Privacy Policy
Understudy
1. Who we are and what this policy covers
Understudy (“Understudy”, “we”, “us”) takes recordings you upload and context you post, and returns a demo URL in which a classifier we operate has chosen which spans to substitute. We do not record, we do not generate screens, and we do not sell a platform around the endpoint.
Registered at Understudy Software Ltd, 12 Hanover Quay, Dublin 2, D02 XY45, Ireland.
We handle personal data in two different situations, and different rules apply to each:
| Whose data | Our role | What applies | |
|---|---|---|---|
| Part A | People who visit this website, ask about the service or write to us | Controller: we decide why and how the data is used | This policy |
| Part B | Recordings you upload and the prospect context you post with each demo | Set out in B.1, because it depends on the data | This policy and the data processing agreement we sign with each customer |
If the data processing agreement (“DPA”) and this policy ever disagree about Part B, the DPA wins.
Part A: this website and our contact with you
This part covers the personal data we collect for our own purposes: running this website, answering requests, and staying in touch with people who are or might become customers.
A.1 What we collect
What you give us. When you send the form on this site, we collect what you type into it, such as your name, email address, phone number or company, and the fact that you agreed to be contacted. If you email or talk to us, we keep that correspondence and any contact details in it.
What is collected automatically. Our web server records the IP address a request came from, the browser used, the pages requested, the page you came from and the time. These logs exist to keep the site running and secure.
We don’t ask for sensitive data (the “special categories” in Article 9 GDPR) through this website, so please don’t send any through the form.
A.2 Why we use it, and what allows us to
| Why | What | Legal basis (GDPR Art. 6) |
|---|---|---|
| Answering your request and working out whether the service fits | What you sent in the form, our correspondence | Art. 6(1)(b): steps you asked for before a contract |
| Looking after customers, billing and support | Contact details, correspondence | Art. 6(1)(b): carrying out a contract |
| Keeping the site running, secure and free of abuse | Server logs | Art. 6(1)(f): our legitimate interest in running a secure service |
| Contacting you about the service | Email address, company | Art. 6(1)(f): our legitimate interest in business-to-business marketing. You can object at any time |
| Meeting tax, accounting and legal duties | Billing and contract records | Art. 6(1)(c): a legal obligation |
Where we rely on legitimate interest, we have weighed that interest against your rights, and you can ask to see the assessment.
A.3 How long we keep it
- Requests from people who don’t become customers: 12 months from our last contact, then deleted.
- Customer contact and contract records: for the length of the agreement plus 6 years, to cover legal claims and accounting rules.
- Server logs: 30 days.
- A record that you objected or opted out: kept indefinitely, so we can keep respecting it.
A.4 Your rights
If you are in the EEA or the UK, you can ask to see your data, correct it, have it deleted, limit or object to how we use it, get a copy you can take elsewhere, and withdraw consent where we rely on it. Write to [email protected] and we will answer within one month.
You can also complain to a data protection authority. If you are in the EEA, that can be the authority where you live or work.
Part B: data inside the service
Two things reach us and they carry different risks. A recording is your product, captured by you, and whatever tenant you recorded against is in it. A context object is about a third party, usually a company and sometimes a named person, and you are handing it to us so that it appears on a screen. This part describes both.
B.1 What we handle, and in what role
Account data, meaning your work email, company and billing details, we hold as a controller. Recordings, context objects, generated demos and their analytics we process as your processor, on your instruction, for as long as you keep them.
- The recordings you upload. Frames, the captured element tree and audio if present. Whatever was on screen in the tenant you recorded is in them, including any real customer data you left there.
- The context you post. The fields you send with each call: company name, industry, system names, figures, and any string you choose to substitute. We store the object so a demo can be regenerated and audited.
- Demo analytics. Which steps a viewer reached, how long they spent and whether they finished, tied to the demo URL rather than to a named person unless you put a name in the context.
- Reviewer decisions. Which flagged spans a person on your side approved or corrected, stored as a span with its screen context and the confirmed rule.
We do not enrich. Nothing you post is looked up, matched against a third-party database or used to infer anything about the company named in it.
A demo URL is unguessable but it is a link, and a link can be forwarded. Treat a demo containing a prospect's figures the way you would treat an email containing them.
If you record against a live tenant, real customer data enters our processing. We recommend a seeded tenant during onboarding and we cannot enforce it.
B.2 What we do with it
Generated demos. Stored with their context object and their analytics until they expire or you delete them. Expiry defaults to 30 days from generation and you can set it per call.
Deletion is one call. Deleting a demo removes the rendered artifact, its context object and its analytics together. There is no archived copy and nothing survives for reporting.
The reviewer corpus. Approved substitution rules stay in the account that produced them. They are not pooled and not used to improve substitution for anybody else.
The interface taxonomy. Whether a region is a header cell, a chart axis or body copy does carry across accounts. It is a claim about interfaces and contains no string, frame or context of yours.
B.3 AI models: where they run and what they learn from
Where models run. Inference on your recordings and context runs on AWS in eu-west-1 (Ireland), on EC2 GPU instances running models we operate. Those models are trained on Azure Machine Learning in North Europe, also in Ireland. A hosted third-party inference endpoint is used only for offline model evaluation, against a held-out set of captures we made ourselves, under a zero-retention and no-training agreement, and it is listed in our subprocessor register. From the first quarter of 2027 that endpoint may be Azure OpenAI in North Europe, under zero data retention. No customer recording, frame or context object is ever sent to it.
Training. We do not train on customer recordings or context objects. The exception is exactly this: reviewer approvals train the substitution classifier for the account that produced them and no other, and corrections to the generic interface taxonomy, meaning whether a region is a header cell, a chart axis or body copy, are shared across accounts because they describe interfaces rather than your product and carry no string of yours. We train on Azure Machine Learning in North Europe (Ireland) and serve the result on AWS in eu-west-1.
Where a person decides. The classifier proposes a substitution; below 0.95 confidence it substitutes nothing and flags the span instead, so an uncertain call produces a more generic demo rather than a wrong one. Flagged spans wait in a queue for a named person on your side to approve or correct. No automated decision made here has a legal effect on any person: the subject of every classification is a region of a screen you recorded.
B.4 Where the data is kept
Amazon Web Services, eu-west-1 (Ireland): recording ingest, rendering and substitution-classifier inference on EC2, including GPU instances running models we operate, and recordings, context objects and generated demos in S3.
Microsoft Azure, North Europe (Ireland): Azure Machine Learning trains the substitution classifier on each account's reviewer approvals and trains the shared interface taxonomy.
Both providers process in Ireland, and both are listed in our subprocessor register. Demo URLs are served from eu-west-1 with no global edge cache, which costs a viewer in Sydney some milliseconds and keeps the frames in one jurisdiction.
Offline model evaluation uses a held-out set of our own captures and never touches customer recordings. From the first quarter of 2027 it may run on Azure OpenAI in North Europe, under zero data retention.
B.5 How long we keep it, and what deleting can’t remove
Generated demos, their context objects and their analytics: until expiry, which defaults to 30 days, or until you delete them.
Recordings: for the life of the account, because every demo is derived from one. Deleting a recording deletes the demos derived from it.
Reviewer corpus: for the life of the account, deleted with it.
Account and billing records: seven years after closure, which is the Irish statutory retention period.
API request logs without payloads: 90 days.
B.6 Requests from people whose data is in the service
A context object may name a person at the prospect company. If one of them asks you what you hold, the answer is in your account and exportable; if they ask us, we will route them to you as the controller of that decision. For data we hold about you as a customer, write to [email protected] and we will answer within 30 days.
For everyone
5. Moving data between countries
Understudy is a company in Ireland, inside the EEA. Section B.4 says where the data in the service is kept. If any personal data we control ever has to leave the EEA, for example because a supplier named on our subprocessor page handles it elsewhere, it is protected by the European Commission’s Standard Contractual Clauses or another safeguard the GDPR accepts. You can ask us for a copy.
6. Security
We protect data in line with the risk. That includes encryption in transit and at rest, access limited to the people and systems that need it, each customer’s data kept separate from every other’s, and a log of every access to production systems.
If a personal data breach affects you, we tell you without undue delay, and at the latest within 36 hours of finding out, with the information you need to meet your own reporting duties.
7. Children
The service is sold to businesses and is not meant for children. We don’t knowingly collect personal data from anyone under 16.
8. Changes to this policy
We may update this policy. If a change matters, we email customers at least 30 days before it takes effect. The version number and date at the top of this page change every time.
9. Contact
Privacy questions and anything else: [email protected]
By post: Understudy, Understudy Software Ltd, 12 Hanover Quay, Dublin 2, D02 XY45, Ireland