ProdExplainerProdExplainer

Legal

GDPR

How we meet UK GDPR and EU GDPR obligations, and how we act as your processor.

Last updated 19 August 2026

Controller and processor

For your account and billing data, Conso4s Ltd is the controller. For the content you upload and the videos you generate, you are the controller and we act as your processor: we process that content only on your documented instructions, which are the settings and actions you choose in the app.

Data processing terms

Our data processing terms are incorporated into the Terms of Service and follow Article 28 UK GDPR. A signed copy, and a signed Data Processing Agreement for procurement, is available on request from [email protected].

  • We process personal data only on your instructions.
  • Everyone with access is under a duty of confidentiality.
  • We apply the security measures described on our Security page.
  • We engage sub-processors only under equivalent written terms, and give notice of changes.
  • We assist you with data subject requests, impact assessments and breach notification.
  • On termination we delete or return personal data, subject to the retention periods we must keep for law.

Sub-processors

We keep a current list of sub-processors, including hosting, AI model providers, email delivery, payment processing and monitoring. Request the list from [email protected] and we will notify you of additions so you can object.

International transfers

Where personal data leaves the UK or the EEA, we rely on the UK International Data Transfer Addendum, EU Standard Contractual Clauses or an adequacy decision, supported by encryption in transit and at rest.

Data subject rights

Access, rectification, erasure, restriction, portability and objection are all supported. Where we are the processor, we will forward any request that reaches us directly to you as controller, and help you answer it within the statutory deadline.

Breach notification

If a personal data breach affects your data we will notify you without undue delay and, where we are the controller, notify the ICO within 72 hours of becoming aware where the breach is reportable.

Records and contact

We maintain records of processing under Article 30. For any GDPR matter, including DPAs, sub-processor lists and audit requests, contact [email protected].