Synthesia acts as the data controller for individual users and as a data processor for business customers who use the platform on behalf of their own users or employees, with a separate legal agreement governing each relationship.
This analysis describes what Synthesia's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The distinction between controller and processor determines who is ultimately responsible for your data rights; if you are an employee or end user of a business that uses Synthesia, your data rights may need to be exercised through that business rather than directly with Synthesia.
If your employer or organization uses Synthesia and you interact with the platform through them, the business customer is likely the data controller and bears primary responsibility for your data, which may affect who you need to contact to exercise rights like access or deletion.
How other platforms handle this
Where ZipRecruiter processes your Personal Data in the capacity of a service provider (data processor), and you seek access, or want to correct, amend, or delete your Personal Data...we will provide you with the data controller's contact information, so you can contact them directly.
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
"In some cases, we act as a data controller in respect of your personal data. In other cases, particularly where we process data on behalf of our business customers, we act as a data processor. Where we act as a data processor, our processing activities are governed by a Data Processing Agreement with the relevant business customer.Excerpt from Synthesia's Privacy Policy
(1) REGULATORY LANDSCAPE: GDPR Articles 26, 28, and 29 govern the controller-processor relationship, requiring a written Data Processing Agreement that specifies the subject matter, duration, nature, and purpose of processing, as well as the obligations …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The distinction between controller and processor determines who is ultimately responsible for your data rights; if you are an employee or end user of a business that uses Synthesia, your data rights may need to be exercised through that business rather than directly with Synthesia.
If your employer or organization uses Synthesia and you interact with the platform through them, the business customer is likely the data controller and bears primary responsibility for your data, which may affect who you need to contact to exercise rights like access or deletion.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Synthesia.