Data Processing Addendum
This Data Processing Addendum ("DPA") is incorporated into the Prism Terms of Service (the "Agreement") between Channel 1, Inc. ("Channel 1") and the customer entity that accepts the Agreement ("Customer"). It applies to the extent Channel 1 processes Personal Data contained in Customer Content on Customer's behalf in providing the Service.
1. Definitions
1.1 "Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and applicable U.S. state privacy laws including the California Consumer Privacy Act as amended ("CCPA").
1.2 "Personal Data" means information relating to an identified or identifiable natural person that is contained in Customer Content and processed by Channel 1 on Customer's behalf.
1.3 "Processing," "Controller," "Processor," "Business," "Service Provider," and "Data Subject" have the meanings given in applicable Data Protection Laws.
1.4 "Subprocessor" means a third party engaged by Channel 1 to process Personal Data on its behalf in providing the Service.
1.5 "Standard Contractual Clauses" or "SCCs" means the clauses approved by the European Commission in Implementing Decision (EU) 2021/914, as supplemented by the UK Addendum issued by the UK Information Commissioner's Office.
2. Roles and Scope
2.1 As between the parties, Customer is the Controller (or, where Customer acts on behalf of its own customers, a Processor) and Channel 1 is a Processor (or Subprocessor) of Personal Data.
2.2 For CCPA purposes, Channel 1 acts as a Service Provider, and Customer discloses Personal Data to Channel 1 only for the limited and specified purposes described in Section 3.3. Channel 1: (a) will process Personal Data only for those purposes; (b) will not sell or share Personal Data; (c) will not retain, use, or disclose Personal Data outside its direct business relationship with Customer or for any purpose other than providing the Service, except as permitted by the CCPA; (d) will provide the same level of privacy protection as required of businesses under the CCPA; (e) grants Customer the right to take reasonable and appropriate steps to ensure that Channel 1 uses Personal Data in a manner consistent with Customer's CCPA obligations (including through the measures in Section 9), and, upon notice, to stop and remediate any unauthorized use; (f) will notify Customer without undue delay if it determines it can no longer meet its CCPA obligations; (g) will assist Customer in responding to consumer requests as set out in Section 7 and, as applicable, with cybersecurity audits, risk assessments, and requirements relating to automated decisionmaking technology under the CCPA and its regulations; and (h) will ensure that its contract with each Subprocessor processing Personal Data complies with the CCPA. Channel 1 certifies that it understands and will comply with these restrictions.
2.3 This DPA does not apply to personal information Channel 1 processes as a controller in its own right (e.g., Customer's account, billing, and usage data), which is governed by the Channel 1 Privacy Policy.
2.4 Customer-Directed Third-Party Services. If Customer connects an account, API key, voice, or other resource for a third-party service selected and controlled by Customer, Customer instructs Channel 1 to transmit the Personal Data necessary to operate that connection. The third party is not Channel 1's Subprocessor merely because Customer directs the connection; Customer is responsible for its relationship and data-protection arrangements with that provider. Channel 1 remains responsible for securing the credential and transmission while under Channel 1's control.
3. Processing Instructions
3.1 Channel 1 will process Personal Data only on Customer's documented instructions, including regarding international transfers, unless processing is required by applicable law to which Channel 1 is subject. In that case, Channel 1 will inform Customer of the legal requirement before processing, unless that law prohibits such notice on important grounds of public interest. Customer's documented instructions consist of: (a) the Agreement and this DPA; (b) Customer's configuration and use of the Service and its features; and (c) any other written instructions Customer provides that are consistent with the Agreement.
3.2 Channel 1 will inform Customer if, in its opinion, an instruction infringes Data Protection Laws (without obligation to provide legal advice).
3.3 Details of processing. Subject matter: provision of the Prism platform. Duration: the subscription term plus the post-termination export and deletion windows. Nature and purpose: hosting, transcoding, transcription, AI-assisted analysis, indexing, editing, rendering, storage, delivery, support, security, reliability, and debugging of Customer Content. To diagnose product behavior, Channel 1 may store prompts, responses, and related logs containing Customer Content in Channel 1-controlled systems while the account is active, limited to what is reasonably necessary for troubleshooting, support, security, and reliability and subject to periodic review. Such content-bearing logs follow the deletion period in Section 11 after termination; they may be retained longer only for an active investigation, legal obligation, or dispute. Non-content metadata and properly de-identified data may be retained longer. Categories of Data Subjects: individuals appearing or referenced in Customer Content (e.g., interview subjects, presenters, members of the public in footage). Categories of Personal Data: image and likeness, voice, name, prompts, transcripts, and other information contained in media and text submitted by Customer. Personal data of Customer's Authorized Users relating to accounts, billing, and Service usage is processed by Channel 1 as a controller under its Privacy Policy and is outside the scope of this DPA, except to the extent it appears within Customer Content.
3.4 Special categories. Customer Content may incidentally include special categories of Personal Data and data relating to criminal convictions and offences (for example, footage or reporting that reveals political opinions, religious beliefs, health information, sexual orientation, or alleged offences). Channel 1 processes such data solely as part of Customer Content, under Customer's instructions, applies the Annex II measures to all Customer Content without differentiation, and does not use such data for any independent purpose. Customer is responsible for ensuring it has a lawful basis and, where required, an applicable condition (including any journalistic-purposes provisions of applicable law) for submitting such data for processing.
3.5 No biometric identification in self-serve Prism. The self-serve Service does not perform biometric identification or create biometric templates. Processing of ordinary footage, images, and voices for transcription, analysis, and user-directed editing does not authorize Channel 1 to identify individuals by biometric characteristics. Any future enterprise biometric functionality requires a separate written agreement and applicable notices and consents.
4. Confidentiality and Personnel
4.1 Channel 1 will ensure that personnel authorized to process Personal Data are bound by confidentiality obligations and access Personal Data only as needed to provide the Service.
5. Security
5.1 Channel 1 will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex II. Channel 1 may update these measures provided the updates do not materially reduce overall protection.
6. Subprocessors
6.1 Customer generally authorizes Channel 1 to engage Subprocessors. The current named list, locations, and processing functions will be made available through a customer-accessible subprocessor page or register at https://www.meetprism.com/legal/subprocessors, and Customer may subscribe there to change notifications. Public-facing policies may describe providers by category for security and vendor-management flexibility.
6.2 Channel 1 will provide at least 15 days' advance notice before adding or replacing a Subprocessor. If an emergency involving security, availability, law, or provider discontinuation makes advance notice impracticable, Channel 1 may engage the replacement sooner and will notify Customer without undue delay. If Customer reasonably objects on data-protection grounds and the parties cannot resolve the objection, Customer may terminate the affected subscription and receive a pro rata refund of prepaid base subscription fees for the unused period — Customer's sole remedy for such objection.
6.3 Channel 1 will enter into a written agreement with each Subprocessor imposing, in substance, the same data-protection obligations that apply to Channel 1 under this DPA, including all obligations required by applicable Data Protection Laws, and Channel 1 remains fully liable for its Subprocessors' performance.
7. Data Subject Requests
7.1 Taking into account the nature of the processing, Channel 1 will provide reasonable assistance (including through Service functionality such as search, export, and deletion tools) to enable Customer to respond to Data Subject requests. If a Data Subject contacts Channel 1 directly regarding Personal Data processed under this DPA, Channel 1 will redirect the request to Customer without responding substantively, unless required by law.
8. Personal Data Breach
8.1 Channel 1 will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting Personal Data processed under this DPA, and will provide information reasonably available to help Customer meet its own notification obligations. Channel 1's notification is not an admission of fault.
9. Assistance and Audits
9.1 Channel 1 will provide reasonable assistance with Customer's data protection impact assessments and consultations with supervisory authorities, to the extent required by Data Protection Laws and taking into account the information available to Channel 1.
9.2 Channel 1 will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant independent audit reports or certifications if and when available. Customer will review available documentation first. Where it is reasonably insufficient, or an audit is required by Data Protection Laws or a supervisory authority, Channel 1 will allow and contribute to an audit conducted by Customer or its independent auditor. Audits will be remote where practicable; subject to reasonable confidentiality, scope, timing, and security conditions; and no more than once in any 12-month period except following a Personal Data breach affecting Customer's Personal Data or where required by a supervisory authority. Customer bears its own costs and Channel 1's reasonable costs of an audit unless the audit identifies a material violation of this DPA by Channel 1, in which case Channel 1 will bear its reasonable participation costs.
10. International Transfers
10.1 Customer authorizes Channel 1 to transfer Personal Data to the United States and to locations disclosed in the customer-accessible Subprocessor register, subject to this Section. Channel 1's production hosting for the self-serve Service uses multiple cloud regions within the United States.
10.2 For transfers from the EEA, the SCCs (Module Two: Controller → Processor, and Module Three: Processor → Processor, as applicable) are incorporated by reference and deemed executed by the parties' acceptance of the Agreement, completed as follows: Clause 7 (docking) included; Clause 9 option 2 (general authorization, notice period per Section 6.2); Clause 11 optional language excluded; Clause 17: Irish law; Clause 18: courts of Ireland; Annexes I–III as set out in the Annexes to this DPA.
10.3 For transfers from the UK, the ICO's International Data Transfer Addendum to the EU SCCs is incorporated as follows: Part 1 (Tables 1–4) is completed using the parties' details in Annex I, the SCC module selections and options in Section 10.2, and the appendix information in Annexes I–III, with the "ending this Addendum when the Approved Addendum changes" option exercisable by [importer / exporter / neither — counsel to select]; Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses. For transfers from Switzerland, the SCCs apply as adapted for the Swiss Federal Act on Data Protection: references to the GDPR are read as references to the FADP, the competent supervisory authority under Annex I includes the Swiss Federal Data Protection and Information Commissioner, and data subjects in Switzerland may enforce their rights in Switzerland.
11. Return and Deletion
11.1 During the 30-day export window following termination (Agreement §10.4), Customer may export Customer Content including Personal Data. After that export window, Channel 1 will delete Personal Data from active systems within the next 30 days, except where longer retention is required by law, an active security investigation, or a dispute. Retained data will be isolated and protected, used only for the retention purpose, and deleted when retention is no longer required. Protected backup copies are deleted or overwritten in the ordinary course.
12. Liability and Order of Precedence
12.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where prohibited by Data Protection Laws. In the event of conflict: (a) the SCCs prevail over this DPA; (b) this DPA prevails over the Agreement with respect to Personal Data processing.
Annex I — Processing Details
Parties: the Customer identified in the order record created at signup or checkout — full legal name, address, registration number where applicable, and contact details, which Customer must provide accurately and which complete the party tables of Annex I and the UK Addendum Part 1 — (data exporter, Controller/Processor) and Channel 1, Inc., 8605 Santa Monica Blvd PMB 69591, West Hollywood, CA 90069 (data importer, Processor). Contact: privacy@channel1.ai. Processing details: as set out in Sections 3.3–3.5. Sensitive data (Annex I.B): Customer Content may incidentally include special categories of personal data and data relating to criminal convictions and offences, as described in Section 3.4. Applied restrictions and safeguards: processing solely as part of Customer Content under Customer's documented instructions; no independent use, profiling, or enrichment of sensitive attributes; uniform application of the Annex II technical and organizational measures (including encryption in transit and at rest and role-based access controls) to all Customer Content; personnel confidentiality obligations per Section 4; and deletion per Section 11. Frequency: continuous during the subscription.
Competent supervisory authority: [determine per SCC Clause 13 based on the exporter's establishment, any Art. 27 representative, and affected data subjects — do not hard-code].
Annex II — Technical and Organizational Measures
| Domain | Measures |
|---|---|
| Access control | Role-based access, strong authentication for personnel, least-privilege access, prompt access changes following role changes or termination, and formal access reviews at least annually |
| Encryption | TLS 1.2+ in transit; AES-256 at rest across object storage, relational, and vector layers |
| Infrastructure | Cloud hosting in multiple regions within the United States; logical tenant isolation; network and environment controls appropriate to risk |
| Monitoring | Centralized security and operational logging, alerting, vulnerability management, and restricted access to content-bearing debugging logs |
| Incident response | Documented IR plan with defined severity levels and notification workflow |
| Business continuity | Documented backup, recovery, and continuity procedures tested periodically |
| Personnel | Background checks where permitted, security training, confidentiality agreements |
| Assurance | Independent reports or certifications may be made available under confidentiality if and when completed |
Annex III — Subprocessors
The authorized, named Subprocessor list is maintained in the customer-accessible register described in Section 6.1 and incorporated into this Annex III by reference. At launch, the relevant categories are: cloud hosting and storage providers in multiple United States regions; an AI analysis provider used to analyze footage and related Customer Content under a paid business account; and a transcription provider configured not to use Customer Content for generalized model improvement. The register must state each provider's legal name, service, processing location, and processing purpose. A customer-selected synthetic-voice provider connected with the customer's own account or API key is a Customer-Directed Third-Party Service under Section 2.4, not a Channel 1 Subprocessor for that connection. Payment processing and basic public-website delivery providers do not process Customer Content and are not Subprocessors under this DPA.