Sundream

Data Processing Addendum

The global data-protection terms under which Sundream processes customer personal data, incorporated into the Terms of Service.

Last updated: August 20, 2026


How this applies

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer") and Smith & Johnson, Inc., a Delaware corporation ("Sundream"). It applies automatically, with no separate signature, where Sundream processes personal data on your behalf and that processing is subject to applicable privacy, data-protection, or data-security law, including the EU GDPR, UK GDPR, Swiss Federal Act on Data Protection, and applicable comprehensive U.S. state privacy laws (collectively, "Applicable Data Protection Laws").

Where this DPA conflicts with the Terms of Service, this DPA governs for matters of data protection. A separate negotiated agreement, if we have one with you, governs over both.

If your procurement process requires a countersigned copy, request one at support@sundream.studio.

Roles

For personal data in workspace content and related collaborator information that Customer directs Sundream to process, Customer is the controller and Sundream is the processor. If Customer processes that data for another controller, Customer is a processor and Sundream is its subprocessor. The terms controller and processor include equivalent roles such as business, service provider, and contractor under Applicable Data Protection Laws.

For data we process to run our business — account administration, billing, security, and product analytics of our own service — Sundream acts as a controller, and our Privacy Policy governs.

Scope of processing

Customer instructions and responsibilities

The Terms, this DPA, Customer's configuration and use of the service, and other mutually agreed written instructions are Customer's documented instructions. Instructions outside the service's scope or requiring material additional work must be agreed in writing. If we reasonably believe an instruction violates Applicable Data Protection Laws, we will inform Customer unless prohibited by law and may suspend the affected processing while the parties resolve it.

Our obligations

Security

We maintain technical and organisational measures appropriate to the risk, including encryption of data in transit, access controls and authentication, tenant isolation, logging and monitoring, review of subprocessors, and restriction of production access to personnel who require it.

Our measures include procedures for managing access changes, responding to security incidents, securely disposing of data and media under our control, and reviewing material changes that may affect personal-data security. The infrastructure providers identified on our Subprocessors page maintain the physical and environmental safeguards for their facilities.

Security measures evolve. We may update them provided the overall level of protection is not reduced.

U.S. state privacy laws

For personal data governed by an applicable comprehensive U.S. state privacy law, the parties intend Sundream to act as Customer's service provider, contractor, or processor. Customer discloses personal data to Sundream only for the limited and specified purposes in the Terms, this DPA, and Customer's documented instructions.

Subprocessors

You give general authorisation for Sundream to engage subprocessors. Our current subprocessors are listed on the Subprocessors page, which we keep current.

We impose written data-protection obligations on each subprocessor no less protective than those in this DPA for the processing it performs, and remain responsible for its performance. To receive advance notice of a new or replacement subprocessor, subscribe by writing to support@sundream.studio.

Customer may object on reasonable data-protection grounds within 15 days after receiving notice. The parties will work in good faith on a commercially reasonable alternative. If none is available, Customer may stop using the affected feature or terminate the affected paid service, and remains responsible for fees accrued before termination.

International transfers

Sundream is located in the United States, and our subprocessors process data in the United States and the other locations identified on the Subprocessors page. Personal data submitted from the EEA, UK, or Switzerland will therefore be transferred outside its place of origin.

For a restricted transfer subject to the EU GDPR, the European Commission's Standard Contractual Clauses in Decision 2021/914 (SCCs) are incorporated by reference and deemed executed. Module Two applies where Customer is a controller, and Module Three applies where Customer is a processor. For a UK restricted transfer, the SCCs as modified by the UK Information Commissioner's International Data Transfer Addendum B1.0 are incorporated and deemed executed. For a Swiss restricted transfer, the SCCs apply with references to the GDPR, European Union, and supervisory authority read as references to the Swiss FADP, Switzerland, and the Swiss Federal Data Protection and Information Commissioner where required.

We carry out transfer risk assessments where required and will cooperate with you on any supplementary measures reasonably needed.

Standard Contractual Clause selections

For the SCCs: Customer is the data exporter and Sundream is the data importer. Customer's legal name, address, and contact details are those associated with its account or order form; Sundream's details appear in How this applies and Contact. The processing description appears in Scope of processing; the technical and organisational measures appear in Security; and approved subprocessors appear on the Subprocessors page. The competent supervisory authority is determined under SCC Clause 13 based on Customer's establishment, representative, or the affected data subjects.

Audits

We will respond to reasonable written requests for information needed to verify compliance with this DPA, including summaries of our security measures and any third-party reports we hold.

Where that information is genuinely insufficient to satisfy a supervisory authority or a legal obligation, you may conduct an audit no more than once in any twelve-month period, plus any additional audit a competent authority legally requires, on at least thirty days' written notice. The parties will agree a reasonable scope and duration; the audit must occur during business hours, avoid unreasonable disruption, protect other customers and our confidential information, and use an independent non-competitor bound by confidentiality. You bear your own costs and our reasonable costs for assistance beyond the ordinary service.

Return and deletion

When the affected service ends, Sundream will stop processing Customer personal data except as needed to return, delete, or anonymize it, or as law otherwise permits or requires. Customer may request return of reasonably available personal data before deletion using available export tools or another commercially reasonable secure format.

If Customer does not request return, we will delete or anonymize the data under the account-erasure and retention process in our Privacy Policy. We may retain a limited copy only where law requires or permits, protected under this DPA, isolated from other processing, and deleted or anonymized when the retention basis ends. Backups remain isolated from ordinary use and are overwritten on their normal rotation.

AI and automated processing

Delivering generation, speech, and voice-cloning features requires transmitting your prompts, references, voice samples, and related project context to the AI subprocessors listed on the Subprocessors page. This is processing on your instruction: it happens only when you invoke a feature that requires it.

Sundream will not use Customer personal data to train, fine-tune, develop, or improve Sundream's or a third party's AI or machine-learning model unless that processing is reasonably necessary to provide a feature on Customer's documented instruction or Customer expressly authorizes it in writing. We contractually prohibit AI subprocessors from using Customer personal data for their own model training, fine-tuning, development, or improvement unless Customer expressly authorizes that use in writing. Providers may retain request data for limited service-operation, security, and abuse-monitoring periods under the applicable business or API terms.

Sundream does not provide a feature that uses Customer personal data to make decisions producing legal or similarly significant effects about a data subject. If that changes, we will disclose the processing and reasonably assist Customer with applicable transparency, assessment, explanation, and data-subject-rights obligations.

Changes, liability, and term

We may update this DPA when reasonably necessary to comply with Applicable Data Protection Laws or replace a transfer mechanism, provided the update does not materially reduce protection or materially increase Customer's obligations without agreement.

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, but nothing in those limits restricts a data subject's rights under the SCCs or Applicable Data Protection Laws where those rights cannot be limited by contract.

This DPA takes effect when you begin using the service and continues until all personal data processed on your behalf has been deleted or returned in accordance with it.

Contact

Data protection enquiries, subprocessor change notifications, and requests for a countersigned copy: support@sundream.studio, or by post to Smith & Johnson, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States.