Skip to main content
RecallStream
How it worksSourcesAPIPricingFAQAboutContact
Sign inStart free →
How it worksSourcesAPIPricingFAQAboutContact
Sign inStart free →

Data Processing Agreement

Last updated: June 23, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Sole Proprietor (FOP) Kharchenko Yaroslav Oleksandrovych ("RecallStream", "Processor") and the Customer ("Controller"). It applies to the extent RecallStream processes Personal Data on behalf of the Customer in the course of providing the Service. Counter-signed copies are available on request for Business customers — email privacy@recallstream.com.

  • "Applicable Data Protection Law" means the EU General Data Protection Regulation 2016/679 (GDPR), the UK GDPR, the Ukrainian Law on Personal Data Protection, and any other applicable national data protection legislation.
  • "Controller" means the Customer, who determines the purposes and means of processing Personal Data.
  • "Processor" means RecallStream, which processes Personal Data on behalf of the Controller.
  • "Personal Data" has the meaning given in the GDPR: any information relating to an identified or identifiable natural person.
  • "Customer Personal Data" means Personal Data that the Controller submits to the Service or that RecallStream processes on the Controller's behalf to provide the Service.
  • "Sub-processor" means any third party engaged by RecallStream to process Customer Personal Data.
  • "Security Incident" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.

Subject Matter

RecallStream processes Customer Personal Data to: (a) provide the recall-feed aggregation, normalisation, and webhook-delivery service; (b) store and manage the Customer's watchlist configurations, webhook endpoint registrations, API keys, and recall event history; and (c) deliver recall match events to Customer-registered endpoints and make them available via the API.

Data Subjects

The categories of data subjects whose Personal Data RecallStream processes on behalf of the Customer include: the Customer's authorised users who access the RecallStream platform; individuals holding API keys issued under the Customer's account.

Categories of Personal Data

  • Identification data: name, email address
  • Authentication data: hashed API keys (rr_…), session identifiers
  • Account contact information: email address, billing name
  • Network and device data: IP addresses, browser user-agent strings
  • Usage metadata: timestamps, API request logs, webhook delivery logs

Duration

Processing continues for the duration of the Customer's subscription and until data is deleted in accordance with Section 9.

RecallStream processes Customer Personal Data only on documented instructions from the Controller, including instructions given through the Controller's use of the Service (e.g., creating watchlists, registering webhook endpoints, deleting account data). The Terms of Service and this DPA constitute the Controller's complete instructions as of the date of this DPA.

If RecallStream is required to process Customer Personal Data for any other purpose by applicable law, RecallStream will inform the Controller of that legal requirement before processing unless prohibited by law.

RecallStream ensures that persons authorised to process Customer Personal Data are subject to contractual or statutory duties of confidentiality. RecallStream does not permit access to Customer Personal Data by any personnel who do not require it to perform their role in delivering the Service.

RecallStream implements and maintains technical and organisational measures appropriate to the risk, including:

  • Encryption in transit: TLS 1.2 or higher enforced on all Service endpoints; HSTS enabled.
  • Storage protection: Customer Personal Data is stored on EU (Germany) infrastructure with access restricted to the operator; database backups are stored in access-controlled EU object storage with a 30-day lifecycle.
  • Credential protection: passwords hashed with Argon2; API keys stored as one-way hashes; webhook signing secrets encrypted (AES-256-GCM) at the application layer; none logged in plaintext.
  • Access controls: role-based access control (RBAC) within the Service; production access limited to the operator, authenticated with SSH keys, with no shared or standing third-party access.
  • Log redaction: automated redaction of credentials and secrets in the logging pipeline before storage.
  • Backups: daily database backups stored in access-controlled EU object storage, expiring automatically after 30 days.
  • Incident response: documented Security Incident Response Plan with defined roles, escalation paths, and notification timelines.

See our Security page for a full overview.

RecallStream engages the following sub-processors to process Customer Personal Data. The Controller authorises RecallStream to use these sub-processors, subject to the flow-down obligations in this Section.

Sub-processorRoleLocation
Hetzner Online GmbHCloud infrastructure (compute, database hosting) and access-controlled object storage for database backupsEU (Germany)
Cloudflare, Inc.CDN, DDoS protection, DNSUSA (EU data processed in EU)
Resend, Inc.Transactional email delivery (verification, match alerts)USA
Plausible Insights OÜWebsite analytics (cookieless — aggregate only, no personal data)EU (Estonia)

Paddle.com Market Ltd acts as Merchant of Record and independent controller for payment data (see our Privacy Policy); it is not a sub-processor of Customer Personal Data.

RecallStream will notify the Controller before adding new sub-processors and will accept objections on reasonable data-protection grounds.

RecallStream will assist the Controller in fulfilling data subject requests (access, rectification, erasure, restriction, portability) within the timeframes required by Applicable Data Protection Law. The Controller may submit DSR assistance requests via privacy@recallstream.com.

RecallStream will notify the Controller of a confirmed Security Incident without undue delay and, where feasible, within 72 hours of becoming aware of it. Notification will include the nature of the incident, categories of data affected, likely consequences, and measures taken or proposed. The Controller is responsible for notifying supervisory authorities and data subjects as required by Applicable Data Protection Law.

Upon termination of the Service, RecallStream will delete Customer Personal Data within 30 days, unless retention is required by applicable law. Backup copies will be purged within 35 days. Upon request submitted within the 30-day window, RecallStream will provide the Controller with a machine-readable export of Customer Personal Data before deletion.

RecallStream will make available to the Controller all information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller, no more than once per calendar year, with reasonable prior notice and subject to reasonable confidentiality restrictions.

Where RecallStream transfers Customer Personal Data from the EEA or UK to a third country, it relies on Standard Contractual Clauses (Module 2 or 3 as applicable) approved by the European Commission, and the UK International Data Transfer Addendum where required. Copies are available on request.

In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with respect to the processing of Customer Personal Data. A countersigned DPA takes precedence over this published version.

For DPA enquiries, countersigned copy requests, or data protection questions:

  • Privacy / DPA: privacy@recallstream.com
  • Security incidents: security@recallstream.com
  • Post: Sole Proprietor (FOP) Kharchenko Yaroslav Oleksandrovych, Komunalna St 16, Hlukhiv, Sumy Oblast, 41400, Ukraine
RecallStream

Cross-agency product-recall intelligence — normalized, near-real-time, developer-friendly.

Sole Proprietor (FOP) Kharchenko Yaroslav Oleksandrovych
Komunalna St 16, Hlukhiv, Sumy Oblast, 41400, Ukraine

Product

  • Pricing
  • API Docs
  • FAQ

Sources

  • openFDA
  • CPSC
  • NHTSA
  • EU Safety Gate
  • FSIS (coming soon)

Company

  • About
  • Contact
  • Security

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Refund Policy
  • Data Sources & Licensing
  • Acceptable Use
  • Do Not Sell / Share
  • Accessibility
  • DPA Overview

© 2026 RecallStream