Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that Synthesia may retain Other Information including contact data, usage data, technical data, and financial data after a user deletes their account, for purposes including legitimate business interests, audits, legal compliance, dispute resolution, and agreement enforcement. No specific maximum retention period is stated for post-deletion retention.
This analysis describes what Synthesia's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision reserves the right to retain user data beyond account deletion without specifying a defined post-deletion retention period, which may require evaluation under GDPR's data minimization and storage limitation principles. The absence of a stated maximum retention duration creates ambiguity for data subjects seeking to exercise erasure rights.
Interpretive note: The policy does not specify maximum post-deletion retention periods, creating ambiguity about whether retention durations are proportionate under GDPR storage limitation requirements.
Under this clause, deleting a Synthesia account does not result in immediate deletion of all associated Other Information; the agreement states that contact information, usage data, technical data, and financial data may be retained for unspecified periods for audit, legal, and business purposes. Users may submit erasure requests to support@synthesia.io, though the policy notes erasure may prevent continued use of some services.
Cross-platform context
See how other platforms handle Post-Account-Deletion Data Retention and similar clauses.
Compare across platforms →Monitoring
Synthesia has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We may retain Other Information pertaining to you for as long as necessary for the purposes described in this Privacy Policy (such as to provide the Services, including any optional features you use, and to provide customer support). This may include keeping your Other Information after you have deleted your account for the period of time needed for us to pursue legitimate business interests, conduct audits, comply with (and demonstrate compliance with) legal obligations, resolve disputes, and enforce our agreements.Excerpt from Synthesia's Privacy Policy
1. REGULATORY LANDSCAPE: This provision engages GDPR Article 5(1)(e) storage limitation principle, which requires personal data to be kept no longer than necessary for the specified purpose, and Article 17 right to erasure. UK GDPR contains equivalent provisions. The UK ICO and EU supervisory authorities enforce these obligations. The provision's open-ended retention language may require evaluation against these standards, particularly regarding whether 'legitimate business interests' constitutes a sufficiently specific retention justification. 2. GOVERNANCE EXPOSURE: Medium. Retaining personal data after account deletion for broadly stated purposes such as 'legitimate business interests' and 'audits' without defined retention periods may be inconsistent with GDPR storage limitation obligations. This is a common industry practice but has been a focus of regulatory scrutiny in the EU and UK. 3. JURISDICTION FLAGS: EU and UK users have the strongest enforcement posture regarding post-deletion retention under GDPR and UK GDPR. California users may have rights under the CCPA regarding retention of personal information. Illinois users should assess whether any retained data includes biometric identifiers subject to BIPA retention limits. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers whose employees use Synthesia should assess whether the open-ended post-deletion retention of Other Information is consistent with their own data retention policies and any contractual obligations to data subjects. The DPA with Synthesia should address the retention of Other Information generated by authorized users. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should request Synthesia's data retention schedule to assess whether post-deletion retention periods for each category of Other Information are defined and proportionate. GDPR teams should evaluate whether the legitimate interests basis for post-deletion retention is documented in a legitimate interests assessment. EU and UK teams may wish to raise the absence of specific retention periods in DPA negotiations.
This provision reserves the right to retain user data beyond account deletion without specifying a defined post-deletion retention period, which may require evaluation under GDPR's data minimization and storage limitation principles. The absence of a stated maximum retention duration creates ambiguity for data subjects seeking to exercise erasure rights.
Under this clause, deleting a Synthesia account does not result in immediate deletion of all associated Other Information; the agreement states that contact information, usage data, technical data, and financial data may be retained for unspecified periods for audit, legal, and business purposes. Users may submit erasure requests to support@synthesia.io, though the policy notes erasure may prevent continued use of …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Synthesia.