Data Processing Addendum
Last updated: 2026-10-03This Data Processing Addendum ("DPA") forms part of the agreement between you (the "Customer") and aidubbing AI ("aidubbing", the "Provider") for the processing of personal data under our Terms of Service. It reflects the requirements of Article 28 of the EU General Data Protection Regulation.
1. Definitions
"Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach", "Supervisory Authority" and "SCCs" have the meanings given in the GDPR and the European Commission's Standard Contractual Clauses.
2. Roles
You are the Controller of the personal data in the content you upload. aidubbing acts as the Processor and processes that data only on your documented instructions - namely, to perform the transcription, translation, dubbing, lip-sync and export functions you request.
aidubbing acts as an independent Controller for the limited data it needs to run and secure its own service: account and billing records, security logs and aggregate usage statistics. That data is described in our Privacy Policy.
3. Processing details
| Item | Detail |
|---|---|
| Subject matter | AI video translation and localization services |
| Duration | For the term of the Agreement, plus the retention periods below |
| Nature of processing | Storage, extraction of audio, transcription, translation, speech synthesis, video rendering, export |
| Purpose | To produce the localized outputs you request |
| Personal data categories | Video, audio and images of Data Subjects; names and voices; contact details in project titles; user account and billing data |
| Data subject categories | Your end users, customers, employees or any person appearing or speaking in uploaded media |
4. Sub-processors
You authorise the use of these sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Payment processor (Creem) | Billing | United States |
| AI and speech model providers | Transcription, translation, speech synthesis | United States / European Union |
| Object storage provider | Media storage and delivery | Selected at deployment |
| Email delivery provider | Transactional email | Selected at deployment |
| Cloud infrastructure provider | Hosting and logging | Selected at deployment |
We will give at least 30 days' notice of any intended change to this list, and you may object in writing during that period. If we cannot resolve the objection, you may terminate the affected service without penalty.
5. Security measures
We maintain the following technical and organisational measures:
- TLS 1.2 or higher for all data in transit, and encryption at rest for stored media.
- Owner-scoped database queries so one customer can never read another's data.
- Password hashing with bcrypt; no plaintext credentials stored.
- Short-lived, signed access tokens with refresh rotation.
- Media stored under per-user paths with non-guessable identifiers.
- Audit logging of administrative access and changes.
- Regular dependency scanning and a documented incident response procedure.
6. Confidentiality
Every person we authorise to process personal data is bound by confidentiality obligations at least as protective as those in this DPA.
7. Security incidents
On becoming aware of a Personal Data Breach, we will notify you without undue delay and in any event within 48 hours, with the information required under Article 33(3) GDPR: the nature of the breach, the categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed. We will cooperate with your notification to the competent Supervisory Authority.
8. Data subject rights
Taking into account the nature of the processing, we will assist you - where reasonably possible - with requests to exercise rights under Chapter III GDPR: access, rectification, erasure, restriction, portability and objection. Because the content is yours, you can also delete a project yourself, which starts erasure immediately. Requests concerning your own account can be sent to support@vozo.ai.
9. Audit rights
We will make available the information necessary to demonstrate compliance with Article 28 and, on reasonable written request with at least 30 days' notice, allow an independent auditor appointed by you to audit our controls once per year at your cost. We will address findings raised by such an audit with reasonable diligence.
10. Deletion and return
On termination, and at your request at any time, we delete or return all personal data processed on your behalf, unless the law requires us to retain it. Media and generated outputs are purged within 30 days; billing records are retained for 7 years for tax obligations; security logs for 12 months. Deletion from backups completes within 90 days.
11. International transfers
Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses (Module 2, controller to processor), completed with the UK Addendum where relevant. Where an adequacy decision applies, we rely on that instead. A current list of transfer mechanisms is available on request.
12. Liability
Liability under this DPA is subject to the limitation of liability in our Terms of Service, except where the law does not permit a limitation for data protection breaches.
13. Order of precedence
If this DPA conflicts with the Terms of Service on the protection of personal data, this DPA prevails.
14. Contact
To execute this DPA or to raise a data protection question, contact support@vozo.ai. We will countersign within 10 business days.
15. Signatures
| Customer | aidubbing AI (Provider) |
|---|---|
| Name: Title: Email: Date: |
Name: Authorised representative Email: support@vozo.ai Date: |