Synthesia
low riskAI Media Generationsynthesia.io, app.synthesia.ioverified 2026-06-27
Data-handling profile
- Trains on input
- No — does not train on customer inputs
- Retention
- Synthesia does not use Customer Data (inputs or outputs) to pre-train AI Components; any fine-tuning on customer data occurs only under the customer's written instruction, per governing agreement.
- Data region
- EU
- Certifications
- SOC 2 Type IIISO 27001ISO 27701ISO 42001
- DPA available
- Yes
- Breach history
- none known
- EU AI Act
- Synthetic avatar/video generation falls under EU AI Act transparency obligations (Art. 50) requiring disclosure of AI-generated/deepfake content; Synthesia publishes AI governance practices addressing this.
Sources
- https://security.synthesia.io/
- https://www.synthesia.io/legal/privacy-policy
- https://www.synthesia.io/legal/ai-governance-practices
- https://www.synthesia.io/post/synthesia-is-iso-27001-certified
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Change history
No material changes recorded since monitoring began.