Data processing agreement
Data processing agreement
Last updated: 6 August 2026
Purpose
When you use Launchr to develop and deliver campaigns, you may upload personal data. That can be contact details in briefs and contact lists (names, email addresses, phone numbers), and it can be personal data in the material itself, for example voices in audio recordings and identifiable people in images and video. In that situation you are the data controller for that personal data, and Launchr ApS is the data processor.
This data processing agreement (DPA) governs the processing of personal data you upload to Launchr, in accordance with GDPR article 28.
Parties
- Data controller: your company (as a registered user of Launchr)
- Data processor: Launchr ApS, CVR 46553837, Kaprifolievej 12, 8600 Silkeborg, Denmark
Nature and purpose of the processing
We process the personal data you upload solely in order to deliver the Service, including:
- development of campaign material with AI services (text, images, film, audio and voices);
- preparation and delivery of campaign material to broadcasters and media owners;
- communication with receiving stations on your behalf;
- audit trails on deliveries for your documentation;
- support for you in connection with the Service.
Sub-processors
We use the sub-processors below to deliver the Service. The list is complete and split into two groups: AI services that can receive your material, and infrastructure. Transfers to countries outside the EU/EEA take place on the basis of the European Commission's Standard Contractual Clauses (SCC, 2021/914), unless the country has an adequacy decision. Statements about training and retention are based on the supplier's published terms; where a term is awaiting written confirmation from the supplier, that is stated explicitly.
AI services that can receive your material
- Anthropic (Claude: text processing, spec parsing, scripts, classification): USA, SCC. Receives text, for example briefs and scripts. According to Anthropic's commercial terms, API data is not used for training; input and output are as a rule deleted within 30 days, and a zero-retention agreement can be entered into.
- Google (Vertex AI: Gemini, Nano Banana, Veo) (storyboard images and film generation): USA, SCC under Google Cloud's data processing terms. Receives images, prompts and reference material. According to its published terms, Google Cloud does not use customer data to train foundation models. EU data residency and zero retention are available for selected services; film generation (Veo) runs in a US region.
- OpenAI (GPT Image: image generation and editing, in particular images with text): USA, SCC under OpenAI's data processing addendum. By default, API data is not used for training; input and output are deleted no later than 30 days after processing.
- ElevenLabs (voice synthesis: voiceover and narration): USA, SCC. Receives script text and audio recordings and generates speech; according to the supplier's terms it is not used for training. Zero Retention Mode and EU data residency are available.
- fal.ai (video generation through hosted models, including Kling): USA, SCC under the supplier's data processing addendum. Receives images and prompts for video generation. The supplier's terms on training and retention for API use, including the terms of the underlying model providers, are awaiting written confirmation; the status is provided on request.
- Cleanvoice (Sigmoid Creativity SRL: audio cleanup, for example filler words and mouth sounds): Romania, EU company. According to the supplier's published data processing agreement, processing and storage take place with sub-suppliers located in the EU/EEA (including Hetzner and DigitalOcean in Germany). Uploaded files are deleted no later than 7 days after processing.
- Auphonic (audio mastering and loudness): Austria, EU. Processing on servers in Germany (Hetzner) plus EU-based file storage. Audio files are deleted automatically after no more than 21 days, API productions after 7 days. A data processing agreement is entered into with the supplier.
- Vectorizer.AI (Cedar Lake Ventures: conversion of logo files to vector graphics): USA. Receives logo and graphics files only, which typically contain no personal data. The supplier's terms on retention and data use are awaiting written clarification; until then we send nothing but logo and graphics material to the service.
- Recraft (generation of graphics and icons in a locked style): USA. Receives graphics material and prompts, typically without personal data. According to the supplier's published terms, API input and output are not used for training; data processing terms (SCC) are awaiting written confirmation.
- Google Maps Platform (Geocoding + Street View, Production location feature only): USA, SCC. Only address strings are sent; no personal data.
Stem separation (separating voice and music) runs on our own audio worker at Fly.io in Stockholm and involves no external AI supplier.
Infrastructure
- Clerk (user management + organizations): USA, SCC + EU data residency for session data
- Supabase (PostgreSQL database): Switzerland (Zurich), a country with an EU adequacy decision
- Cloudflare R2 (file storage): EU region (encryption at rest)
- Resend (transactional email + inbound): EU region for the mail infrastructure; US company, SCC
- Fly.io (video and audio transcoding + audio worker): Sweden (Stockholm), EU region; US company, SCC
- Vercel (Next.js hosting + serverless compute): functions in the EU (Stockholm/arn1) + global edge cache; US company, SCC
- Amazon Web Services (AWS) (Remotion Lambda, parallel film rendering): EU region (Frankfurt/Stockholm). Processes render input only; no persistent storage.
- Inngest (job orchestration for transcoding + watchdog): USA, SCC. Processes job metadata, not the material itself.
- Twilio (SMS to suppliers + phone login with a one-time code, Production only): USA, SCC. Phone numbers + message text.
- Sentry (error monitoring): EU region (sentry.io). May receive error stacks and user ids on errors; no personal data stored persistently.
- Upstash (rate limiting on public login screens): planned, not yet in operation. Putting it into use is notified under the rules below.
Payments are processed by Stripe. Stripe is an independent data controller for card and payment data and therefore does not act as a sub-processor for the material you upload.
We notify you of changes to the list of sub-processors at least 30 days before they take effect, so that you can object.
Cross-border transfers (USA):transfers to sub-processors in the USA take place solely on the basis of the European Commission's Standard Contractual Clauses (SCC, 2021/914) and, for certain suppliers, additionally under the EU-US Data Privacy Framework. We have assessed each supplier's transfer mechanisms in a Transfer Impact Assessment (TIA), published at launchr.dk/en/legal/dpia.
Security measures
We have implemented technical and organizational measures corresponding to article 32 of the GDPR, including:
- Encryption in transit: TLS 1.2+ on all endpoints; HSTS preload listed.
- Encryption at rest: AES-256 at Supabase (database), Cloudflare R2 (files) and Clerk (sessions).
- Access control: Clerk-based organization membership with role-based access (owner/admin/member). Multi-factor login available.
- Multi-tenant isolation: every row in the database carries an
organization_id, and every query filters on the organization the session belongs to. The database can only be reached through the application: Supabase's Data API has no privileges on any table, neither foranonnor forauthenticated. An automated isolation check verifies the invariants as a fixed check on every pull request. - Audit log: every change at campaign level (creation, update, send, approve, delete) is logged in an append-only event stream with timestamp, user id and payload.
- Backup and recovery: Supabase takes point-in-time backups with a 7-day restore window. R2 is replicated across regions.
- Vulnerability handling: Dependabot opens weekly PRs for critical CVEs; npm audit runs as a CI gate.
- Security headers: CSP, HSTS (2 years), X-Frame-Options DENY, strict referrer policy, Permissions-Policy with restrictive defaults.
- API keys: hashed at rest (SHA-256); revealed once on creation. Can be revoked per key.
Impact assessment (DPIA)
We have prepared an impact assessment (DPIA) and a Transfer Impact Assessment for Launchr. Both are published at launchr.dk/en/legal/dpia and are updated as the architecture or the supplier list changes. The assessment is that the processing does not pose a high risk to the rights and freedoms of your data subjects, among other things because:
- the processing does not intentionally cover special categories of personal data (GDPR art. 9);
- no automated decision-making with legal effects takes place (GDPR art. 22);
- technical and organizational measures are in place (see above).
If you as data controller process special categories or carry out profiling using Launchr, you must assess for yourself whether a DPIA is required for your specific use. We assist with relevant documentation on request.
Personal data breaches
If we discover a personal data breach affecting your data, we notify you without undue delay (no later than 24 hours after discovery) with information about the nature and scope of the breach, its likely consequences and the mitigating measures taken.
Your rights as data controller
You have the right to:
- obtain access to information about our processing of your data;
- have your data handed over or deleted on termination;
- carry out, or have carried out, an audit of our technical and organizational measures.
Deletion on termination
On termination we close access to your data. Deletion or anonymization of personal data, including files in R2, takes place according to your instruction: either immediately on termination or after we have handed the data over to you. We confirm in writing once the deletion is done. We do not run automatic deletion jobs on a fixed deadline, so the deletion is carried out as a documented action rather than by a timer.
Governing law and venue
This agreement is governed by Danish law. Disputes are settled by Retten i Viborg (the District Court of Viborg) as the court of first instance.
Acceptance
By using Launchr, your company accepts this data processing agreement. If you need a separately signed agreement (for example because of internal compliance requirements), write to support@launchr.dk, and we will send it for signature through DocuSign or equivalent.