Security & data protection

What happens to your work, stated plainly.

You are uploading scripts, brand assets, and likenesses of real people. That deserves a straight answer about where the data goes, who can reach it, how long it is kept, and what we have not built yet. Every claim on this page is drawn from our published Privacy Notice and Data Processing Addendum, which are the contractual versions.

Last updated 2026-07-30

Your work is never used to train models

Customer Content is not used to train, fine-tune, or improve the models behind the Service. The only exceptions are where you have expressly consented in writing under a separate agreement, or where data is anonymised and aggregated so that no customer or individual is identifiable.

This is a contractual term, not a marketing promise — clause 6.4 of the Terms and clause 3.4 of the DPA — and it survives termination. Our generation sub-processors are contractually required to apply the same restriction to their upstream model providers.

Where your data is processed

GATA's own application, object storage, and database run on AWS in eu-west-2 (London) in a multi-AZ configuration. Content moderation, transcription, and transactional email run in the same region.

Generation is different, and this is the part worth reading carefully. Several model providers are US-based: fal.ai for image and video generation, ElevenLabs for voice synthesis, OpenAI for structured text, and Google Cloud Vertex AI for video analysis in the localisation pipeline. Content sent to those services is processed outside the UK and EEA.

GATA does not offer or guarantee EU or EEA data residency, and we say so in the DPA rather than burying it. Those transfers are covered by the EU Standard Contractual Clauses (Module 2/3) and the UK Addendum, supplemented by EU–US Data Privacy Framework certifications where in force. If EU-only processing is a hard requirement for your procurement, we are not currently the right supplier, and we would rather tell you now.

Encryption

Who can reach production

Administrative access to production is gated behind multi-factor authentication, with hardware-bound credentials where supported, IP-based controls, and just-in-time access where practical. Access is least-privilege and need-to-know, and it is logged.

Production is logically segregated from development and test environments, and customer personal data is not used in development or test except where strictly required and only after pseudonymisation or anonymisation. Security-relevant events — authentication, configuration changes, sub-processor API calls, errors — are logged to dedicated destinations with their own retention and access controls.

How long things are kept

The schedule below is a summary. The authoritative version is Section 7 of the Privacy Notice, replicated in Annex I of the DPA; the two are maintained in lockstep.

DataRetention
Source media you upload (Inputs)30 days after the generation completes
Generated outputsWhile your subscription is active, plus a 30-day export window
Account and contractual dataDuration of the contract plus 6 years
Billing and transactional data6 years from the end of the relevant tax period
Service-usage and telemetry logs13 months
Moderation and abuse-prevention signals24 months
Support conversations3 years from closure
Email-verification codesHashed; cleared on verification or after 15 minutes
Backups35 days rolling

Deletion from active systems is automated by S3 lifecycle rules and a scheduled retention job, not left to manual housekeeping. Enterprise customers can negotiate different periods in an order form.

Sub-processors

The full list is published as its own document and doubles as Annex III of the DPA, naming each vendor's legal entity, what it processes, where, and under which transfer mechanism. We notify customers at least 30 days before adding or replacing a sub-processor, and you have a documented objection route.

Just as informative is what we do not run. As of 2026-07-30 there is no third-party error monitoring or browser crash reporting, no third-party support desk, no outbound marketing-email platform, no session-replay or behavioural-recording tool, and no advertising or retargeting platform. Support reaches us by direct email.

See the full sub-processor list.

Analytics and consent

Google Analytics 4 is the only measurement tool, and it loads only after a visitor explicitly accepts cookies. If your browser sends a Global Privacy Control signal, the decision is forced to rejected and no banner is shown at all. Details are in the Cookie Notice.

Incident response

We maintain a documented incident-response procedure covering detection, containment, eradication, recovery, post-incident review, and notification, including the personal-data breach notification timelines in clause 8.3 of the DPA. Database snapshots and S3 versioning support point-in-time recovery inside the backup window, and restoration procedures are tested periodically.

To report a security issue, email support@gata.ai with "Security" in the subject line. We will acknowledge and work with you on disclosure; please give us a reasonable window to remediate before publishing.

What we do not claim

A trust page that only lists strengths is not worth much. Three things are worth being explicit about:

Vulnerability management is automated: dependency, container, and infrastructure scanning run in the deployment pipeline with a severity-based remediation SLA, alongside code review, static analysis, and secrets scanning.

For procurement and Enterprise

The DPA is pre-published and applies to every paid plan with no separate negotiation, which is usually the fastest route through a vendor review. Enterprise adds SSO, audit logs, a custom MSA, and negotiated terms including retention — see pricing or talk to us.

GATA AI is operated by Exchester Ltd, a company registered in England and Wales (company number 12601661), registered office 2nd Floor College House, 17 King Edwards Road, Ruislip, London, HA4 7AE.

Frequently asked

Is my content used to train AI models?

No. Customer Content is not used to train, fine-tune or improve the models behind the Service, except where you have expressly consented in writing in a separate agreement, or where the data is anonymised and aggregated so that no customer or individual is identifiable. This is a contractual commitment in clause 6.4 of the Terms of Service and clause 3.4 of the DPA, not just a policy statement.

Where is my data processed?

GATA's own application and storage run on AWS in eu-west-2 (London) in a multi-AZ configuration. However, several generation sub-processors are US-based — fal.ai for image and video, ElevenLabs for voice, OpenAI for structured text — so customer content may be processed outside the UK and EEA. GATA does not offer or guarantee EU/EEA data residency. Those transfers run under the EU Standard Contractual Clauses and the UK Addendum.

How long do you keep my uploads?

Source media you upload is deleted from active systems 30 days after the generation using it completes, via an automated S3 lifecycle rule. Generated outputs are kept while your subscription is active plus a 30-day export window after termination. Backups roll off within 35 days. The full schedule is in Section 7 of the Privacy Notice.

Is GATA SOC 2 or ISO 27001 certified?

Not currently. GATA relies on the independent attestations of its infrastructure sub-processors — AWS, Stripe and others hold SOC 2 Type II and ISO 27001 — and on the security architecture set out in Annex II of the DPA. We would rather say this plainly than imply a certification we do not hold. Enterprise customers can request our security documentation directly.

Do you have a DPA I can sign?

Yes. The GATA Data Processing Addendum is published in full and incorporates the EU Standard Contractual Clauses and the UK Addendum, with the sub-processor list as Annex III. It applies to every paid plan without needing separate negotiation; Enterprise customers can additionally negotiate a custom MSA and order form.

Do you use analytics or session recording?

Analytics only, and only after explicit consent. Google Analytics 4 loads solely once a visitor accepts cookies, and if your browser sends a Global Privacy Control signal the decision is forced to rejected with no banner shown. We deploy no session-replay tooling, no advertising or retargeting pixels, and no third-party crash reporting.