Last updated: 28 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between FusedFrames Technologies Ltd ("FusedFrames") and the customer named on the account ("Customer"). It applies automatically, without signature, wherever FusedFrames processes personal data on Customer's behalf in the course of providing the Service. Customers who require a countersigned copy can request one at legal@fusedframes.com, and questions about this DPA can be sent to the same address.
"Data Protection Law" means the UK GDPR and the Data Protection Act 2018, the EU GDPR and any other data protection law that applies to the processing under this DPA. "Customer Data" means personal data that Customer or its users submit to the Service or that the Service captures on Customer's behalf, as described in Section 11. Other capitalised terms have the meanings given in the Agreement or in Data Protection Law.
For Customer Data, Customer is the controller (or a processor acting for another controller, in which case Customer warrants it has the authority to bind that controller to this DPA) and FusedFrames is the processor. FusedFrames is an independent controller of the account, billing, security, support and service-generated technical data described in its Privacy Policy; that processing is outside this DPA.
FusedFrames will process Customer Data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law that applies to FusedFrames, in which case FusedFrames will inform Customer of that requirement before processing unless the law prohibits it. The Agreement, this DPA and Customer's configuration of the Service (including recording rules, sharing settings, the data sharing setting and deletion actions) are Customer's complete instructions. FusedFrames will inform Customer if, in its opinion, an instruction infringes Data Protection Law. FusedFrames may create aggregated, de-identified data that no longer identifies any individual and use it to operate and improve the Service, and it will not attempt to re-identify such data.
FusedFrames ensures that every person it authorises to process Customer Data is bound by a contractual or statutory duty of confidentiality, and that access is limited to what each person needs to operate, support or secure the Service.
FusedFrames implements and maintains appropriate technical and organisational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, as required by Article 32, including the measures described in Section 12. FusedFrames may update those measures, provided the protection of Customer Data is not materially reduced.
Customer gives FusedFrames general authorisation to engage the sub-processors listed at /legal/subprocessors, and FusedFrames imposes data protection obligations on each of them that are no less protective than this DPA. FusedFrames remains fully liable to Customer for the performance of each sub-processor's obligations.
FusedFrames will update that page, and notify subscribed customers by email, at least 30 days before a new or replacement sub-processor processes Customer Data. Customer may object on reasonable data protection grounds within that period; the parties will then work in good faith to resolve the objection, and if it cannot be resolved, Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for it.
Taking into account the nature of the processing, FusedFrames will assist Customer, including through the export, deletion, correction and access controls built into the Service, in fulfilling Customer's obligations to respond to data subject requests and its obligations under Articles 32 to 36 (security, breach notification, data protection impact assessments and prior consultation). If a data subject contacts FusedFrames directly about Customer Data, FusedFrames will redirect them to Customer and will not respond substantively except on Customer's instruction or where required by law.
FusedFrames will notify Customer without undue delay, and in any event within 72 hours of becoming aware, of a personal data breach affecting Customer Data, and will provide the information reasonably available to it about the nature of the breach, its likely consequences and the measures taken or proposed to address it, supplementing the notice as further information becomes available.
Customer can export Customer Data and delete recordings, libraries or entire workspaces through the Service at any time; deleting a workspace permanently deletes its Customer Data. On termination of the Agreement, FusedFrames will delete remaining Customer Data, and will do so within 30 days of a written request, unless the law requires FusedFrames to keep it. Residual copies in encrypted backups are deleted in the ordinary course as backups are cycled.
FusedFrames will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA and, where that information is insufficient, will allow an audit by Customer or an independent auditor mandated by it: no more than once in any 12-month period, on at least 30 days' notice, during business hours, without disrupting the Service and subject to confidentiality obligations.
Where FusedFrames transfers Customer Data outside the UK or the EEA, it does so under adequacy decisions or appropriate safeguards as described in the Privacy Policy. Where Customer's provision of Customer Data to FusedFrames is itself a restricted transfer, the EU Standard Contractual Clauses (Module Two, or Module Three where Customer is a processor) and, for UK transfers, the UK International Data Transfer Addendum are incorporated into this DPA by reference, with Customer as data exporter and FusedFrames as data importer.
Where Data Protection Law requires additional processor or service provider commitments, they are given here: FusedFrames does not sell or share Customer Data, does not retain, use or disclose it for any purpose other than providing the Service under the Agreement, will notify Customer if it can no longer meet its obligations under Data Protection Law and imposes the same restrictions on its sub-processors.
Each party's liability under this DPA is subject to the limitations of liability in the Agreement. This DPA is governed by the law that governs the Agreement.