Data Processing Addendum
Last updated:
This is a template for review by legal counsel before launch — not legal advice.
This Data Processing Addendum ("DPA") forms part of the agreement between Piktor ("Processor") and the customer ("Controller") for use of the Service. It applies where Piktor processes personal data on the Controller's behalf and reflects the requirements of the GDPR and similar laws.
Roles of the parties
The Controller determines the purposes and means of processing the personal data it submits to the Service. Piktor acts as Processor and processes that personal data only on the Controller's documented instructions, including as set out in the agreement and this DPA.
Details of the processing
- Subject matter — provision of AI on-model image generation.
- Duration — the term of the agreement, plus the deletion period below.
- Nature and purpose — hosting, processing, and generating imagery from the Controller's Input.
- Types of personal data — account contact details and any personal data contained in Input the Controller chooses to upload (for example, images that include identifiable people).
- Categories of data subjects — the Controller's staff and any individuals depicted in the Controller's Input.
Controller instructions
Piktor will process personal data only on the Controller's instructions and will tell the Controller if, in its opinion, an instruction breaches data protection law — unless it is prohibited from doing so.
Confidentiality
Piktor ensures that personnel authorised to process personal data are bound by confidentiality and are trained on their obligations.
Security measures
Piktor implements appropriate technical and organisational measures — including encryption in transit and at rest, access controls, network protection, logging, and regular testing — to protect personal data against accidental or unlawful loss, access, or disclosure.
Subprocessors
The Controller authorises Piktor to engage subprocessors — such as cloud hosting, image processing, payment, analytics, and email vendors — to support the Service. Piktor imposes data protection terms on each subprocessor no less protective than this DPA, remains responsible for their performance, and will give notice of intended changes so the Controller can object.
Data subject requests
Taking into account the nature of the processing, Piktor will assist the Controller with appropriate measures to respond to requests from data subjects exercising their rights, and will promptly forward any such request it receives directly.
Personal data breach
Piktor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide the information reasonably required to help the Controller meet its own notification obligations.
International transfers
Where personal data is transferred across borders, the parties rely on an approved transfer mechanism such as the Standard Contractual Clauses, which are incorporated by reference where they apply.
Audits
Piktor will make available the information reasonably necessary to demonstrate compliance with this DPA and will allow for audits, including inspections, by the Controller or an auditor it mandates, on reasonable notice and subject to confidentiality.
Return and deletion of data
On termination, Piktor will — at the Controller's choice — delete or return the personal data it processes and delete existing copies within 90 days, unless the law requires it to retain them.
Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the agreement.
Contact us
To exercise any right under this DPA or to request our current subprocessor list, email hello@piktor.co.
Questions about this document? Email hello@piktor.co.