VEDEO · Legal

Data Processing Addendum

Last updated: September 2026

This addendum forms part of the Terms of Service and governs our processing of personal data on your behalf. Where it conflicts with the Terms, this addendum takes precedence for data protection matters.

This addendum applies where you use VEDEO for business purposes and personal data of your own contacts, staff or customers is involved. For personal use, our Privacy Policy is the operative document.

Roles of the parties

For personal data you submit to VEDEO in the course of using the service, you are the controller and we are the processor. We process that data only on your documented instructions — your use of the service being the primary instruction — except where law requires otherwise, in which case we will tell you unless prohibited from doing so.

For your own account and billing data we act as a controller in our own right, and our Privacy Policy applies.

Scope, nature and duration

ItemDetail
Subject matterGenerating short-form video from text you supply
DurationFor as long as your account is active, plus the retention periods described below
Nature and purposeStorage, transmission, automated text and speech generation, media retrieval and video composition
Types of personal dataAny personal data contained in prompts, scripts or uploaded material you choose to submit; your account contact details
Categories of data subjectYour personnel and any individuals referenced in the content you submit
Special category dataNot requested and not required. Do not submit it.

Our obligations

  • Process personal data only on your instructions, and only for the purposes above.
  • Ensure personnel with access are bound by confidentiality.
  • Apply the technical and organisational measures described below.
  • Assist you, so far as is reasonable, with data subject requests and with data protection impact assessments.
  • Make available the information you need to demonstrate our compliance.
  • Delete or return personal data at the end of the engagement, as set out below.

Sub-processing

You give general authorisation for us to engage sub-processors. Each is engaged under a written contract imposing data protection obligations no less protective than those in this addendum, and we remain liable for their performance.

We describe sub-processors by the role they perform rather than by name, so that this document stays accurate when a vendor in a role is replaced. The current roles are:

RoleProcessing performedData involved
Cloud hosting providerHosts the application, the rendering service and generated-file storageAll data, in transit and at rest
Managed database providerStores structured platform recordsAccount, project, generation and billing records
Payment processorTakes payment, manages subscriptionsContact and payment data
Email delivery providerSends transactional emailEmail address and message contents
Language model providerGenerates the scriptPrompt text and creative direction
Speech synthesis providerGenerates narration audioScript text
Stock media librariesSupply footageShort search terms derived from the script

We maintain a register naming the specific provider in each role, available on request. We will give you at least 30 days' notice before adding or replacing a sub-processor in a role, and you may object on reasonable data protection grounds; if we cannot resolve your objection, you may terminate the affected part of the service without penalty.

International transfers

Processing takes place primarily in the United States. Where personal data is transferred from the United Kingdom or European Economic Area, the transfer is made under Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies, and supplemented by the measures in the security section.

Technical and organisational measures

  • Encryption of data in transit across all public networks.
  • Passwords hashed with a memory-hard algorithm and a server-side secret held outside the database.
  • Opaque session tokens stored only as hashes, in cookies restricted against cross-site sending.
  • Network isolation of the rendering service, which is unreachable from the public internet and accepts only authenticated calls from the application.
  • Per-object authorisation checks on every read of customer content, including file downloads, which are proxied rather than served directly.
  • Rate limiting on authentication and on generation, and the ability to suspend an account immediately.
  • Least-privilege administrative access, with credential material excluded from administrative views.
  • Versioned, reviewed database migrations and an immutable financial ledger.

Personal data breaches

We will notify you without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting your data. The notification will describe the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and the measures taken or proposed. We will not make a public statement identifying you without your agreement unless legally required.

Audit

On reasonable written notice, and no more than once in any twelve-month period unless required by a supervisory authority, we will respond to a reasonable security questionnaire and provide the information necessary to demonstrate compliance with this addendum. Any on-site audit must be conducted during business hours, must not unreasonably disrupt the service, and is subject to confidentiality.

Return and deletion

You can export your generated videos at any time while your account is active. On termination we will delete personal data processed on your behalf within 90 days, except where we are required to retain it by law — financial records, for example, are kept for the statutory period. Backups are overwritten on their ordinary cycle.

Contact

Data protection enquiries, sub-processor register requests and audit requests should be sent to the support address published at vedeo.studio, marked for the attention of the data protection contact.