If your use of Synthesia involves processing personal data (such as employee names, faces, or voices), a separate Data Processing Agreement governs how that data is handled, and that agreement is part of these terms.
This analysis describes what Synthesia's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The specific obligations, data subject rights, sub-processor disclosures, and security measures that protect your personal data under GDPR are governed by the DPA, which is not reproduced in the main terms and requires separate review.
Customers processing personal data through Synthesia must review the Data Processing Agreement separately to understand their full GDPR or UK GDPR obligations, including sub-processor lists, security standards, and data subject rights fulfillment mechanisms.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
"To the extent that Synthesia processes any personal data on your behalf in connection with the Services, such processing will be subject to the Data Processing Agreement (DPA) which is incorporated into this Agreement by reference. The DPA sets out the terms on which Synthesia will process personal data on your behalf.Excerpt from Synthesia's Terms of Service
REGULATORY LANDSCAPE: The incorporation of a DPA by reference directly engages GDPR Articles 28 and 29, which require written contracts between controllers and processors covering specific mandatory terms.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The specific obligations, data subject rights, sub-processor disclosures, and security measures that protect your personal data under GDPR are governed by the DPA, which is not reproduced in the main terms and requires separate review.
Customers processing personal data through Synthesia must review the Data Processing Agreement separately to understand their full GDPR or UK GDPR obligations, including sub-processor lists, security standards, and data subject rights fulfillment mechanisms.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Synthesia.