Data processing agreement
Under Art. 28 GDPR between you (controller) and [to be filled in] (processor). It applies when the main contract is concluded; you do not have to sign it separately.
2026-10-09
Subject and duration
What is processed is what you put into the product and create in it, for the term of the main contract.
Types of data and data subjects
Contact data of your staff, the content of your company profile, uploaded images and therefore possibly pictures of people. Data subjects: your staff, your customers, people shown.
Instructions
We process the data only on your instructions. Using the product is the instruction; anything beyond it you instruct in writing.
Sub-processors
You agree to the following sub-processors. We announce changes 30 days ahead; you may object and terminate in that case.
Railway Corporation — Servers, database and media storage (the media storage runs on Tigris Data, Inc.) — USA; servers in the EU region Amsterdam (Netherlands) — All content and accounts
Stripe Payments Europe, Ltd. — Payments, invoices, tax calculation — Ireland (EU), group in the USA — Name, address, VAT id, payment data
Resend — Sign-in links and system messages — EU region — Email address
Anthropic Ireland, Limited (Claude) — Text models for the advisor, the agent, the director and the content check — Ireland (EU), processing in the USA — Company profile, scripts, prompts and pictures the model is to look at (such as stills for the director)
Google Cloud (Vertex AI, EU-Region) — Standard voice and a video model — EU (europe-west4) — The text to be spoken; for the video model, prompts and reference images
fal.ai (Features & Labels, Inc.) — Image, video and 3D models, lip sync, music, upscaling — USA — Prompts and reference images; for lip sync, the clip and the voice
Higgsfield Inc. — Image and video models — USA — Prompts and reference images
ElevenLabs Inc. — Text to speech — USA — The text to be spoken
OpenAI Ireland Ltd. — Image model — Ireland (EU), group in the USA — Prompts and reference images
Sentry (EU) — Error reports — EU — Technical error data, no content
Technical and organisational measures
Encryption in transit (TLS) and in object storage; access to customer data only through the application and only for authorised accounts; roles and permissions per organization; separated environments; backups with restore tests; logging of security-relevant events; signed, expiring links for media; rate limits against abuse; a virus scan of every uploaded file in our own server environment before it is processed, then re-encoding of images without metadata.
Assistance and notifications
We help you with access, erasure and rectification requests, inside the product through export and deletion. We report any data breach without delay, at the latest within 48 hours of becoming aware.
Deletion at the end
After the contract ends we delete your data within 30 days unless a legal retention duty says otherwise. On request you get a full export first.
Audits
You may verify compliance; usually a written self-assessment is enough, in individual cases an audit announced in advance during business hours.
