Data Processing Terms

The GDPR Article 28 terms under which RiverScript processes customer content as your processor.

Last updated: August 22, 2026

These Data Processing Terms ("DPT") apply when you use RiverScript in a professional, employment, or business capacity and the content you process through it contains personal data of other people — for example a recorded client meeting, an interview, or a lecture.

They apply automatically and nothing needs to be signed. They form part of the Terms of Service between you and Lex Valo (Business ID: 3617726-2), Finland ("RiverScript", "we", "us"). If you need a countersigned copy for your own records, email [email protected] and we will provide one.

Where these terms conflict with the Terms of Service or the Privacy Policy on the processing of Customer Content, these terms take precedence.


1. Definitions

Customer Content — the audio and video you upload or record through the Services, and the transcripts, translations, summaries, and AI outputs generated from it.

Controller, processor, personal data, processing, personal data breach, supervisory authority — as defined in the GDPR (Regulation (EU) 2016/679).

Data Protection Law — the GDPR and any national law implementing or supplementing it that applies to the processing, including the Finnish Data Protection Act (1050/2018), and the UK GDPR where relevant.


2. Roles

You are the controller of the personal data contained in Customer Content. We are your processor in respect of it.

You decide what to record, whom to record, why, and how long to keep it. We do not make any of those decisions and we have no independent purpose of our own for Customer Content.

For account data, billing data, security and anti-abuse data, and analytics we act as an independent controller. Our handling of that data is described in the Privacy Policy and is outside these terms.


3. Your instructions

We process Customer Content only on your documented instructions. Your instructions consist of:

  • the Terms of Service and these terms;
  • the operations you carry out in the Services — uploading, recording, transcribing, translating, summarizing, chatting with AI about a transcript, exporting, sharing, deleting;
  • any further written instruction we agree to.

We will tell you if, in our opinion, an instruction infringes Data Protection Law. We may decline to carry out an instruction that would require us to break the law.

If we are required by EU or member state law to process Customer Content beyond your instructions, we will inform you of that requirement before processing, unless the law prohibits us from doing so.

We will not use Customer Content for any purpose of our own. In particular, we will not use it to train, fine-tune, evaluate, or benchmark any model, and we will not sell it, share it for marketing, or use it for advertising or profiling. This is a binding commitment and not a policy we can change unilaterally for content already processed.


4. Confidentiality

Access to Customer Content is limited to the person who operates RiverScript, and only in the narrow circumstances set out in the "What We Never Do With Your Content" section of the Privacy Policy: at your request, to diagnose a technical fault that cannot be diagnosed otherwise, or where we receive a substantiated report of illegal content or a breach of the Terms of Service, or where the law requires it.

Everyone with such access is bound by an obligation of confidentiality.


5. Security

We implement appropriate technical and organizational measures under Article 32 GDPR. They are described in Annex 2 below and on the Security page.

We keep those measures under review and may update them, provided the level of protection is not reduced.


6. Subprocessors

You give us general authorization to engage subprocessors. The current list, including what each one processes and where it is located, is on the Subprocessors page.

Before a new subprocessor starts processing Customer Content, we will update that page and notify customers who have asked to be notified. You may object on reasonable data protection grounds within 30 days of the notice. If you do, we will work with you to find an alternative. If no reasonable alternative is available, you may terminate the affected part of the Services and we will refund any amount you have prepaid for the unused period.

We impose data protection obligations on each subprocessor that are no less protective than these terms, and we remain fully liable to you for their performance.


7. Assisting you with data subject requests

The Services give you direct control over Customer Content: you can view, edit, export in common machine-readable formats, and delete transcripts yourself at any time, and delete all of your content at once from Settings → Privacy. In most cases this is all that is needed to answer a request for access, correction, erasure, or portability.

If someone exercising their rights contacts us directly about content that belongs to you, we will not respond to it substantively. We will pass the request on to you where we can identify the relevant account, and act on your instructions.

Where you still need help, we will provide reasonable assistance, taking into account the nature of the processing and the information available to us.


8. Personal data breaches

If we become aware of a personal data breach affecting Customer Content, we will notify you without undue delay at the email address on your account, and provide the information available to us: what happened, which data and how many people are likely affected, the likely consequences, and the measures we have taken or propose to take.

We will assist you, to the extent reasonable, in meeting your own notification obligations under Articles 33 and 34 GDPR.


9. Data protection impact assessments

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority under Articles 35 and 36 GDPR. The Privacy Policy, the Security page, the Subprocessors page, and Annex 1 below are intended to give you most of what such an assessment requires.


10. Deletion and return

  • Audio and video submitted to us is automatically and permanently deleted 7 days after upload. This happens regardless of your account status and cannot be extended.
  • Transcripts and derived output remain available to you until you delete them. You can delete any item, or all of your content, yourself at any time.
  • On termination, you may export your content before you close the account. When you delete your account, your content is deleted with it.
  • Backups. Deleted data may persist in our database backups for up to 7 days, after which it rolls out of the backup cycle. Backup copies are not accessible in the ordinary running of the service and are not used for any other purpose.

At your written request we will confirm in writing that deletion has taken place.


11. Information and audits

On request, we will make available the information necessary to demonstrate compliance with Article 28 GDPR, which for a service of this size normally means the documentation published on this site plus written answers to your questions.

Where that is genuinely not sufficient, we will contribute to an audit or inspection carried out by you or an auditor you appoint, on the following basis: no more than once in any 12-month period unless a supervisory authority requires otherwise or a personal data breach has occurred; at least 30 days' written notice; remote and documentary wherever possible; limited to information relevant to the processing of your Customer Content; conducted so as not to disrupt the Services; subject to confidentiality; and at your cost beyond a reasonable level of effort on our side.


12. International transfers

Our core infrastructure — servers, database, and transcript storage — is located in the European Union (Finland). Some subprocessors are located outside the EU/EEA, as identified on the Subprocessors page.

Transfers outside the EU/EEA take place under the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), or under the EU-US Data Privacy Framework where the provider is certified. Where the Standard Contractual Clauses apply, Module Three (processor to processor) applies to transfers we make as your processor, and the descriptions in Annex 1 and Annex 2 below serve as the corresponding annexes.


13. Your responsibilities as controller

You are responsible for:

  • establishing a valid legal basis for recording and processing the material you put into the Services, including any consent required from the people appearing in it;
  • complying with the rules on recording that apply where you are — see Recording Responsibly;
  • providing the information required by Articles 13 and 14 GDPR to the people whose personal data you process;
  • ensuring your instructions to us comply with Data Protection Law;
  • deciding how long to keep transcripts, and deleting what you no longer need;
  • deciding whether to share a transcript publicly, and with whom.

14. Term, changes, and governing law

These terms apply for as long as we process Customer Content for you, and survive termination for as long as any Customer Content remains.

We may update these terms to reflect changes in the Services or in the law. If a change materially reduces your rights, we will notify registered users by email before it takes effect.

These terms are governed by the laws of Finland. The GDPR applies as directly applicable EU law.

Questions: [email protected].


Annex 1: Details of the processing

Subject matter. Provision of audio and video transcription, translation, summarization, and related AI features.

Duration. For the term of your use of the Services, plus the retention periods in section 10.

Nature and purpose. Receiving, storing, converting, and transcribing audio and video; generating translations, summaries, and AI chat responses from the resulting text; storing the results in your account; delivering exports and shared links you request.

Types of personal data. Whatever is contained in the material you submit. Typically: voices and speech content, names, and anything the speakers say about themselves or others. Recordings may contain special categories of personal data if you choose to record such conversations; you are responsible for establishing an Article 9 condition where that is the case.

Categories of data subjects. The people who appear in, are mentioned in, or are otherwise identifiable from the material you submit — for example participants in a meeting, interviewees, speakers at a lecture, clients, colleagues, or patients.

Processing operations. Storage, format conversion, automated speech recognition, machine translation, text generation, indexing for your own search, export, deletion.

Frequency. Continuous, for as long as you use the Services.


Annex 2: Technical and organizational measures

Location. Servers, database, and transcripts are hosted in the European Union (Hetzner Cloud, Helsinki, Finland).

Encryption in transit. All communication between the web application or Desktop client and RiverScript is encrypted over HTTPS/TLS. Database connections are encrypted.

Storage of audio. Audio and video are stored on object storage reachable only through authenticated, time-limited URLs, and are automatically deleted 7 days after upload.

Access control. Production access is restricted to the person who operates the service. Within the application, content is accessible only to the account that owns it, or to a person holding a share link the account holder generated.

Data minimization by design. Source media is deleted on a fixed schedule rather than kept; analytics are anonymous or session-only; no advertising or tracking infrastructure exists in the product.

Resilience and restoration. The database is backed up continuously and can be restored to a point in time, so that access to data can be restored in a timely manner after an incident (Article 32(1)(c) GDPR).

Availability of your data to you. Self-service export in multiple formats, self-service deletion of individual items, of all content, or of the entire account.

Vulnerability handling. Security reports are received at [email protected] and triaged on receipt; see the Security page.

Subprocessor management. Each subprocessor is engaged under a data processing agreement, is permitted to process content only to deliver its specific function, and is prohibited from using it for its own purposes including model training.