Legal
GDPR
How we meet UK GDPR and EU GDPR obligations, and how we act as your processor.
Last updated 19 August 2026
Controller and processor
For your account and billing data, Conso4s Ltd is the controller. For the content you upload and the videos you generate, you are the controller and we act as your processor: we process that content only on your documented instructions, which are the settings and actions you choose in the app.
Data processing terms
Our data processing terms are incorporated into the Terms of Service and follow Article 28 UK GDPR. A signed copy, and a signed Data Processing Agreement for procurement, is available on request from [email protected].
- We process personal data only on your instructions.
- Everyone with access is under a duty of confidentiality.
- We apply the security measures described on our Security page.
- We engage sub-processors only under equivalent written terms, and give notice of changes.
- We assist you with data subject requests, impact assessments and breach notification.
- On termination we delete or return personal data, subject to the retention periods we must keep for law.
Sub-processors
We keep a current list of sub-processors, including hosting, AI model providers, email delivery, payment processing and monitoring. Request the list from [email protected] and we will notify you of additions so you can object.
International transfers
Where personal data leaves the UK or the EEA, we rely on the UK International Data Transfer Addendum, EU Standard Contractual Clauses or an adequacy decision, supported by encryption in transit and at rest.
Data subject rights
Access, rectification, erasure, restriction, portability and objection are all supported. Where we are the processor, we will forward any request that reaches us directly to you as controller, and help you answer it within the statutory deadline.
Breach notification
If a personal data breach affects your data we will notify you without undue delay and, where we are the controller, notify the ICO within 72 hours of becoming aware where the breach is reportable.
Records and contact
We maintain records of processing under Article 30. For any GDPR matter, including DPAs, sub-processor lists and audit requests, contact [email protected].
