Rehearsable icon

Rehearsable

Return to Rehearsable


Data Processing Addendum


Last updated: 21-Apr-2026


1. Definitions 2. Processing of Personal Data 3. Processor Personnel 4. Security 5. Sub-processing 6. Data Subject Rights 7. Personal Data Breach 8. DPIA and Prior Consultation 9. Deletion or Return of Data 10. Audit Rights 11. Data Transfer 12. General Schedule 1: Sub-processors Schedule 2: Processing Details

This Data Processing Addendum ("DPA") forms part of the Terms of Use ("Terms") between Rehearsable and the Creator for the provision of the Rehearsable services. Words and expressions defined in the Terms have the same meanings when used in this DPA.

1. Definitions

  • "Creator Personal Data" means any Personal Data processed by Rehearsable on behalf of the Creator pursuant to or in connection with a Subscription.
  • "Data Protection Laws" means: (i) the UK GDPR (as defined in the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019); (ii) the Data Protection Act 2018; (iii) the Privacy and Electronic Communications (EC Directive) Regulations 2003; and (iv) any other data protection laws and regulations, orders and any codes of practice, guidelines and recommendations issued by the Commissioner or any replacement or equivalent body.
  • "Sub-processor" means any third party appointed by Rehearsable to process Personal Data on behalf of the Creator.

The terms "Controller", "Data Subject", "Personal Data", "Personal Data Breach", "Processing", "Processor" and "Commissioner" shall have the same meaning as in the UK GDPR.


2. Processing of Creator Personal Data

2.1 This DPA applies to the Processing of Creator Personal Data by Rehearsable in the course of providing the Services. For the purposes of the Services and this DPA, the parties anticipate that the Creator is a Controller and Rehearsable is a Processor.

2.2 Rehearsable shall:

  • comply with all applicable Data Protection Laws in the processing of Creator Personal Data; and
  • not process Creator Personal Data other than on the Creator's documented instructions, unless required by applicable law.

2.3 The Creator instructs Rehearsable to process Creator Personal Data to provide the Services. The details of processing are set out in Schedule 2. Rehearsable may process Creator Personal Data otherwise than in accordance with the Creator's instructions if required to do so by applicable laws. In such case Rehearsable shall inform the Creator of that legal requirement, unless prohibited from doing so by applicable laws.

2.4 The Creator is responsible for the lawfulness of the processing of Creator Personal Data in connection with the Services. The Creator shall:

  • have provided, and will continue to provide all notices and have obtained, and will continue to obtain, all consents, permissions and rights necessary under applicable laws for Rehearsable to lawfully process Creator Personal Data for the purposes contemplated by the Terms;
  • have complied with all Data Protection Laws applicable to the collection and provision of Creator Personal Data to Rehearsable; and
  • ensure its processing instructions comply with all Data Protection Laws.

2.5 Rehearsable shall inform the Creator if, in its opinion, an instruction infringes Data Protection Laws.


3. Processor Personnel

Rehearsable shall ensure that access to the Creator Personal Data is strictly limited to those of its employees who need access for the purposes of providing the Services and that each employee authorised to process Creator Personal Data is subject to confidentiality obligations or professional or statutory obligations of confidentiality.


4. Security

4.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Rehearsable shall implement appropriate technical and organisational measures to ensure a level of security appropriate to that risk in accordance with Article 32 of the UK GDPR.

4.2 In assessing the appropriate level of security, Rehearsable shall take account of the risks presented by processing, in particular from a Personal Data Breach.


5. Sub-processing

5.1 The Creator grants Rehearsable general authorisation to engage Sub-processors to process Creator Personal Data.

5.2 Rehearsable shall agree data protection terms with each Sub-processor that provide at least the same level of protection as this DPA.

5.3 The Creator authorises Rehearsable to use those Sub-processors set out in the Sub-processor List in Schedule 1. Subject to clause 5.4, Rehearsable may from time to time engage additional or replacement Sub-processors, provided that Rehearsable updates the Sub-processor List and gives the Creator written notice of such update at least thirty (30) days prior to the engagement being effective.

5.4 If the Creator notifies Rehearsable in writing of any grounds on which it objects to a Sub-processor that has been added to the Sub-processor List within fourteen (14) days after the date on which Rehearsable gives notice to the Creator:

(a) Rehearsable shall work with Creator in good faith to make available a commercially reasonable change in the provision of the Services which avoids the use of the proposed Sub-processor; and

(b) where such a change cannot be made and Rehearsable chooses to retain the Sub-processor, Rehearsable shall notify the Creator of that fact.

5.5 Rehearsable shall remain liable to the Creator for the performance of the Sub-processor's obligations.


6. Data Subject Rights

6.1 Taking into account the nature of the processing, Rehearsable shall assist the Creator by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Creator's obligations to respond to requests to exercise Data Subject rights under Data Protection Laws.

6.2 Rehearsable shall:

  • promptly notify the Creator if it receives a request from a Data Subject under any Data Protection Law in respect of Creator Personal Data; and
  • not respond to that request except on the documented instructions of the Creator or as required by applicable law, in which case Rehearsable shall, to the extent permitted by applicable law, inform the Creator of that legal requirement before responding to the request.

7. Personal Data Breach

7.1 Rehearsable shall notify the Creator without undue delay upon becoming aware of a Personal Data Breach affecting Creator Personal Data, providing sufficient information to allow the Creator to meet any obligations to report or inform the Commissioner or Data Subjects of the Personal Data Breach under Data Protection Laws.

7.2 Rehearsable shall co-operate with the Creator and take reasonable commercial steps as directed by the Creator to assist in the investigation, mitigation and remediation of each Personal Data Breach.


8. Data Protection Impact Assessment and Prior Consultation

Rehearsable shall provide reasonable assistance to the Creator with any data protection impact assessments and prior consultations with the Commissioner which the Creator reasonably considers to be required under Data Protection Laws, taking into account the nature of the processing and information available to Rehearsable.


9. Deletion, Return or Anonymisation of Creator Personal Data

9.1 Upon termination of the Services, Rehearsable shall, at the Creator's option, delete or return all Creator Personal Data within 60 days of the end of the relevant Subscription, unless applicable law requires longer retention of the Creator Personal Data. The Creator acknowledges that Creator Personal Data may be fully anonymised and retained for business purposes such as product improvement and analytics.

9.2 Data in backups and system logs may be retained longer for security and operational purposes before being deleted or anonymised.


10. Audit Rights

10.1 Rehearsable shall make available to the Creator information necessary to demonstrate compliance with this DPA, including details of its security practices and compliance measures.

10.2 Rehearsable may satisfy audit requirements by providing relevant third-party certifications, audit reports, or security questionnaire responses when available.

10.3 Physical or remote system audits require Rehearsable's prior written consent, at least 30 days' notice, and may be subject to reasonable fees. Such audits shall be conducted during normal business hours and shall not unreasonably disrupt Rehearsable's operations. The Creator may conduct no more than one on-site or remote system audit per 12-month period unless required by the Commissioner or following a Personal Data Breach.


11. Data Transfer

11.1 Rehearsable shall only transfer Creator Personal Data outside of the UK:

  • to a country or territory formally recognized by the United Kingdom as providing an adequate level of data protection ("Adequate Country"); or
  • with appropriate safeguards in place as required by Data Protection Laws.

12. General

12.1 In the event of any conflict between this DPA and the Terms of Use, this DPA shall take precedence with respect to data protection matters.

12.2 Clauses 13.1 – 13.10 (General Terms) of the Terms are incorporated in this DPA as if set out herein in full.

12.4 Questions about this DPA should be directed to hello@rehearsable.ai.


Schedule 1: Sub-processors

Sub-processor Purpose Location
Google Cloud Cloud hosting; database EU
Google Workspace Business email; customer support communications Global
Google Authentication services Global
Microsoft Authentication services Global
OpenAI AI language model services USA
Anthropic AI language model services USA
PostHog Product analytics EU
Sentry Error monitoring EU
Cloudflare Security, CDN Global
Usercentrics Cookie consent management EU

Last updated: 21-Apr-2026


Schedule 2: Processing Details

Element Description
Subject matter Creator Personal Data processed by Rehearsable in connection with the Services
Duration For the Subscription Term, plus any retention period specified in clause 9
Nature of processing Collection, storage, organisation, retrieval, use, copying, disclosure, and erasure of Creator Personal Data
Purpose of processing To provide the Services
Types of Personal Data First names, last names, job titles, qualifications, email addresses, and other personal information input by Authorised Users or generated via the Services; usage data, technical data (IP address, device information)
Categories of Data Subjects Authorised Users, being customers of, employees of, and other individuals authorised by the Creator