NewOur fastest Text-to-Speech model yet with 1000+ voices ・ Sub-50ms latency

Data Processing Agreement

Version: July 2026

Download PDF

This Data Processing Agreement governs the Processing of Personal Data carried out by GRADIUM as part of its provision of the Services to Client, as Data Processor.

1. Definitions

All capitalized terms used in this Data Processing Agreement will have the following meanings.

  • Client Personal Data means any Personal Data Processed by GRADIUM as a Data Processor on behalf of Client or Third-Party Controller.
  • Data Controller, Data Processor, Data Security Breach, Data Subject, Personal Data, Processing, and Supervisory Authority shall have the meaning given to them under European Data Protection Laws.
  • Data Processing Agreement means this document.
  • European Data Protection Laws means the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the e-Privacy Directive 2002/58/EC (as amended by Directive 2009/136/EC), their national implementations in the EEA, including the European Union, and all other data protection laws of the EEA, the United Kingdom (“UK”), and Switzerland, each as applicable, and as may be amended or replaced from time to time.
  • International Data Transfer means any transfer of Personal Data to a Restricted Country.
  • Non-EEA Country means any country located outside of the European Economic Area (EEA), regardless of whether it benefits from an adequacy decision from the European Commission.
  • Restricted Country means any country located outside of the European Economic Area (EEA) and that does not benefit from an adequacy decision from the European Commission.
  • SCC means the clauses annexed to the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to the GDPR.
  • Sub-Processor means any Data Processor appointed by GRADIUM.
  • Third-Party Controller means a Data Controller for which Client is a Data Processor.
  • UK Addendum means the addendum to the SCCs issued by the UK Information Commissioner under Section 119A(1) of the UK Data Protection Act 2018 (version B1.0, in force March 21, 2022).
  • The terms ”Share”, and ”Shared” shall have the same meaning given to them under the CCPA. The terms ”Sell” and ”Selling” shall have the meaning defined in Applicable Privacy Laws in the U.S.

All capitalized terms not defined herein shall have the meaning ascribed to them in the Terms of Service.

2. Role of the Parties and Purpose of the Processing

Client is the Data Controller and GRADIUM is the Data Processor with respect to the Processing detailed in Appendix 1. GRADIUM processes Client Personal Data on behalf of Client when Client uses the Services, as set out in Appendix 1.

If Client is a Data Processor on behalf of a Third-Party Controller, then Client shall (i) act as the single point of contact for GRADIUM; (ii) obtain all necessary authorizations from such Third-Party Controller; (iii) ensure that the Third-Party Controller provided notice and obtained any consents necessary for Processing by GRADIUM as set forth in this Data Processing Agreement; and (iv) undertakes to issue all instructions and exercise all rights on behalf of such other Third-Party Controller.

3. Mutual Obligations

Each Party shall comply with their respective obligations under the Applicable Privacy Laws and shall not, by any act or omission, cause the other to be in breach of any such obligations under the Applicable Privacy Laws.

4. Obligations of Data Processor

The Parties agree that the subject matter, nature, purpose and duration of Processing performed by GRADIUM under this Data Processing Agreement as Data Processor, the type of Personal Data, and categories of Data Subjects, are as described in this Agreement and in Appendix 1.

When providing the Services, GRADIUM makes the following commitments as Data Processor:

  • a) GRADIUM shall process Client Personal Data only on Client's documented lawful instructions as set out in this Data Processing Agreement or as otherwise necessary to provide the Services. In this regard, such instructions may be provided by Client via the use of the Services and via this Data Processing Agreement. GRADIUM shall process Client Personal Data for no purpose other than as authorized under this Data Processing Agreement, unless required to do so by applicable laws. In such a case, GRADIUM shall promptly inform Client of such legal requirement, unless prohibited to do so by applicable laws.
  • b) GRADIUM shall ensure that GRADIUM’s staff members have committed themselves to confidentiality of Client Personal Data, that staff members Processing Client Personal Data have a need to know the relevant Client Personal Data for the provision of the Services and that Sub-Processors are under confidentiality obligations substantially similar to the confidentiality obligations imposed on GRADIUM pursuant to the Data Processing Agreement.
  • c) Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, GRADIUM shall implement and maintain the Security Measures to protect Client Personal Data from any Data Security Breach. The Security Measures implemented by GRADIUM under this Data Processing Agreement are listed in Appendix 3. Client acknowledges that such Security Measures are subject to technical progress and development and that GRADIUM may update them from time to time, provided that such updates do not materially decrease the overall security of the Processing governed by this Data Processing Agreement. GRADIUM shall provide Client with reasonable and timely assistance to allow Client to comply with its obligations under Article 32 of the GDPR.
  • d) Taking into account the nature of the Processing and the information available to GRADIUM, GRADIUM shall notify Client without undue delay and not later than forty-eight (48) hours after having become aware of a Data Security Breach affecting Client Personal Data. GRADIUM shall cooperate with Client, and if requested by Client, GRADIUM shall (i) provide Client with reasonable information about the Data Security Breach in its possession such as the nature of the personal data affected, or the cause and origin of the Data Security Breach, and (ii) provide reasonable assistance to Client to mitigate or remediate the Data Security Breach.

GRADIUM has no obligation to assess Client Personal Data in order to identify if they are subject to any specific legal requirements.

Upon Client’s written request, taking into account the nature of the Processing and the information available to GRADIUM, this latter shall provide Client with commercially reasonable assistance to conduct a data protection impact assessment and to conduct a prior consultation with a Supervisory Authority when required by Applicable Privacy Laws and reasonably requested by Client, solely with respect to the Processing and Client Personal Data.

Taking into account the nature of the Processing, GRADIUM shall provide Client with commercially reasonable assistance (by appropriate technical and organizational measures) with respect to the fulfilment of Client’s obligation to respond to requests from Data Subjects to exercise their rights under the Applicable Privacy Laws (a “Data Subject Request”). In the event GRADIUM receives a Data Subject Request directly from a Data Subject, it shall (unless prohibited by applicable laws) promptly notify Client of such Data Subject Request, and direct the Data Subject to Client. Client will be responsible for responding to any such Data Subject Request.

GRADIUM shall immediately inform Client if, in its opinion, Client’s Processing instruction infringes the Applicable Privacy Laws. In such event, GRADIUM is entitled to refuse to perform the Processing of Client Personal Data that it believes to be in violation of the Applicable Privacy Laws.

5. Use of Sub-Processors

Client hereby provides a prior and general authorization allowing GRADIUM to appoint any Sub-Processors to assist GRADIUM in the provision of the Services and in the Client Personal Data Processing described in Appendix 1, in accordance with the terms provided in this Data Processing Agreement.

GRADIUM commits that Sub-Processors (i) are to fulfil obligations at least equivalent to those set out in this Data Processing Agreement with respect to Personal Data protection; (ii) provide guarantees regarding Personal Data protection at least equivalent to those presented by the measures implemented by GRADIUM. GRADIUM remains liable to Client for the fulfilment by the Sub-Processors of their contractual obligations towards GRADIUM.

Client hereby agrees that GRADIUM may appoint Sub-Processors from the list of Sub-Processors in Appendix 2 of this Data Processing Agreement. GRADIUM shall update the list of any Sub-Processor to be appointed at least thirty (30) days prior to the date on which the Sub-Processor shall commence the Processing of Client Personal Data.

Client may object in writing to GRADIUM’s appointment of a new Sub-Processor within fifteen (15) days of such notice, provided that such objection is based on reasonable and substantiated grounds relating to compliance with Applicable Privacy Laws. If Client provides observations during this fifteen (15)-day period, GRADIUM and Client will consult and negotiate in good faith to find a mutually acceptable resolution to address any objections raised by Client. If GRADIUM chooses to retain the Sub-Processor, GRADIUM shall inform Client at least thirty (30) days before authorizing the Sub-Processor to Process Client Personal Data, and either party may immediately discontinue providing or using the relevant parts of the Services, as applicable, and may terminate the relevant parts of the Services within thirty (30) days.

6. International Transfer of Client Personal Data

Unless GRADIUM otherwise explicitly commits not to transfer any Client Personal Data to a Non-EEA Country, Client authorizes GRADIUM to transfer Client Personal Data directly or indirectly to any country deemed to have an adequate level of data protection by the European Commission. Client also authorizes GRADIUM to perform International Data Transfers directly or indirectly to a Restricted Country (a) on the basis of adequate safeguards in accordance with Applicable Privacy Laws, including but not limited to the EU-US Data Privacy Framework, or (b) pursuant to the SCCs, as the case may be the UK Addendum if applicable, or any other transfer mechanism allowed pursuant to Applicable Privacy Laws.

This Section only applies if Client is located in a Restricted Country. By accepting this Data Processing Agreement, GRADIUM and Client conclude Module 4 (Processor-to-Controller) of the SCCs where Client is a Data Controller, and Module 3 (Processor-to-Processor) of the SCCs to the extent Client is a Data Processor on behalf of a Third-Party Controller, which are hereby incorporated and completed as follows and apply to any International Data Transfer conducted by GRADIUM acting as a Data Processor:

  • The “data exporter” is GRADIUM and the “data importer” is Client.
  • The optional docking clause in Clause 7 is not implemented.
  • Option 2 of Clause 9(a) is implemented and the time period therein is specified in Section 5 above.
  • The optional redress clause in Clause 11(a) is struck.
  • Option 2 in Clause 17 is implemented and the governing law in Clause 17 is the law of France.
  • The courts in Clause 18 are the Courts of France.
  • Annex I and II to the Modules 3 and 4 of the SCCs are Appendices 1 and 3 to this Data Processing Agreement respectively.

If GRADIUM has explicitly committed not to transfer any Client Personal Data to a Non-EEA Country, the aforementioned parts of this Section shall not apply and GRADIUM undertakes not to transfer any Client Personal Data to a Non-EEA Country.

7. Audit

Documentary audit. Upon Client’s written request, GRADIUM will make available all documents and information to demonstrate that the Processing carried out by GRADIUM as Data Processor complies with this Data Processing Agreement in a timely manner, to the extent that is commercially reasonable and required by the Applicable Privacy Laws, subject to confidentiality and trade secrets. Documentary audits can be requested maximum once per year.

Onsite audit. For this Section, “Auditor” will have the meaning of either Client or the third-party auditor mandated by Client under this Section to conduct an audit or inspection as set out in this Section solely with respect to the Processing and compliance with this Data Processing Agreement. Only to the extent Client cannot reasonably be satisfied with GRADIUM’s compliance with this Data Processing Agreement through the exercise of the documentary audit set out in this Section, Auditor may conduct up to one (1) onsite audit per year to verify GRADIUM’s compliance with this Data Processing Agreement, under the conditions defined below:

  1. Client demonstrates that Auditor is subject to strict confidentiality obligations.
  2. Client demonstrates that Auditor is independent, impartial and with expertise in data protection, and is not a competitor of GRADIUM.
  3. The procedure described below is followed:
    1. Client gives GRADIUM a thirty (30) days’ prior written notice of such audit or inspection (hereafter “Audit”).
    2. During this thirty (30)-day period, Client and GRADIUM mutually agree in writing upon the scope (which must be limited to Processing operations related to the provision of Services to Client), timing and duration and starting date of the Audit.
    3. Client ensures that the Audit will not impact GRADIUM’s organization or GRADIUM’s activities, and is carried out during regular business hours.
  4. GRADIUM will not give access to its premises for the purposes of the Audit:
    1. To an Auditor’s employee who does not provide GRADIUM with reasonable evidence of identity and authority.
    2. To any Auditor’s employee who requests access to GRADIUM’s premises outside regular business hours.
  5. GRADIUM will not give access to premises other than its corporate site; for example, GRADIUM will not provide access to Sub-Processors’ premises.
  6. The Audit is conducted by the Auditor in a reasonable manner and in good faith, an identical copy of the Audit report shall be given to both Parties following the completion of the Audit. Each Party may make observations regarding the Audit report.
  7. All costs relative to the Audit will be at the charge of Client unless the Audit reveals a breach by GRADIUM of this Data Processing Agreement or Applicable Privacy Laws.

8. Obligations of Data Controller

Client agrees and commits to the following:

  • Client is responsible for compliance with the requirements of Applicable Privacy Laws applicable to Data Controllers. In particular, Client guarantees that the Processing is compliant with the Applicable Privacy Laws and in particular that the Data Subjects are informed of the Processing via an appropriate information notice and have given their consent as necessary to comply with Applicable Privacy Laws, in particular where the Processing described in Appendix 1 includes sensitive data or special categories of data within the meaning of Applicable Privacy Laws.
  • Client is solely responsible for the accuracy and appropriateness of Personal Data and the means by which such Personal Data is acquired in compliance with the Applicable Privacy Laws. Client is solely responsible for providing GRADIUM with instructions that comply with this Data Processing Agreement and the Applicable Privacy Laws.
  • Client undertakes to document in writing any additional instructions regarding the Processing by GRADIUM.

9. Return and Destruction of Personal Data

Upon the termination of Client’s access to and use of the Services, GRADIUM will, up to forty-five (45) days following such termination, delete or return to Client, at Client’s choice, all Client Personal Data detained by GRADIUM except as otherwise authorized in writing by Client pursuant to Section 11 (Processing of GRADIUM as Data Controller). Client acknowledges and accepts that Client Personal Data will no longer be accessible upon the expiry of the forty-five (45)-day period.

Without prejudice to any Zero Data Retention feature implemented as applicable, GRADIUM may retain Client Personal Data to the extent required by applicable law but only to the extent and for such period as required by such law and always provided that GRADIUM shall ensure the confidentiality of all such Client Personal Data.

10. California Provisions

These CCPA Terms apply when the California Consumer Privacy Act of 2018, Cal. Civ. Code §§1798.100–1798.199.100, as amended, and the CCPA regulations, Cal. Code Regs. §§7000–7304 (together, the “CCPA”) applies to Client’s use of the Services to process the Personal Information contained in Client Personal Data and Account Data.

Where the CCPA applies, GRADIUM acknowledges that it does not receive Personal Data as consideration for any Services provided to Client. GRADIUM: (i) is responsible for compliance with its obligations under this Data Processing Agreement, (ii) is responsible for compliance with its obligations as a service provider under the CCPA, and (iii) shall provide the same level of privacy protection as required by the CCPA. GRADIUM shall notify Client if it reasonably determines that it cannot meet its obligations under the CCPA, and in such circumstances, and upon provision of notice to GRADIUM, Client shall be entitled to take reasonable and appropriate steps to remediate unauthorized use of Personal Data. GRADIUM must not process the Personal Data for any purpose other than for the purpose of performance of the Agreement, except where and to the extent permitted by the CCPA.

GRADIUM shall not: (i) Sell or Share Client Personal Data; (ii) retain, use, or disclose Client Personal Data for any purpose other than for the purpose of performance of the Services except as expressly permitted under the CCPA; (iii) retain, use, or disclose Client Personal Data with Personal Data obtained from, or on behalf of, sources other than Client, except as expressly permitted under the CCPA; or (iv) process Client Personal Data for targeted and/or cross context behavioral advertising. GRADIUM certifies that it understands the restrictions set out in this Section and will comply with them. Solely for the purpose of the CCPA, GRADIUM shall promptly notify Client if it determines that it can no longer meet its obligations under the CCPA.

11. Processing of GRADIUM as Data Controller

GRADIUM processes Personal Data as Data Controller for the purposes set forth in GRADIUM’s Privacy Policy available at the following link and any succeeding link: https://gradium.ai/privacy.

GRADIUM shall not reuse Client Personal Data for its own purposes, including to improve current and future Services or to train any AI model or product. By exception, GRADIUM may reuse Client Personal Data only where Client has given its prior authorization in the course of the performance of the Agreement.

GRADIUM undertakes to comply with the Applicable Privacy Laws in relation to all Processing for which it is classified as Data Controller. The information related to such Processing are set forth in Gradium’s Privacy Policy and Client undertakes to direct all its users of the Services to this Privacy Policy.

12. Duration

This Data Processing Agreement will remain in force as long as the Client uses the Services.

13. Jurisdiction and Governing Law

Any dispute arising from this Data Processing Agreement will be resolved by the competent courts of Paris, France in accordance with the Terms of Service.

This Data Processing Agreement is governed by the laws of France.


Appendix 1 — Detail of Processing

Parties

Client as Data Controller or Data Processor of a Third-Party Controller, and data importer for the purposes of SCCs as applicable.

GRADIUM as Data Processor and data exporter for the purposes of SCCs as applicable.

Duration of Processing

If the Zero Data Retention feature is not activated, GRADIUM shall store Client Personal Data as Data Processor solely for the duration of the Services.

If the Zero Data Retention feature is applicable, GRADIUM shall not store any Input and Output after their respective ingestion and generation for a duration longer than necessary to the generation of Output and shall not be retained further. Notwithstanding the foregoing, GRADIUM may retain Voice Sample recordings that are (i) explicitly and separately provided by Client for the sole purpose of Voice Reproduction, and (ii) reasonably necessary to deliver the Voice Reproduction pursuant to the Services.

Subject-Matter and Nature of Processing

Generation of Output and Voice Reproduction based on Client’s Input at Client’s request.

Frequency of the Processing

On a continuous basis.

Purpose of Processing

The purpose of the Processing of Client Personal Data is provision of the Services.

Data Subjects

Data subjects whose characteristics, such as their voice, are present in Client’s Input and, as applicable, reproduced in Output.

Categories of Personal Data

Voice input, voice recordings, text input, or other content included in Client’s Input, and text or voice Output generated by GRADIUM based on Input provided by Client.

Sensitive Data

The Processing is not designed to include sensitive data or special categories of data within the meaning of Applicable Privacy Laws. If such Personal Data are processed, they will only be collected and processed according to Client’s instructions for providing the Services.


Appendix 2 — List of Subprocessors

The list of Sub-Processors is available on our website trust.gradium.ai.


Appendix 3 — Security Measures

All the security measures are listed at trust.gradium.ai.