Data processing agreement
Data-processing terms for customers that submit personal data to PixMender while acting as a controller or processor.
Effective · Last updated
Application and roles
These data-processing terms apply when a customer uses PixMender to process personal data and applicable law requires controller-to-processor terms. They supplement the Terms of Use. The customer is the controller or processor that determines the permitted instructions; PixMender is the processor or subprocessor for submitted images, prompts and related job data.
Processing details
The subject matter is automated image cleanup, restoration, enhancement, storage, delivery and related support. Processing lasts for the account or applicable order, subject to the file-retention period and legally required records. Data subjects may include the customer, its users and people depicted in or connected with submitted material. Data may include images, identifiers, instructions, technical metadata and any personal data the customer chooses to include.
Documented instructions
PixMender will process customer personal data only to provide and secure the service, follow the customer's documented use of product controls and comply with law. If an instruction appears to violate applicable data-protection law, PixMender may notify the customer and pause the affected processing unless law prohibits notice.
Customer obligations
The customer is responsible for a lawful basis, required notices and consents, data accuracy, permitted instructions and responding to data subjects. The customer must avoid submitting unnecessary sensitive data, configure credentials and webhooks securely, and ensure its use complies with the Terms and Acceptable Use Policy.
Confidentiality and security
PixMender restricts access to personnel and service providers who need it for their function and who are bound by confidentiality duties. Measures include encrypted transport, private object storage, short-lived signed links, credential hashing, scoped access, upload validation, logging and scheduled file deletion. Security is maintained according to risk, available technology and the nature of processing.
Subprocessors
The customer authorizes PixMender to use subprocessors for hosting, content delivery, authentication, transactional email, payment verification and requested AI processing. Relevant functions currently include Cloudflare, Google, Resend, TronGrid and configured inference infrastructure. PixMender remains responsible for imposing data-protection obligations appropriate to each subprocessor's role. Reasonable advance notice of an intended addition or replacement will be provided through the service or account email, and the customer may object on reasonable data-protection grounds before the change takes effect.
International transfers
Where customer personal data is transferred from the EEA to a country without an adequacy decision, the parties will use an applicable lawful transfer mechanism, such as approved standard contractual clauses, together with supplementary measures where appropriate. The customer authorizes transfers necessary for its selected processing functions subject to those safeguards.
Requests and compliance assistance
Taking into account the nature of processing, PixMender will provide reasonable assistance with data-subject requests, security assessments, breach obligations and consultations required by applicable law. If a request concerns data controlled by the customer, PixMender will direct the requester to the customer where appropriate and will not independently answer on the customer's behalf unless required by law.
Personal-data incidents
PixMender will notify the customer without undue delay after confirming a personal-data breach affecting customer personal data and will provide available information reasonably needed for the customer's legal assessment. Notification is not an admission of fault or liability. The customer remains responsible for notices to authorities and data subjects unless law assigns that duty to PixMender.
Deletion and return
Submitted image files, intermediate files and results receive a 24-hour expiry time, after which automated cleanup retries until deletion succeeds. At the customer's choice, on account closure or the end of processing PixMender will delete or return remaining customer personal data and delete existing copies, except for records that applicable law requires PixMender to retain. Protected backups are isolated from ordinary use and age out under their normal retention cycle.
Information and audits
PixMender will make information reasonably necessary to demonstrate compliance with these terms available to the customer. Audits should first use current documentation and written responses; any additional inspection must be legally required, proportionate, confidential, scheduled in advance and designed to avoid exposing another customer's data or compromising service security.
Order of terms and contact
If these data-processing terms conflict with the Terms of Use on processing customer personal data, these terms control for that subject. The rest of the Terms, including liability provisions, continues to apply. Customers that require signed terms, transfer clauses or a current subprocessor description should contact [email protected] before submitting regulated or high-risk data.