Synthesia procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “ We may transfer your personal data to recipients located outside of the United Kingdom (“ UK ”) and European Economic Area (“EEA”). When we transfer your personal data outside of the UK or EEA, we ensure it benefits from an adequate level of data protection by relying on: Adequacy decisions. These are decisions from the European Commission under Article 45 GDPR (or equivalent decisions under other laws) which recognise that a country outside of the EEA offers an adequate level of data protection. Standard contractual clauses. The European Commission has approved contractual clauses under Article 46 GDPR that allow companies in the EEA to transfer data outside the EEA. These (and their approved equivalent for the UK and Switzerland) are called standard contractual clauses. We rely on standard contractual clauses to transfer personal data as described in this Privacy Policy to countries without an adequacy decision. In certain situations, we rely on exceptions provided for under applicable law to transfer personal data to a third country. You may obtain a copy of these adequacy decisions or standard contractual clauses by contacting us at support@synthesia.io .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “We may transfer your personal data to recipients located outside of the United Kingdom (“ UK ”) and European Economic Area (“EEA”). When we transfer your personal data outside of the UK or EEA, we ensure it benefits from an adequate level of data protection by relying on: Adequacy decisions. These are decisions from the European Commission under Article 45 GDPR (or equivalent decisions under other laws) which recognise that a country outside of the EEA offers an adequate level of data protection. Standard contractual clauses. The European Commission has approved contractual clauses under Article 46 GDPR that allow companies in the EEA to transfer data outside the EEA. These (and their approved equivalent for the UK and Switzerland) are called standard contractual clauses. We rely on standard contractual clauses to transfer personal data as described in this Privacy Policy to countries without an adequacy decision.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “Standard contractual clauses. The European Commission has approved contractual clauses under Article 46 GDPR that allow companies in the EEA to transfer data outside the EEA. These (and their approved equivalent for the UK and Switzerland) are called standard contractual clauses. We rely on standard contractual clauses to transfer personal data as described in this Privacy Policy to countries without an adequacy decision. In certain situations, we rely on exceptions provided for under applicable law to transfer personal data to a third country. You may obtain a copy of these adequacy decisions or standard contractual clauses by contacting us at support@synthesia.io .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Certain jurisdictions distinguish between a "controller" or "processor" of personal data. A controller is the decision-maker and exercises overall control over how and why personal data is collected and used. In general, the Customer is the controller of Customer Data. A processor acts on behalf of, and only on the instructions of, the relevant controller. In general, Synthesia is the processor of Customer Data and the controller of Other Information (which is described in the ‘Personal data that we process’ section below). Synthesia is the controller of Other Information and a processor of Customer Data. In addition to the definitions provided for in the Agreement, the following words and abbreviations have the meaning provided below: " personal data " means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. "processing" means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. "processor" means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of Synthesia.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “We and our vendors will store and use the Biometric Data described above only until it is no longer needed for the achievement of the above listed purposes. For the creation of an Avatar, Biometric Data is stored and used as long as the Avatar is available on the Platform or as otherwise instructed by our Customer. For authenticating the Avatar submission, Biometric Data is stored and used only until we confirm the results of the samples comparison which usually occurs within few minutes of the submission. After the relevant processing has been completed or where instructed by our Customer, we permanently destroy your Biometric Data, unless otherwise required by law or legal process to retain the data. We require our vendor(s) to similarly delete or destroy Biometric Data.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We will retain Customer Data in accordance with Customer’s instructions (including to perform any applicable terms in the Agreement and through Customer’s use of Platform functionality) and as required by applicable law. The deletion of Customer Data and other use of the Services by the Customer may result in the deletion and/or de-identification of certain associated Other Information. We may retain Other Information pertaining to you for as long as necessary for the purposes described in this Privacy Policy (such as to provide the Services, including any optional features you use, and to provide customer support). This may include keeping your Other Information after you have deleted your account for the period of time needed for us to pursue legitimate business interests, conduct audits, comply with (and demonstrate compliance with) legal obligations, resolve disputes, and enforce our agreements.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “We will retain Customer Data in accordance with Customer’s instructions (including to perform any applicable terms in the Agreement and through Customer’s use of Platform functionality) and as required by applicable law. The deletion of Customer Data and other use of the Services by the Customer may result in the deletion and/or de-identification of certain associated Other Information.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Other entities as part of a business transfer - if Synthesia undertakes or is involved in any merger, acquisition, reorganisation, sale of assets, bankruptcy, or insolvency event, then we may sell, transfer, or share some or all of our assets, including your personal data, in connection with such transaction or in contemplation of such transaction, such as due diligence. ” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “In order to effectively verify the authenticity of submissions, we may use a third-party verification systems or vendors, including but not limited to Amazon Web Services EMEA SARL.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ The policies and practices for sharing and/or disclosure of Customer Data to third parties is determined by the Customer. Synthesia has no control over the Customer's or any other third parties' choice to share and/or disclose Customer Data. Synthesia may share and disclose Customer Data in accordance with a Customer's instructions, including any applicable terms in the Master Subscription Agreement and Data Processing Addendum. In certain circumstances we may share and/or disclose the personal data described in this Privacy Policy. Our affiliated companies - we will share your information with our affiliated companies in order to facilitate company business and as part of our regular reporting activities. Our service providers - we will share your information with affiliated and unaffiliated service providers which assist us in carrying out the processing activities described in this Privacy Policy. Our service providers include payment processing providers, IT service providers, our auditors, and our legal, accounting and other professional advisors. Regulators, law enforcement, public or government authorities, or courts - we will share your information if and to the extent we are required or permitted to do so by law or where disclosure is reasonably necessary to (i) comply with applicable law; (ii) comply with a valid legal request or respond to claims against Synthesia; (iii) respond to a valid legal request relating to a criminal investigation to address alleged or suspected illegal activity, or to respond to or address any other activity that may expose us, you, or any other of our Users to legal or regulatory liability; (iv) enforce and administer our Terms of Service; (v) respond to requests for or in connection with current or” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “We do not sell or rent personal information to any third-party.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ prospective legal claims or legal proceedings concerning Synthesia and/or third parties; or (vi) protect the rights, property or personal safety of Synthesia, our employees, our Users, or members of the public. ” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Our affiliated companies - we will share your information with our affiliated companies in order to facilitate company business and as part of our regular reporting activities. Our service providers - we will share your information with affiliated and unaffiliated service providers which assist us in carrying out the processing activities described in this Privacy Policy. Our service providers include payment processing providers, IT service providers, our auditors, and our legal, accounting and other professional advisors.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Where we are under an obligation to disclose personal data such as, for example, if we receive a valid legal request for certain personal data (such as a search warrant), we will access, preserve and/or share your personal data with regulators, law enforcement or others. The way in which the personal data will be processed depends on the specific circumstances.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ To share personal data with others, including law enforcement and to respond to legal requests, where we are not under a legal obligation to do so. The categories of personal data that we access, preserve, use and share depend on the specific circumstances. For example, responses to legal requests where not compelled by law, will typically include limited personal data (such as contact details and login information).” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We process personal data to comply with a legal obligation including, for example, to access, preserve, or disclose certain personal data if there is a valid legal request.” | Captured 2026-06-07Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.