FLIGHTCAST DATA PROCESSING ADDENDUM
This Data Processing Addendum ("DPA") forms part of the Flightcast Enterprise SaaS Agreement governing Customer's use of the Services (the "Agreement") between:
Flightcast Inc. ("Flightcast", "Processor"), and
the entity agreeing to the Agreement ("Customer", "Controller").
This DPA applies where Flightcast processes Personal Data on behalf of Customer in connection with the Services.
1. Definitions
For purposes of this DPA:
- "Applicable Data Protection Law" means the GDPR and any applicable EU Member State data protection laws.
- "GDPR" means Regulation (EU) 2016/679.
- "Personal Data" means any information relating to an identified or identifiable natural person that is collected from or provided to Flightcast by the Customer pursuant to the Agreement.
- "Processing" means any operation performed on Personal Data.
- "Data Subject" means the individual to whom Personal Data relates.
- "Personal Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
- "Sub-processor" means any third party engaged by Flightcast to process Personal Data on behalf of Customer.
2. Roles of the Parties
Customer acts as the Controller of Personal Data processed in connection with the Services.
Flightcast acts as a Processor, processing Personal Data solely on documented instructions from Customer as set forth in the Agreement and this DPA.
Flightcast acts as an independent Controller with respect to Personal Data it processes for its own business purposes, including marketing, service improvement, fraud prevention, billing administration, and product analytics.
3. Subject Matter and Duration
3.1 Subject Matter
Flightcast provides podcast hosting, content distribution, analytics, AI-enabled services, and related functionality.
3.2 Duration
Processing shall continue for the duration of the Agreement unless otherwise required by Applicable Data Protection Law.
4. Nature and Purpose of Processing
Flightcast may process Personal Data for the following purposes:
- Hosting and delivery of podcast audio and video files
- Distribution of podcast content to third-party platforms
- Generating listener analytics
- Hashing and processing listener IP addresses
- AI transcript generation and content enhancement features
- Customer account management and billing
- Customer support services
- Implementation of tracking pixels or advertising tools at Customer's instruction
5. Types of Personal Data
Depending on Customer's use of the Services, Personal Data processed may include:
- Customer account information (name, email address, billing contact)
- Team member account information
- Hashed listener IP addresses
- Device and usage metadata
- Tracking pixel data implemented at Customer instruction
- Podcast transcripts, which may contain personal names or other identifiers
- Support communications
Flightcast does not store raw listener IP addresses.
6. Categories of Data Subjects
Data Subjects may include:
- Customer personnel and team members
- Podcast listeners
- End users interacting with embedded players
- Customer billing contacts
7. Processor Obligations
Flightcast shall:
- Process Personal Data only on documented instructions from Customer.
- Ensure that persons authorized to process Personal Data are bound by confidentiality obligations.
- Implement appropriate technical and organizational security measures as described in Annex II.
- Notify Customer without undue delay and no later than seventy-two (72) hours after becoming aware of a Personal Data Breach.
- Assist Customer, taking into account the nature of processing, in responding to Data Subject requests.
- Delete or return Personal Data upon termination of the Services, subject to applicable law and backup retention.
- Make available information reasonably necessary to demonstrate compliance with this DPA.
8. Sub-processors
Customer authorizes Flightcast to engage Sub-processors.
Flightcast shall:
- Maintain an up-to-date list of Sub-processors
- Impose data protection obligations on Sub-processors consistent with this DPA
- Remain responsible for Sub-processor performance
Current Sub-processors are listed in Annex III.
9. International Data Transfers
Flightcast infrastructure is located in the United States.
Where the Controller is subject to GDPR, and Personal Data originating in the European Economic Area ("EEA") is transferred to a country outside the EEA that has not been deemed to provide an adequate level of data protection, the parties incorporate by reference the European Commission Standard Contractual Clauses (2021), Module 1 (Controller to Controller) and Module 2 (Controller to Processor), as applicable, available at:
eur-lex.europa.eu/eli/dec_impl/2021/914/oj
The parties agree that:
- Customer is the Data Exporter (Controller).
- Flightcast Inc. is the Data Importer (Processor).
- Annex I, II, and III of this DPA satisfy the corresponding annex requirements of the Standard Contractual Clauses ("SCCs").
- Clause 7 is not applicable.
- Option 2 is applicable for Module 2, Clause 9.
- The optional language in Clause 11 is not applicable.
- The governing law for purposes of Clause 17 of the SCCs shall be the law of Ireland and Option 1 for Clause 17 shall be applicable.
- Disputes shall be resolved in the courts of Ireland pursuant to Clause 18 of the SCCs.
- Flightcast has evaluated the laws and practices of the United States and has not identified any laws or practices that prevent it from fulfilling its obligations under the Standard Contractual Clauses.
10. California Consumer Privacy Act
Where the Customer is subject to the California Consumer Privacy Act ("CCPA"), the parties agree that with regard to Personal Data subject to the CCPA being processed by Flightcast:
- Flightcast is a "Service Provider" and Customer is a "Business" as defined by the CCPA.
- Customer discloses the Personal Data for podcast hosting and related services under the Agreement, including without limitation, distribution, analytics, AI processing, support, and billing ("Business Purpose") and Service Provider shall process the Personal Data solely for the Business Purpose.
- Flightcast shall not: (a) sell or share Personal Data; (b) retain, use, or disclose the Personal Data for any purpose other than the Business Purpose, including for any commercial purpose other than such Business Purpose, except as otherwise permitted by the CCPA; (c) retain, use, or disclose the Personal Data outside the direct business relationship between Flightcast and Customer; and (d) combine the Personal Data with personal information that it receives from, or on behalf of, another person or collects from its own interaction with the consumer, except as expressly permitted by the CCPA;
- Flightcast shall: (a) comply with all applicable requirements of the CCPA; (b) provide the same level of privacy protection as required of businesses under the CCPA to the Personal Data; (c) enable Customer to comply with consumer requests made pursuant to CCPA of which Customer informs Flightcast, and shall provide the information necessary to comply with such requests; and (d) notify Customer after it makes a determination that it can no longer meet its obligations under the CCPA.
- Customer has the right: (a) to take reasonable and appropriate steps to ensure that Flightcast uses the Personal Data in a manner consistent with Customer's obligations under the CCPA; and (b) upon notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of the Personal Data by Flightcast.
- Where Flightcast engages a Sub-processor in providing the Services, Flightcast shall enter into a written contract with the Sub-processor that complies with the CCPA and the provisions in this Section 10.
11. Security of Processing
Flightcast implements appropriate technical and organizational measures including:
- Encryption of Personal Data in transit using TLS
- Infrastructure-level encryption at rest provided by cloud hosting providers
- Role-based access controls restricting production access to authorized engineering personnel
- Multi-factor authentication required for administrative access to production systems
- Logging and monitoring of production system access
- Limited log retention (seven (7) days)
- Incident response escalation procedures
Details are set forth in Annex II.
12. Audit Rights
Upon reasonable request and subject to appropriate confidentiality protections, Flightcast shall make available information reasonably necessary to demonstrate compliance with this DPA.
13. Data Retention and Deletion
Upon termination of the Agreement:
- Customer data may be archived for operational continuity and backup purposes.
- Log data is retained for approximately seven (7) days.
- Customers may request deletion of stored Personal Data, subject to legal retention requirements.
14. Data Subject Requests
Flightcast shall assist Customer in responding to valid Data Subject requests where required by Applicable Data Protection Law.
Privacy-related inquiries may be directed to:
privacy@flightcast.com
15. Limitation of Liability
Each party's liability under this DPA shall be subject to the limitations of liability set forth in the Agreement, except as otherwise required by Applicable Data Protection Law.
ANNEX I - PROCESSING DETAILS
Controller: Customer
Contact Information: See the Agreement.
Activities relevant to the data transferred under the SCCs: use of the Services in accordance with the Agreement.
Signature: See the Agreement.
Processor: Flightcast Inc.
Contact Information: See the Agreement.
Activities relevant to the data transferred under the SCCs: provision of the Services in accordance with the Agreement.
Signature: See the Agreement.
Categories of Data Subjects whose Personal Data is being transferred: Customer personnel, podcast listeners, billing contacts.
Categories of Personal Data being transferred: As described in Section 5.
Sensitive Data transferred: Not applicable.
Frequency of the transfer: Ongoing during the Agreement.
Nature of Processing: Hosting, distribution, analytics, AI processing, support, and billing.
Purpose of the data transfer and further processing: Provision of podcast hosting and related services under the Agreement.
The period for which the personal data will be retained: Pursuant to the Agreement and Section 13 herein, and as permitted by applicable law.
ANNEX II - TECHNICAL AND ORGANIZATIONAL MEASURES
Flightcast maintains:
- Encryption in transit using TLS
- Infrastructure-level encryption at rest
- Role-based access controls
- Multi-factor authentication for administrative production access
- Restricted production access to authorized engineering personnel
- Logging and monitoring of access
- Incident response procedures
- Seven-day log retention
ANNEX III - SUB-PROCESSORS
As of the effective date of this DPA, Flightcast uses:
- Cloudflare (hosting and CDN services)
- OVH (infrastructure services)
- Tinybird (analytics services)
- Resend (email delivery services)
- Stripe (payment processing)
- Crisp (customer support platform)
- OpenRouter (AI processing services)
- PostHog (product analytics)
- RunPod (transcription, transcoding, and AI/media processing)
- Opus/Opus.pro (clip generation)
- Headliner (clip generation)
- Postmark (inbound email processing, if applicable)
- Dub (attribution and tracking, if applicable)
- AWS, S3-compatible storage, Cloudflare R2, and OVH object storage (storage and media infrastructure)
- OpenAI/Anthropic via OpenRouter (AI processing, if applicable)
- Emit.run (job execution, if applicable)
Flightcast may update this list from time to time.