Confidential informationProtection and permitted disclosure
Confidential information does not include material already public without breach, already lawfully known, independently developed, or lawfully received without restriction. It may be shared with personnel, advisers, and service providers who need it and are bound to protect it, or where law requires disclosure.
Data rolesCustomer instructions govern campaign personal data
Vario Ads is a controller for its account, billing, security, support, and measurement data. Where we process Customer Personal Data solely to provide the requested service, the customer is controller and Vario Ads acts as processor on the customer's documented instructions.
Processing scheduleSubject matter, duration, purpose, data, and people
The subject matter is Customer Personal Data used to provide creative analysis, storage, image or video generation, delivery, support, and security. Processing lasts for the agreement and the documented deletion or backup cycle. It may involve collecting, storing, organising, retrieving, transmitting, analysing, transforming, generating, securing, returning, and deleting data. Data can include names, contact and workspace identifiers, images, likenesses, voices, product or website material, briefs, prompts, scripts, chats, campaign or testimonial content, generated media, and technical or provider task metadata. People may include customer personnel and contractors, creators or talent, customers or testimonial subjects, website users, and anyone depicted or mentioned in Customer Content or an Output.
Instructions and confidentialityDocumented instructions control processing and transfers
We process only on documented customer instructions, including for a restricted international transfer, unless UK law requires otherwise. If law requires processing outside those instructions, we will notify the customer first unless prohibited. Everyone authorised to access the data must be bound by confidentiality. We will immediately tell the customer if, in our reasonable view, an instruction infringes applicable data-protection law and will not carry out the affected instruction unless and until it can lawfully proceed.
Security and assistanceArticle 32 measures, rights, incidents, and impact assessments
Taking account of risk, available technology, and implementation cost, we use appropriate technical and organisational measures designed to protect confidentiality, integrity, availability, and resilience; restore access after an incident; and test controls proportionately. We will notify the customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. We will provide reasonable technical and organisational help with data-subject requests and, taking account of the processing and information available to us, help the customer meet duties concerning security, breach notification, data-protection impact assessments, and prior consultation with the ICO.
SubprocessorsWritten authorisation, equivalent protection, notice, and objection
The customer gives general written authorisation for the subprocessors used to process Customer Personal Data for selected features and identified through the Privacy Policy or a current provider notice. Before any intended addition or replacement, we will give advance notice and a reasonable opportunity to object on genuine data-protection grounds. We will not appoint the subprocessor to process Customer Personal Data unless written terms require equivalent Article 28 protection, and Vario Ads remains responsible to the customer for that subprocessor's performance of those obligations. Listing a provider as technically available does not authorise it for Customer Personal Data; unless a separate compliant provider and transfer record is confirmed, Kling-backed generation must be limited to material that does not identify a real person.
End of processingReturn or deletion follows the customer's lawful choice
Unless the customer requests return before processor services end, the default outcome is deletion of relevant active Customer Personal Data on the applicable service or provider deletion cycle. If return is requested in time, we will make the data reasonably available before deletion. We will delete remaining copies unless UK law requires retention. Copies already held in protected backups may remain until overwritten or deleted under the relevant backup cycle, must not be returned to ordinary use except for necessary recovery, and remain protected in the meantime.
Evidence and auditInformation, inspections, and proportionate safeguards
On reasonable request, we will provide information needed to demonstrate these processor commitments and allow and contribute to a proportionate audit or inspection by the customer or its independent auditor. Requests must use existing reports and remote evidence first where suitable, give reasonable notice, avoid unreasonable disruption, protect other customers and security, and be at the customer's cost unless the audit identifies a material breach by Vario Ads.
Customer dutiesLawful collection, notice, and instructions
The customer retains all controller rights and duties, must have a lawful basis for personal data it submits, provide required notices and documented instructions, respond to affected people, and avoid asking us to process data unlawfully. Do not submit children's, special-category, biometric, criminal-offence, or other regulated or high-risk data unless the parties first agree a lawful and necessary process in writing.