This Data Processing Agreement ("DPA") forms part of and is incorporated into the agreement for the provision of the POVSync services (the "Principal Agreement") between:
Customer and POVSync are each a "party" and together the "parties." This DPA reflects the parties' agreement with respect to the Processing of Personal Data by POVSync on behalf of Customer in connection with the POVSync service (the "Service").
In the event of a conflict between this DPA and the Principal Agreement, this DPA prevails with respect to the subject matter of data protection. Capitalized terms not defined here have the meaning given in the Principal Agreement or in Applicable Data Protection Law.
1.1 "Applicable Data Protection Law" means all laws and regulations applicable to the Processing of Personal Data under this DPA, including (a) Regulation (EU) 2016/679 ("GDPR"); (b) the GDPR as incorporated into United Kingdom law by the Data Protection Act 2018 and the European Union (Withdrawal) Act 2018 ("UK GDPR"); and (c) the Swiss Federal Act on Data Protection ("FADP"), in each case as amended or superseded.
1.2 "Controller," "Processor," "Data Subject," "Personal Data," "Personal Data Breach," "Processing," and "Supervisory Authority" have the meanings given in the GDPR.
1.3 "Sub-processor" means any third party engaged by POVSync to Process Personal Data on behalf of Customer.
1.4 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of Personal Data to third countries adopted by the European Commission in Decision (EU) 2021/914 of 4 June 2021.
1.5 "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, in force 21 March 2022.
1.6 "Restricted Transfer" means a transfer of Personal Data to a country or organization that is not subject to an adequacy decision under Applicable Data Protection Law.
2.1 Roles of the parties. The parties acknowledge that, with respect to the Processing of Personal Data under the Service, Customer is the Controller and POVSync is the Processor. Where Customer is itself acting as a processor on behalf of a third party, POVSync acts as a sub-processor; in that case Customer warrants that it has the authority and instructions necessary to engage POVSync on the terms of this DPA.
2.2 Customer responsibility. Customer is responsible for determining the purposes and means of Processing and for ensuring it has a lawful basis under Applicable Data Protection Law for Processing the Personal Data it submits to the Service — including the recording, uploading, and Processing of stream recordings that may capture incidental third parties (such as co-streamers and other roleplay participants) and chat participants. Customer is responsible for providing any notices and obtaining any consents required of a Controller.
2.3 Authorized users (editor seats). Editors and other users that Customer invites to its account act under Customer's authority and on Customer's instructions. They are not independent controllers. Customer is responsible for the acts and omissions of its authorized users as if they were Customer's own.
2.4 Processor instructions. POVSync shall Process Personal Data only as a Processor acting on behalf of Customer and shall not Process such Personal Data for its own purposes.
3.1 Subject matter. Provision of the POVSync service: ingesting Customer's stream video-on-demand ("VOD") recordings, transcribing them, detecting and classifying segments using automated and AI models, and rendering an edited recap.
3.2 Duration. For the term of the Principal Agreement, plus any period necessary to delete or return Personal Data in accordance with Section 11.
3.3 Nature and purpose of Processing. Automated ingestion, transcoding, transcription, segment detection, AI-assisted classification, rendering of recap video, storage of the produced recap, and associated account and support operations — all for the sole purpose of providing the Service to Customer.
3.4 Types of Personal Data.
| Category | Description |
|---|---|
| Video imagery | Facial images and likenesses of the creator and any individuals appearing in the source VOD (e.g., co-streamers, roleplay participants) |
| Audio / voice | Voice recordings and other audible identifiers within the VOD |
| Transcripts | Text transcriptions derived from the VOD audio |
| Chat data | Chat usernames/handles and chat message content associated with the stream |
| Account data | Customer's registration data (name, email, authentication identifiers, billing reference) |
3.5 Categories of Data Subjects.
3.6 Special categories. The Service is not intended to Process special-category data (Article 9 GDPR). To the extent stream content incidentally contains such data, Customer is responsible for the lawful basis and any Article 9 condition.
3.7 Frequency. Continuous / on demand, each time Customer submits a VOD for Processing.
4.1 POVSync shall Process Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by Union or Member State law to which POVSync is subject. Where such a legal requirement applies, POVSync shall, unless prohibited by law on important grounds of public interest, inform Customer of the legal requirement before Processing.
4.2 The Principal Agreement, this DPA, and Customer's configuration and use of the Service through its account constitute Customer's complete and documented instructions. Additional or alternate instructions must be agreed in writing and may be subject to changes in fees or scope.
4.3 POVSync shall promptly inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law (without obligation to conduct a legal review of the lawfulness of Customer's instructions).
5.1 POVSync shall ensure that persons authorized to Process the Personal Data are bound by an appropriate obligation of confidentiality (whether contractual or statutory) and are subject to access on a need-to-know basis.
5.2 POVSync shall ensure such persons receive appropriate training on their data protection responsibilities.
6.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, POVSync shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as further described in Annex II.
6.2 Transient source-media handling as a built-in safeguard. As a data-minimization measure (Article 5(1)(c)) and a security measure, source VOD media is automatically and permanently deleted within 24 hours of Processing. Only the produced recap output is retained, on Customer's instruction, until deletion under Section 11. This minimizes the volume and persistence of raw source Personal Data held by the Service.
6.3 POVSync may update its security measures from time to time provided the updates do not materially reduce the overall level of security of the Service.
7.1 General authorization. Customer provides general written authorization for POVSync to engage Sub-processors to Process Personal Data, subject to this Section 7. The Sub-processors engaged as at the effective date are listed in the Sub-processor List below.
7.2 Notice and right to object. POVSync shall give Customer at least [30] days' prior notice of the addition or replacement of any Sub-processor (by email and/or by updating the published Sub-processor List with a subscription mechanism). Customer may object on reasonable data-protection grounds within the notice period. If the parties cannot resolve the objection, Customer may, as its sole remedy, terminate the affected portion of the Service for which the Sub-processor is used.
7.3 Flow-down terms. POVSync shall impose on each Sub-processor, by written contract, data-protection obligations that are substantially equivalent to those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organizational measures.
7.4 Continuing liability. POVSync remains fully liable to Customer for the performance of each Sub-processor's data-protection obligations.
8.1 Taking into account the nature of the Processing, POVSync shall assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests by Data Subjects exercising their rights under Applicable Data Protection Law (including access, rectification, erasure, restriction, portability, and objection).
8.2 If POVSync receives a request directly from a Data Subject in relation to Customer's Personal Data, it shall not respond on the substance (other than to acknowledge and direct the Data Subject to Customer where appropriate) and shall forward the request to Customer without undue delay.
9.1 POVSync shall notify Customer without undue delay, and in any event within 24–48 hours, after becoming aware of a Personal Data Breach affecting Customer's Personal Data, to enable Customer to meet its 72-hour notification obligation to the relevant Supervisory Authority.
9.2 The notification shall, to the extent known and reasonably available, describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Where information is not available at the time, it may be provided in phases without undue further delay.
9.3 POVSync shall take reasonable steps to mitigate and remediate the breach and shall reasonably cooperate with Customer. POVSync shall not make any public statement attributing the breach to Customer without Customer's prior written consent, except as required by law.
10.1 Taking into account the nature of the Processing and the information available to POVSync, POVSync shall provide reasonable assistance to Customer with: (a) its obligations to keep Personal Data secure under Article 32; (b) data protection impact assessments under Article 35; and (c) prior consultation with a Supervisory Authority under Article 36.
11.1 Source media. As described in Section 6.2, source VOD media is deleted automatically within 24 hours of Processing.
11.2 On termination. Upon termination or expiry of the Principal Agreement, POVSync shall, at Customer's choice, delete or return all Personal Data (including produced recaps and account-associated Personal Data) and delete existing copies, within [30–90] days, unless Union or Member State law requires continued storage.
11.3 POVSync may retain Personal Data to the extent and for the period required by applicable law, in which case it shall continue to protect that Personal Data in accordance with this DPA and Process it only as necessary for the required retention purpose. Backups are deleted in the ordinary course of the backup-rotation cycle.
11.4 On request, POVSync shall certify in writing that it has complied with this Section 11.
12.1 POVSync shall make available to Customer all information reasonably necessary to demonstrate compliance with Article 28 and this DPA.
12.2 Reports first. Customer agrees that, in the first instance, POVSync may satisfy audit requests by providing current third-party certifications and audit reports (such as SOC 2 Type II and/or ISO/IEC 27001) covering the Service.
12.3 Audit on cause. Where such reports are insufficient to address a specific, reasonable concern — or following a Personal Data Breach or a Supervisory Authority requirement — Customer (or an independent auditor it mandates, who is not a competitor of POVSync and is bound by confidentiality) may conduct an audit on [30] days' prior written notice, no more than once per twelve (12) months (save where required by a Supervisory Authority or following a Personal Data Breach), during business hours, subject to reasonable security and confidentiality requirements and without unreasonable disruption to POVSync's operations.
13.1 Customer authorizes POVSync to transfer Personal Data outside the EEA, the UK, and Switzerland where necessary to provide the Service, including to the Sub-processors listed below, provided an appropriate transfer mechanism is in place.
13.2 EU SCCs. To the extent a Restricted Transfer from the EEA occurs, the parties incorporate the SCCs by reference, with Module Two (Controller-to-Processor) applying as between Customer (data exporter) and POVSync (data importer). The clauses are completed as follows: the optional docking clause (Clause 7) does not apply; the general authorization option under Clause 9(a) applies with a 30-day notice period; the Clause 11 independent-redress option does not apply; the governing law (Clause 17) is the law of Ireland; the forum (Clause 18) is the courts of Ireland. Annex I, II, and III of the SCCs are populated by Sections 3–6 of this DPA and the Sub-processor List.
13.3 Onward transfers (sub-processors). Where a Sub-processor is located in a third country, POVSync and the Sub-processor enter into the SCCs (Module Two or Module Three, Processor-to-Processor, as applicable) or another valid transfer mechanism.
13.4 UK transfers. To the extent a Restricted Transfer of UK Personal Data occurs, the SCCs are supplemented by the UK Addendum, with Tables 1–3 populated from this DPA and Table 4 specifying that the neither party may end the Addendum as set out in Section 19 of the Addendum.
13.5 Swiss transfers. To the extent a Restricted Transfer of Swiss Personal Data occurs, the SCCs apply with the adaptations required by the FADP and FDPIC guidance (references to the GDPR and to Supervisory Authorities read as references to the FADP and the FDPIC; the clauses also protect data of legal entities to the extent required).
13.6 Conflict. In the event of any conflict between the SCCs / UK Addendum and this DPA, the SCCs / UK Addendum prevail with respect to the relevant Restricted Transfer.
14.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement.
14.2 This DPA takes effect on the effective date of the Principal Agreement and continues for so long as POVSync Processes Personal Data on behalf of Customer.
14.3 This DPA is governed by the law specified in the Principal Agreement, except where Applicable Data Protection Law or the SCCs require otherwise.
*Effective date: August 18, 2026. POVSync will provide notice of changes per Section 7.2.*
| Sub-processor | Purpose | Data accessed | Location | Safeguard |
|---|---|---|---|---|
| Anthropic, PBC | AI segment detection and classification | Transcripts (text derived from VOD audio) | United States | EU SCCs (Module Two/Three) + DPA; zero-data-retention (ZDR) processing option enabled so inputs/outputs are not retained or used for model training |
| Modal Labs, Inc. | Transcription and recap rendering (GPU compute) | Source VOD video/audio (transient, ≤24h), transcripts | United States | EU SCCs + DPA; transient processing, source media deleted ≤24h |
| Cloudflare, Inc. (R2) | Storage of source media (transient) and produced recap output | Source VOD (transient, ≤24h), produced recap, associated metadata | United States | EU SCCs + DPA; encryption at rest; lifecycle deletion of source media ≤24h |
| Vercel Inc. | Frontend web hosting | Account data in transit; no persistent storage | United States | EU SCCs + DPA; encryption in transit |
| Supabase, Inc. | Managed Postgres — account records and processing metadata | Account data (email, authentication identifiers), processing metadata | United States | EU SCCs + DPA; encryption in transit and at rest |
| Discord, Inc. | Clip-approval notifications and support messaging, where the creator has connected Discord | Account handle, clip links and titles, message content the creator sends us | United States | EU SCCs + DPA; used only where the creator connects it; encryption in transit |
| Render Services, Inc. | API hosting and orchestration backend | Account data, processing metadata; no persistent storage of source VOD | United States | EU SCCs + DPA; encryption in transit and at rest |
*Bracketed placeholders (legal names, addresses, locations, dates, jurisdictions, notice periods, and SCC option selections) must be completed and the document reviewed by a qualified attorney before execution.*
Terms · Privacy · DPA · Acceptable Use