The Spanish version is the legally binding version. Read the Spanish text.
- The B2B agreement needs identified parties and instructions.
- Material is handled only for the authorised job.
- Subprocessors and transfers need verification.
- Return and deletion are specified in the contract.
1. Parties and the need for an agreement
Where a business client determines processing purposes and means while the studio acts only on instructions, an appropriate agreement is required. The client is controller and the identified provider acts as processor for specified operations. This text sets out conditions to complete with parties, subject, duration and data categories; browsing does not automatically sign it. The provider’s own invoicing may involve a different legal role. Actual roles must be assessed before recordings containing third-party personal data are received.
2. Subject and instructions
The scope may include receipt, recording, editing, export and limited retention of commissioned material. Instructions specify participants, data types, purpose and authorised uses. The processor will not use recordings for its own advertising, model training or voice cloning within this service. Potentially unlawful instructions should be flagged before execution. Purpose changes require written review. The client must obtain permissions and provide necessary information to affected individuals.
3. Confidentiality and security
Access should be restricted to authorised people under confidentiality duties and necessary tasks. Transfer channels, access controls, backups and recovery procedures must fit the risk. Personal account passwords are not requested. A security incident should be reported to the controller without undue delay, using available information about impact and measures. Absolute freedom from incidents is not promised. Actual measures and the contact person need documentation before professional processing begins.
4. Subprocessors and transfers
No unverified contracted-provider list is asserted. Actual hosting, email and file-transfer providers need an annex stating role and location. FormSubmit is a planned integration disabled until terms, agreement and transfers are checked. External providers need authorisation and appropriate obligations before accessing data. Processing outside the EEA requires a valid mechanism and assessment of safeguards. A generic public policy is insufficient to claim every requirement has been met.
5. Assistance and closure
Within the scope and available information, the processor helps address rights, assess risks and handle incidents. At closure, data is returned or deleted under instructions unless retention is legally required. The proposed creative archive is 6 months after delivery, but a B2B contract may require a different documented arrangement. Backups follow an agreed schedule. Reasonable compliance information and proportionate review should be supported. Read privacy, terms and contact guidance to complete the annex before sensitive material is sent.
Also read: Service terms · Privacy policy · Contact and booking.