AI Vendor Directory · Image, video & audio generation
Does Synthesia train on your data?
No — does not train on your data by default. Vendor-stated default: no. AI Governance Practices page states: "Synthesia does not use Customer Data, including inputs or outputs, to pre-train its AI Components"; any fine-tuning that processes customer data (e.g., personal avatars) requires the customer's written instructions under the governing agreement. Applies to business plans generally; no opt-out needed. Customer data is stored in the EU (Ireland, backups Frankfurt) per the security practices page (updated Feb 3, 2026).
By the Shieldra Compliance Team · Last updated 2026-07-29
What is Synthesia?
AI avatar video platform for training, comms, and marketing video from text. EU-hosted; the strongest paper trail of the media-generation vendors (first ISO 42001-certified GenAI video company).
Key facts
- Vendor: Synthesia Ltd. — https://www.synthesia.io
- Trains on customer data by default: no
- Source for the training answer: https://www.synthesia.io/legal/ai-governance-practices
- Data residency: EU
- Last verified: 2026-07-29
What certifications does Synthesia hold?
- SOC 2 Type II
- ISO 27001
- ISO 42001
- GDPR
Security, DPA, and subprocessor links
- Security / trust page: https://www.synthesia.io/legal/security-practices
- Subprocessor list: https://www.synthesia.io/legal/subprocessors
What is your EU AI Act role when you build on Synthesia?
Synthesia positions itself as provider and the customer as deployer; avatar videos are squarely Article 50 territory — deployers must disclose AI-generated/deepfake content. Synthesia states its components, used per its AUP, are not high-risk systems under the EU AI Act.
What to record in your AI registry
- Provider: Synthesia Ltd.
- Model type: third party api
- Data typically flowing to the vendor: scripts and training content, presenter likeness video/voice (consent-gated), generated video
Sources
- https://www.synthesia.io/legal/security-practices
- https://www.synthesia.io/legal/ai-governance-practices
- https://security.synthesia.io/
Disclaimer
Curated from vendor-published pages on the date above. Vendor terms change - verify against the cited sources before relying on a profile for a procurement decision. Last verified 2026-07-29.
Frequently asked questions
Does Synthesia train AI models on your data?
No — does not train on your data by default. Vendor-stated default: no. AI Governance Practices page states: "Synthesia does not use Customer Data, including inputs or outputs, to pre-train its AI Components"; any fine-tuning that processes customer data (e.g., personal avatars) requires the customer's written instructions under the governing agreement. Applies to business plans generally; no opt-out needed. Customer data is stored in the EU (Ireland, backups Frankfurt) per the security practices page (updated Feb 3, 2026).
What certifications does Synthesia hold?
Per the vendor's published pages as of 2026-07-29: SOC 2 Type II; ISO 27001; ISO 42001; GDPR.
Where does Synthesia store your data?
Vendor-listed data residency options as of 2026-07-29: EU.
What is your EU AI Act role when you build on Synthesia?
Synthesia positions itself as provider and the customer as deployer; avatar videos are squarely Article 50 territory — deployers must disclose AI-generated/deepfake content. Synthesia states its components, used per its AUP, are not high-risk systems under the EU AI Act.