Launch policy set
Data Processing Addendum
Controller-processor terms for personal data a business customer places in Ozelaro.Version 2026-07-22.launch-candidate-v2 · Effective 22 July 2026This policy applies to the public preview from its effective date. Paid-service terms become binding only when this exact version is shown and affirmatively accepted at checkout. Ozelaro is not yet accepting paid orders, and mandatory statutory rights always take priority.
1. Scope and roles
This Addendum applies when a business customer is controller of personal data in customer content and Ozelaro processes it on the customer's documented instructions to provide the service. It forms part of the accepted service agreement. The customer is controller and Ozelaro is processor for that data; each remains an independent controller for its own account, security, billing, legal, and compliance processing.
Processing covers hosting, extracting approved facts, editing, captioning, translation, voice generation, QA, delivery, authorised scheduling/publishing, support, security, and deletion. Data subjects may include the customer's staff, clients, property owners, prospects, speakers, and people visible or audible in authorised footage. Data types are described in the Privacy Policy and order.
2. Instructions and customer duties
The agreement, product settings, connected-account authorisation, job submission, review decision, and support instructions are the documented instructions. Ozelaro will process only on those instructions unless law requires otherwise, in which case it will notify the customer unless prohibited. Ozelaro will immediately flag an instruction it reasonably believes violates data-protection law.
The customer warrants it has a lawful basis, gives required notices, limits data to what is necessary, obtains speaker and publicity permissions, answers data-subject requests as controller, and does not submit prohibited special-category or child data. The customer decides whether publishing personal data to a social platform is lawful.
3. Confidentiality and security
People authorised to process customer personal data must be bound by confidentiality and receive access only as necessary. Ozelaro will maintain measures proportionate to risk, including tenant isolation, access control, HTTPS, encrypted secrets and tokens, signed webhooks, logging, idempotency, backups, vulnerability and incident procedures, and verified media cleanup. The customer remains responsible for its endpoints, users, source files, and account configuration.
4. Subprocessors
The customer gives general written authorisation for the subprocessors on the Service Providers page that are marked approved for production. Ozelaro will require materially equivalent data-protection duties and remain responsible for their processing to the extent required by law. Ozelaro will give reasonable advance notice, targeted at 15 days, before a new production subprocessor handles customer content where practicable.
A customer may object on reasonable data-protection grounds during the notice period. The parties will seek a practical alternative; if none exists, either may terminate the affected service without penalty and any refund follows mandatory law and the unused prepaid portion where appropriate.
5. Assistance, breaches, and rights
Taking into account the processing, Ozelaro will reasonably assist the customer with data-subject requests, security, breach assessment and notification, data-protection impact assessments, regulator consultation, and evidence needed for compliance. Ozelaro will notify the customer without undue delay after becoming aware of a customer-personal-data breach and provide available details as the investigation progresses.
6. Return, deletion, and audit
At the end of processing, Ozelaro will return or delete customer personal data at the customer's choice, unless law requires retention. Routine source, final, voice, OAuth, log, and backup periods are in the Privacy Policy. Ozelaro will provide deletion or cleanup evidence where the product supports it.
Ozelaro will provide information reasonably necessary to demonstrate compliance and allow a proportionate audit by the customer or an independent auditor under confidentiality, normally no more than once per year unless a breach, regulator, or credible non-compliance concern justifies more. Audits must avoid exposing another tenant's data and may use current third-party reports first.
7. Restricted transfers
Ozelaro will not make a restricted transfer without an applicable adequacy decision, Standard Contractual Clauses, UK IDTA/Addendum, binding corporate rules, or another lawful mechanism, plus supplementary assessment where required. The customer authorises transfers inherent in an approved connected-platform publish instruction after receiving the relevant platform information.
Email hi@ozelaro.tech.