This Data Processing Addendum ("DPA") forms part of the Terms of Use ("Terms") between Rehearsable and the Creator for the provision of the Rehearsable services. Words and expressions defined in the Terms have the same meanings when used in this DPA.
The terms "Controller", "Data Subject", "Personal Data", "Personal Data Breach", "Processing", "Processor" and "Commissioner" shall have the same meaning as in the UK GDPR.
2.1 This DPA applies to the Processing of Creator Personal Data by Rehearsable in the course of providing the Services. For the purposes of the Services and this DPA, the parties anticipate that the Creator is a Controller and Rehearsable is a Processor.
2.2 Rehearsable shall:
2.3 The Creator instructs Rehearsable to process Creator Personal Data to provide the Services. The details of processing are set out in Schedule 2. Rehearsable may process Creator Personal Data otherwise than in accordance with the Creator's instructions if required to do so by applicable laws. In such case Rehearsable shall inform the Creator of that legal requirement, unless prohibited from doing so by applicable laws.
2.4 The Creator is responsible for the lawfulness of the processing of Creator Personal Data in connection with the Services. The Creator shall:
2.5 Rehearsable shall inform the Creator if, in its opinion, an instruction infringes Data Protection Laws.
Rehearsable shall ensure that access to the Creator Personal Data is strictly limited to those of its employees who need access for the purposes of providing the Services and that each employee authorised to process Creator Personal Data is subject to confidentiality obligations or professional or statutory obligations of confidentiality.
4.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Rehearsable shall implement appropriate technical and organisational measures to ensure a level of security appropriate to that risk in accordance with Article 32 of the UK GDPR.
4.2 In assessing the appropriate level of security, Rehearsable shall take account of the risks presented by processing, in particular from a Personal Data Breach.
5.1 The Creator grants Rehearsable general authorisation to engage Sub-processors to process Creator Personal Data.
5.2 Rehearsable shall agree data protection terms with each Sub-processor that provide at least the same level of protection as this DPA.
5.3 The Creator authorises Rehearsable to use those Sub-processors set out in the Sub-processor List in Schedule 1. Subject to clause 5.4, Rehearsable may from time to time engage additional or replacement Sub-processors, provided that Rehearsable updates the Sub-processor List and gives the Creator written notice of such update at least thirty (30) days prior to the engagement being effective.
5.4 If the Creator notifies Rehearsable in writing of any grounds on which it objects to a Sub-processor that has been added to the Sub-processor List within fourteen (14) days after the date on which Rehearsable gives notice to the Creator:
(a) Rehearsable shall work with Creator in good faith to make available a commercially reasonable change in the provision of the Services which avoids the use of the proposed Sub-processor; and
(b) where such a change cannot be made and Rehearsable chooses to retain the Sub-processor, Rehearsable shall notify the Creator of that fact.
5.5 Rehearsable shall remain liable to the Creator for the performance of the Sub-processor's obligations.
6.1 Taking into account the nature of the processing, Rehearsable shall assist the Creator by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Creator's obligations to respond to requests to exercise Data Subject rights under Data Protection Laws.
6.2 Rehearsable shall:
7.1 Rehearsable shall notify the Creator without undue delay upon becoming aware of a Personal Data Breach affecting Creator Personal Data, providing sufficient information to allow the Creator to meet any obligations to report or inform the Commissioner or Data Subjects of the Personal Data Breach under Data Protection Laws.
7.2 Rehearsable shall co-operate with the Creator and take reasonable commercial steps as directed by the Creator to assist in the investigation, mitigation and remediation of each Personal Data Breach.
Rehearsable shall provide reasonable assistance to the Creator with any data protection impact assessments and prior consultations with the Commissioner which the Creator reasonably considers to be required under Data Protection Laws, taking into account the nature of the processing and information available to Rehearsable.
9.1 Upon termination of the Services, Rehearsable shall, at the Creator's option, delete or return all Creator Personal Data within 60 days of the end of the relevant Subscription, unless applicable law requires longer retention of the Creator Personal Data. The Creator acknowledges that Creator Personal Data may be fully anonymised and retained for business purposes such as product improvement and analytics.
9.2 Data in backups and system logs may be retained longer for security and operational purposes before being deleted or anonymised.
10.1 Rehearsable shall make available to the Creator information necessary to demonstrate compliance with this DPA, including details of its security practices and compliance measures.
10.2 Rehearsable may satisfy audit requirements by providing relevant third-party certifications, audit reports, or security questionnaire responses when available.
10.3 Physical or remote system audits require Rehearsable's prior written consent, at least 30 days' notice, and may be subject to reasonable fees. Such audits shall be conducted during normal business hours and shall not unreasonably disrupt Rehearsable's operations. The Creator may conduct no more than one on-site or remote system audit per 12-month period unless required by the Commissioner or following a Personal Data Breach.
11.1 Rehearsable shall only transfer Creator Personal Data outside of the UK:
12.1 In the event of any conflict between this DPA and the Terms of Use, this DPA shall take precedence with respect to data protection matters.
12.2 Clauses 13.1 – 13.10 (General Terms) of the Terms are incorporated in this DPA as if set out herein in full.
12.4 Questions about this DPA should be directed to hello@rehearsable.ai.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud | Cloud hosting; database | EU |
| Google Workspace | Business email; customer support communications | Global |
| Authentication services | Global | |
| Microsoft | Authentication services | Global |
| OpenAI | AI language model services | USA |
| Anthropic | AI language model services | USA |
| PostHog | Product analytics | EU |
| Sentry | Error monitoring | EU |
| Cloudflare | Security, CDN | Global |
| Usercentrics | Cookie consent management | EU |
Last updated: 21-Apr-2026
| Element | Description |
|---|---|
| Subject matter | Creator Personal Data processed by Rehearsable in connection with the Services |
| Duration | For the Subscription Term, plus any retention period specified in clause 9 |
| Nature of processing | Collection, storage, organisation, retrieval, use, copying, disclosure, and erasure of Creator Personal Data |
| Purpose of processing | To provide the Services |
| Types of Personal Data | First names, last names, job titles, qualifications, email addresses, and other personal information input by Authorised Users or generated via the Services; usage data, technical data (IP address, device information) |
| Categories of Data Subjects | Authorised Users, being customers of, employees of, and other individuals authorised by the Creator |