---
title: Data Processing Addendum | ReplayPilot
description: How ReplayPilot processes your end users’ data on your behalf, and the subprocessors involved.
canonical: https://replaypilot.com/policies/dpa
---

# Data Processing Addendum | ReplayPilot

DPA

# Data Processing Addendum

Last updated August 12, 2026

If GDPR, UK GDPR, or a similar law applies to the session data you collect through ReplayPilot, this page is the data processing addendum (DPA) that governs how we handle it on your behalf. It supplements, not replaces, our Privacy Policy.

## The short version

- For your end users' session data, you're the controller, and we're the processor: we only act on your instructions.
- We only use the subprocessors listed below, all of them chosen for the infrastructure they run, not for access to your data. (Alert integrations you turn on yourself, like Slack or a webhook, are your own choice, not ours; see "Subprocessors" below.)
- Cloudflare's own Standard Contractual Clauses cover cross-border transfers to the US, and flow down to you as our customer.
- This applies automatically to every account, so there's no separate document to sign.

## Roles

For the account data covered by our [Privacy Policy](/policies/privacy), meaning your name, email, and billing details, we're the controller. For the session data your own site sends us through our snippet, you're the controller (or, under some frameworks, the "business") and we're the processor (or "service provider"). We process that data only to provide the service, on your documented instructions, and for no other purpose.

## What we process, and how

The subject matter, duration, and nature of processing are exactly as described in our [Privacy Policy](/policies/privacy): clicks, page changes, form field names, console errors, and network requests captured by our recording snippet. We mask that data for passwords and card numbers before storage, and retain it for the period your plan specifies. The categories of data subjects are your site's own visitors and users.

## Subprocessors

We keep this list short on purpose, since every subprocessor here is infrastructure we run on, not a party we hand data to for their own use:
- Cloudflare: Workers, D1, R2, Vectorize, Workers AI, Email (for alert delivery), and Turnstile (for bot verification) host, store, and process session data. Cloudflare's own [Data Processing Addendum](https://www.cloudflare.com/cloudflare-customer-dpa/) is incorporated into our agreement with them automatically, as a self-serve customer with no separate signature required on our end, and it includes Standard Contractual Clauses covering data transferred out of the EU/UK.
- Paddle: acts as merchant of record for paid accounts, handling billing, payment processing, and tax collection, and doesn't touch session data.
- ReplayPilot: we also run our own product on replaypilot.com and inside our own dashboard, to monitor and improve the service. It's not an external service either. It runs on the same Cloudflare infrastructure listed above, against our own database, and anything it captures gets the same masking and protections described in this DPA.

We'll update this list if that ever changes, and update the date at the top when we do.

Separately, you might turn on an alert integration: Slack, Discord, GitHub, Linear, Jira, or a custom webhook. The destination you choose then receives the alert payload, which can include a session ID and page URL. That's a subprocessor of your own choosing, not ours. You pick the destination and control the connection, so it isn't on the list above.

## Security

Our security measures are described in full in the "How we protect it" section of our [Privacy Policy](/policies/privacy): encryption in transit, automatic masking before storage, and Cloudflare's own infrastructure-level protections.

## Breach notification

If we become aware of a breach affecting your end users' data, we'll notify you without undue delay. We'll tell you what we know at the time and what we're doing about it.

## Deletion and return

You can delete an individual session, a project, or your whole account at any time, self-serve, and the "How long we keep it" section of our [Privacy Policy](/policies/privacy) explains how that works today.

## Precedence and questions

If anything here conflicts with our [Terms of Service](/policies/terms) on how we handle your end users' data, this page governs. Questions about this addendum go to [privacy@replaypilot.com](mailto:privacy@replaypilot.com).

## Questions?

Email us and a real person will answer.[hello@replaypilot.com →](mailto:hello@replaypilot.com)