, preventing or correcting failures and bugs, as well as the illicit use or misuse of the Services, and (4) enforce the Agreement and enhance the safety and integrity of the Services.
11.2 For any communication and request regarding the processing operations carried out according to this Section, Bending Spoons can be reached at the following address privacy-streamyard@bendingspoons.com.
11.3. When Section 11.1. applies, the Customer and Bending Spoons undertake to process the Personal Data in accordance with Applicable Privacy Law.
-
Miscellaneous
- All communications relating to this DPA and privacy matters, directed to the Processor, must be addressed to the contacts specified in Annex I of this DPA. All communications related to this DPA and privacy matters, directed to the Customer, must be addressed to the email address provided by the Customer during the subscription to the Agreement. Each Party will notify the other of any update in its contact details.
- This DPA will remain in effect for the term of the Agreement and, in any event, during the performance of the Service, in which case it will terminate upon completion of the Service, subject to Section 10 (Return and Deletion of Personal Data).
- Any obligations under this DPA that by their nature are intended to survive after termination of the Agreement will continue to apply after termination.
- Deviations from and additions to this Agreement are only valid if agreed explicitly and in writing.
- All provisions in this DPA are an integral part of the general relationship between the Customer and the Processor. The performance of this DPA will not result in the recognition of any specific consideration, remuneration, indemnification, compensation or reimbursement in favor of the Processor in addition to that established in the Agreement.
- In the event of a conflict between the terms of this DPA and the Agreement, this DPA will prevail.
ANNEX I - Description of Processing
ANNEX I - Description of Processing
A. LIST OF PARTIES
Data exporter(s): Customer
Name: As provided by the Customer when entering into the Agreement.
Address: As provided by the Customer when entering into the Agreement.
Contact person: As provided by the Customer when entering into the Agreement.
Activities relevant to the data transferred under these Clauses: As described in Section B below
Role (controller/processor): controller
Data importer(s):
Name: Bending Spoons US Inc.
Address: 169 Madison Ave, Suite 11218, New York, NY 10016
Contact person: Privacy Team at privacy-streamyard@bendingspoons.com
Activities relevant to the data transferred under these Clauses: As described in Section B below
Role (controller/processor): processor
B. DESCRIPTION OF PROCESSING AND TRANSFER
Categories of data subjects whose personal data is transferred
Data subjects mentioned or represented in the audio-visual content, chat, and messages of the Customer during the use of the Services.
Viewers of the audio-visual content.
Categories of personal data transferred
Audio-visual content, chats, and messages. Viewers' information.
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures
N/A as under the Agreement the Customer cannot provide any Sensitive data.
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis)
On a continuous basis through the use of the Services.
Nature of the processing
The Processor will process the Personal Data only for the purpose of providing the Services to the Customer.
Purpose(s) of the data transfer and further processing:
Provision of the Services.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
Audio-visual content will be retained according to conditions mentioned in the plan selected by the Customer, as detailed at this link, except to the extent that the Agreement or applicable laws state otherwise.
The other Personal Data will be retained as long as the Customer remains active, and for 3 years after that moment, except to the extent that the Agreement or Applicable Privacy Law states otherwise. The Customer can delete the content at any time.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing
Sub-processors are employed to receive support for the provision of the Services.
C. COMPETENT SUPERVISORY AUTHORITY
The competent supervisory authority in accordance with Clause 13 of the Standard Contractual Clauses is the Italian Garante per la protezione dei dati personali.