FeaturesPricingFAQ
Sign inStart free
LEGAL

Data Processing Agreement

The processor terms for creator and fan data. This forms part of your agreement with us and applies whenever you connect a creator.

Effective July 29, 2026 · version 1.0
CONTENTS
Parties and rolesSubject matter and durationData and data subjectsOur obligationsYour obligationsSecurity measuresSubprocessorsData subject requestsBreaches and assessmentsReturn and deletionAuditsInternational transfersLiability and precedence
01

Parties and roles

This Data Processing Agreement is between your agency ("you", the controller) and Fandash ("we", "us", the processor). It is incorporated into our Terms of Service and takes effect when you accept those terms or connect a creator, whichever happens first. You do not need to sign a separate copy, though we will sign one on request.

It applies to personal data we process on your behalf. It does not apply to data we process as controller for our own purposes, such as your team's account records, which our Privacy Policy covers. Terms used here that are defined in the GDPR carry their GDPR meaning.

02

Subject matter and duration

Subject matter. Providing the Fandash platform to you: mirroring your creators' Fanvue data, presenting it, and running the messaging, attribution, payroll, scheduling, and AI features you choose to use.

Nature and purpose. Collection, structuring, storage, retrieval, consultation, use, transmission, generation of derived content, and erasure, in each case to operate the service on your instructions and for no independent purpose of our own.

Duration. From acceptance until your account closes and the deletion in section 10 completes, unless the law requires us to keep something longer.

03

Data and data subjects

Categories of data subject. Creators on your roster, fans who interact with those creators, and the members of your team who use the platform.

Categories of personal data. Identifiers and profile data such as handle, display name and avatar; subscription and relationship status; conversation content including attachments, read state and translations; purchase, spending and refund history; engagement and retention signals; notes and list membership your team creates; AI-generated content and the inputs used to produce it; and, where you enable it, creator reference audio and the derived voice model.

Special categories. Conversation content on an adult platform can reveal data concerning sex life or sexual orientation, and a voice model is biometric data. You confirm that you have identified an Article 9(2) condition for this processing, ordinarily explicit consent, that you can evidence it, and that you have given the data subjects the information Articles 13 and 14 require. We process such data only on your instructions and apply the measures in section 6 to it.

04

Our obligations

We process personal data only on your documented instructions, including for transfers to a third country, unless the law requires otherwise. Your instructions are these terms, the DPA, the settings and features you configure in the product, and any further written instruction we accept. If we are required by law to process beyond your instructions we will tell you first, unless that law forbids telling you.

If we consider an instruction to infringe the GDPR or other data protection law, we will tell you promptly and may pause that processing until it is resolved.

Everyone we authorise to process your data is bound by a duty of confidentiality, in their contract of employment or engagement, and has had training appropriate to their access. We do not sell your data, we do not use it to train our own models, and we do not use it for our own analytics beyond aggregated, de-identified statistics that cannot be traced back to you, your creators, or any fan.

05

Your obligations

You are responsible for the lawfulness of the data you bring into Fandash and of the instructions you give us. You confirm that you have a lawful basis for each purpose, that you have given the required privacy information to creators and fans, that you hold any consent needed for AI features including voice cloning and sentiment analysis, and that you will keep those records. You will not instruct us to do anything unlawful, and you will configure roles and permissions so that only the right people in your agency see personal data. If a data subject withdraws consent or objects, it is your job to change the setting or tell us to stop.

06

Security measures

We implement appropriate technical and organisational measures under Article 32, taking account of the state of the art, the cost of implementation, and the risk to data subjects. They currently include:

  • Encryption. Data encrypted in transit and at rest. Creator connection tokens additionally encrypted with AES-256-GCM before storage and never written to logs.
  • Tenant isolation. Each agency's data isolated in the database by row-level security tied to the signed-in identity, so isolation does not depend on application code filtering correctly.
  • Access control. Least-privilege access for our staff, granular roles and permissions for yours, and no password sharing with creators: connections use the platform's own authorization flow and can be revoked in one click.
  • Accountability. An audit trail over significant actions, recording actor, event, and time.
  • Resilience. Managed, backed-up infrastructure with restoration testing, and the ability to restore availability after an incident.
  • Secure development. Review before changes ship, automated testing, dependency patching, and secrets held outside source control.

We may change these measures as the service evolves, but not in a way that materially reduces protection.

07

Subprocessors

You give us general authorisation to engage subprocessors. Each is engaged under a written contract imposing data protection obligations no less protective than these, and we remain fully liable to you for their performance. The current list:

ProviderWhat they doWhere
SupabaseDatabase, authentication, and file storage. Holds the mirrored platform data.European Union
VercelApplication hosting and content delivery, plus page-view and performance analytics when you consent to those.European Union (Frankfurt), vendor established in the United States
InngestRuns background sync jobs and scheduled work.United States
ResendSends transactional email such as invites and sync notices.United States
AnthropicGenerates captions and produces fan sentiment snapshots from conversation transcripts.United States
OpenAIGenerates captions.United States
ReplicateHosts models used for caption and media generation.United States
DeepLTranslates messages between languages.European Union (Germany)
SexyVoice.aiCreates and runs creator voice clones, using reference audio supplied with the creator's documented consent.Outside the European Economic Area

This list was last updated on July 29, 2026. We give notice to account owners before a new provider starts processing personal data, so that an agency can object.

We give you at least 30 days notice by email to your account owner before a new subprocessor starts processing your data. If you reasonably object on data protection grounds within that period, tell us and we will work with you to find an alternative; if we cannot, you may terminate the affected part of the service without penalty and receive a refund for the unused period.

08

Data subject requests

Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures in meeting your obligations to respond to requests to exercise rights under Chapter III of the GDPR, including access, rectification, erasure, restriction, portability, and objection. The product itself lets you find, correct, export, and delete most records directly. If a data subject contacts us about data we hold on your behalf, we will not respond substantively ourselves: we will forward it to you without undue delay and tell the person we have done so. Where you need more than the product provides, ask us at privacy@fandash.io and we will help at no charge for reasonable volumes.

09

Breaches and assessments

We notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting data we process for you. The notice describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. We give you the information you need to notify your supervisory authority within your own 72 hour deadline, and we will not delay your notification while we investigate.

We also assist you, on request and taking into account the information available to us, with data protection impact assessments and any prior consultation with a supervisory authority arising from processing we carry out for you.

10

Return and deletion

At the end of the provision of services you choose whether we return or delete the personal data we hold for you. By default we do both in sequence: for 30 days after closure you may request an export in a structured, commonly used, machine-readable format, and after that window we delete the data from our production systems. Backups containing it roll off within a further 35 days, and we do not restore a backup to retrieve deleted data except to recover from an incident.

We may retain data where the law requires it, in which case we keep only what is required, for only as long as required, and continue to protect it under this agreement. We confirm deletion in writing on request.

11

Audits

We make available to you the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits and inspections conducted by you or an auditor you mandate. In the first instance we will answer a reasonable security questionnaire and provide our current documentation. Where that is genuinely insufficient, you may audit on 30 days written notice, no more than once a year unless a supervisory authority requires otherwise or we have had a breach affecting your data. Audits happen in business hours, must not unreasonably disrupt the service, are subject to confidentiality, and must not give access to another customer's data. Each side bears its own costs.

12

International transfers

Production data is stored in the European Union. Where a subprocessor processes personal data outside the European Economic Area, the transfer is made under the European Commission's Standard Contractual Clauses, which are incorporated into this agreement by reference and which you instruct us to enter into on your behalf with that subprocessor, or under an adequacy decision where one applies. We apply supplementary measures including encryption in transit, access control, and data minimisation. Where a transfer risk assessment is needed we will provide the information we hold to support it.

13

Liability and precedence

Each side is liable under this agreement as the GDPR provides. Nothing here limits a data subject's rights or a supervisory authority's powers. Subject to that, the liability provisions in our Terms of Service apply to this agreement, and the cap there is a single aggregate cap across both documents rather than a separate one for each.

If this agreement conflicts with the Terms of Service or the Privacy Policy, this agreement governs for personal data processed on your behalf. It is governed by the laws of Ireland, and we update it in line with the change process in the Terms of Service. Questions go to privacy@fandash.io.

The AI back office for Fanvue agencies. Fandash is an independent product and is not affiliated with, endorsed by, or sponsored by Fanvue.
ProductAI & automationsAttributionPricingFAQ
AccountStart freeSign in
LegalPrivacyTermsData processingCookie settings
© 2026 Fandash · all figures NET
Cookies at Fandash

Strictly necessary cookies keep sign in and security working; they are always on. Everything else stays off until you say so: preferences, analytics, and campaign measurement. You can change your choice anytime under Cookie settings in the footer. More in our Privacy Policy.