The processor terms for creator and fan data. This forms part of your agreement with us and applies whenever you connect a creator.
This Data Processing Agreement is between your agency ("you", the controller) and Fandash ("we", "us", the processor). It is incorporated into our Terms of Service and takes effect when you accept those terms or connect a creator, whichever happens first. You do not need to sign a separate copy, though we will sign one on request.
It applies to personal data we process on your behalf. It does not apply to data we process as controller for our own purposes, such as your team's account records, which our Privacy Policy covers. Terms used here that are defined in the GDPR carry their GDPR meaning.
Subject matter. Providing the Fandash platform to you: mirroring your creators' Fanvue data, presenting it, and running the messaging, attribution, payroll, scheduling, and AI features you choose to use.
Nature and purpose. Collection, structuring, storage, retrieval, consultation, use, transmission, generation of derived content, and erasure, in each case to operate the service on your instructions and for no independent purpose of our own.
Duration. From acceptance until your account closes and the deletion in section 10 completes, unless the law requires us to keep something longer.
Categories of data subject. Creators on your roster, fans who interact with those creators, and the members of your team who use the platform.
Categories of personal data. Identifiers and profile data such as handle, display name and avatar; subscription and relationship status; conversation content including attachments, read state and translations; purchase, spending and refund history; engagement and retention signals; notes and list membership your team creates; AI-generated content and the inputs used to produce it; and, where you enable it, creator reference audio and the derived voice model.
Special categories. Conversation content on an adult platform can reveal data concerning sex life or sexual orientation, and a voice model is biometric data. You confirm that you have identified an Article 9(2) condition for this processing, ordinarily explicit consent, that you can evidence it, and that you have given the data subjects the information Articles 13 and 14 require. We process such data only on your instructions and apply the measures in section 6 to it.
We process personal data only on your documented instructions, including for transfers to a third country, unless the law requires otherwise. Your instructions are these terms, the DPA, the settings and features you configure in the product, and any further written instruction we accept. If we are required by law to process beyond your instructions we will tell you first, unless that law forbids telling you.
If we consider an instruction to infringe the GDPR or other data protection law, we will tell you promptly and may pause that processing until it is resolved.
Everyone we authorise to process your data is bound by a duty of confidentiality, in their contract of employment or engagement, and has had training appropriate to their access. We do not sell your data, we do not use it to train our own models, and we do not use it for our own analytics beyond aggregated, de-identified statistics that cannot be traced back to you, your creators, or any fan.
You are responsible for the lawfulness of the data you bring into Fandash and of the instructions you give us. You confirm that you have a lawful basis for each purpose, that you have given the required privacy information to creators and fans, that you hold any consent needed for AI features including voice cloning and sentiment analysis, and that you will keep those records. You will not instruct us to do anything unlawful, and you will configure roles and permissions so that only the right people in your agency see personal data. If a data subject withdraws consent or objects, it is your job to change the setting or tell us to stop.
We implement appropriate technical and organisational measures under Article 32, taking account of the state of the art, the cost of implementation, and the risk to data subjects. They currently include:
We may change these measures as the service evolves, but not in a way that materially reduces protection.
You give us general authorisation to engage subprocessors. Each is engaged under a written contract imposing data protection obligations no less protective than these, and we remain fully liable to you for their performance. The current list:
This list was last updated on July 29, 2026. We give notice to account owners before a new provider starts processing personal data, so that an agency can object.
We give you at least 30 days notice by email to your account owner before a new subprocessor starts processing your data. If you reasonably object on data protection grounds within that period, tell us and we will work with you to find an alternative; if we cannot, you may terminate the affected part of the service without penalty and receive a refund for the unused period.
Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures in meeting your obligations to respond to requests to exercise rights under Chapter III of the GDPR, including access, rectification, erasure, restriction, portability, and objection. The product itself lets you find, correct, export, and delete most records directly. If a data subject contacts us about data we hold on your behalf, we will not respond substantively ourselves: we will forward it to you without undue delay and tell the person we have done so. Where you need more than the product provides, ask us at privacy@fandash.io and we will help at no charge for reasonable volumes.
We notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting data we process for you. The notice describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. We give you the information you need to notify your supervisory authority within your own 72 hour deadline, and we will not delay your notification while we investigate.
We also assist you, on request and taking into account the information available to us, with data protection impact assessments and any prior consultation with a supervisory authority arising from processing we carry out for you.
At the end of the provision of services you choose whether we return or delete the personal data we hold for you. By default we do both in sequence: for 30 days after closure you may request an export in a structured, commonly used, machine-readable format, and after that window we delete the data from our production systems. Backups containing it roll off within a further 35 days, and we do not restore a backup to retrieve deleted data except to recover from an incident.
We may retain data where the law requires it, in which case we keep only what is required, for only as long as required, and continue to protect it under this agreement. We confirm deletion in writing on request.
We make available to you the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits and inspections conducted by you or an auditor you mandate. In the first instance we will answer a reasonable security questionnaire and provide our current documentation. Where that is genuinely insufficient, you may audit on 30 days written notice, no more than once a year unless a supervisory authority requires otherwise or we have had a breach affecting your data. Audits happen in business hours, must not unreasonably disrupt the service, are subject to confidentiality, and must not give access to another customer's data. Each side bears its own costs.
Production data is stored in the European Union. Where a subprocessor processes personal data outside the European Economic Area, the transfer is made under the European Commission's Standard Contractual Clauses, which are incorporated into this agreement by reference and which you instruct us to enter into on your behalf with that subprocessor, or under an adequacy decision where one applies. We apply supplementary measures including encryption in transit, access control, and data minimisation. Where a transfer risk assessment is needed we will provide the information we hold to support it.
Each side is liable under this agreement as the GDPR provides. Nothing here limits a data subject's rights or a supervisory authority's powers. Subject to that, the liability provisions in our Terms of Service apply to this agreement, and the cap there is a single aggregate cap across both documents rather than a separate one for each.
If this agreement conflicts with the Terms of Service or the Privacy Policy, this agreement governs for personal data processed on your behalf. It is governed by the laws of Ireland, and we update it in line with the change process in the Terms of Service. Questions go to privacy@fandash.io.