Last Updated: 2026-05-29
This GDPR Compliance Notice applies to users located in the European Economic Area (EEA). It supplements our Privacy Policy and specifically describes how we fulfill our obligations under the General Data Protection Regulation (GDPR).
For purposes of the GDPR, UnMark acts as the controller of personal data. Our details are: UnMark, 101 Main St, Wilmington, DE 19801, United States. Data Protection Officer (DPO) contact: dpo@mail.unmarkvideo.com. As a company established outside the European Union, we have designated dpo@mail.unmarkvideo.com as our point of contact for EU data protection matters. Inquiries regarding the processing of personal data of individuals in the EEA may also be directed to this address. For any GDPR-related inquiries, please contact us using the above information. This GDPR Notice supplements our Privacy Policy; for complete information about our data handling practices, please read our full Privacy Policy.
We process your personal data based on the following lawful bases: Contract Performance — information needed to provide video processing services (email, username); Legitimate Interest — we process usage data and technical logs for the legitimate interests of maintaining and improving service performance, detecting and preventing fraud and abuse, and ensuring the security of our platform, where such interests are not overridden by your data protection rights; Consent — marketing communications (withdrawable at any time); Legal Obligation — necessary data processing to comply with applicable laws and regulations (e.g., tax recordkeeping, law enforcement requests). Provision of account information (email, username) is necessary to enter into and perform the service contract; if you do not provide this data, we cannot create your account or deliver the Service. Provision of data for marketing purposes is voluntary and you may withdraw consent at any time without affecting the core functionality of the Service. We may disclose your personal data to the following categories of recipients: cloud infrastructure and content delivery providers (Vercel, AWS), payment processing providers (Creem), log management and monitoring providers (Axiom), and transactional email service providers. A complete list of service providers and sub-processors is maintained on our Sub-processors page, in Section 4 of our Privacy Policy, and in Section 5 of our Data Processing Agreement.
Under the GDPR, you have the following rights: Access — obtain a copy of your personal data we hold; Rectification — request correction of inaccurate or incomplete data; Erasure (Right to be Forgotten) — request deletion under certain conditions; Restriction of Processing — restrict certain processing activities; Data Portability — receive your data in a structured format; Object — object to processing based on legitimate interests or public interest; Rights related to automated decision-making — not be subject to decisions based solely on automated processing.
Our servers are primarily located in the United States. When transferring personal data from the EEA, UK, or Switzerland to the US or other third countries, we implement the following safeguards as required by the GDPR: EU Standard Contractual Clauses (SCCs) — We use the European Commission's Standard Contractual Clauses (2021/914) as the legal transfer mechanism for data transfers from the EEA. These clauses include Module 2 (controller-to-processor) and Module 3 (processor-to-processor) as applicable, including the requisite technical and organizational measures described in Annex II. UK International Data Transfer Agreement (IDTA) — For transfers from the United Kingdom, we use the UK IDTA or UK Addendum to the EU SCCs as applicable. Additional Safeguards — We supplement legal transfer mechanisms with Transport Layer Security (TLS 1.3) encryption for all data in transit, AES-256 encryption for data at rest, and contractual obligations on all sub-processors (see our Sub-processors page). Supplementary Measures Assessment — We regularly conduct transfer impact assessments to evaluate the laws and practices of third countries and implement supplementary technical, contractual, and organizational measures as needed. You may request a copy of the applicable SCCs by contacting privacy@mail.unmarkvideo.com. Our current Sub-processor list and Data Processing Agreement are available on our website.
We retain your personal data only for as long as necessary for the purposes for which it was collected: Account information — duration of account plus 30 days after closure (for dispute resolution); Processing logs — 90 days after processing completion; Payment records — 7 years per tax and legal requirements; Marketing preferences — until consent withdrawal or account closure.
In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it and notify you without undue delay where feasible. The notification will include the nature of the breach and its approximate scope.
You have the right to lodge a complaint with a data protection supervisory authority in your member state of residence. We will fully cooperate with any investigation by a supervisory authority.