The published policy is rendered from the current policy record.
Effective Date: July 1, 2026
Last Updated: July 1, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer" or "Controller") and ActorConsole ("Processor") for the use of ActorConsole's services.
1. Definitions
Personal Data: Any information relating to an identified or identifiable natural person
Processing: Any operation performed on Personal Data (collection, storage, use, transfer, deletion)
Controller: The party that determines the purposes and means of processing (the Customer)
Processor: The party that processes Personal Data on behalf of the Controller (ActorConsole)
Sub-processor: A third-party processor engaged by ActorConsole
GDPR: The EU General Data Protection Regulation (Regulation 2016/679)
2. Scope and Purpose
This DPA applies when the Customer uses ActorConsole to process Personal Data, including:
Account information (name, email)
Actor metadata and content
API credentials for connected services
Usage analytics
ActorConsole processes Personal Data solely to provide the Service as described in the Terms of Service.
3. Roles
Customer is the Controller — You determine what Personal Data is submitted to the Service and the purposes for which it is processed.
ActorConsole is the Processor — We process Personal Data only in accordance with your instructions and as necessary to provide the Service.
We will notify the Customer at least 30 days before engaging a new Sub-processor. Notification will be sent via email to the account owner.
4.2 Objection to New Sub-processors
The Customer may object to a new Sub-processor within 30 days of notification by contacting dpa@actorconsole.com. If we cannot reasonably accommodate the objection, the Customer may terminate the affected Service without penalty.
5. Data Security
ActorConsole implements appropriate technical and organizational measures to protect Personal Data:
5.1 Encryption
At rest: AES-256-GCM encryption for all stored credentials and sensitive data
In transit: TLS 1.2 or higher for all data transmission
5.2 Access Controls
Role-based access control (RBAC) with least-privilege principles
Multi-factor authentication for administrative access
Regular access reviews
5.3 Infrastructure
Cloud hosting with SOC 2 Type II compliance
Automated backups and disaster recovery
Network isolation and firewall protections
5.4 Incident Response
Documented incident response procedures
Notification to the Customer within 72 hours of a confirmed data breach
Cooperation with Customer's investigation of any security incident
6. Data Subject Rights
6.1 Assistance
ActorConsole will assist the Customer in responding to data subject requests by:
Responding to data access or correction requests forwarded by the Customer
6.2 Response Time
We will respond to data subject requests forwarded by the Customer within 5 business days.
7. Data Transfers
7.1 International Transfers
Personal Data may be transferred to and processed in countries other than the Customer's country of residence.
7.2 Safeguards
For transfers outside the EEA/UK, we rely on:
Standard Contractual Clauses (SCCs) where applicable
Adequacy decisions where available
Appropriate technical and organizational safeguards
8. Data Retention and Deletion
8.1 Retention
Personal Data is retained for the duration of the Service agreement and as follows after termination:
Account data: deleted within 30 days
Usage data: deleted within 30 days
Payment records: retained as required by law (up to 7 years)
Support tickets: retained for 36 months
8.2 Deletion Process
Upon Customer request or account termination:
Customer data is flagged for deletion
Data is removed from active systems within 30 days
Backups are purged within 90 days
A deletion confirmation is provided to the Customer
9. Auditing
9.1 Right to Audit
The Customer may request an audit of ActorConsole's compliance with this DPA once per calendar year.
9.2 Audit Process
Requests must be submitted in writing to dpa@actorconsole.com with 30 days' notice
Audits are conducted during business hours with reasonable scope
The Customer bears audit costs unless a material breach is identified
9.3 Third-Party Audits
ActorConsole may provide SOC 2 Type II reports or equivalent third-party audit reports in lieu of an on-site audit.
10. Liability and Indemnification
10.1 Liability
Each party's liability under this DPA is subject to the limitations set forth in the Terms of Service.
10.2 Indemnification
ActorConsole shall indemnify the Customer against fines or penalties imposed by a supervisory authority resulting from ActorConsole's failure to comply with its obligations under this DPA.
11. Term and Termination
This DPA remains in effect for the duration of the Service agreement. Upon termination, the provisions regarding data retention, deletion, and audit survive for the applicable period.
12. Governing Law
This DPA is governed by the laws of India, consistent with the Terms of Service. For GDPR purposes, the data protection authority of the Customer's EU/UK jurisdiction applies.