Privacy Policy
1. Introduction
VIVIXSG PTE. LTD. (“Vivix”, “we”, “us”, or “our”) provides an application programming interface (API) that offers real-time interactive video, digital human, image, and audio generation capabilities (the “Services”). We are incorporated in Singapore and our Services are hosted in the United States.
This Privacy Policy explains how we collect, use, and share personal information. It applies to individuals who register for the Services (our “Customers”) and to personal information processed through the Services.
Important Note on Our Role
Under data protection laws, a “controller” determines the purposes and means of processing personal data, while a “processor” processes personal data on behalf of a controller. This distinction is based on the actual activities performed, not merely on labels in a contract.
For the processing activities described in this Privacy Policy:
- When we process Customer account information (such as email addresses for account management and IP addresses for service region verification), we act as a controller.
- When we process end-user data submitted through our API (such as images, audio, video, and text prompts) on behalf of our Customers, we act as a processor. Our Customers are the controllers and determine the purposes and means of processing. If you are an end-user of one of our Customers, please contact that Customer directly for privacy-related requests.
Please read this Privacy Policy carefully and in its entirety. By accessing or using any part of the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices described herein, please do not use our Services.
If you are under 13 years old, do not meet the age requirements for using or accessing the Services in your jurisdiction, or if there are other legal restrictions applicable to your user status, please comply with local laws by refraining from using the Services. You should only access or use the Services if you meet the applicable age requirements in your jurisdiction. If you are between 13 and 18 years old, please ensure that you have understood this Policy and, where required by applicable law, obtained the necessary consent from your parent or legal guardian. If you are a parent or guardian and become aware that your child has provided us with personal data, please contact us immediately. Should we learn that personal data has been collected from anyone under 13 years old (or the applicable legal age) without verified parental consent, we will promptly take measures to delete such data from our servers.
If you are located in the European Economic Area (EEA), the United Kingdom, Switzerland (collectively, the “EEA+” areas), or the United States, please also read carefully and fully, and consent to the EEA+ Addendum, the US Addendum to this Privacy Policy respectively.
2. Information We Collect
2.1 Where We Act as Controller
We collect the following limited information directly from you, where we act as a controller:
- Account Information: When you register for an account, we collect your email address and account credentials. Your email is stored to identify your account and to communicate with you (e.g., service announcements, security alerts).
- IP Address: When you access our website, developer portal, or API, we collect your IP address to determine whether you are located in a permitted service region. We do not use your IP address for analytics or profiling.
- Communications Information: Information you provide when you contact us for support or otherwise communicate with us.
2.2 Where We Act as Processor (End-User Data)
When our Customers integrate our API into their applications, we process the following categories of personal data as a processor on their behalf:
- Images: photographs or other visual representations uploaded by end-users to generate AI outputs.
- Audio Recordings: voice recordings uploaded for voice cloning, lip-sync, or audio generation.
- Video Recordings: video files uploaded to generate or modify digital human avatars.
- Text Prompts: text inputs provided to guide content generation.
- Biometric Data: For the purpose of generating digital human avatars, we may process face geometry and voiceprints extracted from images, audio, or video submitted via the API. This processing is performed solely in accordance with our Customers’ instructions and applicable legal requirements.
- Metadata: Information about how, when, and by whom content was submitted.
Vivix does not directly collect this end-user data. It is provided to us by our Customers, who are responsible for obtaining all necessary consents from end-users and for determining the lawful bases for processing.
3. Biometric Data
Some features of the Services process biometric data, such as facial geometry derived from images/video and voiceprints derived from audio recordings. Biometric data is sensitive information under applicable laws.
- Consent: Where we act as a processor, our Customers are responsible for obtaining all required consents from individuals whose biometric data is processed. We do not directly obtain consent from end-users.
- Use: We use biometric data solely to provide the Services in accordance with Customer instructions (e.g., to generate the requested avatar or media), and for security, fraud prevention, and legal compliance.
- No Sale: We do not sell biometric data.
- Retention: Where we act as a processor, we retain biometric data only as long as needed to provide the Services in accordance with Customer instructions, or until the earlier of the purpose being satisfied or the opting out of Customer, after which it is deleted. Our Customers may request deletion at any time.
- De-Identification for Training: Where biometric data is used to train or improve our models, we first apply measures designed to de-identify the data. All subprocessors are contractually prohibited from using customer data to train their own models. See Section 5 for training opt-out.
- US State Biometric Laws: Where applicable, we handle biometric information consistent with US state biometric laws (including, where applicable, the Illinois Biometric Information Privacy Act (BIPA), Texas, and Washington laws).
4. How We Use Your Information
4.1 Where We Act as Controller
- To create and manage your account.
- To determine whether you are located in a permitted service region (using IP address) and to secure our Services.
- To comply with legal obligations regarding applicable laws.
- To communicate with you regarding service updates, security alerts, and support.
4.2 Where We Act as Processor (On Behalf of Customers)
- To provide, operate, secure, and maintain the Services.
- To generate requested AI outputs (videos, images, audio, text) based on Customer inputs.
- To prevent fraud and abuse, and to ensure the security of our systems.
- To improve and develop our AI models using de-identified data, as described in Section 5 below.
5. Model Improvement and De-Identified Data Use
5.1 General Approach
We use data submitted through the API—including prompts, images, audio, video, and other content—to train and improve our AI models. We apply measures designed to de-identify data before using it for model training, meaning that direct identifiers (such as API keys and source IP addresses) are removed. De-identified data is processed solely for model improvement purposes and is not intended to identify any specific individual.
5.2 Opt-Out Mechanism
Customers may opt out of having their data used for model training by contacting us at customerservice@vivix.ai. Opt-out requests for end-user data must be submitted by the Customer on behalf of those individuals. We will implement your opt-out request within a reasonable timeframe. Please note that past training that has already occurred using data received prior to the opt-out request will not be reversed.
5.3 Subprocessor Restrictions
All third-party subprocessors engaged by Vivix are contractually prohibited from using any data processed through our Services to train their own models.
6. How We Share Information
We share information only in the following circumstances:
- Service Providers / Subprocessors: With third parties that help us operate the Services, such as cloud hosting, content moderation, and analytics. We maintain a current list of subprocessors. All subprocessors are contractually prohibited from using any data processed through our Services to train their own models.
- Legal and Safety: To comply with law, respond to lawful requests (including subpoenas, court orders, or government requests), enforce our terms, or protect rights and safety (including reporting child sexual abuse material to the appropriate authorities).
- Business Transfers: In the event of a merger, acquisition, reorganization, sale of all or substantially all of our assets, change of ownership or control, financing transaction, or transfer of any portion of our business or assets to any of our affiliated entities, your personal information may be transferred as part of such transaction. We will notify you via email or a prominent notice on our website prior to such transfer. The new entity will be required to honor the commitments made in this Privacy Policy.
- With Your Consent: Where you have provided explicit consent.
We do not sell personal information. We also do not “share” personal information for cross-context behavioral advertising as those terms are defined under California law.
7. Data Location and International Transfers
Our Services and data are hosted in the United States. If you access the Services from outside the US (including the EEA or UK), your information will be transferred to and processed in the US.
- Transfers from the EEA, Switzerland, and the UK: We rely on Standard Contractual Clauses (SCCs) approved by the European Commission pursuant to Article 46 of the GDPR, together with supplementary measures where required, and the UK International Data Transfer Addendum for transfers from the United Kingdom.
- No transfer to any countries of concern: No U.S. or EEA personal data processed through our API is transferred to, or stored in any other “country of concern” as defined in 28 CFR Part 202.
Further details are provided in the EEA+ Addendum below.
8. Compliance and Access Controls
We have implemented technical and organizational measures to keep compliance with applicable laws in the U.S., including zero-trust network architecture, geo-IP access restrictions (blocking access attempts from countries of concern), strict access logging, and contractual prohibitions.
We reserve the right to modify these measures as necessary to maintain compliance with evolving U.S. regulations. These measures do not constitute a guarantee that all unauthorized access will be prevented.
9. Data Retention and Deletion
- Account information (controller): Retained for as long as your account is active, plus a reasonable period thereafter (not to exceed sixty (60) days after account closure), unless longer retention is required by law.
- IP address (controller): Retained transiently; not stored beyond the duration necessary to determine region eligibility.
- End-user data processed on behalf of Customers (processor): Retained in accordance with Customer instructions and our DPA. Upon termination of a Customer’s account or upon a Customer’s request, we will delete in accordance with our agreement after a certain period of time.
- Biometric data (as processor): Retained only as long as needed to provide the Services in accordance with Customer instructions, or until the earlier of the purpose being satisfied or the opting out of Customer, after which it is deleted.
- API logs and metadata: Retained for up to thirty (30) days for security and operational purposes.
- De-identified data used for model training (controller): May be retained indefinitely in de-identified form.
You may request account deletion by contacting us at customerservice@vivix.ai.
10. Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access controls (RBAC) and multi-factor authentication (MFA) for personnel accessing production systems.
- Regular security monitoring, logging, and vulnerability assessments.
- Contractual requirements for all subprocessors to implement appropriate security measures.
No system is perfectly secure, and we cannot guarantee absolute security of your information.
11. Your Rights
11.1 Rights for Information Where Vivix Acts as Controller
Depending on your jurisdiction of residence, you may have the following rights with respect to personal data for which Vivix acts as a controller:
- Access: To request confirmation of whether we process your personal data and to obtain a copy.
- Rectification: To request correction of inaccurate or incomplete personal data.
- Erasure: To request deletion of your personal data, subject to legal exceptions.
- Restriction: To request that we restrict processing of your personal data in certain circumstances.
- Data Portability: To request a copy of your personal data in a structured, machine-readable format.
- Objection: To object to processing based on legitimate interests or for direct marketing.
- Withdraw Consent: To withdraw any consent you have provided.
To exercise these rights, contact us at customerservice@vivix.ai. We will verify your identity before processing your request and respond within the timeframes required by applicable law.
11.2 Rights for End-User Data Processed on Behalf of Customers
If you are an end-user of one of our Customers, your privacy rights with respect to data submitted through our API should be exercised directly with the applicable Customer, who is the data controller. Under applicable laws (including the GDPR), the Customer is responsible for responding to your request within the required timeframes. Vivix will assist our Customers in responding to end-user rights requests as required by applicable law and our DPA.
11.3 Opt-Out of Model Training
As described in Section 5, you may opt out of having your data used for model training at any time by contacting us at customerservice@vivix.ai. Opt-out requests for end-user data must be submitted by the Customer on behalf of those individuals.
12. Customer Responsibilities
If you are a Customer using our API, you acknowledge and agree that you are solely responsible for:
- Obtaining all necessary consents and providing all required notices to end-users under applicable laws, including but not limited to, where applicable, GDPR Article 6, Article 9 for biometric data, and ePrivacy Directive.
- Ensuring that your use of our API complies with all applicable age-related requirements, including obtaining parental consent where required, or preventing children from using your service if such consent is not obtained.
- Implementing appropriate content moderation and AI labeling in your application, as required by applicable laws (including EU AI Act transparency obligations).
- Complying with export control, sanctions, and data protection laws relevant to your jurisdiction and the jurisdictions of your end-users.
We act as a processor of end-user data submitted through our API. You remain the data controller for such data and are responsible for establishing the legal bases for processing, responding to end-user rights requests, and complying with all laws applicable to your use of our Services.
13. Cookies and Tracking Technologies
Our website and developer portal may use cookies and similar tracking technologies to enhance user experience and analyze site traffic. You can control cookies through your browser settings. No tracking technologies are used in our API processing infrastructure.
14. Children’s Privacy
The App is not intended for use by children under the age of 13 (or the digital age of consent in your country/region, or other applicable age thresholds under local law). We do not knowingly collect personal data from children.
If you do not meet the age requirements for using or accessing the Services in your country/region, please comply with local laws by refraining from using the Services. You should only access or use the Services if you meet the applicable age requirements. If you are a parent or guardian and believe your child has provided us with information, please contact us immediately. If we discover that we have collected personal information from a minor without verified parental consent, we will take immediate steps to delete that information from our servers.
For users between the ages of 13 and 18 (or the applicable age of majority in their jurisdiction), we rely on your representation that you are capable of consenting to the Terms of Service and our Privacy Policy on your own behalf, or that you have obtained the necessary consent from your parent or legal guardian, as required by applicable law. If you are a parent or guardian and you believe your child has provided us with personal data without your consent, please contact us immediately. We do not intentionally collect personal data from minors and reserve the right to delete any data discovered to have been collected from a minor without proper consent.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date at the top of this policy and, where appropriate, notify you via email or through our developer portal. All other changes will be effective as soon as we post them on our website. Your continued use of the Services after the effective date constitutes your acceptance of the updated policy.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at legal@vivix.ai.
EEA+ Addendum
This Addendum supplements the main Privacy Policy and applies to individuals located in the European Economic Area (EEA), Switzerland, and the United Kingdom (collectively, “EEA+”). In the event of any conflict, this Addendum controls for EEA+ individuals.
1. Data Controller and Contact
For personal data processed as a processor on behalf of our Customers, the Customer is the data controller. Please contact the applicable Customer directly for any GDPR-related requests concerning end-user data.
2. Legal Bases for Processing
The table below sets out the legal bases under the GDPR for all processing activities described in the main Privacy Policy.
| Processing Activity | Categories of Personal Data | Our Role | Legal Basis (GDPR) |
|---|---|---|---|
| Account registration and management | Email address, credentials | Controller | Performance of a contract (Article 6(1)(b)) |
| Determining permitted service region | IP address | Controller | Legitimate interests (Article 6(1)(f)) and Legal obligation (Article 6(1)(c)) — to ensure compliance with geographic restrictions and legal requirements |
| De-identified data processing for model training and improvement | De-identified prompts, images, audio, video, usage data | Controller (for de-identified data) | Legitimate interests (Article 6(1)(f)) — to improve the quality and performance of our AI Services |
| Providing the API Services (generating AI outputs based on Customer inputs) | Images, audio, video, text prompts, source content | Processor (on behalf of Customer) | Performance of a contract with our Customer (Article 6(1)(b)). The Customer is the controller. |
| Security, fraud prevention, and system integrity | API call logs, metadata, IP addresses (transient) | Controller / Processor (as applicable) | Legitimate interests (Article 6(1)(f)) — to protect our systems and prevent abuse |
| Opt-out of model training (processing of requests) | Email address, customer identifier | Controller | Legal obligation (Article 6(1)(c)) — to honor opt-out requests |
Processing of Special Categories of Personal Data (Article 9 GDPR)
Where we process biometric data (face geometry, voiceprints) as a processor on behalf of our Customers, our Customers are responsible for establishing a legal basis under Article 9(2) of the GDPR, such as explicit consent (Article 9(2)(a)). We do not independently determine the legal basis for such processing. For any processing where we act as a controller, we do not process special categories of personal data as defined in Article 9(1) of the GDPR.
3. Your GDPR Rights
You have the right to: access, rectify, erase, restrict processing, data portability, object to processing based on legitimate interests or direct marketing, and withdraw consent (where applicable). To exercise these rights, contact us at customerservice@vivix.ai. We will respond within one month. You also have the right to lodge a complaint with a supervisory authority. We encourage you to contact us first to resolve any concerns.
4. Automated Decision-Making
We do not use personal data for fully automated decision-making that produces legal or similarly significant effects concerning you independently. Our API generates outputs based on Customer inputs; any subsequent decisions are the responsibility of our Customers.
5. Retention
- Account email: retained for the duration of your account plus a reasonable period (≤ sixty (60) days after closure).
- IP address (for region check): retained transiently; not stored beyond the duration necessary to determine region eligibility.
- Biometric data (as processor): retained as set forth in Section 9 of the main Privacy Policy.
- De-identified data used for model training: retained indefinitely in de-identified form.
6. Updates
We may update this Addendum as described in the main Privacy Policy.
US Addendum
This Addendum supplements the main Privacy Policy and applies to residents of California and other U.S. states with applicable comprehensive privacy laws (including but not limited to, as applicable, Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, Delaware, Iowa, Nebraska, New Hampshire, and New Jersey). In the event of any conflict, this Addendum controls for U.S. residents.
1. California Residents (CCPA/CPRA)
The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, the “CCPA”), grants California residents certain rights regarding their personal information.
1.1 Notice of Collection
We collect the following categories of personal information from California residents:
| Category | Examples | Collected? |
|---|---|---|
| Identifiers | email address, IP address, account name | Yes |
| Internet or other electronic network activity information | API usage logs, website interactions, access times | Yes |
| Biometric information (where applicable) | Facial geometry, voiceprints (processed as a processor) | Yes |
| Inferences | Derived from usage patterns | No |
We collect this information for the purposes described in the main Privacy Policy: providing and maintaining the Services, security and fraud prevention, and model improvement (using de-identified data). We disclose this information to service providers and subprocessors as necessary to operate the Services, as described in Section 6 of the main Privacy Policy.
We do not sell personal information. We also do not “share” personal information for cross-context behavioral advertising as those terms are defined under the CCPA.
1.2 Your CCPA Rights
If you are a California resident, you have the following rights:
- Right to Know: You have the right to request that we disclose: (a) the categories of personal information we have collected about you; (b) the categories of sources from which the personal information is collected; (c) the business or commercial purpose for collecting or sharing your personal information; (d) the categories of third parties with whom we share your personal information; and (e) the specific pieces of personal information we have collected about you.
- Right to Delete: You have the right to request deletion of your personal information that we have collected from you, subject to certain exceptions (e.g., where we need to retain the information to complete a transaction, detect security incidents, or comply with legal obligations).
- Right to Correct: You have the right to request correction of inaccurate personal information that we maintain about you.
- Right to Opt-Out of Sale/Sharing: You have the right to opt out of the “sale” or “sharing” of your personal information for cross-context behavioral advertising. As stated above, we do not sell or share personal information.
- Right to Limit Use of Sensitive Personal Information: You have the right to limit the use and disclosure of sensitive personal information (including biometric data) to what is necessary to provide the Services. We use sensitive personal information solely for this purpose.
- Right to Non-Discrimination: You have the right not to receive discriminatory treatment for exercising any of your CCPA rights.
1.3 Automated Decision-Making Technology (ADMT)
We use automated decision-making technology in the form of AI models that generate outputs (videos, images, audio, text) based on inputs provided by our Customers or their end-users. When we act as a processor on behalf of a Customer, the Customer is responsible for providing any required notices and obtaining any required opt-outs regarding ADMT. If you are an end-user of one of our Customers, please contact that Customer directly for information about its use of ADMT.
1.4 Sensitive Personal Information
We process sensitive personal information (biometric data) solely for the purpose of providing the Services as requested by our Customers. We do not use sensitive personal information for any other purpose. We do not sell or share sensitive personal information.
1.5 Shine the Light
California Civil Code Section 1798.83 permits California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing purposes.
1.6 Exercising Your California Rights
To exercise any of your CCPA rights, please contact us at customerservice@vivix.ai with the subject line “California Privacy Request.” We will verify your identity before processing your request. To verify your identity, we may ask you to provide information that matches the information we have on file about you (such as your email address or account information). If we cannot verify your identity, we will not be able to fulfill your request.
You may also designate an authorized agent to make a request on your behalf. To do so, the authorized agent must provide us with a signed written authorization from you (or a valid power of attorney) and may be required to verify their own identity.
2. Residents of other states of U.S.
Residents of the following states have rights under applicable state privacy laws (including but not limited to the Virginia Consumer Data Protection Act, Colorado Privacy Act, Connecticut Data Privacy Act, Utah Consumer Privacy Act, Oregon Consumer Privacy Act, Texas Data Privacy and Security Act, Montana Consumer Data Privacy Act, Delaware Personal Data Privacy Act, Iowa Consumer Data Protection Act, Nebraska Data Privacy Act, New Hampshire Privacy Act, and New Jersey Data Protection Act); your rights may include:
- Right to Confirm and Access: To confirm whether we process your personal data and to access such data.
- Right to Delete: To delete personal data provided by or obtained about you.
- Right to Correct: To correct inaccuracies in your personal data (except in Iowa and Utah).
- Right to Data Portability: To obtain a copy of your personal data in a portable and, to the extent technically feasible, readily usable format.
- Right to Opt Out: To opt out of the processing of your personal data for: (a) targeted advertising; (b) the sale of personal data; and (c) profiling in furtherance of decisions that produce legal or similarly significant effects concerning you. We do not engage in these activities where we act as a processor; where we act as a controller, we do not sell personal data, engage in targeted advertising, or conduct such profiling.
- Right to Appeal: If we deny your request, you have the right to appeal our decision by contacting us with “Privacy Request Appeal” in the subject line.
To exercise these rights, contact us at customerservice@vivix.ai. We will respond within the timeframes required by applicable law, generally in forty-five (45) days for most states.