Skip to content

Last updated July 15, 2026

Data processing addendum

This data processing addendum ("DPA") forms part of the terms of service between SyntarEngine Ltd, No. 3, Avenue des Orchidees, Quatre Bornes, Mauritius ("SyntarEngine", "we") and the customer accepting the terms ("customer", "you"). It applies where the customer materials you upload, or the output composed from them, contain personal data protected by applicable data protection law, including the GDPR, the UK GDPR, and the Mauritius Data Protection Act 2017.

1. Roles and scope

Roles. For personal data contained in customer materials and in the output composed from them ("customer personal data"), you are the controller and we are your processor. Where you are yourself a processor for your own client, for example as an agency or production company working on a client's brand, you warrant that your instructions to us are consistent with your controller's instructions, and we act as your subprocessor.

Out of scope. This DPA does not cover personal data we process as a controller in our own right: account data, usage and device data, support communications, the erasure-suppression token, and transaction metadata, all described in our privacy policy, and buyer and payment data processed by the merchant of record as an independent controller.

Precedence. For the processing of customer personal data, this DPA prevails over any conflicting provision of the terms of service. The standard contractual clauses incorporated in section 12 prevail over this DPA where they conflict.

2. Details of processing

The subject matter, duration, nature and purpose of processing, the categories of data subjects, and the categories of personal data are set out in Annex 1.

3. Instructions

We process customer personal data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by law we are subject to, in which case we inform you of that legal requirement before processing unless the law prohibits it. Your instructions are: the terms of service, this DPA, and your use of the service's features and settings, including the briefs you submit, the review-gate decisions you make, and the erasure and deletion controls you operate. We will inform you if, in our opinion, an instruction infringes applicable data protection law; we are not obliged to perform a legal review of your instructions.

No training. We do not use customer personal data to train foundation models, and our corporate agreements with the generative model providers listed in Annex 3 prohibit their use of it for model training.

4. Confidentiality

We ensure that every person we authorize to process customer personal data is bound by a contractual or statutory obligation of confidentiality, and that access is limited to what each role requires.

5. Security

We implement and maintain the technical and organizational measures set out in Annex 2, appropriate to the risk of the processing, taking into account the state of the art and the nature of the data. We may update the measures from time to time, provided the updates do not materially reduce the overall level of protection during a subscription period.

6. Subprocessors

General authorization. You authorize us to engage the subprocessors listed in Annex 3. We impose on every subprocessor, by written contract, data protection obligations no less protective than those in this DPA, and we remain fully liable to you for the subprocessor's performance.

Changes. We will give you at least 30 days' notice before adding or replacing a subprocessor, by email to the account owner and by updating the published list at syntarengine.com/subprocessors, which mirrors Annex 3. If you have a reasonable data-protection objection to the change, notify us within the notice period; we will work with you in good faith on a resolution, and if none is available you may cancel the affected subscription and receive a pro-rated refund of prepaid, unused fees for the remaining period, executed by the merchant of record.

7. Data subject rights

Taking into account the nature of the processing, we assist you with appropriate technical and organizational measures, insofar as possible, in fulfilling your obligation to respond to data subjects exercising their rights: the in-product deletion and erasure controls, asset and output export, and, where a request cannot be served through the product, assistance via privacy@syntarengine.com. If a data subject contacts us directly about processing under this DPA, we will not respond on the merits except to direct them to you, unless the law requires otherwise.

8. Personal data breaches

We notify you without undue delay after becoming aware of a personal data breach affecting customer personal data, and in any event within 48 hours of becoming aware, with the information reasonably available to us at the time: the nature of the breach, the categories and approximate volumes of data and data subjects concerned, the likely consequences, and the measures taken or proposed. We update the notification as the investigation develops. Notification is not an admission of fault.

9. Assistance

Taking into account the nature of the processing and the information available to us, we assist you in ensuring compliance with your obligations concerning security, breach notification to authorities and data subjects, data protection impact assessments, and prior consultation with supervisory authorities, insofar as those obligations relate to processing under this DPA.

10. Deletion and return

During the subscription, you can export and delete customer personal data through the product at any time. On termination or expiry of the subscription, we delete customer personal data within 90 days, subject to the export window in the terms of service, unless the law we are subject to requires continued storage, in which case we protect the data and isolate it from further processing. On your written request made before deletion, we will instead return the data in a structured, commonly used, machine-readable format. Deletion extends to subprocessors under the contracts described in section 6.

11. Audits and information

We make available to you the information reasonably necessary to demonstrate compliance with this DPA, including summaries of security measures, subprocessor contracts on a confidential basis, and available third-party attestations or certifications as we obtain them. Where that information is reasonably insufficient, you (or an independent auditor you mandate, who is not our competitor and is bound to confidentiality) may audit our compliance: once in any 12-month period, on at least 30 days' written notice, during business hours, without disrupting operations, at your cost. Audits of subprocessors are satisfied by the audit rights and attestations available under our contracts with them.

12. International transfers

We are established in Mauritius, and the subprocessors in Annex 3 process data in the United States and other countries.

EU/EEA data. Where customer personal data is subject to the GDPR and is transferred to us, the parties enter into the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), which are incorporated into this DPA by reference: Module Two (controller to processor) where you are a controller, Module Three (processor to processor) where you are a processor; with the docking clause enabled; Clause 9 option 2 (general authorization, 30 days' notice); Clause 17 governed by Irish law; Clause 18 courts of Ireland; Annexes I and II of the clauses completed with the contents of Annexes 1, 2, and 3 of this DPA, with you as data exporter and SyntarEngine Ltd as data importer.

UK data. Where customer personal data is subject to the UK GDPR, the clauses above apply as amended by the UK International Data Transfer Addendum issued by the Information Commissioner, incorporated by reference and completed with the same annex contents.

Onward transfers. Transfers from us to the subprocessors in Annex 3 are governed by standard contractual clauses or another valid transfer mechanism in our contracts with them.

Mauritius. Our processing in Mauritius is additionally subject to the Data Protection Act 2017, supervised by the Mauritius Data Protection Office.

13. Liability, term, and general

Each party's liability under or in connection with this DPA, including the incorporated standard contractual clauses to the extent permitted, is subject to the limitations and exclusions in section 10 of the terms of service; nothing in this section limits a data subject's rights under the standard contractual clauses or applicable law. This DPA takes effect on your acceptance of the terms of service, remains in force as long as we process customer personal data, and terminates automatically on completion of deletion under section 10. If any provision is invalid, the remainder stays in force.


Annex 1: details of processing

ItemDescription
Subject matterProvision of the SyntarEngine platform: composing finished video from the customer's briefs and uploaded materials
DurationThe subscription term plus the deletion period in section 10
Nature and purposeHosting, storage, transmission to the generation and reasoning subprocessors, composition of image, motion, and sound, validation against the customer's brand configuration, and delivery of output; all as directed by the customer through the product
Categories of data subjectsThe customer's team members named in briefs and materials; individuals appearing in uploaded brand materials and reference assets; individuals whose likeness is used in character assets, with documented consent held with the asset; individuals appearing in generated output
Categories of personal dataNames and roles appearing in briefs; images, video, and voice recordings of individuals in uploaded materials; likeness data in consent-documented character assets; personal data appearing in composed output
Special categoriesNot intended for the service. The customer instructs its users not to upload special-category data; where an image incidentally reveals such data, processing is limited to the composition purpose above
FrequencyContinuous, as driven by the customer's use of the product
Competent supervisory authorityDetermined in accordance with Clause 13 of the incorporated Standard Contractual Clauses: where the customer (data exporter) is established in an EU Member State, the supervisory authority of that Member State governs; where the customer is not established in an EU Member State but is subject to the GDPR via Article 3(2), the competent authority is the supervisory authority of the Member State in which our Article 27 representative is registered

Annex 2: technical and organizational measures

  • Encryption of personal data in transit (TLS 1.2 or higher) and at rest.
  • Role-based access control and least-privilege access for personnel; access to production systems logged and reviewed.
  • Separation of cryptographic keys in a hardened key-management system, including the keys underpinning the erasure architecture.
  • Logical tenant separation of customer data, including the multi-brand isolation described in the product documentation.
  • Immediate erasure architecture: confirmed erasure requests execute at request time; residual backup copies expire on the backup rotation cycle and erasure is re-applied on any restore.
  • Vulnerability management, dependency updates, and environment separation between development and production.
  • Personnel confidentiality obligations and data protection awareness.
  • Incident response procedure with the 48-hour customer notification commitment in section 8.
  • Business continuity through the managed cloud infrastructure of the subprocessors in Annex 3, with tested backup and recovery.

Annex 3: subprocessors

SubprocessorRoleLocation
GoogleFoundation-model generation infrastructure: image, video, and audio compositionUnited States
ElevenLabsMusic, voice, and sound-effects generationUnited States
AnthropicReasoning layer behind Cora, the AI Cinematographer: brief and production-instruction processingUnited States
VercelHosting and deployment infrastructureUnited States
SupabaseDatabase and storage infrastructureUnited States
RailwayCloud compute running the production pipeline and its workflow stateUnited States

The merchant of record is not a subprocessor; it processes buyer and payment data as an independent controller under its own terms.