Comprehensive data processing transparency and security commitments
This Data Processing Agreement (DPA) governs the processing of personal data by SYNAPSE SPARK STUDIO LTD (operating as Repurpose) on behalf of our customers. This agreement ensures compliance with applicable data protection laws including GDPR, CCPA, and other regional privacy regulations.
By using our services, you agree to the data processing terms outlined in this agreement.
Company: SYNAPSE SPARK STUDIO LTD
Registration: 87654321
Address: Office 13464, 182-184 High Street North, East Ham, London, E6 2JA, United Kingdom
DPO Contact: privacy@repurpose.online
As the data controller, we ensure data subjects can exercise their rights including access, rectification, erasure, restriction, portability, and objection. We respond to requests within 30 days.
User authentication, account administration, billing
Contractual necessity
Video translation, voice synthesis, editorial services
Contractual necessity
Performance monitoring, error tracking, service improvement
Legitimate interest
Customer support, service notifications, marketing
Consent / Legitimate interest
End-to-end encryption for all data transfers and storage
Implementation: AES-256 encryption, TLS 1.3 for transmission
Role-based access with multi-factor authentication
Implementation: RBAC, MFA, principle of least privilege
Customer data processed in isolated environments
Implementation: Containerized processing, network segmentation
Comprehensive logging of all data access and processing
Implementation: Immutable audit trails, real-time monitoring
Only collect and process necessary data
Implementation: Automated deletion, data retention policies
When processing data outside the EEA, we ensure adequate protection through:
We may engage sub-processors to provide specific services. All sub-processors are bound by data protection obligations equivalent to those in this DPA.
We will notify customers at least 30 days before adding new sub-processors. You may object to new sub-processors and terminate the agreement if we cannot accommodate your objection.
Immediate detection, containment, and risk assessment
Notification to affected customers with incident details
Regulatory notification where required by law
Full investigation, remediation, and prevention measures
We maintain comprehensive audit capabilities to demonstrate compliance:
For data processing questions, requests, or concerns:
Response Time: We respond to all data processing requests within 30 days as required by GDPR. Complex requests may require an extension, which we will communicate within the initial 30-day period.