Legal
Data Processing Agreement (DPA)
Last updated: August 27, 2026
Data Processing Agreement (DPA)
Last updated: 2026-08-27
Public draft pending counsel validation (CF-06 / LIVE-02). This is not a countersigned processor DPA.
This document describes the framework under which Runway Ready AI SL (controller) and processors handle RunwayReady user personal data under GDPR Art. 28.
1. Parties
Controller: Runway Ready AI SL, CIF B27598499, Calle Faraday 7, Parque Científico de Madrid, 28049 Madrid, Comunidad de Madrid, Spain. Data protection contact: contact@runwayready.ai.
Typical processors: Apple, Google Cloud / Firebase / Vertex AI (EU), Google Play, Stripe, Shippo, fal.ai (US; DPA/SCC pending CF-04/ENG-05), OpenRouter, Brevo (email — not SendGrid), Sentry, Meta (gated on marketing consent and ATT). Full list in the Privacy Policy and vendor SLA section.
2. Subject matter & duration
Processing of account, wardrobe images, marketplace, and analytics data (if consented) while the service is active or until deletion instruction.
3. Instructions
Processors act only on documented controller instructions and not for unauthorized own marketing purposes.
4. Security & sub-processors
Appropriate technical and organizational measures; sub-processors under equivalent obligations; international transfers with SCCs or other safeguards.
5. Data-subject rights & deletion
Assist the controller with DSARs; delete or return data at end of processing, except legal retention.
Contact: contact@runwayready.ai · AEPD: https://www.aepd.es
United Kingdom addendum (UK GDPR / PECR / DPA 2018)
Sources read 2026-08-27. Not legal advice. The in-app language pack is en for en-GB as well as en-US.
If UK GDPR applies, the Information Commissioner’s Office (ICO) is the UK supervisory authority: ico.org.uk. PECR governs cookies, electronic marketing, and similar technologies in the UK (consent for non-essential storage/access, separate from document-acceptance).
Restricted transfers from the UK (e.g. to the US — fal.ai, Stripe, OpenRouter) require adequacy, an exception, or appropriate safeguards such as the ICO International Data Transfer Agreement (IDTA) or the UK Addendum to EU SCCs, plus a transfer risk assessment / data-protection test so protection is not materially lower than in the UK.
Counsel-open: countersigned IDTA/UK Addendum with fal.ai and other US processors is not complete (CF-04 / ENG-05).
Primary sources (accessed 2026-08-27): ICO — international transfers / IDTA · PECR · DPA 2018 · Cal. Civ. Code 1798.120 opt-out of sale/share · Cal. Civ. Code 1798.135 methods · CPPA FAQs · OPC — PIPEDA · Quebec Law 25 / CAI · OAIC — Australian Privacy Principles · Privacy Act 1988 (Cth) · DPDP Act 2023 · DPDP Rules 2025 (notice / grievance)