Data Processing Addendum
The global data-protection terms under which Sundream processes customer personal data, incorporated into the Terms of Service.
Last updated: August 20, 2026
How this applies
This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer") and Smith & Johnson, Inc., a Delaware corporation ("Sundream"). It applies automatically, with no separate signature, where Sundream processes personal data on your behalf and that processing is subject to applicable privacy, data-protection, or data-security law, including the EU GDPR, UK GDPR, Swiss Federal Act on Data Protection, and applicable comprehensive U.S. state privacy laws (collectively, "Applicable Data Protection Laws").
Where this DPA conflicts with the Terms of Service, this DPA governs for matters of data protection. A separate negotiated agreement, if we have one with you, governs over both.
If your procurement process requires a countersigned copy, request one at support@sundream.studio.
Roles
For personal data in workspace content and related collaborator information that Customer directs Sundream to process, Customer is the controller and Sundream is the processor. If Customer processes that data for another controller, Customer is a processor and Sundream is its subprocessor. The terms controller and processor include equivalent roles such as business, service provider, and contractor under Applicable Data Protection Laws.
For data we process to run our business — account administration, billing, security, and product analytics of our own service — Sundream acts as a controller, and our Privacy Policy governs.
Scope of processing
- Subject matter: provision of the Sundream AI film production service.
- Duration: the term of your subscription, plus the retention and deletion periods described in our Privacy Policy.
- Nature and purpose: hosting, storage, transmission, generation of media, and the support and security operations needed to deliver those.
- Types of personal data: account identifiers and contact details, and any personal data contained in workspace content you upload or generate — including likenesses in reference images and generated media, recorded or uploaded voice samples, cloned or designed voice profiles, provider voice identifiers, and consent or provenance metadata.
- Categories of data subjects: your personnel and collaborators with workspace access, and any individuals appearing in or identified by the content you submit.
- Frequency: ongoing, as initiated by Customer and authorized users through their use of the service.
- Subprocessor transfers: as described on the current Subprocessors page.
Customer instructions and responsibilities
The Terms, this DPA, Customer's configuration and use of the service, and other mutually agreed written instructions are Customer's documented instructions. Instructions outside the service's scope or requiring material additional work must be agreed in writing. If we reasonably believe an instruction violates Applicable Data Protection Laws, we will inform Customer unless prohibited by law and may suspend the affected processing while the parties resolve it.
- Customer is responsible for the lawfulness, accuracy, quality, and origin of personal data it submits, for having a valid legal basis, and for providing all required notices and obtaining all required permissions or consents.
- Customer must use available permissions and security features appropriately, protect account credentials and systems used to access Sundream, and notify us promptly of suspected compromise.
- Customer must not submit payment-card numbers, financial-account credentials, government identification numbers, or protected health information subject to HIPAA unless Sundream has agreed in writing to the processing and any additional safeguards. Customer must not use Sundream to knowingly collect personal data directly from children under 16 without that agreement and all legally required notices, permissions, and safeguards.
- Because Sundream supports authorized voice and likeness workflows, Customer may submit biometric or other sensitive data only where it has a valid legal basis, has completed any required assessment, and has obtained express consent or other authorization required by law and our AI Safety Policy.
Our obligations
- Process personal data only on your documented instructions, which your use of the service and the Terms constitute, except where law requires otherwise — in which case we will tell you unless legally prohibited.
- Ensure personnel authorised to process personal data are bound by confidentiality.
- Implement appropriate technical and organisational measures as described below.
- Assist you, taking into account the nature of processing, in responding to data subject requests, and in your obligations for security, breach notification, and data protection impact assessments.
- If we receive a data-subject request concerning Customer-controlled data, notify Customer unless prohibited by law and direct the requester to Customer. Customer remains responsible for the response unless law requires otherwise.
- Notify you without undue delay after becoming aware of a personal data breach affecting your data, provide the details reasonably available at the time, take commercially reasonable mitigation steps within our control, and reasonably cooperate with your investigation and legally required notifications. A notice is not an admission of fault or liability.
- Delete or return personal data at the end of the service, subject to the retention described in our Privacy Policy and any legal obligation to retain.
- Make available the information reasonably necessary to demonstrate compliance with this DPA.
Security
We maintain technical and organisational measures appropriate to the risk, including encryption of data in transit, access controls and authentication, tenant isolation, logging and monitoring, review of subprocessors, and restriction of production access to personnel who require it.
Our measures include procedures for managing access changes, responding to security incidents, securely disposing of data and media under our control, and reviewing material changes that may affect personal-data security. The infrastructure providers identified on our Subprocessors page maintain the physical and environmental safeguards for their facilities.
Security measures evolve. We may update them provided the overall level of protection is not reduced.
U.S. state privacy laws
For personal data governed by an applicable comprehensive U.S. state privacy law, the parties intend Sundream to act as Customer's service provider, contractor, or processor. Customer discloses personal data to Sundream only for the limited and specified purposes in the Terms, this DPA, and Customer's documented instructions.
- Sundream will provide the level of privacy protection required of a service provider, contractor, or processor under the applicable law and will notify Customer if we determine we can no longer meet that obligation.
- Sundream will not sell or share Customer personal data; retain, use, or disclose it outside the direct business relationship or for a commercial purpose other than providing the service; or combine it with personal data received from another source or from Sundream's independent interaction with a data subject, except as permitted by applicable law and necessary to provide the service.
- Customer may take reasonable and appropriate steps under the audit provisions below to verify compliant processing and, on reasonable notice, to stop and remediate unauthorized use.
- The subprocessor notice and objection process below satisfies any applicable requirement to authorize or receive notice of subcontractors.
Subprocessors
You give general authorisation for Sundream to engage subprocessors. Our current subprocessors are listed on the Subprocessors page, which we keep current.
We impose written data-protection obligations on each subprocessor no less protective than those in this DPA for the processing it performs, and remain responsible for its performance. To receive advance notice of a new or replacement subprocessor, subscribe by writing to support@sundream.studio.
Customer may object on reasonable data-protection grounds within 15 days after receiving notice. The parties will work in good faith on a commercially reasonable alternative. If none is available, Customer may stop using the affected feature or terminate the affected paid service, and remains responsible for fees accrued before termination.
International transfers
Sundream is located in the United States, and our subprocessors process data in the United States and the other locations identified on the Subprocessors page. Personal data submitted from the EEA, UK, or Switzerland will therefore be transferred outside its place of origin.
For a restricted transfer subject to the EU GDPR, the European Commission's Standard Contractual Clauses in Decision 2021/914 (SCCs) are incorporated by reference and deemed executed. Module Two applies where Customer is a controller, and Module Three applies where Customer is a processor. For a UK restricted transfer, the SCCs as modified by the UK Information Commissioner's International Data Transfer Addendum B1.0 are incorporated and deemed executed. For a Swiss restricted transfer, the SCCs apply with references to the GDPR, European Union, and supervisory authority read as references to the Swiss FADP, Switzerland, and the Swiss Federal Data Protection and Information Commissioner where required.
We carry out transfer risk assessments where required and will cooperate with you on any supplementary measures reasonably needed.
Standard Contractual Clause selections
For the SCCs: Customer is the data exporter and Sundream is the data importer. Customer's legal name, address, and contact details are those associated with its account or order form; Sundream's details appear in How this applies and Contact. The processing description appears in Scope of processing; the technical and organisational measures appear in Security; and approved subprocessors appear on the Subprocessors page. The competent supervisory authority is determined under SCC Clause 13 based on Customer's establishment, representative, or the affected data subjects.
- Clause 7, the optional docking clause, is not used. Under Clause 9, Option Two (general written authorization) applies with the 15-day notice period above. The optional language in Clause 11 is not used.
- For EU transfers, Clause 17 Option One applies and the SCCs are governed by Irish law; under Clause 18, disputes are resolved by the courts of Ireland. Data subjects retain the forum rights the SCCs give them.
- For UK transfers, Tables 1 through 3 of the UK Addendum are populated by this DPA and the SCC selections above, and the data importer may terminate the Addendum as permitted by Table 4. The mandatory clauses of the UK Addendum apply.
- For Swiss transfers, the SCCs protect data relating to identified or identifiable legal entities to the extent the FADP covers that data, and Swiss data subjects may bring proceedings in Switzerland where the SCCs require.
- If a regulator, data subject, or customer controller requires an executed full-form copy, request one at support@sundream.studio. We may replace a transfer mechanism when legally necessary if the replacement does not materially reduce protection.
Audits
We will respond to reasonable written requests for information needed to verify compliance with this DPA, including summaries of our security measures and any third-party reports we hold.
Where that information is genuinely insufficient to satisfy a supervisory authority or a legal obligation, you may conduct an audit no more than once in any twelve-month period, plus any additional audit a competent authority legally requires, on at least thirty days' written notice. The parties will agree a reasonable scope and duration; the audit must occur during business hours, avoid unreasonable disruption, protect other customers and our confidential information, and use an independent non-competitor bound by confidentiality. You bear your own costs and our reasonable costs for assistance beyond the ordinary service.
Return and deletion
When the affected service ends, Sundream will stop processing Customer personal data except as needed to return, delete, or anonymize it, or as law otherwise permits or requires. Customer may request return of reasonably available personal data before deletion using available export tools or another commercially reasonable secure format.
If Customer does not request return, we will delete or anonymize the data under the account-erasure and retention process in our Privacy Policy. We may retain a limited copy only where law requires or permits, protected under this DPA, isolated from other processing, and deleted or anonymized when the retention basis ends. Backups remain isolated from ordinary use and are overwritten on their normal rotation.
AI and automated processing
Delivering generation, speech, and voice-cloning features requires transmitting your prompts, references, voice samples, and related project context to the AI subprocessors listed on the Subprocessors page. This is processing on your instruction: it happens only when you invoke a feature that requires it.
Sundream will not use Customer personal data to train, fine-tune, develop, or improve Sundream's or a third party's AI or machine-learning model unless that processing is reasonably necessary to provide a feature on Customer's documented instruction or Customer expressly authorizes it in writing. We contractually prohibit AI subprocessors from using Customer personal data for their own model training, fine-tuning, development, or improvement unless Customer expressly authorizes that use in writing. Providers may retain request data for limited service-operation, security, and abuse-monitoring periods under the applicable business or API terms.
Sundream does not provide a feature that uses Customer personal data to make decisions producing legal or similarly significant effects about a data subject. If that changes, we will disclose the processing and reasonably assist Customer with applicable transparency, assessment, explanation, and data-subject-rights obligations.
Changes, liability, and term
We may update this DPA when reasonably necessary to comply with Applicable Data Protection Laws or replace a transfer mechanism, provided the update does not materially reduce protection or materially increase Customer's obligations without agreement.
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, but nothing in those limits restricts a data subject's rights under the SCCs or Applicable Data Protection Laws where those rights cannot be limited by contract.
This DPA takes effect when you begin using the service and continues until all personal data processed on your behalf has been deleted or returned in accordance with it.
Contact
Data protection enquiries, subprocessor change notifications, and requests for a countersigned copy: support@sundream.studio, or by post to Smith & Johnson, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States.