Data Protection Addendum
This Data Protection Addendum (“DPA”) forms part of the Terms of Service (or other similarly titled written or electronic agreement addressing the same subject matter) (“Agreement”) between Customer (as defined in the Agreement) and Flowframe, Inc., trading as Velo, under which Velo provides Customer with the software and services (the “Services”). Customer and Velo are individually a “Party” and together the “Parties”.
The Parties enter into this DPA to meet the requirements of the EU GDPR, the UK GDPR and the CCPA in relation to Velo’s Processing of Personal Data as part of its obligations under the Agreement.
This DPA applies to Velo’s Processing of Personal Data provided by Customer as part of Velo’s obligations under the Agreement.
Except as modified below, the terms of the Agreement remain in full force and effect.
1. Definitions
1.1Terms not defined in this DPA have the meaning given to them in the EU GDPR or the Agreement.
1.2“Agreement” means the master subscription agreement, terms of service, order form or other written or electronic agreement between Velo and Customer for the provision of the Services.
1.3“Applicable Data Protection Law” means the laws and regulations applicable to the Processing of Personal Data under this DPA, including the EU GDPR, the UK GDPR, the UK Data Protection Act 2018 and the CCPA.
1.4“CCPA” means the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020, together with its implementing regulations.
1.5“Customer Personal Data” means Personal Data within Customer Data that Velo Processes on Customer’s behalf under the Agreement. It does not include Velo Account Data.
1.6“Effective Date” means the date Customer accepts the Agreement or, if earlier, the date Velo first Processes Customer Personal Data for Customer.
1.7“EU GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
1.8“Restricted Transfer” means a transfer of Personal Data from the European Economic Area or the United Kingdom to a country not covered by an adequacy decision or adequacy regulations.
1.9“Services” means the Velo AI video platform at usevelo.ai and any related products, applications, application programming interfaces and support services provided under the Agreement.
1.10“SCCs” means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
1.11“Sub-processor” means a third party Velo engages to Process Customer Personal Data in providing the Services.
1.12“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.
1.13“Velo Account Data” means Personal Data about Customer’s relationship with Velo: the names and business contact details of Customer’s administrators and authorised users, billing and payment records, subscription and entitlement records, support correspondence, and the security, audit and usage telemetry Velo’s systems generate.
1.14“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” have the meanings given in the EU GDPR. “Business”, “Service Provider”, “Sell”, “Share” and “Consumer” have the meanings given in the CCPA.
2. Purpose and Order of Precedence
2.1This DPA sets out Velo’s obligations in relation to the Processing of Customer Personal Data and is limited to Velo’s obligations under the Agreement.
2.2If there is a conflict, the SCCs and the UK Addendum prevail over this DPA, and this DPA prevails over the Agreement. Precedence applies only to the subject matter of the conflict.
2.3This DPA does not cover Personal Data that Velo Processes as an independent Controller. Clause 3.3 and the Privacy Policy govern that Processing.
2.4Where Customer enters into the Agreement for its Affiliates, Customer warrants it has authority to bind them, and references to Customer include those Affiliates.
3. Roles of the Parties
3.1For Customer Personal Data, Customer is the Controller (or the Processor, where Customer acts for a third-party controller) and Velo is the Processor (or Sub-processor). Under the CCPA, Customer is the Business and Velo is a Service Provider.
3.2Velo Processes Customer Personal Data only on Customer’s documented instructions. Those instructions are this DPA, the Agreement, the configuration choices Customer makes in the Services, and any further written instructions the Parties agree.
3.3Velo Processes Velo Account Data as an independent Controller, to provide, secure, bill and support the Services, to meet its legal obligations, and to produce aggregated statistics that identify neither Customer nor any Data Subject. Velo does not use Velo Account Data for advertising and does not Sell or Share it.
3.4Velo will tell Customer if it considers an instruction to infringe Applicable Data Protection Law, and may suspend the affected Processing until the instruction is withdrawn, amended or confirmed. Velo is not liable for the consequences of that suspension.
4. Customer Obligations
4.1Customer is responsible for the lawfulness of the Customer Personal Data it provides to, or generates within, the Services, and for the lawfulness of its instructions to Velo.
4.2Customer warrants that it has a valid legal basis for the Processing, has given Data Subjects the privacy notices required, and has obtained the consents and authorisations Applicable Data Protection Law requires.
4.3The Services capture screen recordings, microphone audio, images of faces and voice samples. Customer must obtain any consent or authorisation required before an individual’s voice or likeness is recorded, cloned or synthesised through the Services, and must not use the Services on any individual’s voice or likeness without that individual’s prior authorisation. Customer is responsible for ensuring recordings do not capture Personal Data it may not disclose to Velo.
4.4Customer must not submit to the Services, and must take reasonable steps to stop its users submitting, special categories of Personal Data under Article 9 of the EU GDPR, criminal-offence data, payment card data, government-issued identification numbers or protected health information. The Parties may agree otherwise in writing in advance, with whatever additional safeguards that requires.
4.5Customer will promptly tell Velo about any Data Subject request, complaint or regulatory enquiry relating to Velo’s Processing where Customer needs Velo’s assistance.
5. Velo’s Obligations
Velo shall:
- Process Customer Personal Data only on Customer’s documented instructions, including as to transfers, unless applicable law requires otherwise, in which case Velo will inform Customer of that requirement before Processing unless the law prohibits it on important grounds of public interest;
- not Sell or Share Customer Personal Data, and not retain, use or disclose it for any purpose other than performing the Services or outside the direct business relationship between the Parties, except as Applicable Data Protection Law permits;
- not combine Customer Personal Data with Personal Data from any other source, except as necessary to perform the Services or as Applicable Data Protection Law permits;
- implement and maintain the measures set out in Annex II;
- ensure that persons authorised to Process Customer Personal Data are bound by an obligation of confidentiality;
- engage Sub-processors only under clause 8;
- assist Customer under clauses 10, 11, 12 and 13; and
- return or delete Customer Personal Data under clause 16.
6. Confidentiality and Personnel
6.1Velo grants access to Customer Personal Data only to personnel who need it to perform Velo’s obligations under the Agreement, on a least-privilege, need-to-know basis.
6.2Personnel with access to Customer Personal Data are bound by written confidentiality obligations that survive the end of their engagement, and complete security and privacy training on joining and at least annually after that.
6.3Velo background screens personnel who will have access to Customer Personal Data, so far as local law permits.
7. Security of Processing
7.1Velo implements and maintains the technical and organisational measures set out in Annex II. Those measures are appropriate to the risk, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of the Processing.
7.2Velo may update Annex II, provided no update materially reduces the overall security of the Services during the term of the Agreement.
7.3Customer is responsible for configuring the security features the Services provide, including single sign-on, role-based access, sharing controls and link expiry, to suit its own risk assessment.
7.4Velo is working toward SOC 2 Type II and ISO/IEC 27001 readiness, targeted for 1 September 2026. Velo holds neither a SOC 2 report nor an ISO/IEC 27001 certificate today, and will update this page when it does.
8. Sub-processors
8.1Customer authorises Velo to engage Sub-processors to Process Customer Personal Data. Annex III lists those authorised today.
8.2Velo will give Customer at least thirty (30) days’ notice before adding or replacing a Sub-processor, by email to the administrative contact on Customer’s account and by updating Annex III. Customer may subscribe to change notifications at usevelo.ai/subprocessors.
8.3Velo’s agreement with each Sub-processor imposes data protection obligations no less protective than those in this DPA. Velo remains liable to Customer for its Sub-processors’ acts and omissions as if they were its own.
8.4Each Sub-processor receives the minimum Personal Data its function requires, over encrypted channels, and may not use Customer Personal Data for its own purposes.
9. Artificial Intelligence
9.1The Services use third-party AI models to generate scripts, narration, translations and video. Annex III identifies each AI Sub-processor and the data it receives.
9.2Velo does not send the names, email addresses or profile photographs of Customer’s authorised users to the large language model providers listed in Annex III. Those providers receive prompts, source material Customer submits or designates, publicly available company information, and content Velo has generated.
9.3Where Customer uses voice, avatar or media generation, the audio recordings, voice samples and images Customer submits go to the voice and media Sub-processors listed in Annex III to produce the requested output. Source material Customer designates, including screen recordings and uploaded documents, may contain Personal Data; Velo Processes it only to produce that output.
9.4Velo does not use Customer Personal Data to train, fine-tune or develop any AI or machine learning model, and its agreements with its AI Sub-processors do not permit them to do so, unless Customer authorises it in writing.
9.5Speech-to-text runs on Velo’s own infrastructure. No third-party transcription provider receives it.
9.6Velo does not carry out automated decision-making producing legal or similarly significant effects on Data Subjects within the meaning of Article 22 of the EU GDPR.
10. Data Subject Rights
10.1The Services let Customer access, correct, export and delete Customer Personal Data. Customer will use that functionality first when responding to Data Subject requests.
10.2Where a request cannot be met through the Services, Velo will give Customer reasonable assistance, taking account of the nature of the Processing, so Customer can respond within the time limits Applicable Data Protection Law imposes.
10.3If a Data Subject approaches Velo directly about Customer Personal Data, Velo will acknowledge receipt, direct them to Customer and forward the request. Velo will not respond substantively.
10.4This assistance is free, unless a request is manifestly unfounded or excessive or needs engineering work well beyond the functionality of the Services. Velo will notify Customer of any charge in advance.
11. Personal Data Breach
11.1Velo will notify Customer of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within seventy-two (72) hours of becoming aware of it.
11.2The notification will set out, so far as known and supplemented as Velo learns more: the nature of the breach and the categories and approximate number of Data Subjects and records affected; the likely consequences; the measures taken or proposed to address it; and a Velo contact point.
11.3Velo will contain, investigate and remediate the breach, document what happened and what it did, and give Customer reasonable assistance with Customer’s own notifications to Supervisory Authorities and Data Subjects.
11.4Velo will not notify a Supervisory Authority or Data Subject on Customer’s behalf, or name Customer in such a notification, without Customer’s prior written consent, unless the law requires it.
11.5Notifying or responding to a Personal Data Breach is not an admission of fault or liability by Velo.
12. Impact Assessments
12.1Velo will give Customer reasonable assistance with data protection impact assessments and prior consultations with a Supervisory Authority, limited to Velo’s Processing of Customer Personal Data and to the information available to Velo. Velo may charge for assistance that requires material effort.
13. Audit and Information Rights
13.1Velo will give Customer the information reasonably needed to demonstrate compliance with Article 28 of the EU GDPR, including the current Annex II, Velo’s security white paper, completed security questionnaires, and any third-party audit reports or certifications Velo holds.
13.2Where that is not enough, Customer may audit Velo’s Processing on thirty (30) days’ written notice, once in any twelve (12) month period. Audits run during business hours, must not unreasonably disrupt Velo’s operations, and must not reach the data, systems or facilities of any other Velo customer.
13.3The once-a-year limit does not apply where a Supervisory Authority requires an audit, or where one follows a confirmed Personal Data Breach affecting Customer Personal Data.
13.4Customer bears the cost of an audit, including Velo’s reasonable cost of cooperating. Any auditor Customer appoints must not be a competitor of Velo and must be bound by confidentiality obligations no less protective than those in the Agreement. What an audit reveals is Velo’s Confidential Information.
14. International Data Transfers
14.1Velo Processes Customer Personal Data in the United States. Sub-processors may Process it in the United States and elsewhere, as Annex III states.
14.2For Restricted Transfers from the European Economic Area, the SCCs are incorporated into this DPA and deemed executed on the Effective Date, as follows:
- Module Two (controller to processor) applies where Customer is a Controller, and Module Three (processor to processor) where Customer is itself a Processor acting for a third-party controller;
- in Clause 7, the docking clause applies;
- in Clause 9(a), Option 2 applies, with the thirty (30) day notice period set out in clause 8.2;
- in Clause 11(a), the optional independent dispute resolution provision does not apply;
- in Clause 17, Option 1 applies and the law of Ireland governs;
- in Clause 18(b), the courts of Ireland have jurisdiction;
- Annexes I, II and III of this DPA populate Annexes I, II and III of the SCCs; and
- the certification of deletion under Clause 8.5 and Clause 16(d) is provided on Customer’s written request.
14.3For Restricted Transfers from the United Kingdom, the UK Addendum is incorporated and deemed executed on the Effective Date. Neither Party may terminate it under Table 4 when the ICO issues a revised approved addendum under section 18. Annexes I, II and III of this DPA populate Tables 1 to 3.
14.4If the SCCs or the UK Addendum are invalidated, replaced or amended, or another transfer mechanism becomes necessary, the Parties will put a lawful alternative in place without undue delay.
14.5Velo will tell Customer if a public authority makes a legally binding request for Customer Personal Data, unless the law forbids it. Velo will challenge requests that appear unlawful or overbroad and disclose only what it is legally required to disclose.
15. California Consumer Privacy Act
15.1This clause applies to Customer Personal Data that is personal information of a California Consumer. Customer is the Business and Velo is a Service Provider.
15.2Velo is prohibited from, and will not: (a) Sell or Share that personal information; (b) retain, use or disclose it for any purpose other than the business purposes specified in the Agreement and this DPA, including for its own commercial purposes; (c) retain, use or disclose it outside the direct business relationship between the Parties; or (d) combine it with personal information from another source, except as the CCPA permits.
15.3Velo certifies that it understands the restrictions in clause 15.2 and will comply with them.
15.4Velo will tell Customer promptly if it can no longer meet its obligations as a Service Provider. Customer may then take reasonable steps to stop and remediate any unauthorised use of personal information.
15.5Velo will give Customer reasonable assistance with verifiable Consumer requests to know, delete, correct, opt out of Sale or Sharing, and limit the use of sensitive personal information. Velo will apply any deletion instruction to Customer Personal Data it holds and pass it to its Sub-processors.
15.6Customer’s disclosure of personal information to Velo under the Agreement is not a Sale or a Share, and Velo provides no monetary or other valuable consideration for it.
16. Return and Deletion
16.1Customer may access, export and delete Customer Personal Data through the Services at any time during the term of the Agreement.
16.2For thirty (30) days after the Agreement ends, Velo will keep Customer Personal Data available for export. Customer may instead instruct Velo in writing during that period to return it in a commonly used, machine-readable format.
16.3After that period, Velo will delete Customer Personal Data from production systems within a further thirty (30) days, and from encrypted backups within the backup rotation cycle, which does not exceed thirty-five (35) days from deletion in production.
16.4Velo may keep Customer Personal Data where the law requires, for as long as the law requires. Retained data stays subject to this DPA and is Processed only for the purpose requiring its retention.
16.5Velo will certify deletion in writing on Customer’s written request.
17. Liability
17.1Each Party’s liability under this DPA is subject to the exclusions and limitations of liability in the Agreement.
17.2Nothing in this DPA limits either Party’s liability to a Data Subject under the SCCs or the UK Addendum, or any liability that cannot be limited under Applicable Data Protection Law.
18. Term and Survival
18.1This DPA takes effect on the Effective Date and continues for as long as Velo Processes Customer Personal Data under the Agreement.
18.2Clauses 6, 11, 14, 16, 17 and 19, and the SCCs and UK Addendum so far as their terms require, survive termination or expiry.
19. General
19.1Velo may update this DPA to reflect changes in Applicable Data Protection Law, the Services or its Sub-processors, provided no update materially reduces Customer’s protections. Velo will give at least thirty (30) days’ notice of a material change, by email to the administrative contact on Customer’s account and by updating the date at the top of this page.
19.2If a provision is held invalid or unenforceable, the rest continues in force and the Parties will agree a valid provision closest to the original intent.
19.3This DPA is governed by the law and jurisdiction stated in the Agreement, except that the SCCs and the UK Addendum are governed as set out in clause 14.
19.4Accepting the Agreement constitutes acceptance of this DPA and, where applicable, execution of the SCCs and the UK Addendum under clause 14, by Customer on its own behalf and for any Affiliate it acts for. A signed counterpart is available on request at support@usevelo.ai.
Annex I — Details of Processing
Populates Annex I of the SCCs and Tables 1 and 3 of the UK Addendum.
A. List of Parties
| Item | Data Exporter | Data Importer |
|---|---|---|
| Name | Customer, as defined in the Agreement | Flowframe, Inc., trading as Velo |
| Address | As stated in the Agreement or Order Form | 131 Continental Drive, Suite 305, Newark, Delaware 19713, United States |
| Contact | The administrative contact on Customer’s account | support@usevelo.ai |
| Activities relevant to the transfer | Use of the Velo AI video platform to create, translate, host and distribute video content | Provision of the Velo AI video platform and related support services |
| Role | Controller (or Processor, where Customer acts on behalf of a third-party controller) | Processor (or Sub-processor) |
| Signature and date | Deemed signed on the Effective Date under clause 14.2. | Deemed signed on the Effective Date under clause 14.2. |
B. Description of Transfer
| Item | Description |
|---|---|
| Categories of Data Subjects | Customer’s authorised users and administrators; employees, contractors and other personnel of Customer who appear in, narrate or contribute to video content; Customer’s own customers, prospects and end users who appear in source material or who view or interact with published videos; any other individuals whose Personal Data Customer chooses to submit to the Services. |
| Categories of Personal Data | Identity and contact data (name, business email address, username, job title, profile photograph); authentication and account data (identity-provider identifiers, role and workspace membership, session records); content data (screen recordings, uploaded documents, URLs and other source material designated by Customer, scripts, prompts, project metadata and generated video output); media and likeness data (microphone audio, voice samples and recordings, images of faces, synthesised voice and avatar outputs); usage and technical data (IP address, device and browser information, log-in activity, viewer interaction and analytics data for published video pages); support data (correspondence and attachments submitted to Velo support). |
| Special categories of data | None. Clause 4.4 prohibits Customer from submitting special categories of Personal Data, criminal-offence data, payment card data, government-issued identifiers or protected health information without the Parties’ prior written agreement. Velo does not use voice or facial data to uniquely identify a natural person. |
| Frequency of transfer | Continuous, for the duration of the Agreement. |
| Nature and purpose of Processing | Hosting, storage, transcription, translation, generation, rendering, encoding, delivery and analytics of video content; authentication and access control; provision of technical support; security monitoring, logging and incident response; billing and account administration. |
| Duration of Processing | The term of the Agreement, plus the return and deletion periods in clause 16. |
| Transfers to Sub-processors | As set out in Annex III. Each Sub-processor Processes Customer Personal Data only for the function stated against it, for as long as Velo engages it. |
| Retention period | Retained for the term of the Agreement and deleted under clause 16. Backups and audit logs run on a rolling cycle not exceeding thirty-five (35) days. |
C. Competent Supervisory Authority
Where Customer is established in the European Economic Area, the competent Supervisory Authority is the Supervisory Authority of the EEA Member State in which Customer is established. Where Customer is not established in the EEA but has appointed a representative under Article 27 of the EU GDPR, it is the Supervisory Authority of the Member State in which that representative is established. In all other cases, the competent Supervisory Authority is the Irish Data Protection Commission. For transfers subject to the UK Addendum, the competent authority is the UK Information Commissioner’s Office.
Annex II — Technical and Organisational Measures
Populates Annex II of the SCCs. Measures marked “In progress” are commitments on the stated timeline, not controls in place today.
| Measure | Implementation |
|---|---|
| Hosting and infrastructure | The Services run on Amazon Web Services in a private VPC in a single United States region. Cloudflare provides DNS, edge TLS termination and web application firewall protection in front of the application. The control plane (user management, storage, database and rendering) runs only in Velo’s AWS environment and is never deployed inside customer infrastructure. |
| Encryption in transit | TLS at the Cloudflare edge and again at Velo’s AWS load balancer. The production database enforces SSL. Customer Personal Data reaches Sub-processors over TLS. |
| Encryption at rest | AES-256 across Amazon RDS, EBS volumes and S3. S3 public access is blocked and object versioning is on. A dedicated AWS KMS key store holds the keys and protects Velo’s CloudTrail logs. Credentials and secrets live in AWS Secrets Manager. |
| Authentication | Delegated to WorkOS over OpenID Connect; Velo stores no passwords. Every request carries a signed JWT verified against the WorkOS JWKS endpoint. Enterprise single sign-on, OAuth social log-in and reCAPTCHA are supported. |
| Authorisation and access control | Role-based per workspace (owner, member and Library-level roles), enforced server-side on every action. Administrative functions are restricted to administrator roles. Internal access to production and to Customer Personal Data is least-privilege, need-to-know, and reviewed periodically. |
| Tenant isolation | Every record is bound to a workspace identifier, verified server-side on every request. Client-supplied identifiers are never trusted. Rendering and agent workloads run on non-root, locked-down ephemeral machines, scoped, network-allowlisted and destroyed after each run. |
| Personnel | Written confidentiality obligations, background screening so far as local law permits, and security and privacy training on joining and at least annually after that. Acceptance of Velo’s information security and HR policies is recorded. |
| Logging and audit | The application and the agent planner emit audit events to a central logging layer. CloudTrail records control-plane activity, CloudWatch collects application logs, Sentry captures errors and traces. Error and trace payloads are scrubbed of sensitive values such as session tokens before they leave. Log validation and centralised metrics run across the environment. |
| Monitoring and alerting | Continuous monitoring through Sentry, operational metrics and health checks. Alerts route through Amazon SNS into Velo’s incident channels for triage. |
| Incident response | Procedures for detecting, triaging, containing and remediating security incidents, and notification of affected customers under clause 11. In progress: a formal incident-response runbook and severity-based response SLAs, targeted for 1 September 2026. |
| Vulnerability and patch management | Velo monitors security advisories affecting its infrastructure and dependencies and patches on a risk-prioritised basis. In progress: a documented vulnerability management programme, recurring automated scanning and annual third-party penetration testing, targeted for 1 September 2026. |
| Backup and resilience | Amazon RDS automated backups and CloudTrail logs are retained thirty-five (35) days. S3 object versioning recovers overwritten or deleted objects. In progress: documented recovery objectives and periodic restoration testing, targeted for 1 September 2026. |
| Data minimisation with Sub-processors | Sub-processors receive only the minimum data their function requires. Speech-to-text runs in-house on Velo infrastructure and reaches no third-party transcription provider. Billing, email and CRM Sub-processors receive account metadata only, never video content. |
| Deletion | Deletion follows clause 16 and propagates to backups within the thirty-five (35) day rotation cycle. In progress: automated hard-deletion tooling, configurable share-link expiry and a self-service data subject request workflow, targeted for 1 September 2026. |
| Governance and certification | Velo is working toward SOC 2 Type II and ISO/IEC 27001 readiness, targeted for 1 September 2026, and is aligning its privacy programme with the EU GDPR. Velo holds neither today. |
Annex III — Authorised Sub-processors
Populates Annex III of the SCCs. Changes are notified under clause 8.2.
Infrastructure and platform
| Sub-processor | Function | Data received | Location |
|---|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting, compute, storage, managed database, key management and audit logging | All Customer Personal Data | United States |
| Cloudflare, Inc. | DNS, edge TLS termination, content delivery and web application firewall | Traffic in transit; IP addresses | Global edge |
| WorkOS, Inc. | Identity, authentication and single sign-on | Account metadata only — no video content | United States |
| Mux, Inc. | Video encoding, storage and delivery | Video content and viewer analytics | United States |
| Sentry (Functional Software, Inc.) | Error and performance monitoring | Scrubbed application logs, errors and traces | United States |
Artificial intelligence and media generation
| Sub-processor | Function | Data received | Location |
|---|---|---|---|
| Anthropic, PBC | Large language model inference for script, summary and content generation | Prompts, Customer-designated source material and generated content. No Customer account records. | United States |
| OpenAI, L.L.C. | Large language model inference for script, summary and content generation | Prompts, Customer-designated source material and generated content. No Customer account records. | United States |
| Google LLC | Large language model inference (Gemini) for script, summary and content generation | Prompts, Customer-designated source material and generated content. No Customer account records. | United States |
| Amazon Bedrock (Amazon Web Services, Inc.) | Managed model inference executed within Velo’s own AWS account | Prompts and Customer-designated source material | United States |
| ElevenLabs, Inc. | Voice synthesis, cloning and narration | Audio recordings, voice samples and text to be narrated | United States |
| fal.ai (Features & Labels, Inc.) | Generative media and voice inference | Audio, image and video generation inputs and outputs | United States |
| Cleanvoice AG | Audio clean-up and post-processing of narration and recordings | Audio recordings and voice samples | European Union |
| browser-use | Agent tooling for navigating Customer-designated source material | Customer-designated source material | United States |
| Firecrawl (Sideguide Technologies, Inc.) | Retrieval and structuring of Customer-designated web source material | Customer-designated source material | United States |
| Composio | Agent tooling and third-party integration orchestration | Customer-designated source material and integration metadata | United States |
Business operations
| Sub-processor | Function | Data received | Location |
|---|---|---|---|
| Stripe, Inc. | Payment processing and subscription billing | Billing and transaction data. No video content. | United States |
| Intercom, Inc. | Customer support and in-product messaging | Support correspondence and account metadata | United States |
| PostHog, Inc. | Product analytics | Usage and technical data | United States |
| Google LLC (Google Analytics) | Website analytics | Website usage and technical data | United States |
Velo affiliates providing operational, engineering and support functions may access Customer Personal Data under Velo’s direction, subject to the same obligations. Velo remains liable for their acts and omissions.
Questions about this DPA, requests for a countersigned copy, or security documentation: support@usevelo.ai
See also the Privacy Policy, Terms of Service and Sub-processor list.