GDPR & DPA

At ScriptMe AB, we prioritize the security of your data. We understand the importance of maintaining its confidentiality, integrity, and availability. With rising privacy concerns, we employ robust measures to protect your information from unauthorized access, loss, or misuse. Your trust is paramount to us, and we are committed to upholding the highest standards of data security to ensure your peace of mind.

At ScriptMe AB we comply with the GDPR and DPA regulations and data policies in force in the European Union. Both the handling of personal data and the use of such data are endorsed in these policies, taking care of your data and privacy strictly and with utmost care.

 

GDPR Compliance 

On the basis of the new adequacy decision at 10 July 2023, by European Commission, personal data can flow safely from the EU to US companies participating in the Framework, without having to put in place additional data protection safeguards. Link here 

Data Retention Policy

Right of owning data
Users that upload video or audio for processing retain 100% ownership of their material. ScriptMe and its subprocessors have no rights to the video, audio, or the output of the processing. The uploaded material will never be published, shared, or used for AI training. It will be used solely for the purpose of delivering the requested solution to the user.

Original Uploaded Files: To protect your privacy and manage data storage efficiently, all original files uploaded to our service are retained for a period of six months. After this period, files are permanently deleted from our servers.

Enterprise customers may choose custom retention periods, including automatic deletion immediately after processing, 30 days, 90 days, or customer-defined retention schedules.

Preview Files: Preview files generated by our service are retained for a period of two years. This allows for extended access and review opportunities. After two years, these files are permanently deleted.

Transcription Files: Transcription files in JSON format are retained for 15 days to support ongoing revisions and updates. Only the most recent version of a transcription file is saved. Older versions are automatically deleted after this period.

Right to delete data
Users can permanently delete their uploaded video and audio at any time. Backups of the deleted material will be automatically removed within 7 days. Upon user request, the ScriptMe Team can also delete the data within 24 hours.

Security Controls

ScriptMe employs industry-standard security controls including:

  • Role-based access controls
  • Multi-factor authentication for administrative accounts
  • Continuous monitoring and logging of administrative access
  • Regular security reviews and vulnerability management procedures

 

ScriptMe as a Data Processor

ScriptMe AB cannot control and have no relationship to data subjects who's data you are processing through us. If you are using our services to process personal data, ScriptMe AB will be a data processor in relationship to you as the data controller. The purpose of the processing and what data is to be processed through our services is determined by you when you use our services.

ScriptMe AB will never use data that you process through our services for anything other than to comply with your requests, if forced by lawful request by a public institution or to protect our interests in a court of law should there be a dispute relating to this agreement.

ScriptMe AB will inform you within 24 hours of a detected data breach.

ScriptMe AB ensures that you can comply with rights requests by data subject by ensuring you have access to the data that you process using our services at all times.

ScriptMe AB guarantees that the services we provide have adequate organizational and technical security measures in place. At your behest we will provide documents.

All the data shared between the user browser and Scriptme AB servers, is secured via HTTPS (TLS 1.2), and when data is saved on our ends is encrypted using the AES-256 algorithm.

Access to customer content is restricted to authorized personnel on a strict need-to-know basis for the purpose of providing support, troubleshooting, or maintaining the Service. All access is governed by internal security procedures and is logged and monitored.

 

ScriptMe AB uses the following sub-processors to ensure our services function

Stripe, Inc – for processing payments, ScriptMe AB does not process credit card information (US based).

Stripe is a technology company that provides online payment processing services. Stripe handles ScriptMe AB payments. ScriptMe AB doesn't keep any credit card information. This affects you only if you pay by credit card.

Link to Stripe Privacy Center

Amplitude Inc – for logging activity and ensure the service is running smoothly (US based), no access to users uploade video/audio.

Amazon Web Services (AWS) – ScriptMe utilizes Amazon Web Services (AWS), a U.S.-based cloud infrastructure provider, for the secure storage and processing of data within our Services. All user data is hosted exclusively on AWS infrastructure. ScriptMe does not use any AWS artificial intelligence or machine learning services. Our use of AWS is limited to services such as Amazon S3 (storage), AWS Lambda (serverless execution), database hosting, security, and encryption, we also run ScriptMe AI in AWS. Customer media content is stored and processed within AWS infrastructure located in [EU region(s)] unless otherwise agreed.

Speechmatics Ltd, registered in England and Wales, to process audio files and generate transcriptions in JSON format. Speechmatics acts as a processor on behalf of ScriptMe and does not retain, store, or otherwise use user-uploaded audio or related data beyond the duration necessary to provide the transcription service. All rights and ownership of user data remain with the user.

Google Analytics GA4 – for tracking and analyzing traffic on the website, if you have allowed cookies (US based).

Crisp – for chat support (based in France).

Mailgun – used for handling email communication within the application. No video or audio is accessed by Mailgun.

A number of these sub-processor and vendors require data transfers to the USA. Meaning that you until the EU-Commission declares the USA a safe third country another transfer mechanism must be applied for the use of our services to process data relating to EU-citizens.

 

European Commission adopts new adequacy decision for safe and trusted EU-US data flows

On the basis of the new adequacy decision, personal data can flow safely from the EU to US companies participating in the Framework, without having to put in place additional data protection safeguards.

We offer a variant of our services for controllers who do not wish to process data using US based vendors, for more information contact us at hey@scriptme.io.

This document was last updated on Okt 03, 2025