Data Processing Addendum
BUBI Productions Ltd · Company number 15104027 · Registered in England and Wales. Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. Email: info@bubiproductions.com · Phone: +44 7367 390 611
How BUBI Productions Ltd handles personal data on a Partner's behalf. This addendum forms part of our Terms of Service under clause 13, and applies whenever we process personal data the Partner controls. It is written to do what Article 28 of the UK GDPR requires, in the same plain language as everything else we publish.
Last updated: 30 August 2026.
1. Roles and scope
For the personal data inside the Partner's material and accounts, the Partner is the controller and BUBI is the processor. That covers, typically: people who appear in footage and photos the Partner supplies or BUBI shoots for them; the Partner's team members named in briefs and threads; the Partner's audience and channel statistics, which are aggregated but can identify individuals such as commenters; and correspondence the Partner asks us to work from. For data BUBI holds for its own purposes (enquiries, invoicing, its own records, this website), BUBI is the controller and the Privacy Notice applies instead.
2. Subject matter, duration, nature and purpose
We process this data to produce, deliver and manage the commissioned work: production, editing, design, channel management, reporting and the standards work around them. Processing lasts for the engagement plus the retention clocks in Terms clause 11, and no longer.
3. Instructions
We process only on the Partner's documented instructions: the proposal, the brief, and written directions in the project thread. If the law requires us to process otherwise, we tell the Partner first, unless the law forbids telling. If an instruction looks to us like it would break data-protection law, we say so before acting on it.
4. Confidentiality and people
Everyone who touches Partner data is bound in writing first, under Terms clause 6: the founders, and the specialist bench, each bound at least as strictly as we are bound to the Partner. BUBI answers to the Partner for all of them as for itself.
5. Security
The measures are the ones the Terms already promise, applied as security controls: delegated access rather than credentials, with any shared credential rotated at the end and named on the exit list; account access, logins and analytics held by the founders only; work carried only through BUBI's or the Partner's own storage and transfer, never personal accounts; and transfer through the providers in the schedule below, under their encryption in transit and at rest. We review these measures as the work and the risks change.
6. Sub-processors
The Partner authorises the providers in the schedule. We tell active Partners in writing before adding or replacing one, and the Partner may object on reasonable grounds before the change takes effect; each provider is bound by a written contract imposing data-protection obligations at least as protective as this addendum.
Schedule of sub-processors, as at 30 August 2026: Google Workspace (email, documents, cloud drive storage) · Frame.io, an Adobe service (video review and delivery) · Adobe Creative Cloud (production files and tooling) · Slack (project conversations, where the Partner prefers it) · WhatsApp (conversations, where the Partner prefers it) · Notion (project planning notes) · vidIQ (channel statistics for managed accounts) · Apple (devices and their synced storage). Providers that serve only BUBI's own website, payments and analytics are not sub-processors of Partner data; they are listed in the Privacy Notice.
No sub-processor trains any system on Partner data: per Terms clause 12, where a provider would use customer data for training by default, we exercise its opt-out and keep the confirmation.
7. Transfers
Some providers process data outside the UK. Where they do, transfers rely on UK adequacy regulations or the appropriate safeguard contracts (the UK IDTA or Addendum with standard contractual clauses), through the provider's own compliant terms.
8. Helping the Partner
We help the Partner meet their own obligations, promptly and at no charge for reasonable requests: passing on and assisting with data-subject requests that reach us about Partner-controlled data (the Partner decides; we act); assisting with security, breach handling, and impact assessments where our processing is involved. If we become aware of a personal-data breach affecting Partner data, we tell the Partner without undue delay, with what we know and what we are doing.
9. Return and deletion
Return runs on the Terms clause 11 machinery: the Partner's library ships as the work ships, and copies are available within the retention clocks. At the end of the applicable clock, or earlier on the Partner's written request, we delete the Partner-controlled personal data we hold, except where law requires retention, and confirm the deletion in writing on request.
10. Showing our work
On written request we provide the information reasonably needed to demonstrate this addendum is being kept, and once in any twelve months the Partner may audit that compliance, on reasonable notice, at their cost, and without access to any other partner's material or data.