Legal · Data protection
GDPR Compliance
Last updated: September 2026
1. Our Commitment to GDPR
DemoFast is committed to compliance with the General Data Protection Regulation (GDPR) and respects the privacy rights of individuals in the European Union (EU) and European Economic Area (EEA). This page explains how we comply with GDPR and how you can exercise your rights.
2. Two Roles: Controller and Processor
DemoFast handles two different kinds of personal data, and our legal role is different for each. Which section applies to you depends on how you came into contact with us.
2.1 We are the controller of your account data
When you sign up, subscribe, contact support or browse this website, we decide why and how that data is processed. This covers:
- Your name, email address and profile photo
- Workspace and team membership
- Subscription, billing and purchase records
- Sign-in sessions, including device and browser description
- Product usage analytics and support correspondence
2.2 We are a processor of your demo content and your leads
When you record a demo, you decide what to record. When you turn on lead capture, you decide what to ask viewers. We store and serve that material on your instructions and do not use it for our own purposes. This covers:
- Screenshots of the pages you record
- Interactive page captures, where enabled on your plan
- Annotations, titles and other text you add
- Lead submissions: the email address, name and answers viewers give your demos
- View statistics for your published demos
For this category you are the controller and we are your processor. You are responsible for having a lawful basis to record what you record and to ask viewers what you ask them, and for telling those people how their data is used.
2.3 Data Processing Agreement
Article 28 requires a written contract for the processing described in 2.2. Our Data Processing Agreement covers it — it names every sub-processor, sets out our security measures, and incorporates the EU Standard Contractual Clauses for international transfers. Request a copy, countersigned if you need that, from support@demofa.st.
3. What a Recording Captures
A recording is a series of screenshots of whatever was on screen when you clicked, and on paid plans an optional structured copy of the page so viewers can click through it. Anything visible on the pages you record — including other people's personal data — is captured unless it is masked or you avoid recording it.
Protections applied automatically, on every plan:
- Values typed into form fields are replaced with asterisks before anything is uploaded
- Password fields are always masked, and masking happens in your browser — the original text never reaches us
Blurring specific elements in the screenshot itself is a Pro feature. On other plans the screenshot is not blurred, so avoid recording screens containing personal data you do not intend to publish.
Recording checkouts, banking or health screens is not recommended on any plan. See our Privacy Policy for the full detail.
4. Legal Basis for Processing
Where we act as controller (section 2.1), we process personal data under the following legal bases:
4.1 Contract Performance
Processing necessary to provide the Service you've signed up for, including:
- Account management
- Demo creation and management
- Premium feature access
- Payment processing
4.2 Legitimate Interest
Processing necessary for our legitimate business interests:
- Service improvement and optimization
- Fraud prevention and security
- Customer support
- Product usage analytics
4.3 Consent
For marketing communications, where we send them. You can withdraw consent at any time.
4.4 Legal Obligation
To comply with applicable laws, such as tax and accounting requirements.
4.5 Automated Decision-Making
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects (Article 22).
5. Your GDPR Rights
Under GDPR, you have the following rights:
5.1 Right to Access (Article 15)
You can request a copy of all personal data we hold about you. We will provide this within 30 days.
How to exercise: Email support@demofa.st or contact us through your account settings.
5.2 Right to Rectification (Article 16)
You can correct inaccurate or incomplete personal data.
How to exercise: Update your information in Settings → Account, or contact us.
5.3 Right to Erasure / "Right to be Forgotten" (Article 17)
You can request deletion of your personal data when:
- It's no longer necessary for the purposes collected
- You withdraw consent
- You object to processing
- It was unlawfully processed
How to exercise: Settings → Security → Delete account. You will be asked to type your email address to confirm.
Your sessions end immediately and the account can no longer be used. Everything is permanently erased after a 30-day grace period, which exists so an accidental deletion can be reversed by contacting support. Workspaces you own alone are deleted with their demos, stored files and view history; a workspace with another owner is transferred to them rather than destroyed, so other people's work is not erased along with your account.
Note: We retain billing records where required by law (financial records for 7 years).
5.4 Right to Restriction of Processing (Article 18)
You can request we limit how we use your data while we investigate a concern.
5.5 Right to Data Portability (Article 20)
You can receive your data in a structured, machine-readable format and transfer it to another service. Lead data can be exported yourself at any time as CSV from a demo's analytics page.
How to exercise: For everything else, email support@demofa.st and we will send a JSON export within 30 days.
5.6 Right to Object (Article 21)
You can object to processing based on legitimate interests or for direct marketing.
How to exercise: Unsubscribe from marketing emails or contact us to object to specific processing.
5.7 Right to Withdraw Consent (Article 7)
Where processing is based on consent, you can withdraw it at any time.
5.8 If you watched a demo or submitted your details to one
Demos are published by our customers, not by us. If you gave your email address to a demo, or appear in one, the controller is the business that published it — contact them first. You can also write to us and we will identify the customer and pass the request on, or act on it directly where they instruct us to.
5.9 Right to Lodge a Complaint
You have the right to file a complaint with your local supervisory authority.
Find your data protection authority: EDPB Member List
6. Sub-Processors
We use the following providers, each under a data processing agreement with appropriate safeguards. This list is kept current; material additions are announced on this page.
- Cloudflare (R2): storage of screenshots, page captures and uploaded images
- Vercel: hosting of this website and the web application
- Google: optional sign-in with Google
- Polar: subscription and one-time payment processing
- Resend: transactional email — verification, password reset, invitations
- PostHog: product analytics inside the signed-in application. EU-hosted. Not used on published demos — see section 12
- Slack: internal operational notifications, which include the name and email address of new signups
Card details are handled entirely by our payment processor. We never receive or store card numbers.
7. Data Controller and Contact
7.1 Who we are
DemoFast is the data controller for the account data described in section 2.1, and a processor for the demo content and lead data described in section 2.2.
7.2 Data protection contact
We are not required to appoint a formal Data Protection Officer under Article 37. Data protection questions and rights requests go to support@demofa.st.
8. International Data Transfers
Your data may be transferred outside the EU/EEA to countries that may not offer the same level of data protection. We ensure adequate protection through:
- Standard Contractual Clauses (SCCs): EU-approved data transfer contracts
- Adequacy Decisions: Transfers only to countries approved by the EU Commission
- Additional Safeguards: Encryption in transit, access controls, least-privilege credentials
9. Data Retention
We retain personal data for different periods:
- Account Data: until you delete your account, then a 30-day grace period, then permanent erasure
- Demo Data: until you delete the demo or your account — there is no trash can, deletion is immediate
- Lead Data: until you delete it or close your account. Deleting a demo does not delete the leads it collected, so a demo can be removed without losing the pipeline it produced
- Demo View Statistics: until you close your account. Deleting a demo does not delete its view history, so past traffic figures stay accurate — the views did happen. No visitor can be identified from them after the day they occurred
- Billing Records: 7 years (legal requirement)
- Support Tickets: 2 years
- Product Analytics: signed-in application usage, retained according to our analytics provider's configured retention period
- Server Logs: retained according to our hosting providers' log retention periods
One technical note: images and stylesheets captured from a recorded page are stored once and shared between the demos that reference them. When the last demo referencing a file is deleted, that file is removed by a daily clean-up, so it can persist for up to 24 hours after the demo itself is gone.
10. Security Measures
We implement technical and organizational measures to protect your data:
Technical Measures
- TLS 1.2 or higher for all data in transit
- Passwords stored only as salted hashes, never in readable form
- Form field values masked in your browser before upload
- Private demo files served only through authenticated, workspace-scoped requests
- Secure OAuth authentication and server-side session revocation
- Regular dependency and security updates
Organizational Measures
- Access controls and least privilege principle
- Data processing agreements with vendors
- Regular security reviews
- Incident response procedures
11. Data Breach Notification
In the event of a data breach affecting your personal data:
- We will notify the relevant supervisory authority within 72 hours
- We will inform affected users without undue delay
- Where we act as your processor, we will notify you without undue delay so you can meet your own obligations
- We will describe the nature of the breach and steps being taken
12. Cookies and Tracking
12.1 Watching a demo
Published demos set no cookies and store nothing in your browser. This applies both to demo links and to demos embedded in another company's website, so no consent banner appears inside our customers' products.
View counts are worked out on our server instead. To tell repeat views apart without storing anything on your device, we derive a one-way code from your connection and browser, mixed with a secret that is changed every night. The code cannot be reversed, and tomorrow's code for the same person is unrelated to today's — so views can be counted, but no viewer can be recognised from one day to the next or followed between different companies' demos. Your IP address itself is never stored.
12.2 This website
Sets no analytics or advertising cookies.
12.3 The signed-in application
For account holders at app.demofa.st only:
- Essential storage: your sign-in session and interface preferences. Required for the application to work
- Product analytics: PostHog, used to understand how account holders use the product
We set no advertising cookies and do not sell or share personal data for advertising.
To object to product analytics, email support@demofa.st or enable your browser's tracking protection.
13. Children's Data
We do not knowingly process data of individuals under 13 (or 16 in EU/EEA countries where applicable). If you're under the applicable age, please do not use our Service.
14. How to Exercise Your Rights
To exercise any of your GDPR rights:
- Email us: support@demofa.st
- Check your settings first: profile details, password, active sessions and account deletion are all self-service
- Include in your request: Your name, email address, and the specific right you're exercising
Response time: We will respond within 30 days (may extend to 60 days for complex requests).
Free of charge: We do not charge fees unless requests are manifestly unfounded or excessive.
15. Updates to GDPR Policy
We may update this GDPR compliance statement. Material changes will be communicated via email and on this page with an updated "Last updated" date.
16. Contact Information
For any GDPR-related inquiries, please contact us at:
support@demofa.stSee also: Terms of Service | Privacy Policy