Version: 2026-08-31
Brand: Netanza / Media Forge
This Data Processing Addendum (DPA) supplements the Media Forge Terms of Service or applicable order form between Netanza, operating the Media Forge service (Netanza, Processor) and the Customer identified in the applicable agreement (Customer, Controller) when Netanza processes personal data contained in Customer Content on Customer's behalf.
Customer determines the purposes and means of processing personal data contained in Customer Content and instructs Netanza to perform the media-processing operations requested through the Service. Netanza processes that personal data only to provide, secure, support, and operate the Service according to Customer's documented instructions, except where law requires otherwise.
For Netanza's own account administration, billing, security, fraud prevention, and legal obligations, the parties acknowledge that Netanza may process limited information as an independent controller/business rather than as Customer's processor.
Customer's documented instructions consist of:
the Agreement and this DPA;
authorized API requests and configured processing parameters;
Customer-selected source and destination locations;
support instructions submitted by authorized Customer personnel; and
other written instructions mutually agreed by the parties.
Netanza will notify Customer if, in Netanza's reasonable view, an instruction violates applicable data-protection law, unless prohibited from doing so.
Processing may include receiving, accessing, reading, copying as technically necessary, decoding, inspecting metadata, transcoding, transforming, stitching, packaging, encrypting in transit/at rest through platform services, storing temporarily, transmitting, deleting, and generating operational records necessary to provide requested media-processing Jobs.
The purpose is to provide the Media Forge private media-processing API and related support, security, billing, and reliability functions.
Depending on Customer Content, personal data may include images, video, audio, metadata, identifiers, voices, likenesses, location or device metadata, and other information chosen by Customer. Data subjects may include Customer personnel, Customer end users, media subjects, or other individuals whose data Customer lawfully submits.
Customer is responsible for determining whether special-category/sensitive data may be submitted and for obtaining any required lawful basis or consent.
Netanza processes Customer Content for the duration of the requested Job and any applicable platform-managed output-retention period. Platform-managed derived outputs are currently subject to a 30-day automatic deletion lifecycle. Customer-controlled destinations are governed by Customer's own retention settings.
Upon termination or Customer request, Netanza will delete or return processor-controlled Customer Content where reasonably practicable, subject to ordinary lifecycle behavior, backup/technical constraints, and legal preservation obligations. Operational, billing, security, and audit records that do not contain the media payload may be retained as reasonably necessary.
Netanza will limit personnel access to Customer personal data to people who require access for an authorized operational, support, security, abuse, or legal purpose and who are subject to confidentiality obligations.
Routine human review of Customer Content is not part of the Service.
Netanza will maintain reasonable technical and organizational measures appropriate to the Service, including as applicable:
tenant-scoped authenticated authorization;
least-privilege service identities and bounded deployment authority;
protected secrets and credential rotation/revocation controls;
encrypted cloud transport and storage services;
production network and edge controls;
audit and usage records;
controlled CI/CD and infrastructure-as-code authority;
output-retention lifecycle controls;
incident containment procedures; and
separation of Customer Content from billing/usage authority.
Netanza may update safeguards as technology and risk evolve without materially reducing overall protection.
Customer authorizes Netanza to use subprocessors reasonably necessary to provide the Service. Netanza will maintain an up-to-date subprocessor register before customer contracting that identifies the provider, purpose, and relevant processing location/category.
Netanza will impose data-protection obligations on subprocessors appropriate to the processing they perform. For customers whose applicable law requires advance notice or objection rights, the order form or subprocessor register will state the applicable notice mechanism.
Taking into account the nature of processing, Netanza will provide reasonable assistance to Customer in responding to legally valid requests from data subjects where the relevant personal data is within Netanza's processor-controlled systems and Customer cannot reasonably fulfill the request without Netanza's assistance.
Netanza will ordinarily direct a requester concerning Customer Content to the Customer as controller.
Netanza will notify Customer without undue delay after confirming a security incident involving unauthorized acquisition of or access to Customer personal data in Netanza's processor-controlled systems, where notification is required by applicable law or contract.
Notification will include information reasonably available concerning the nature of the incident, affected data, likely consequences, and mitigation. Notification is not an admission of fault or liability.
Upon reasonable written request and subject to confidentiality and security restrictions, Netanza will provide information reasonably necessary to demonstrate compliance with this DPA. The parties will first use documentation, certifications, reports, and remote review before requiring an on-site audit.
Any audit must avoid access to other customers' data, secrets, or systems and may be subject to reasonable frequency, scope, scheduling, and cost controls unless applicable law requires otherwise.
If Netanza receives legally binding process seeking Customer personal data, Netanza will, where legally permitted, notify Customer before disclosure and will disclose only information it reasonably determines is required.
If Customer personal data is transferred across borders and applicable law requires a transfer mechanism, the parties will incorporate the then-applicable standard contractual clauses, data-transfer addendum, or other lawful mechanism by reference or order form. Netanza will not represent that a specific jurisdictional transfer mechanism applies until the Customer/jurisdiction is identified.
To the extent an applicable U.S. state privacy law treats Netanza as a processor, service provider, or contractor for Customer Content, Netanza will process covered personal data only for the business purposes specified in the Agreement and this DPA, will not sell that Customer Content personal data, and will not retain, use, or disclose it outside the permitted relationship except as allowed by applicable law.
Customer represents that:
it has a lawful basis and all required rights/permissions for the personal data submitted;
its instructions comply with applicable law;
it will not submit data prohibited by the AUP;
it has implemented appropriate security for Customer-controlled sources/destinations; and
it will provide legally required notices to data subjects.
The liability limitations in the Agreement apply to this DPA unless applicable law requires otherwise. If this DPA conflicts with the Agreement on processing of Customer personal data, this DPA controls for that subject matter.
This DPA remains effective while Netanza processes Customer personal data as Customer's processor under the Agreement and survives only as necessary to complete deletion, return, security, audit, or legal obligations.
Subject matter - Private API-based media processing and related service operations
Duration - Job duration plus applicable retention/legal-preservation period
Purpose - Customer-directed inspection, transformation, transcoding, stitching, packaging, delivery, support, security, billing/reliability
Data subjects - As determined by Customer; may include Customer personnel, end users, media subjects, other individuals
Personal-data categories - Media payload, audiovisual likeness/voice, metadata, identifiers, operational request data as supplied by Customer
Special data - Only if Customer lawfully submits it; not required by the Service
Deletion - Platform-managed derived outputs: currently 30-day automatic lifecycle; Customer destinations: Customer-controlled
Processor: Netanza, operating the Media Forge service
Privacy contact: the contact address published on the Netanza Contact page
Security contact: the contact address published on the Netanza Contact page
Current subprocessor register: Subprocessors
Netanza is completing its operating legal entity name, registered business address, and dedicated privacy and security mailboxes. The final values will be stated in this Annex and in the applicable order form before Netanza executes this DPA with a Customer.