Skip to content
Features Pricing Privacy Legal
Try scrimpl

Legal

Data Processing Addendum

Last updated 8 October 2026 · Version 2026-10-07

On this page

On this page

  1. Parties and scope
  2. When scrimpl is a processor
  3. Details of processing
  4. scrimpl's obligations
  5. Subprocessors
  6. Personal data breaches
  7. International transfers
  8. Audits
  9. End of processing
  10. Liability
  11. Security measures
  12. Signatures (optional)

The short version

  • This addendum is for businesses. It applies when scrimpl processes personal data on your behalf, as GDPR Article 28 requires.
  • Your libraries stay on your own Macs, so most of your data never reaches us.
  • We act as your processor when we pass an AI request (a screenshot, its text and an instruction) through our API to Anthropic's Claude. Nothing from it is stored.
  • It applies automatically to business customers who accept the Terms. For a signed copy, email hello@scrimpl.com.

Parties and scope

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Milos Zdrale, Sime Milutinovića Sarajlije 1, 71123 Istočno Sarajevo, Bosnia and Herzegovina ("scrimpl", the processor) and the business customer that accepts the Terms ("Customer", the controller). It applies to personal data that scrimpl processes on the Customer's behalf ("Customer Personal Data"), in line with Article 28 of the GDPR, the UK GDPR and the Law on Personal Data Protection of Bosnia and Herzegovina ("Data Protection Law").

If this DPA and the Terms conflict on data protection, this DPA wins. If the Standard Contractual Clauses apply and conflict with this DPA, the Clauses win.

When scrimpl is a processor

scrimpl runs on the Customer's own Macs. Libraries, settings and local logs are stored there, under the Customer's control, and scrimpl does not receive them. scrimpl processes Customer Personal Data only when an authorised user runs an AI feature: the app sends the request (the screenshot or part of it, text read from it, the user's instruction and the settings the job needs) to the scrimpl API, which passes it to Anthropic's Claude API and returns the result. The request is held in memory only while it runs.

The account data of the Customer's users (email, plan, credits, request records without content) and billing data are handled by scrimpl and Paddle as controllers, under the Privacy Policy, not under this DPA. What AI agents connected by the Customer's users receive from scrimpl is governed by the Customer's own agreement with those agents' providers.

Details of processing

This section is Annex I to the Standard Contractual Clauses where they apply.

Subject matterProviding scrimpl's AI features (simplifying, editing, translating and annotating product screenshots, and related video features) to the Customer.
DurationFor as long as the Customer uses scrimpl under the Terms. Each AI request is processed only for the time it takes to answer it.
Nature and purposeReceiving screenshots, text and instructions from the Customer's Macs, passing them to the AI model and returning the result. No storage and no other use.
Types of personal dataWhatever personal data the Customer chooses to include in screenshots and instructions, for example names, email addresses, profile pictures, messages, order or customer numbers.
Data subjectsThe Customer's staff and authorised users, and people whose data appears in the Customer's screenshots, such as the Customer's own customers or colleagues.
Special categoriesNot intended. The Customer should not send special categories of data (such as health data) and should blur them first; scrimpl has a tool for that.
FrequencyContinuous, each time an authorised user runs an AI feature.

scrimpl's obligations

scrimpl will:

  1. process Customer Personal Data only on the Customer's documented instructions, which are the Terms, this DPA and the Customer's use of scrimpl's features, and tell the Customer if it believes an instruction breaks Data Protection Law;
  2. make sure everyone who can access Customer Personal Data is bound by confidentiality;
  3. keep the technical and organisational measures in Security measures below;
  4. use subprocessors only as set out in Subprocessors;
  5. help the Customer, as far as it reasonably can, to answer requests from data subjects exercising their rights;
  6. help the Customer meet its obligations on security, breach notification, data protection impact assessments and prior consultation (GDPR Articles 32 to 36), taking into account the nature of the processing and the information available to scrimpl;
  7. delete Customer Personal Data when the service ends (see End of processing); and
  8. make available the information needed to show compliance with this DPA, and allow for audits as set out in Audits.

Subprocessors

The Customer gives scrimpl general authorisation to use subprocessors. The full list is on the Subprocessors page (Annex III where the Standard Contractual Clauses apply). For Customer Personal Data they are Vercel Inc. (hosting the scrimpl API) and Anthropic, PBC (Claude API). scrimpl puts data protection obligations on each subprocessor by written contract that are no less protective than this DPA, and remains responsible for them.

scrimpl will update the Subprocessors page, and notify Customers who have asked to be notified, at least 30 days before a new subprocessor starts processing Customer Personal Data. The Customer may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the Customer may stop using the affected feature or end the Terms and receive a refund of prepaid fees for the unused period.

Personal data breaches

scrimpl will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. scrimpl will add information as it becomes available.

International transfers

scrimpl is established in Bosnia and Herzegovina, and its subprocessors process requests in the United States and other regions. Where the Customer is in the EU or the EEA and Customer Personal Data is transferred to scrimpl, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), are incorporated into this DPA by reference, with the Customer as data exporter and scrimpl as data importer. For them: the docking clause (Clause 7) applies; Clause 9(a) Option 2 (general written authorisation, with the 30 days' notice above) applies; the optional wording in Clause 11 does not; the supervisory authority under Clause 13 is the one competent for the Customer; and under Clauses 17 and 18 the Clauses are governed by the law of, and disputes go to the courts of, the EU Member State where the Customer is established, or Ireland if that law does not allow third-party beneficiary rights. Annex I is Details of processing, Annex II is Security measures and Annex III is the Subprocessors page.

Where the Customer is in the UK, the UK International Data Transfer Addendum to those Clauses applies in the same way. Onward transfers to subprocessors are covered by the Standard Contractual Clauses (Module Three, processor to processor) and the UK Addendum in each subprocessor's data processing agreement, including Anthropic's and Vercel's.

Audits

On written request, scrimpl will answer the Customer's reasonable questions and provide the documentation needed to show compliance with this DPA. If that is not enough, the Customer may audit scrimpl's processing of Customer Personal Data once a year, with at least 30 days' notice, during business hours, at its own cost, through an independent auditor bound by confidentiality. Audits required by a supervisory authority or after a breach are not limited to once a year.

End of processing

scrimpl does not keep Customer Personal Data after answering a request: screenshots, text and results are not stored on scrimpl's systems. Anything held for the Customer when the Terms end will be deleted within 30 days, unless the law requires it to be kept. Data stored on the Customer's own Macs stays under the Customer's control.

Liability

Each party's liability under this DPA is subject to the limitation of liability in the Terms, except where Data Protection Law does not allow it to be limited.

Security measures

This section is Annex II to the Standard Contractual Clauses where they apply.

  • Local first. Libraries and settings are stored on the Customer's Macs. scrimpl stores no screenshots, text read from them or results on its own systems.
  • No content at rest. The scrimpl API holds an AI request in memory only while it runs. Request records and logs keep time, feature, model, tokens, cost and status, never content.
  • In transit. The app, the API and Anthropic talk only over HTTPS (TLS).
  • Access to the app. The scrimpl server on the Mac answers only that Mac, refuses foreign hosts and cross-site requests, and requires an access token for AI agents.
  • Accounts. Sign-in is handled by Supabase Auth: a password (stored only as a hash), a one-time email code, or Google. Account rows are protected by row-level security so that each user can read only their own; plans and balances can be changed only by the server.
  • Credentials. scrimpl's API keys are kept only in the hosting provider's encrypted environment settings, never in the app or in code, and only the founder can access them.
  • Minimisation. Text recognition runs on the device. Only what a request needs is sent.
  • People. Everyone with access to Customer Personal Data is bound by confidentiality. Today that is one person, the founder.
  • Incidents. Security reports go to hello@scrimpl.com and are handled under the breach process above.

Signatures (optional)

This DPA applies without a signature to business customers who accept the Terms. If you need a countersigned copy for your records, email hello@scrimpl.com with your company's legal name, address and a contact, and we will send one.

Customer (controller)scrimpl (processor)
Legal nameAs in Parties and scope
Signed by, titleSigned on request
Date

Screenshots that say one thing.

Features Pricing Privacy FAQ Brand
Privacy Terms Cookies Subprocessors DPA

© 2026 scrimpl

Claude is a trademark of Anthropic, PBC. Other product names on this site are trademarks of their owners. scrimpl is an independent product and is not affiliated with or endorsed by them.