Summary
SproutVideo processes customer data as a processor under the GDPR, the UK GDPR, the Swiss FADP and the CCPA/CPRA. This page explains where your data lives, who can access it, how it is protected, how long it is kept, and what our video player does on your viewers’ devices. If you need something not covered here, contact support@sproutvideo.com.
- Data Processing Addendum
- Where your data is stored
- International transfers
- Sub-processors
- Encryption
- Security certifications and Trust Center
- Player Privacy Mode
- What the player stores on a viewer’s device
- Login-protected videos and viewer identity
- Lead capture and consent
- Analytics and Usage Data
- Artificial intelligence
- Retention and deletion
- Data subject requests
- Breach notification
- Questions
- List of Data Sub-processors
Data Processing Addendum
We provide a Data Processing Addendum (DPA) for customers processing personal data under the GDPR, UK GDPR, Swiss FADP and CCPA. You can sign and download it here. The DPA incorporates the 2021 EU Standard Contractual Clauses (Module Two), the UK International Data Transfer Addendum and Swiss adaptations. The competent supervisory authority in Schedule A is determined by where your organization is established: your EU Member State’s authority, the UK ICO, the Swiss FDPIC, or the Irish Data Protection Commission for customers established elsewhere. Sub-processors are listed on this page and incorporated by reference.
Where your data is stored
All customer data, including video files, account and viewer records, and analytics, is stored and processed in Amazon Web Services’ US East (Northern Virginia) region, us-east-1. Our analytics database (ClickHouse Cloud) is in the same region. Video is delivered through the Amazon CloudFront content delivery network, which caches video segments and poster images at edge locations worldwide, including in the EU, so that viewers get fast playback. We do not currently offer an EU or EEA data-residency option.
International transfers
Transfers of EU, UK and Swiss personal data to the United States are made under the Standard Contractual Clauses incorporated in Section 6 of our DPA. SproutVideo does not currently participate in the EU-US Data Privacy Framework.
Sub-processors
Our current sub-processors are listed below. Only two of them process your video or audio content: Amazon Web Services (storage, transcoding and delivery) and Mux (live streaming, only if you use it). All other sub-processors process account, billing, support or analytics data. To be notified of changes, subscribe here. Changes are announced with a ten-day objection window as described in Section 5 of the DPA.
Encryption
All data in transit between viewers, your team, our application, our sub-processors and the CDN is encrypted with TLS. Video files, uploads and other stored content are encrypted at rest in Amazon S3 with AES-256. Our production databases are encrypted at rest.
Security certifications and Trust Center
SproutVideo is undergoing a SOC 2 Type II audit; the observation period concluded on September 9, 2026. Our Trust Center at https://trust.sproutvideo.com provides current control status, policies and, once issued, the SOC 2 report under NDA.
Player Privacy Mode
Player Privacy Mode makes the video player collect only anonymized viewing data. With it enabled, the player does not set the persistent viewer identifier cookie, does not set the viewer identity cookie, and truncates viewer IP addresses before they are stored (for example, 203.0.113.77 becomes 203.0.113.0). You can enable it for all media by default and turn it off programmatically once a visitor gives consent, for example from your cookie banner.
One optional exception exists for accounts using login-protected videos: the viewer access history, which records each login, view and download by a viewer login so that shared or misused credentials can be identified, stores a truncated IP address by default under Privacy Mode. Account owners who need the full address for that purpose can enable “Keep full viewer IP addresses in the viewer access history” in Media Settings. This affects only the access history, not engagement analytics. Privacy Mode affects data collected while it is on; it does not alter data collected earlier.
What the player stores on a viewer’s device
The embedded player runs from videos.sproutvideo.com and uses no local storage, session storage, IndexedDB or service workers. It may set the following cookies, all with SameSite=None; Secure; Partitioned:
| Cookie | Purpose | Lifetime | Privacy Mode off | Privacy Mode on |
|---|---|---|---|---|
| svid | Persistent viewer identifier for returning-viewer analytics | 1 year | Set | Not set |
| _s_id | Remembers a viewer’s email and name so a lead-capture form is not shown again | 1 year | Set once a viewer has identified themselves | Not set |
| privacyMode | Remembers that privacyMode=true was passed on the embed URL | 1 year | Only if that parameter is used | Only if that parameter is used |
| video_[id]_password | Token showing the viewer entered the embed password | Browser session | Password-protected videos only | Same |
Login-protected playback and per-viewer attribution do not depend on any cookie and work in browsers that block third-party cookies. If you enable a third-party integration in the player (for example HubSpot), that integration may set its own cookies according to its provider’s policy.
Login-protected videos and viewer identity
When a video is login protected, the viewer signs in with credentials you created. The login is verified on our servers and recorded in the viewer access history with a timestamp and IP address. The viewer’s identity is then passed to the player in a short-lived signed URL, and the player reports engagement (plays, seconds watched, completion) tagged with that login. Engagement events are generated by the player in the viewer’s browser and are not cryptographically bound to the login session; the login event itself is server-verified. Viewer logins can use pseudonymous identifiers: the identifier must be formatted as an email address but does not need to be deliverable, and no email is sent to viewer logins in the embedded flow. Viewer logins do not support two-factor authentication. You can limit plays per access grant and review the access history for each login.
Lead capture and consent
If you use lead capture to collect viewer email addresses, add a privacy policy URL in your Viewer Privacy Options. We display it in the player wherever personal data is collected. Under the GDPR, consent must be specific and informed, so your policy should say how the email addresses will be used.
Analytics and Usage Data
Our analytics record, per viewing session, the video, the time, the seconds watched, the device and browser, the referring page, an approximate location derived from the IP address, and the IP address (truncated under Privacy Mode). A session is linked to a person only if the viewer was identified to the player, through a viewer login or lead capture. Under our DPA, technical and usage information we collect to operate, secure and improve the service, together with aggregated or de-identified data, is “Usage Data” that we process as an independent controller. We access identifiable viewer records only in the course of providing the service to you, for example to respond to your support, export or deletion requests. For our own product and business analysis we use aggregated or de-identified data that does not identify individual viewers. Usage Data is not sold or shared with third parties beyond the sub-processors listed above.
Artificial intelligence
Customer video, audio, transcripts, captions, metadata, personal data and usage data are not used by SproutVideo or by any sub-processor to train, fine-tune or develop AI or machine-learning models. Automated captions are generated by speech-to-text software running on SproutVideo’s own infrastructure; audio is not sent to a third-party AI service and the model is not trained on customer content.
Retention and deletion
- Videos. When you delete a video, or close your account, the video files are deleted from production storage immediately. We do not keep backup copies of video files. Video segments cached on the CDN can only be fetched with a signed URL that expires within six hours and cannot be issued for a deleted video. Poster images expire from CDN caches within 24 hours.
- Databases. Database backups (account and viewer metadata, not video) are retained for five days.
- Engagement records. Viewing analytics are retained for the term of your agreement and until deleted on your written request, as described in Section 2.5 and Schedule A of the DPA. There is no self-service deletion of individual viewer records today; send requests to support@sproutvideo.com and we will carry them out and confirm in writing.
- Lead capture data can be exported through the API and the account’s export tools at any time.
Data subject requests
Individuals have rights of access, correction, erasure, restriction, portability and objection under the GDPR, and equivalent rights under the CCPA. As a processor we assist you in responding: viewer data collected through lead capture or viewer logins can be exported through the API or account tools, and deletion requests are handled through support as above.
Breach notification
If a personal data breach affects your data we will notify you by email without undue delay, and post incidents at https://status.sproutvideo.com, where you can subscribe for updates.
Questions
Contact support@sproutvideo.com for privacy, GDPR or CCPA questions, to request our SOC 2 report under NDA, or to arrange a call with your data protection officer.
List of Data Sub-processors
Current as of: September 2, 2026
| Entity Name | Entity Type | Entity Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud Services Provider | USA |
| Authorize.net | Payment Processor | USA |
| ClickHouse, Inc. | Analytics Database Provider | USA |
| Elasticsearch B.V. | Search Provider | The Netherlands |
| FullStory, Inc. | Web Analytics Services | USA |
| Functional Software, Inc. (Sentry) | Application Error Monitoring | USA |
| Google, Inc. | Web Analytics Services | USA |
| Help Scout PBC | Customer Support Platform | USA |
| MailChimp | Marketing Automation Services | USA |
| Microsoft Corporation (Clarity) | Web Analytics Services | USA |
| Mixpanel, Inc. | Web Analytics Services | USA |
| Mux, Inc. | Live Video Streaming Provider | USA |
| Twilio, Inc. (Including Twilio SendGrid) | Customer Communications Provider and transactional email | USA |
| TYPEFORM S.L | Customer Feedback Platform | Spain |
Other articles in the Account Related Questions section: