Data Processing Agreement
Effective 4 September 2026
1. Parties and roles
Magiska AB, company registration number 559443-8797, Kamgatan 9 E, 415 73 Göteborg, Sweden (“Processor”, “we”), and the account holder identified in the Dubedo account (“Controller”, “you”). Terms defined in the General Data Protection Regulation carry the same meaning here.
You are the controller of the personal data contained in the content you upload. We are your processor for that data. We remain an independent controller for your own account data, which our privacy policy covers and this agreement does not.
2. Scope and instructions
We process personal data only on your documented instructions. Your use of the service is your instruction: uploading a file instructs us to transcribe, translate and dub it; cloning a voice instructs us to derive a speaker embedding and synthesise speech from it; deleting a project instructs us to erase it.
We will tell you if we believe an instruction breaches data protection law, and may decline it. If law requires us to process data beyond your instructions we will tell you first unless that law forbids it.
We will not sell your data, use it for our own purposes, or use it to train artificial intelligence models, and our agreements with our sub-processors prohibit them from doing so.
3. Duration
This agreement runs for as long as we process personal data for you, and ends when we have deleted or returned it under section 10.
4. Confidentiality
Everyone we authorise to access personal data is bound by confidentiality, and access is limited to those who need it to run the service.
5. Security
We maintain the technical and organisational measures in Annex II. We may change them provided the level of protection does not fall.
6. Sub-processors
You give general authorisation for the providers listed at Sub-processors, which forms part of this agreement.
We give at least 30 days' notice before adding or replacing a sub-processor that handles customer content. If you object on reasonable data protection grounds within that period we will work with you to find an alternative, and if we cannot, you may terminate the affected part of the service without penalty and receive a refund of any unused prepaid fees.
We impose data protection obligations on each sub-processor no less protective than those in this agreement, and we remain fully liable to you for their performance.
7. Helping you meet your obligations
Taking into account the nature of the processing and the information available to us, we will help you with:
- Requests from data subjects. If someone contacts us directly about data you control, we will not respond substantively but will pass the request to you without undue delay. The service also lets you access, correct, export and delete content yourself.
- Impact assessments and prior consultation, by supplying information about how we process the data.
- Security of processing, breach notification and communication to data subjects, as section 8 sets out.
We provide reasonable assistance at no charge. We may charge on a time and materials basis where requests are excessive or repetitive.
8. Personal data breaches
We will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting data we process for you. The notification will describe what happened, the categories and approximate number of records and data subjects affected, the likely consequences, and the measures taken or proposed. Where we cannot supply all of it at once we will provide it in stages without further undue delay.
Notifying you is not an admission of fault. Notifying the supervisory authority and the affected individuals is your responsibility as controller.
9. Audit
We will make available the information needed to show compliance with Article 28 of the Regulation, and will answer your reasonable written questions.
Where that is not enough, you may audit us once in any twelve-month period, or more often if a supervisory authority requires it or after a breach affecting your data. Give us 30 days' written notice, conduct the audit during business hours, do not disrupt the service, and treat what you learn as confidential. You bear your own costs; we bear ours for a first audit in any period.
10. Deletion and return
You may delete content at any time from the service, and doing so erases it from active storage immediately, including from object storage.
On termination, and at your choice, we will delete or return all personal data we process for you. Deleting your account performs the deletion.
Encrypted backups are the exception. They expire on a rolling 14-day cycle and are destroyed automatically. We do not restore a backup to remove individual records; deleted data stays isolated in the backup and is not returned to active use except in a genuine disaster recovery, after which we re-apply pending deletions.
We may keep data where law requires, and if we do it stays protected by this agreement.
11. International transfers
Some sub-processors are outside the European Economic Area, as the sub-processor list records. Those transfers rely on the European Commission's standard contractual clauses or on a provider's Data Privacy Framework certification, together with the measures in Annex II.
Where the standard contractual clauses apply, module three, processor to processor, is incorporated by reference for transfers we make as your processor, and module two, controller to processor, for transfers we make as controller of your account data. The annexes below serve as the clauses' annexes, Integritetsskyddsmyndigheten is the competent supervisory authority, and Swedish law governs.
12. Liability and precedence
Liability under this agreement is subject to the limitations in our Terms of Use, except where the Regulation does not permit that.
If this agreement conflicts with the Terms of Use on the processing of personal data, this agreement prevails. If it conflicts with the standard contractual clauses, the clauses prevail.
13. Annex I — Details of the processing
Categories of data subjects
- People who appear or speak in the content you upload
- People named or described in that content
- Your own personnel who use the account
Categories of personal data
- Voice recordings and video containing identifiable people
- Speaker embeddings derived from voice recordings
- Transcripts, including anything spoken about an identifiable person
- Translations and synthesised speech generated from the above
- Speaker labels and timings
- Names, brands and terms supplied as transcription guide words
- File names and project names you choose
Special categories. The service is not designed for special category data. We use speaker embeddings only to reproduce a voice, never to recognise or match one, so they are not used to identify anyone. Do not upload content containing special category data without telling us first, so we can assess whether extra measures are needed.
Nature and purpose. Storage, format conversion, separation of speech from background audio, speech recognition and speaker separation, machine translation, speech synthesis in a chosen voice, mixing and export, all to produce a dubbed version of your material.
Duration. Until you delete the content or your account, subject to the backup cycle in section 10. Frequency. Continuous, on your instruction.
14. Annex II — Technical and organisational measures
Access control
- Authentication through a dedicated identity provider. Every request carries a token verified against that provider's published signing keys, with issuer and audience checked.
- Every route that touches a project, track, transcript or voice filters by the authenticated account, so one customer cannot reach another's data.
- Database access rules deny browser clients any direct read of application tables.
- Administrative functions are restricted to an explicit allowlist of accounts.
Encryption
- TLS for all data in transit, including to sub-processors.
- Encryption at rest for the database and object storage.
- Media is served only through expiring signed links, so a file cannot be fetched by guessing an address.
- Database backups are encrypted before leaving our infrastructure, with the key held separately.
Availability and resilience
- Daily automated database backups, verified by test decryption, retained 14 days.
- Uptime and error monitoring with alerting, configured not to collect personal data.
- Rate limits and per-account daily ceilings on processing operations.
Integrity and accountability
- Structured request logging with request identifiers.
- A ledger recording every processing operation run for an account.
- Automated tests covering account isolation, billing integrity and deletion, run on every change.
- Changes reach production through version control and an automated pipeline.
Deletion
- Users can delete individual projects, voices and their whole account from the interface.
- Deletion removes database records and the corresponding files from object storage in the same operation.
What we do not currently have. No formal information security certification, no independent penetration test, no staffed round-the-clock monitoring, and no formal security awareness training programme. We state this plainly rather than imply otherwise, and will update this annex as it changes.
15. Annex III — Sub-processors
The current list, with each provider's role, location and transfer safeguard, is at Sub-processors and is incorporated here by reference. A copy as at the effective date is attached to the signed version of this agreement on request.