Legal, security and compliance
Eddie's Terms, Privacy Policy and DPA, the Trust Center, SOC 2 Type I and II, GDPR and HIPAA — and the commitment that your content is never used to train AI models.
The short version
- We do not train on your content.
- You own your own IP/content.
- Enterprises: SOC 2 Type I and Type II audited, GDPR and HIPAA certified. Contact us for set up.
The legal documents
| Document | What it covers |
|---|---|
| Terms and Conditions (Portuguese) | Your use of Eddie: subscriptions, credits, exports, acceptable use, account responsibilities. |
| Privacy Policy (Portuguese) | How Press Play Labs, Inc. collects, uses, discloses, retains and protects personal data. |
| Data Processing Addendum | How we process customer personal data as a processor: subprocessors, security, international transfers. Effective once incorporated into your agreement. |
The DPA can be executed — if you need a signed copy rather than the published version, ask.
The Trust Center
Security documentation, current certifications, scope, and the subprocessor list live in one place:
That is where to go for the SOC 2 reports and the request process, the detail on encryption, access control and monitoring, and the current list of subprocessors and what each one is allowed to do. It is kept up to date there rather than restated here, so you are always reading the live version.
Certifications
SOC 2 Type I and Type II. Type I is an auditor confirming our controls are designed properly and were in place on the day they looked. Type II is the same auditor watching those controls over a period of months and testing whether they actually operated the whole time. We have both. Either report is available under NDA through the Trust Center.
GDPR certified. We have appointed a Data Protection Officer and EU and UK Article 27 representatives, all named in the Privacy Policy. Data subject requests go to privacy@heyeddie.ai and we answer within the statutory timeframe.
HIPAA certified. Available for enterprise customers. If your footage involves protected health information, raise it with sales before you upload anything, so the right agreement is in place first.
We wrote up what each of these certifications actually tests, and what none of them promise separately — worth reading if you are the person who has to sign off.
Your content is not training data
This is the question we get asked most, so here is the commitment in full, from the Terms:
We do not train on your content. We do not use your files, projects, prompts, transcripts, edits, or other user content to train AI models.
And, because Eddie uses third-party AI providers to do some of the work:
We do not authorize third-party AI providers to train their models on your user content, files, prompts, transcripts, projects, edits, or data when they process that content on our behalf to provide Eddie AI.
In plain terms: your media is processed to give you the thing you asked for, and that is all. We do not watch your rushes. Nothing is licensed back to us. Those were the commitments before any auditor showed up; the audits are why you no longer have to take them on faith.
Enterprise controls
- SSO and SAML. Your team signs in through your own identity provider, so your existing policy — including MFA — applies to Eddie. See Single sign-on for your team.
- Deployment choice. Eddie's managed cloud, your own cloud, or Eddie's models running on-prem inside your environment. This is the route to take when data residency or isolation requirements rule out standard cloud processing.
- Custom agreements. Signed DPA, security questionnaires, and procurement paperwork are all handled through sales.
Start at contact sales for any of these.
What a workspace shares
Worth knowing before you import a client's footage: inside a workspace, every member can open every project. There are no per-project permissions today. If footage should not be seen by the whole team, use a separate workspace or your personal space.
The full detail is in What everyone in a workspace can see (and spend).
Running a security review
Most questionnaires ask about data residency and regions, retention periods and deletion timelines, the subprocessor list, transfer mechanisms, and incident response. Those answers are maintained in the Trust Center and in the DPA rather than in this article, because they change and a help page that drifts out of date on a compliance point is worse than no help page.
Related: Single sign-on (SSO / SAML) for your team, What everyone in a workspace can see (and spend), Contact support.