Your work is never used to train models
Customer Content is not used to train, fine-tune, or improve the models behind the Service. The only exceptions are where you have expressly consented in writing under a separate agreement, or where data is anonymised and aggregated so that no customer or individual is identifiable.
This is a contractual term, not a marketing promise — clause 6.4 of the Terms and clause 3.4 of the DPA — and it survives termination. Our generation sub-processors are contractually required to apply the same restriction to their upstream model providers.
Where your data is processed
GATA's own application, object storage, and database run on AWS in eu-west-2 (London) in a multi-AZ configuration. Content moderation, transcription, and transactional email run in the same region.
Generation is different, and this is the part worth reading carefully. Several model providers are US-based: fal.ai for image and video generation, ElevenLabs for voice synthesis, OpenAI for structured text, and Google Cloud Vertex AI for video analysis in the localisation pipeline. Content sent to those services is processed outside the UK and EEA.
GATA does not offer or guarantee EU or EEA data residency, and we say so in the DPA rather than burying it. Those transfers are covered by the EU Standard Contractual Clauses (Module 2/3) and the UK Addendum, supplemented by EU–US Data Privacy Framework certifications where in force. If EU-only processing is a hard requirement for your procurement, we are not currently the right supplier, and we would rather tell you now.
Encryption
- In transit. TLS 1.2 or higher, with TLS 1.3 preferred, on all connections to the Service.
- At rest. Customer content in Amazon S3 is encrypted with SSE-KMS. The PostgreSQL database is encrypted at rest. Backups are encrypted at rest.
- Sessions. Refresh tokens are bound to encrypted, HttpOnly cookies. State-changing requests carry a double-submit CSRF token that the backend rejects on mismatch.
- Credentials. Passwords are hashed, never stored in recoverable form.
Who can reach production
Administrative access to production is gated behind multi-factor authentication, with hardware-bound credentials where supported, IP-based controls, and just-in-time access where practical. Access is least-privilege and need-to-know, and it is logged.
Production is logically segregated from development and test environments, and customer personal data is not used in development or test except where strictly required and only after pseudonymisation or anonymisation. Security-relevant events — authentication, configuration changes, sub-processor API calls, errors — are logged to dedicated destinations with their own retention and access controls.
How long things are kept
The schedule below is a summary. The authoritative version is Section 7 of the Privacy Notice, replicated in Annex I of the DPA; the two are maintained in lockstep.
| Data | Retention |
|---|---|
| Source media you upload (Inputs) | 30 days after the generation completes |
| Generated outputs | While your subscription is active, plus a 30-day export window |
| Account and contractual data | Duration of the contract plus 6 years |
| Billing and transactional data | 6 years from the end of the relevant tax period |
| Service-usage and telemetry logs | 13 months |
| Moderation and abuse-prevention signals | 24 months |
| Support conversations | 3 years from closure |
| Email-verification codes | Hashed; cleared on verification or after 15 minutes |
| Backups | 35 days rolling |
Deletion from active systems is automated by S3 lifecycle rules and a scheduled retention job, not left to manual housekeeping. Enterprise customers can negotiate different periods in an order form.
Sub-processors
The full list is published as its own document and doubles as Annex III of the DPA, naming each vendor's legal entity, what it processes, where, and under which transfer mechanism. We notify customers at least 30 days before adding or replacing a sub-processor, and you have a documented objection route.
Just as informative is what we do not run. As of 2026-07-30 there is no third-party error monitoring or browser crash reporting, no third-party support desk, no outbound marketing-email platform, no session-replay or behavioural-recording tool, and no advertising or retargeting platform. Support reaches us by direct email.
See the full sub-processor list.
Analytics and consent
Google Analytics 4 is the only measurement tool, and it loads only after a visitor explicitly accepts cookies. If your browser sends a Global Privacy Control signal, the decision is forced to rejected and no banner is shown at all. Details are in the Cookie Notice.
Incident response
We maintain a documented incident-response procedure covering detection, containment, eradication, recovery, post-incident review, and notification, including the personal-data breach notification timelines in clause 8.3 of the DPA. Database snapshots and S3 versioning support point-in-time recovery inside the backup window, and restoration procedures are tested periodically.
To report a security issue, email support@gata.ai with "Security" in the subject line. We will acknowledge and work with you on disclosure; please give us a reasonable window to remediate before publishing.
What we do not claim
A trust page that only lists strengths is not worth much. Three things are worth being explicit about:
- No SOC 2 or ISO 27001 of our own. We rely on our infrastructure sub-processors' independent attestations — AWS and Stripe hold SOC 2 Type II and ISO 27001 — plus the architecture in Annex II of the DPA. GATA itself holds neither certification today.
- No third-party penetration test yet. We intend to commission independent testing as the user base scales. In the interim, assurance comes from sub-processor attestations and the architectural choices described above.
- No EU-only processing option. As above — generation runs partly in the United States, and we do not offer residency guarantees on any tier.
Vulnerability management is automated: dependency, container, and infrastructure scanning run in the deployment pipeline with a severity-based remediation SLA, alongside code review, static analysis, and secrets scanning.
For procurement and Enterprise
The DPA is pre-published and applies to every paid plan with no separate negotiation, which is usually the fastest route through a vendor review. Enterprise adds SSO, audit logs, a custom MSA, and negotiated terms including retention — see pricing or talk to us.
GATA AI is operated by Exchester Ltd, a company registered in England and Wales (company number 12601661), registered office 2nd Floor College House, 17 King Edwards Road, Ruislip, London, HA4 7AE.
Frequently asked
Is my content used to train AI models?
No. Customer Content is not used to train, fine-tune or improve the models behind the Service, except where you have expressly consented in writing in a separate agreement, or where the data is anonymised and aggregated so that no customer or individual is identifiable. This is a contractual commitment in clause 6.4 of the Terms of Service and clause 3.4 of the DPA, not just a policy statement.
Where is my data processed?
GATA's own application and storage run on AWS in eu-west-2 (London) in a multi-AZ configuration. However, several generation sub-processors are US-based — fal.ai for image and video, ElevenLabs for voice, OpenAI for structured text — so customer content may be processed outside the UK and EEA. GATA does not offer or guarantee EU/EEA data residency. Those transfers run under the EU Standard Contractual Clauses and the UK Addendum.
How long do you keep my uploads?
Source media you upload is deleted from active systems 30 days after the generation using it completes, via an automated S3 lifecycle rule. Generated outputs are kept while your subscription is active plus a 30-day export window after termination. Backups roll off within 35 days. The full schedule is in Section 7 of the Privacy Notice.
Is GATA SOC 2 or ISO 27001 certified?
Not currently. GATA relies on the independent attestations of its infrastructure sub-processors — AWS, Stripe and others hold SOC 2 Type II and ISO 27001 — and on the security architecture set out in Annex II of the DPA. We would rather say this plainly than imply a certification we do not hold. Enterprise customers can request our security documentation directly.
Do you have a DPA I can sign?
Yes. The GATA Data Processing Addendum is published in full and incorporates the EU Standard Contractual Clauses and the UK Addendum, with the sub-processor list as Annex III. It applies to every paid plan without needing separate negotiation; Enterprise customers can additionally negotiate a custom MSA and order form.
Do you use analytics or session recording?
Analytics only, and only after explicit consent. Google Analytics 4 loads solely once a visitor accepts cookies, and if your browser sends a Global Privacy Control signal the decision is forced to rejected with no banner shown. We deploy no session-replay tooling, no advertising or retargeting pixels, and no third-party crash reporting.