Data Processing Policy

Our data-protection principles, controller/processor roles, sub-processors, security measures and how we handle data-subject requests.

Last updated: 26 July 2026 · Media Stream AI Limited, England & Wales

1. Overview

Media Stream AI Limited processes personal data lawfully, fairly and transparently under the UK GDPR, the Data Protection Act 2018 and, where applicable, the EU GDPR. This policy explains how we govern that processing. It complements our Privacy Policy and forms the basis of the data-processing terms we offer to business customers.

2. Data-protection principles

  • Lawfulness, fairness & transparency — every processing activity has a documented lawful basis.
  • Purpose limitation — data is used only for the purposes it was collected for.
  • Data minimisation — we collect the minimum necessary.
  • Accuracy — we keep data accurate and up to date; you can correct yours.
  • Storage limitation — we retain data only as long as needed (see our Privacy Policy).
  • Integrity & confidentiality — appropriate technical and organisational security.
  • Accountability — we can demonstrate compliance through records, DPIAs and audits.

3. Controller & processor roles

For our own Services, MSAI is the data controller. Where we process personal data on behalf of a business customer, MSAI acts as a processor under a written Article 28 agreement, processing only on the customer's documented instructions, with confidentiality obligations on staff, assistance with data-subject requests, and deletion or return of data at the end of the engagement.

4. Sub-processors

We engage a limited set of vetted sub-processors (hosting/cloud, payment processing, analytics, communications) each bound by data-processing terms no less protective than ours. We maintain a current list of sub-processors and give reasonable notice of changes so customers may object. Sub-processors are assessed for security, location and lawful-transfer safeguards before engagement.

5. Records of processing (Art. 30)

We maintain records of processing activities describing purposes, categories of data and data subjects, recipients, transfers, retention periods and security measures, and make these available to supervisory authorities on request.

6. Data protection by design & DPIAs

We embed data protection into new features by default and by design. Before high-risk processing — including novel AI capabilities that may affect individuals — we complete a Data Protection Impact Assessment (DPIA) and, where AI Act obligations apply, a corresponding conformity/risk assessment (see our AI Act statement).

7. Security measures

  • Encryption in transit and at rest; key management and rotation
  • UK-sovereign, segmented inference infrastructure with role-based access control
  • Logging, monitoring, regular penetration testing and vulnerability management
  • Documented incident-response and breach-notification procedures (ICO within 72 hours where required)

8. International transfers

Transfers outside the UK/EEA rely on an adequacy decision or, failing that, the UK IDTA/Addendum or EU SCCs, supported by a transfer risk assessment and supplementary measures.

9. Data-subject & customer requests

We acknowledge and action data-subject rights requests within the statutory timeframe (one month, extendable for complexity) under Articles 12–23 GDPR, and assist controller-customers in meeting their own obligations. Requests: privacy@mediastreamai.com.

10. AI & ethics governance

Training-data provenance, risk classifications and oversight decisions are documented and retained for the period required by the EU AI Act. Models are assessed for bias, robustness and explainability appropriate to their risk class before and during deployment.

11. Complaints

You may lodge a complaint with the ICO (ico.org.uk) or your local EU supervisory authority. We ask that you contact us first so we can try to resolve it.