EU/UK representatives
EU Representative
Press Play Labs, Inc. has appointed Instant EU GDPR Representative Ltd as its EU representative for purposes of Article 27 of the GDPR. Individuals in the European Union may contact our EU representative regarding GDPR-related questions or requests at:
Instant EU GDPR Representative Ltd
Attn: Adam Brogden
Email: contact@gdprlocal.com
Web: www.gdprlocal.com
Office 2, 12A Lower Main Street, Lucan, Co. Dublin K78 X5P8, Ireland
UK Representative
Press Play Labs, Inc. has appointed GDPRLocal Ltd. as its UK representative for purposes of the UK GDPR. Individuals in the United Kingdom may contact our UK representative regarding UK GDPR-related questions or requests at:
GDPRLocal Ltd.
Attn: Adam Brogden
Email: contact@gdprlocal.com
Web: www.gdprlocal.com
1st Floor Front Suite, 27-29 North Street, Brighton, England BN1 1EB
Scope of this Privacy Policy
This Privacy Policy applies to personal data processed through:
- our public websites, including storylines.video and related pages;
- Storylines web applications;
- account registration, authentication, subscriptions, billing, and administration;
- uploaded media, prompts, project files, metadata, exports, and other content processed through the Service;
- integrations, including Google Drive and other third-party services authorized by a user or customer;
- sales, support, security, trust, marketing, product analytics, and customer communications;
- Storylines Labs, beta, experimental, prototype, free, promotional, or limited-release tools, unless a tool-specific privacy notice or agreement says otherwise.
This Privacy Policy does not apply to third-party websites, applications, or services that we do not control. Their own privacy policies govern their processing.
Storylines Labs and experimental tools
From time to time, Press Play Labs, Inc. may make available experimental, beta, prototype, free, promotional, internal, or limited-release tools, features, demos, utilities, or projects under names such as "Storylines Labs," "Labs," or similar labels. These Labs tools are separate from the generally available Storylines platform unless we expressly state otherwise.
Labs tools may be built, tested, changed, suspended, or discontinued more quickly than the main Storylines platform. They may have different functionality, reliability, support, retention, security, privacy, or data-processing characteristics than the main platform. They may also be provided free of charge as marketing, research, product discovery, or experimental tools.
Unless a specific Labs tool includes its own privacy notice or written terms, this Privacy Policy applies to personal data we process through Labs tools. However, Labs tools are not automatically covered by enterprise-specific commitments, service levels, DPAs, BAAs, security addenda, procurement terms, or customer-specific contractual obligations that apply to the main Storylines platform, unless the applicable agreement expressly says so.
You should not submit sensitive, regulated, confidential, production, or business-critical information to a Labs tool unless the tool expressly states that it is intended for that use and the applicable agreement covers that use. If a Labs tool has a separate privacy notice, product notice, or terms, those tool-specific terms will control for that Labs tool to the extent they conflict with this Privacy Policy.
Where a Labs tool is operated as a free or promotional tool, we may process personal data submitted through that tool to provide the tool, secure it, prevent abuse, troubleshoot issues, understand usage, improve our products, and communicate with users about Storylines, subject to applicable law and any consent requirements.
Relationship to our Data Processing Addendum
Our Data Processing Addendum, or DPA, is Storylines' standard data processing addendum for customers and is effective only when incorporated into an applicable agreement, order form, terms of service, master subscription agreement, statement of work, or other written or electronic agreement between Storylines and the customer.
The DPA applies only to the extent Press Play Labs, Inc. processes Customer Personal Data on behalf of a customer in connection with the Services. In that context, the customer is generally the Controller of Customer Personal Data and Press Play Labs, Inc. is generally the Processor, unless the parties expressly agree otherwise in writing.
For purposes of this Privacy Policy, "Customer Content" has the same general meaning used in our DPA: video, audio, images, transcripts, text, files, metadata, project files, comments, instructions, and other content submitted to, uploaded to, connected to, or generated through the Services by or on behalf of a customer. "Customer Personal Data" means personal data contained in Customer Content or otherwise processed by us on behalf of a customer in connection with the Services.
If this Privacy Policy and an applicable DPA conflict with respect to our processing of Customer Personal Data on behalf of a customer, the DPA will control to the extent of that conflict. Contact hello@storylines.video to request a copy.
Controller and processor roles
We process different types of data in different roles.
Controller role
We act as a controller when we determine why and how personal data is processed, including for website visitors, account holders, billing contacts, prospective customers, product analytics, security monitoring, marketing communications, support requests, and company operations.
Processor/service provider role
When a business customer uses Storylines to upload, connect, generate, or process content, we generally process that Customer Content on behalf of the customer under our agreement with that customer and, where applicable, a data processing addendum. In that context, the customer is generally the controller or business, and Press Play Labs, Inc. is generally the processor or service provider.
If you are an end user of an organization that uses Storylines and you have questions about Customer Content or your rights in that content, you may need to contact the organization that provided you access to Storylines.
Categories of personal data we collect
We may collect the following categories of personal data, depending on how you interact with the Service.
Account and profile data
This may include name, email address, authentication credentials, profile photo, workspace or organization name, role, team membership, user ID, and account settings.
Contact, sales, and support data
This may include business contact details, communications with us, support tickets, feedback, survey responses, sales notes, call or meeting information, and related metadata.
Customer Content and project data
When you use Storylines, we may process video files, audio files, images, transcripts, captions, subtitles, project files, edit decisions, prompts, instructions, comments, treatment or brief information, rough cuts, generated outputs, exports, linked cloud-storage files, file names, file paths where provided, metadata, and other content you or your users upload, connect, submit, or generate through the Service.
Restricted or sensitive data
Consistent with our DPA, Storylines does not require customers to submit sensitive or regulated data. Unless expressly agreed in writing, customers should not submit protected health information subject to HIPAA, payment card data subject to PCI DSS, government identification numbers, biometric identifiers used for identification, children's data, special categories of personal data under GDPR, criminal offense data, or other sensitive data subject to heightened legal restrictions. Customer Content may incidentally reveal sensitive information depending on what a customer uploads or connects to the Service, and the customer remains responsible for required rights, notices, consents, and legal bases.
Usage, device, and technical data
This may include IP address, device identifiers, browser type, operating system, application version, pages or features used, referring URLs, timestamps, log files, crash logs, performance data, diagnostic data, session data, clicks, and other interaction data.
Integration data
If you authorize an integration, such as Google Drive, we may process information necessary to connect to that account and perform requested actions, such as accessing files or links you select or authorize. Integrations are not activated automatically and require authorization by the user or customer. Customer-selected third-party services or integrations may process data under the customer's agreement with that third-party provider and are not necessarily our subprocessors.
Billing and transaction data
This may include subscription plan, credit balance, billing contact, invoice information, payment status, transaction identifiers, and limited payment-related information processed by our payment providers. We do not intentionally store full payment card numbers when payment processing is handled by a third-party payment processor.
Marketing and advertising data
This may include email preferences, campaign interactions, referral source, website analytics, advertising identifiers, cookie or tracker data, and related marketing interaction data, where permitted by law.
How we collect personal data
We collect personal data directly from you when you create an account, use the Service, upload or connect content, communicate with us, authorize integrations, submit support requests, or interact with our website or applications.
We may collect certain usage, technical, cookie, tracker, and diagnostic data automatically when you use our website or Service.
We may receive personal data from business customers, authorized users, service providers, integration partners, identity providers, payment processors, analytics providers, advertising partners, and other third parties where permitted by law.
Purposes of processing and legal bases
Where GDPR, UK GDPR, LGPD, or similar laws apply, we rely on the following legal bases.
For LGPD purposes, depending on the processing activity, we may rely on applicable legal bases including performance of a contract or preliminary procedures related to a contract, compliance with legal or regulatory obligations, legitimate interests, consent where required, regular exercise of rights in judicial, administrative, or arbitral proceedings, protection of life or physical safety, health protection where applicable, and protection of credit where applicable.
Providing the Service
We process account data, Customer Content, project data, integration data, usage data, and technical data to create accounts, authenticate users, provide Storylines features, process uploaded or connected content, generate outputs, export files, maintain user settings, and provide support. Legal bases: performance of a contract; legitimate interests; consent where required for specific integrations or optional features.
Security, fraud prevention, and abuse detection
We process usage data, device data, log data, account data, and related information to secure the Service, detect malicious or fraudulent activity, prevent unauthorized access, debug errors, and protect our rights and the rights of users and customers. Legal bases: legitimate interests; legal obligation where applicable.
Customer support and service communications
We process contact data, account data, support requests, communications, and related metadata to respond to inquiries, troubleshoot issues, provide onboarding, send transactional notices, and manage customer relationships. Legal bases: performance of a contract; legitimate interests.
Billing, subscriptions, and business administration
We process billing contact data, subscription data, credit and invoice data, payment status, account data, and communications to administer subscriptions, process payments, maintain records, enforce agreements, and comply with tax, accounting, and legal obligations. Legal bases: performance of a contract; legal obligation; legitimate interests.
Product analytics and improvement
We process usage data, diagnostic data, feature interaction data, support feedback, and aggregated or de-identified information to understand how the Service is used, improve product quality, measure performance, and develop new features. Legal bases: legitimate interests; consent where required by law for cookies, trackers, analytics, or similar technologies.
Marketing and advertising
We process contact data, marketing preferences, website usage data, cookie or tracker data, and campaign interaction data to send marketing communications, measure campaign performance, and advertise Storylines. Legal bases: consent where required; legitimate interests where permitted; compliance with legal obligations for opt-outs.
Legal compliance and claims
We process personal data as needed to comply with applicable laws, respond to lawful requests, enforce agreements, resolve disputes, protect our rights, and establish, exercise, or defend legal claims. Legal bases: legal obligation; legitimate interests.
Customer Content, AI processing, and training
Storylines processes Customer Content to provide the Service, including logging footage, generating transcripts, understanding A-roll and B-roll, assembling rough cuts, responding to prompts, creating exports, and performing related product functions requested by users, customers, or the AI agents they configure.
We do not use Customer Content or Customer Personal Data to train third-party foundation models or general-purpose AI models unless the customer has expressly authorized us to do so in writing. We do not sell Customer Content. We do not disclose Customer Content to third parties for their independent marketing purposes.
We may process Customer Content using subprocessors and infrastructure providers that help us host, store, sync, transcribe, analyze, organize, edit, log, index, search, generate, export, secure, support, troubleshoot, or otherwise provide the Service. These subprocessors are authorized to process Customer Content only as needed to provide services to us and are subject to written data protection obligations designed to protect the data.
We may use aggregated, anonymized, or de-identified information that does not identify a customer, user, or natural person to improve and operate the Service, measure performance, conduct analytics, and develop features.
Cookies, trackers, and similar technologies
We may use cookies, pixels, SDKs, local storage, tags, and similar technologies to operate the website and Service, remember preferences, authenticate users, measure performance, understand usage, provide analytics, and support advertising or marketing.
Where required by law, we will obtain consent before using non-essential cookies or trackers, including analytics, heat mapping, session recording, advertising, or retargeting technologies.
Third-party services that may be used on our website or Service include, depending on configuration:
- Google Analytics 4;
- Google Tag Manager;
- Meta pixel or advertising conversion tools;
- Google Fonts;
- WorkOS (authentication);
- Google OAuth and Google Drive account access;
- Vercel and other hosting or infrastructure providers.
Users may manage cookies through browser settings and, where available, through our cookie banner or consent tool. Disabling certain cookies may affect Service functionality.
Vendor privacy and opt-out resources
For additional vendor-specific privacy and opt-out information, see: Google Privacy Policy; Google Analytics documentation; Google Analytics Opt-out Browser Add-on; Meta Privacy Policy; Meta Ad Preferences; Vercel Privacy Policy; WorkOS Privacy Policy; YourOnlineChoices; Network Advertising Initiative; Digital Advertising Alliance.
Third-party services and subprocessors
We use service providers and subprocessors to help us provide, secure, operate, support, analyze, and improve the Service. These may include hosting providers, identity and authentication providers, cloud storage providers, analytics providers, communications providers, customer support providers, payment processors, security providers, and professional advisors.
Examples may include Vercel, WorkOS, Google services, and other vendors used to operate the Service.
We require service providers and subprocessors to process personal data only for authorized purposes and to apply appropriate confidentiality, security, and data protection obligations.
An updated list of subprocessors or service providers may be requested by contacting hello@storylines.video, unless a separate customer agreement provides a different subprocessor notice process. Where our DPA applies, we will provide notice of material new subprocessors in accordance with the DPA, including the DPA's objection process and emergency replacement provisions.
Sharing and disclosure of personal data
We may disclose personal data as follows:
- to service providers and subprocessors that help us provide, secure, operate, analyze, support, and improve the Service;
- to authorized users, workspace administrators, or business customers as needed to provide the Service;
- to integration partners when you or your organization authorize a connection or request an action;
- to payment processors for billing and subscription administration;
- to professional advisors, such as lawyers, auditors, accountants, insurers, and security consultants;
- to law enforcement, regulators, courts, or other authorities when required by law or necessary to protect rights, safety, or security;
- in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar corporate transaction;
- with your consent or at your direction.
We do not sell personal data.
International data transfers
Press Play Labs, Inc. is based in the United States, and personal data may be processed in the United States and other countries where we, our service providers, or our subprocessors operate. These countries may have data protection laws that differ from those in your country.
Where GDPR, UK GDPR, or similar laws require a transfer mechanism, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or International Data Transfer Agreement, adequacy decisions, or other lawful transfer mechanisms. We may also apply supplementary safeguards where appropriate, such as encryption, access controls, contractual restrictions, and vendor security reviews.
You may contact hello@storylines.video for more information about the transfer mechanism applicable to your personal data.
Data retention
We retain personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law, contract, security need, dispute resolution, or legitimate business need.
Typical retention criteria include:
Account data: retained for the life of the account and for a reasonable period after account closure as needed for legal, security, billing, backup, or legitimate business purposes.
Customer Content and project data: retained for the term of the applicable agreement and thereafter as necessary to comply with the agreement, our DPA where applicable, customer instructions, product settings, deletion actions, standard backup-retention cycles, and applicable law. Customer Content may remain in backups, logs, audit records, and disaster recovery systems for a limited period after deletion, provided those copies remain protected and are not used for active processing except restoration, security, compliance, or legal purposes.
Support and customer communications: retained as needed to provide support, maintain business records, resolve disputes, improve service quality, and comply with legal obligations.
Billing and transaction records: retained as required for tax, accounting, audit, fraud prevention, and legal compliance.
Security logs and diagnostic data: retained as needed to operate and secure the Service, investigate incidents, debug issues, prevent abuse, and comply with legal obligations.
Marketing data: retained until you unsubscribe, object, withdraw consent where consent is required, or the data is no longer needed for marketing or compliance purposes.
When personal data is no longer needed, we delete, anonymize, de-identify, or otherwise handle it in accordance with applicable law and our internal retention practices.
Security
We use administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, disclosure, alteration, loss, misuse, or destruction. These safeguards may include access controls, authentication controls, encryption, logging, monitoring, vendor review, personnel confidentiality obligations, incident response procedures, and other security measures appropriate to the nature of the data and the risks involved.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work to protect personal data using measures appropriate to the Service and our business.
Your privacy rights
Depending on your location and applicable law, you may have the right to:
- request access to personal data we process about you;
- request correction of inaccurate or incomplete personal data;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- object to direct marketing;
- withdraw consent where processing is based on consent;
- request portability of personal data in a structured, commonly used, machine-readable format;
- lodge a complaint with a data protection authority.
To exercise these rights, contact hello@storylines.video. We may need to verify your identity before responding. We will respond within the timeframe required by applicable law. For GDPR requests, we generally respond within one month unless an extension is permitted by law.
If we process your personal data as a processor on behalf of a business customer, we may direct your request to that customer or assist the customer in responding, as required by our agreement and applicable law.
GDPR and UK GDPR rights
Where GDPR or UK GDPR applies, you may have rights to access, rectify, erase, restrict, port, and object to processing of your personal data, and to withdraw consent at any time where processing is based on consent.
Where we process personal data for direct marketing, you may object at any time and we will stop processing your personal data for direct marketing purposes.
Where we process personal data based on legitimate interests, you may object by explaining your particular situation, and we will assess the request as required by law.
You also have the right to lodge a complaint with your local supervisory authority. If you are in the UK, you may contact the UK Information Commissioner's Office. If you are in the EEA, you may contact your local data protection authority.
LGPD rights for Brazil residents
Where LGPD applies, individuals in Brazil may have the right to confirm whether we process their personal data; access personal data; correct incomplete, inaccurate, or outdated personal data; request anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed personal data; request portability where applicable; request deletion of personal data processed based on consent, subject to legal exceptions; receive information about public and private entities with which we have shared personal data; receive information about the possibility of denying consent and the consequences of denial; withdraw consent where processing is based on consent; petition the ANPD; and request review of decisions made solely through automated processing that affect their interests, where applicable.
LGPD requests may be submitted to hello@storylines.video or to the LGPD Encarregado identified above. We may need to verify the requester's identity and authority before responding. We will respond to LGPD requests within the timeframe required by applicable law.
California and other U.S. state privacy rights
Residents of California and other U.S. states may have additional rights under applicable privacy laws, including rights to know, access, correct, delete, port, opt out of certain sharing or targeted advertising, and appeal certain decisions.
We do not sell personal data. If we engage in targeted advertising or cross-context behavioral advertising that is subject to opt-out rights, we will provide a method to opt out as required by law.
To exercise applicable state privacy rights, contact hello@storylines.video.
Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided personal data to us, contact hello@storylines.video and we will take appropriate steps to delete the information as required by law.
Business customers and users are responsible for ensuring that they have the necessary rights, notices, and consents before uploading or processing content that includes personal data of children or minors.
Legal requests and compliance
We may disclose personal data if we believe disclosure is necessary to comply with applicable law, regulation, legal process, or governmental request; enforce our agreements; protect the security or integrity of the Service; prevent fraud, abuse, or security incidents; or protect the rights, property, or safety of Press Play Labs, Inc., our users, customers, or others.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the "Latest update" date below and post the revised Privacy Policy on our website or otherwise provide notice as required by law. If changes materially affect processing based on consent, we will obtain new consent where required.
Contact us
Questions, requests, or complaints about this Privacy Policy or our privacy practices may be sent to:
Press Play Labs, Inc.
1887 Whitney Mesa Dr.
Henderson, NV 89014
United States
Email: hello@storylines.video