Data Processing Agreement
Last updated August 17, 2026
Running a Personade campaign means we handle personal data about the people on your list, and about the rep who records. That data is yours, and we only act on your instructions. This is the written record of that arrangement, required by Article 28 of the UK and EU GDPR.
What this covers
This agreement applies between Personade and you, the customer we run campaigns for. You are the controller of the personal data in your campaigns: the people on your account list, and your rep who records. We are your processor.
A campaign takes one recording from your rep and the list you supply, and produces a personalized video and page for every person on that list. To do that, we handle personal data about those people and about your rep.
It forms part of our Terms of Service and applies automatically to every campaign we run for you. There is nothing for you to sign. If your legal or privacy team needs a copy, this page is it, and you are welcome to send them the link.
Words we use
- Personal data means information about a living person.
- Processing means anything done with it, including storing, sending and deleting.
- Controller means whoever decides why and how data is used. For the data in your campaigns, that is you.
- Processormeans whoever does the work on the controller's instructions. That is us.
- Subprocessor means a company we use to help us do it.
- Data protection law means the UK GDPR, the EU GDPR, and any other privacy law that applies to you or to us.
Who is responsible for what
You are the controller. The data on your list is yours. You are responsible for having a lawful reason to use it this way, and for how the videos are sent. We cannot do either of those for you.
We are the processor. We use the data you give us only to run your campaigns. We do not use it to train models, to build a product, to market to anyone, or for any purpose of our own. We do not sell personal data and we never will.
If we ever have to process your data for our own reasons, for example to comply with a law, we become a controller for that narrow purpose and we will tell you.
Your instructions
Scoping a campaign with us, sending us your list and your recording, and approving the samples is your instruction to us. Annex 1 records what that instruction covers.
If we believe an instruction breaks data protection law, we will tell you, and we may pause rather than carry it out.
What we will not do
We will not use your list for anything except your campaigns: not to train models, not to build our own database, not to contact anyone on it ourselves, and never to sell.
We will not use your rep's voice clone for anyone else's videos, and we delete it on request or when we stop working together. A clone is only ever built from a recording made with the speaker's written consent.
Confidentiality
Only the people who need access in order to run the service have it, and each of them is authenticated individually. Everyone with access is under a duty of confidence that continues after they leave.
We do not disclose your data to anyone else except as set out in Annex 3, or where the law requires it. Where the law requires it we will tell you, unless we are forbidden from doing so.
Security
We keep appropriate technical and organisational measures in place, listed in Annex 2. Security changes over time, so we may improve those measures, but we will not reduce the overall level of protection.
Subprocessors
You agree that we may use the subprocessors described in Annex 3. Each one is under a written contract with data protection terms at least as strict as these. If a subprocessor fails, that is our responsibility to you, not theirs.
If we want to add or replace one, we will update Annex 3 and tell customers at least 30 days beforehand. If you reasonably object on data protection grounds within those 30 days, we will try to find a way around it. If we cannot, you may cancel the affected part of the service and we will refund the unused portion of what you have paid.
When someone asks about their data
A person on your list may ask to see their data, correct it, delete it, or object to it being used. Those requests belong to you, because you are the controller.
If one reaches us by mistake we will not answer it. We will pass it to you without undue delay and help you answer it.
If someone asks us directly to take down the page made about them, we will tell you, and we will take it down.
If something goes wrong
If we discover a personal data breach affecting your data, we will tell you without undue delay and in any case within 48 hours of becoming aware of it.
We will tell you what happened, which categories of data and roughly how many people are affected, the likely consequences, and what we are doing about it. If we do not have all of that at first, we will send what we have and follow up.
We will not notify your regulator or the affected people on your behalf. That decision is yours, and your own reporting deadline runs from when we tell you.
Deletion
When our engagement ends we delete the personal data from your campaigns within 90 days, including from backups on their normal rotation. The voice clone is deleted on request at any time.
If you ask us to delete it sooner, or to send it back to you first, we will do that within 30 days of the request. We keep only what a law requires us to keep, and only for as long as that law requires.
Records and audits
We keep records of what we process for you and will make them available on request.
If your regulator requires an audit, or you have a genuine reason to believe these terms are not being met, we will cooperate with a reasonable audit. Once a year unless the law or an incident requires more, at reasonable notice, during working hours, and without disrupting other customers. Each side covers its own costs.
Sending data outside the UK and EU
Some of our subprocessors are outside the UK and the EEA, including in the United States. Annex 3 says which categories that applies to.
Where we transfer your campaign data out of the UK or the EEA, we rely on the European Commission's Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum. Those clauses are incorporated into this agreement, with Personade acting as data exporter or importer as the case requires, and this agreement supplying the details their annexes call for.
Liability
Each side's liability under this agreement is subject to the limits in our Terms of Service.
How long this lasts
This agreement applies for as long as we process personal data for you. The obligations that should outlive it do, including confidentiality and deletion.
If documents disagree
If this agreement and our Terms of Service conflict on anything about personal data, this agreement wins.
Annex 1. What we process
Why: to produce and deliver a personalized video and landing page for each person on your campaign list, on your instruction.
Whose data: the people on the list you supply, and the rep who records.
What we handle:
- The fields in your list: typically first name, company, role, and the campaign's custom variables such as a pain point, a trigger event or a call to action. You choose the columns; we process what you send.
- Email addresses, where your list includes them for mapping links back to your rows
- The video recording made by your rep, and the voice model built from it with their written consent
- The rendered videos and landing pages, each containing what your script and variables put there
- Watch analytics: whether a page was opened, how far the video was watched, and whether the call to action was clicked
- Delivery records: which links were produced for which rows, and when
What we do not handle: your inboxes, your CRM and your sending. Your team sends every link itself; we never connect to your email or messaging accounts.
Special category data:none is required, and your list should not contain any. The voice model built from your rep's recording is their personal data, created with their consent, used only for your campaigns, and never used to identify anyone.
How long: for the life of our engagement, then as set out above under Deletion.
Annex 2. Security measures
- Encryption in transit using TLS on every connection.
- Encryption at rest for the database and for stored video.
- Access to production data is limited to the people who need it, and is authenticated individually.
- Credentials and API tokens are encrypted at rest and are never sent to a browser.
- Rendered videos are served from unguessable URLs and are deleted with the rest of your data.
- Changes to production are reviewed before release.
- Backups are encrypted and are covered by the deletion terms above.
- Everyone working on Personade is under written confidentiality obligations.
We do not currently hold SOC 2 or ISO 27001 certification. We would rather say so plainly than imply otherwise, and we will update this page if that changes.
Annex 3. Subprocessors
We use a small number of subprocessors to run the service, covering:
- application hosting
- database
- file and video storage
- voice model creation and speech synthesis, which receive the words each video speaks, including the personalized fields for that person
- video rendering, which receives the rep's footage and the finished video
- transactional email and billing, neither of which receives any data about the people on your list
Some of these are in the United States. No subprocessor receives more about a person on your list than is listed in Annex 1, and the vendors that handle speech and rendering receive only the fields the script speaks: no email address, and nothing you did not put in the script.
The current named list, including each one's role and location, is available on request. Email privacy@personade.com and we will send it. We provide it to customers and to their data protection advisers, and we ask that it is not published.
Each subprocessor is under a written contract with data protection terms at least as strict as these. If we add or replace one, we will tell customers at least 30 days beforehand, and you have the right to object as set out above.