1. Scope and roles
APIRecap is operated by MOLEBYTES LTD, trading as APIRecap (“we”, “us” and “our”).
- Company number: 17406550.
- Registered in England and Wales as a private limited company.
- Privacy enquiries: hello@apirecap.com.
- Support and legal notices: hello@apirecap.com.
This agreement, when accepted, supplements the terms and conditions between us and the customer responsible for the workspace. It takes precedence for our processing of personal information on that customer’s behalf.
The customer is the controller, or a processor authorised by its controller to appoint us. We act as its processor or subprocessor for the processing described below. Where the customer acts for a client, it must have authority to give the instructions and authorisations in this agreement.
Our separate controller activities, including managing our business, account administration and optional public-site analytics, are described in the privacy policy.
2. What we process and why
- Subject matter and purpose
- Hosting and versioning the customer’s API documentation, detecting changes, drafting and publishing release notes, managing reader access, sending requested release alerts and supporting that service.
- Activities
- Receiving, storing, organising, comparing, generating text from, displaying, transmitting and deleting information according to the customer’s settings and instructions.
- People concerned
- The customer’s team, clients, API users, documentation readers, release subscribers and people whose details the customer includes in its documents or support requests.
- Information
- Names or other personal details included in documents, logos and release notes; subscriber email addresses, scopes and confirmation/delivery records; access permissions; and page-open records associated with projects, versions and share links. APIRecap’s reader-event records do not store reader IP addresses or user agents; separate infrastructure records may do so.
- Duration
- For the requested service and the deletion and backup periods in section 7. Provider diagnostics have separate stated lifetimes.
The service is not intended for special-category information, criminal-offence information or live credentials. Use synthetic examples and include only personal information necessary for the documented purpose.
3. Processing on your instructions
We will process customer personal information only on documented instructions, including for international transfers, unless UK law requires otherwise. If legally permitted, we will tell you about that requirement before processing. We will inform you if an instruction appears to infringe applicable data protection law.
Your uploads, access settings, note approvals, subscriber features and deletion requests form part of your instructions. Further instructions may be sent to hello@apirecap.com. You must establish a lawful basis, provide required notices and have authority to supply and share the information.
4. Confidentiality and security
We will bind authorised personnel to confidentiality and use appropriate technical and organisational measures under Article 32 of the UK GDPR, including proportionate access controls, resilience, recovery and assessment of those measures.
Application controls include workspace and project permissions, password hashing, hashed publishing-key secrets, encrypted stored share/subscriber tokens, revocable share links and diagnostic redaction. This field-level encryption does not cover all documents, database fields or backup contents. APIRecap does not currently provide multi-factor authentication.
We will maintain appropriate protections for service connections, storage and backups, restrict staff access to authorised purposes, and regularly assess security and recovery measures. These are contractual obligations; no security certification or independent audit is claimed.
5. Subprocessors and international transfers
When agreeing this document, you authorise the listed subprocessors for the stated activities. We will give advance notice of intended additions or replacements and a meaningful opportunity to object on data-protection grounds before the new processing starts. An unresolved objection must be addressed through an alternative arrangement or ending the affected processing.
We will require equivalent applicable data-protection obligations from subprocessors and remain responsible to you for their compliance. Restricted transfers must have an applicable UK adequacy basis or appropriate safeguards and any required assessment.
- Amazon Web Services
- Application hosting, database/storage and RDS snapshots in London,
eu-west-2; transactional email through Amazon SES in London; limited change facts and version numbers through Amazon Bedrock’s UK/EU inference routing. Full documents are not sent in the AI request. See the AI disclosure for locations and model-specific handling. - Better Stack
- Redacted diagnostic logs and exceptions in US West (Oregon), United States. Retention is 2 days for logs and 90 days for errors.
- Google Workspace
- Our support mailbox, if customer personal information is included in a support request. Default data-region settings allow processing outside the UK.
Web3Forms waitlist collection, public-site Google Analytics and payment processing by Stripe concern our separate business activities rather than the documentation processing authorised here. Their handling is disclosed in the privacy policy.
We will provide the applicable provider identity and transfer information on request. Notices of intended subprocessor changes will go to the workspace’s account contact, describe the processing and locations, and explain how to raise an objection.
6. Rights requests and incidents
We will help you fulfil data-subject rights requests through appropriate measures. We will pass customer-data requests to you and follow your instructions unless the law requires a direct response.
We will notify you without undue delay after becoming aware of a personal data breach affecting your information, provide available details and updates, and assist with security, breach notifications, impact assessments and regulator consultation, taking account of the processing and information available to us.
7. Returning and deleting information
At the end of processing, we will, at your choice, return or delete customer personal information and delete remaining copies unless UK law requires retention. Contact hello@apirecap.com to instruct us, including during suspension or closure. We verify your authority, agree the scope and arrange a secure transfer of retained data. Request return before permanent deletion; erased data cannot be returned.
The Owner can download retained workspace data through Account settings and, while recoverable, the closure page. It includes original document content and relevant metadata in a machine-readable form, with APIRecap authentication secrets excluded.
Owner-initiated workspace closure stops ordinary access immediately. The Owner can reopen it or use the limited download option before 30 days; after the deadline, recovery and export are blocked and the hourly purge removes its accounts and content from the live application.
Unconfirmed release subscriptions expire seven days after the latest confirmation request; unsubscribed records are removed after 30 days. Both are cleaned up hourly. Requested active subscriptions remain until ended or their associated content is deleted.
During routine service, team activity and reader events retain 90 days and are pruned hourly; support correspondence retains 12 months after the last reply; local application logs retain the current and previous calendar day. Diagnostics follow the periods in section 5. These routine periods do not override your valid instructions to delete remaining processor copies at the end of processing. We will apply those instructions to relevant provider-held copies too.
Any minimal records retained for our separate controller purposes, such as a necessary security investigation or legal claim, must have a lawful basis and a defined purpose and retention period, as explained in the privacy policy. We will explain any such exception to you. This does not permit us to retain whole workspaces or continue processing customer data on your behalf after it should be deleted.
RDS snapshots retain 30 days in London. Earlier snapshots may contain live-deleted information for up to a further 30 days. Retained backup data must remain beyond ordinary use and expire on that cycle; deletion instructions must be reapplied before a restored database is served.
8. Evidence and audits
We will provide information needed to demonstrate compliance with Article 28 and allow and contribute to audits and inspections by you or your appointed auditor. We will agree practical security and confidentiality arrangements that protect other customers without preventing required scrutiny.
Nothing here removes either party’s direct obligations or individuals’ rights under applicable data protection law. The agreed service terms govern contractual disputes, subject to those protections.
The service terms’ data-protection liability cap applies between the parties only so far as lawful. It does not restrict individuals’ compensation rights, regulatory powers or any non-excludable statutory contribution. Routine compliance information is provided without a separate charge. Any fee for additional, unusually extensive assistance must be agreed in advance and cannot prevent legally required assistance or scrutiny.
9. Agreement and changes
Keep a copy of the accepted version with your service agreement. Changes require the agreement or notice process applicable to that service agreement and cannot reduce mandatory data-protection rights. Subprocessor changes must follow section 5.
Send instructions and questions to hello@apirecap.com. We will keep a record of agreed instructions and the information needed to demonstrate compliance.