This Data Processing Addendum (“DPA”) describes how ACRCloud processes Personal Data on a Customer’s documented instructions when providing the Services. It forms part of the ACRCloud Terms of Use and any applicable order or subscription.

1. Definitions and scope

“Customer Personal Data” means Personal Data contained in Customer Content, Derived Data, or project-related Service Data that ACRCloud processes on Customer’s behalf. “Personal Data,” “Controller,” “Processor,” “Data Subject,” and “Processing” have the meanings given by applicable data-protection law. “Services Agreement” means the ACRCloud Terms of Use, the applicable order, and any plan or subscription governing the Services.

This DPA applies when Customer is a Controller (or Processor acting for another Controller) and ACRCloud processes Customer Personal Data to provide the Services. If this DPA conflicts with the Services Agreement on the processing of Customer Personal Data, this DPA controls. The order controls service-specific details and commercial terms.

2. Roles and instructions

Customer acts as Controller and ACRCloud acts as Processor for Customer Personal Data processed on Customer’s behalf. ACRCloud may act as an independent Controller for account administration, billing, security of its own systems, direct business communications, and operation of its public website; those activities are described in the ACRCloud Privacy Policy and are outside this DPA.

Customer instructs ACRCloud to process Customer Personal Data as necessary to provide, secure, maintain, and support the Services selected by Customer, including the processing described in the applicable order and Section 12. ACRCloud will process Customer Personal Data only on those documented instructions, unless applicable law requires otherwise. Where legally permitted, ACRCloud will inform Customer of such legal requirement before processing. ACRCloud will inform Customer if it believes an instruction infringes applicable data-protection law, unless law prohibits that notice.

3. Customer responsibilities

Customer is responsible for the lawfulness, accuracy, quality, and means of collecting Customer Personal Data; determining and documenting an appropriate legal basis; giving required privacy notices; obtaining required permissions and consents; and responding to Data Subject requests. Customer will ensure that its instructions and use of the Services comply with applicable law.

Audio or video submitted to a Service may contain a person’s voice, image, or other Personal Data. Customer must inform affected individuals where required. Customer may submit children’s data, including children’s voices, only where the applicable Service and a written order expressly authorize that processing, and Customer has obtained all notices, permissions, parental authorizations, and lawful bases required by law. This DPA does not itself make Customer’s collection or use of children’s data lawful, or authorize ACRCloud to solicit Personal Data directly from children.

Customer must not submit special-category Personal Data, biometric-identification data, or other sensitive data unless the applicable Service and a written agreement expressly permit it.

4. ACRCloud obligations

ACRCloud will:

5. Subprocessors

Customer gives ACRCloud general written authorization to use subprocessors for hosting, security, support, billing, and other functions needed to provide the Services. ACRCloud will impose data-protection obligations on each subprocessor that are no less protective than the applicable obligations in this DPA and remains responsible for its subprocessors’ performance.

The current subprocessor list and applicable processing locations are available from ACRCloud on request at support@acrcloud.com. ACRCloud will notify Customer of an intended material addition or replacement by email or through the Console at least 30 days in advance where reasonably practicable. Customer may object within 15 days after notice on reasonable data-protection grounds by contacting ACRCloud. The parties will work in good faith to address the objection. If they cannot resolve it, Customer may stop using and terminate the affected Service without penalty, and ACRCloud may discontinue that affected Service. For urgent security or legal changes, ACRCloud will give notice as soon as reasonably practicable.

6. International transfers

Customer’s project region is the region selected in the Console or identified in the applicable order. For projects in the US West region, Customer Content and project data are processed and stored in that region; authorized personnel may access project data from outside the United States where necessary to operate and support the Service. A US West selection is not a commitment that access is limited to the United States.

Where an EEA Region is selected, the regional processing and access commitments in the Services Agreement apply. Where a transfer of Customer Personal Data is subject to a legal restriction on international transfers, ACRCloud and Customer will use an applicable lawful transfer mechanism and safeguards required by applicable law. Any completed transfer terms in an order or transfer schedule form part of this DPA and control to the extent of a conflict about that transfer.

7. Data-Subject requests

Individuals whose Personal Data is processed by ACRCloud on Customer’s behalf should direct requests to Customer. Customer is responsible for receiving and responding to those requests. ACRCloud will provide the reasonable assistance required by applicable law, taking into account the nature of Processing and the information available to ACRCloud. ACRCloud does not act as the contact point for an individual’s request to delete Customer project data.

8. Retention, return, and deletion

Raw audio and video. ACRCloud temporarily buffers Customer-uploaded raw audio or video only as needed to transmit and process a request. Transient copies are automatically deleted when processing succeeds or fails and are not kept in long-term backups.

Identification API project data. Fingerprints, recognition results, and request logs are not individually deletable through the Console during an active account. ACRCloud does not provide routine support-ticket or email deletion of individual Identification API records. The Customer account owner is responsible for managing account deletion and for responding to its users’ requests.

To close an active paid account, Customer must contact ACRCloud at support@acrcloud.com solely to request a downgrade to a free account. After the downgrade, Customer may initiate self-service deletion of the entire account through the available account controls. The downgrade contact is not a request for ACRCloud to delete Personal Data. Account deletion closes the whole account and ends access to the Services; it is not a control for deleting one individual’s records while keeping the account active.

When the applicable processing services end, including when Customer self-deletes its account, ACRCloud will, at Customer’s choice and through the applicable account-offboarding process, return or delete Customer Personal Data under its control without undue delay and delete existing copies, unless applicable law requires retention. Any legally required retention will be limited to the data and period required by law and protected against further processing. Data retained for security, legal, or backup purposes is subject to the applicable retention schedule and will be deleted when that retention purpose ends.

9. Security and incidents

ACRCloud will maintain safeguards appropriate to the risk, including access controls, encryption in transit, least-privilege access, logging, and secure deletion procedures. A current description of ACRCloud’s safeguards is available on request at support@acrcloud.com.

ACRCloud’s breach notice will describe the nature of the incident and, as information becomes available, its likely consequences and measures taken or proposed. ACRCloud may provide information in phases if a complete account is not immediately available. Customer is responsible for determining whether and how to notify individuals or authorities.

10. Compliance information and audits

On reasonable written request, ACRCloud will provide information reasonably necessary to demonstrate compliance with this DPA and will contribute to audits or inspections conducted by Customer or an independent auditor mandated by Customer, as required by applicable law. Audits must be limited to Processing relevant to Customer, conducted on reasonable prior notice during normal business hours, subject to confidentiality and security requirements, and arranged to avoid unreasonable disruption. Available third-party audit reports or certifications may be used to address requests where appropriate.

11. Term and other terms

This DPA remains in force while ACRCloud processes Customer Personal Data under the Services Agreement. The liability limits, governing law, dispute provisions, and other general terms in the Services Agreement apply to this DPA unless applicable law requires otherwise. Nothing in this DPA limits either party’s non-waivable obligations or rights under applicable data-protection law.

Questions about this DPA or a Customer’s processing arrangements may be sent to support@acrcloud.com.

12. Processing details and security measures

Subject matter and duration

Provision of the Services identified in the applicable order or account, for the duration of the relevant subscription or service, followed by the return or deletion process in Section 8 and any retention required by law or the applicable retention schedule.

Nature and purpose

Receipt and temporary buffering of Customer Content; generation of fingerprints and other Derived Data; comparison and identification; return of recognition results and related metadata; and processing needed for service operation, security, billing, and support.

Categories of Personal Data

Audio, video, voice samples, transcripts, or other Customer Content submitted to the selected Service; project, request, and user identifiers; timestamps and technical logs; recognition results and related metadata where linked to an individual; and Customer-provided metadata. The particular categories depend on Customer’s use of the Services.

Categories of Data Subjects

Customer’s end users and other individuals whose data is included in Customer Content; individuals whose voices or images are captured; and Customer personnel or API users to the extent their identifiers appear in project records. Children are included only where the applicable Service and written order expressly authorize such processing.

Frequency and processing locations

Processing occurs with each API request and related service, security, or support event. The applicable project region is selected in the Console or stated in the order. Authorized personnel may access project data from outside the selected region where permitted by the applicable regional commitment and necessary to operate or support the Service.

Technical and organizational measures

  • Access controls for systems and data;
  • Encryption in transit;
  • Least-privilege access for authorized personnel;
  • Logging to support security and service operation; and
  • Secure deletion procedures for data scheduled for deletion.

Further current information about safeguards is available from ACRCloud on request.