Data Processing Addendum
Last updated · August 21, 2026
Footage routinely contains other people’s faces and voices. When you put it through Dubsmith, you are the controller of that personal data and we process it for you. This addendum sets out the terms of that arrangement. It applies automatically whenever you use the service to process personal data, and forms part of the Terms & Conditions (the “Agreement”).
1. Scope, roles, and definitions
Roles. You are the controller — and under Singapore’s Personal Data Protection Act 2012 (PDPA), the organisation — in respect of personal data contained in the content you submit (“Customer Personal Data”). Dubsmith is the processor, and under the PDPA the data intermediary. Where you are yourself a processor for another controller, we are the subprocessor and your instructions must be consistent with that controller’s.
Applicable laws. “Data Protection Laws” means the privacy and data protection laws applicable to our processing under the Agreement, including the PDPA, the EU and UK GDPR, the Swiss FADP, and comprehensive US state privacy laws, in each case to the extent they apply.
Details of processing. The subject matter is the localization of your media; the duration is the term of the Agreement plus the deletion window in section 9; the nature and purpose are the processing operations needed to deliver the service; the categories of data subject are the people appearing or speaking in your content and your own personnel who use the service; and the categories of personal data are voice and speech recordings, images of faces, the text derived from them, and account and contact details.
Precedence. Where this addendum conflicts with the Agreement on the processing of personal data, this addendum prevails. Where the Standard Contractual Clauses apply to a transfer, they prevail over both for that transfer.
2. Our processing obligations
- We process Customer Personal Data only on your documented instructions. Your use of the service, the Agreement, and this addendum are those instructions; anything beyond them needs to be agreed in writing, and work outside the scope of the service is chargeable at our then-current professional services rates.
- We will tell you if, in our reasonable opinion, an instruction breaches Data Protection Laws — though assessing the lawfulness of your instructions remains your responsibility, not ours.
- Everyone we authorise to access Customer Personal Data is bound by confidentiality obligations.
- We do not sell or share Customer Personal Data, do not retain, use, or disclose it outside the direct business relationship or for any purpose other than providing the service, and do not combine it with data from other sources except as needed to provide the service.
No model training. We will not use Customer Personal Data to train, fine-tune, develop, or improve any artificial-intelligence or machine-learning model, whether ours or a third party’s, and we contractually prohibit our subprocessors — including model providers — from doing so.
No automated decisions about people. The pipeline is automated, but it operates on the media you submit. We do not carry out profiling or automated decision-making producing legal or similarly significant effects on data subjects.
3. Your obligations and warranties
This section is what makes the arrangement workable: we cannot see the consent behind your footage, and you can.
- You warrant that you have a valid legal basis for the processing, including under Articles 6 and 9 of the GDPR where applicable, and that you have given every notice and obtained every consent required — from data subjects and from any other controller — for us and our subprocessors to process Customer Personal Data as contemplated.
- You warrant that you hold the informed consent of every identifiable person whose voice is cloned or synthesised and every performer whose likeness is altered, as required by the Acceptable Use Policy.
- You warrant that Customer Personal Data contains no Restricted Data — government identification numbers, financial account or payment card data, health or medical information, biometric identifiers processed for the purpose of uniquely identifying a person, credentials for third-party accounts, or personal data of children under 16 — unless we have agreed to it in writing in advance and put appropriate additional safeguards in place.
- You are responsible for your own use of the service, including configuring it appropriately for the sensitivity of your data, securing your account credentials, and keeping your own copies of your content.
Your assessment. You confirm that you have evaluated the service and the security measures in section 4 and consider them appropriate to the risk of your processing, including for the purposes of any security obligation you have under Data Protection Laws.
4. Security
We implement and maintain technical and organisational measures appropriate to the risk, taking account of the state of the art and the cost of implementation. These include:
- encryption of personal data in transit over public networks and at rest in object storage;
- role-based access control on a need-to-know and least-privilege basis, with unique credentials and prompt revocation on role change;
- authenticated, signed, replay-protected server-to-server calls between our services, with secrets held in a managed secret store;
- logical segregation of customer data, and audit logging of access and system activity;
- vulnerability management, patching, change control, and network controls including segmentation;
- incident-response procedures, and backup and recovery procedures for foreseeable failures.
We may update these measures to maintain or improve security or to reflect changes in Data Protection Laws, provided the updated measures do not materially reduce the overall level of protection.
5. Security incidents
We will notify you without undue delay after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to Customer Personal Data, and will include the details then known and the steps taken to mitigate it. Unsuccessful attempts that do not compromise security — failed logins, pings, port scans, blocked network attacks — are not security incidents and are not notifiable.
Who notifies whom. You are responsible for any notification you owe to a supervisory authority, to the Personal Data Protection Commission, to data subjects, or to anyone else. If your notification refers to or identifies us, tell us first and consider in good faith any correction we reasonably request. Our notification of, or response to, an incident is not an acknowledgement of fault or liability.
6. Data subject requests
Taking account of the nature of the processing, we will provide you with reasonable and technically feasible assistance to respond to requests from data subjects exercising their rights. Assistance beyond the functionality of the service is chargeable at our then-current professional services rates, and we will give you a good-faith estimate on request.
If a data subject contacts us directly about Customer Personal Data, we will promptly refer them to you and, unless legally required otherwise, leave the response to you.
7. Subprocessors
You give us general authorisation to engage subprocessors. The current list is published at Subprocessors and you authorise everyone on it as at the date you accept this addendum.
- Every subprocessor is engaged under a written contract imposing data protection obligations no less protective than those in this addendum, to the extent applicable to what it does.
- We remain responsible for our subprocessors’ performance and are liable for their acts and omissions as if they were our own.
- Before a new subprocessor starts processing we update the list and notify you by email at least 15 days in advance. You may object on reasonable data-protection grounds within that period, and we will work with you in good faith to find a resolution. If we cannot, your sole and exclusive remedy is to terminate the affected part of the Agreement, paying amounts due up to termination.
8. International transfers
Out of Singapore. Before transferring personal data overseas we take reasonable steps, as section 26 of the PDPA requires, to satisfy ourselves that the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to the PDPA.
Out of the EEA, UK, and Switzerland. Where a transfer is restricted under the GDPR, the UK GDPR, or the FADP and the destination is not covered by an adequacy decision, the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914) apply and are incorporated into this addendum by reference — Module Two where you are a controller, Module Three where you are a processor — as varied by the UK International Data Transfer Addendum for UK transfers and with Switzerland, the FADP and the FDPIC substituted for Swiss transfers. The annexes to the Clauses are populated with the processing details in section 1, the security measures in section 4, and the list at Subprocessors. For EU transfers, the Clauses are governed by the law of Ireland and disputes go to the Irish courts.
Replacement mechanisms. We may, on notice, replace a transfer mechanism with another valid one where necessary to maintain compliance, provided it does not materially reduce the protection of personal data. An executed copy of the Clauses for a specific transfer is available on reasonable written request to contact@dubsmith.io.
9. Return and deletion
On the date processing under the Agreement ceases, we stop processing Customer Personal Data for any purpose other than storage and what is needed to return, delete, or anonymise it.
Within 30 days after that date you may ask us in writing either to return a copy of Customer Personal Data in our possession or to delete it; we will do so within a commercially reasonable period, to the extent technically feasible. If you do not ask within those 30 days, we will delete or anonymise it. We may retain data where law requires, for no longer than required, keeping it confidential, protected by the section 4 measures, and processed only for the purpose that requires its retention. Certification of deletion is provided on written request.
10. Audits
You may audit our compliance with this addendum once per year, and more often only where Data Protection Laws or a competent supervisory authority with jurisdiction over you require it.
- Submit a proposed audit plan at least two weeks in advance describing scope, duration, and start date; we will work with you in good faith to agree a final plan.
- Audits happen during business hours, must not unreasonably disrupt our operations, and are subject to confidentiality. Nothing requires us to breach a duty of confidence owed to anyone else or to expose information that would compromise our security.
- We may object to a third-party auditor that is not independent, is a competitor, or is otherwise manifestly unsuitable.
- Where the controls in question are covered by a SOC 2 Type 2, ISO, or equivalent report issued within the previous 12 months and we confirm no material change, you agree to accept that report instead.
- Audits are at your expense, and you will reimburse our reasonable documented costs, including internal time at our then-current professional services rates.
11. Liability, and how this addendum changes
Each party’s total liability under or in connection with this addendum and the Standard Contractual Clauses is subject to, and counts towards, the exclusions and the aggregate cap in the Terms & Conditions — currently the amounts paid in the 6 months before the event giving rise to the claim. Nothing in this section affects any liability to a data subject under the third-party beneficiary provisions of the Clauses, or any liability that cannot be limited by law.
Changes. We may vary this addendum on written notice to the extent necessary to maintain compliance with Data Protection Laws, provided the variation does not materially reduce the protection given to personal data or materially increase your obligations. This addendum stays in force for as long as we process Customer Personal Data, regardless of the Agreement ending.
Governing law. Except where the Standard Contractual Clauses specify otherwise for a transfer they cover, this addendum is governed by the law of Singapore and subject to the dispute-resolution terms of the Agreement.
12. Accepting this addendum
Using the service to process personal data constitutes acceptance of this addendum by you and by us, and no signature is needed for it to bind. If your procurement process requires a countersigned copy, or if you need the Standard Contractual Clauses executed separately, email contact@dubsmith.io and we will arrange it.

