Skip to main content
← All policies

Data Processing Addendum

Draft prepared 2026-07-30 — pending legal review
This document is a draft prepared from the product’s actual behaviour and is pending review by counsel. It is published for transparency and is not yet the operative agreement. If you need executed terms before that review completes, contact us. [email protected]

For customers who need controller/processor terms — GDPR, UK GDPR, or a similar regime. This addendum forms part of the Terms of Service where it applies. To have it executed as a signed document, email [email protected].

1.Roles

For personal data contained in customer content, you are the controller and Studio 17 LLC is the processor. We process that data only on your instructions — which, in practice, means the jobs you run.

For the limited personal data we process to run our own business — account records, billing, security logs, aggregate product analytics — we are the controller, and the Privacy Policy governs it.

2.Subject matter and details of processing

ElementDetail
Subject matterProvision of Accentor — planning, generating, checking and storing the work you request.
DurationFor the term of your subscription, plus the retention windows in the Privacy Policy.
Nature and purposeStorage, transmission, and automated processing by AI models and deterministic software to produce the outputs you request.
Types of personal dataWhatever you include in briefs, uploads and brand assets; plus account identifiers of your workspace members.
Categories of data subjectsYour workspace members, and any individuals appearing in content you submit.
Special categoriesNot expected. Do not submit special-category or health data without first agreeing terms that cover it.

3.Our obligations

  • Process personal data only on your documented instructions, and tell you if we believe an instruction breaches applicable data protection law.
  • Keep the technical and organisational measures described at Security, and not materially weaken them during the term.
  • Bind personnel with access to confidentiality obligations, and limit access to those who need it.
  • Not train AI models on your content, and not use it for any purpose other than providing the service.
  • Assist you — so far as we reasonably can, given the information available to us — with data protection impact assessments and with consultations with a supervisory authority.

4.Subprocessors

You give general authorisation for us to engage subprocessors. The current list, with the role of each, is published and kept current at Subprocessors.

  • Each subprocessor is bound by data protection obligations no less protective than those in this addendum.
  • We remain responsible to you for a subprocessor’s performance.
  • We will give you notice before a new subprocessor begins processing your data. Ask to be added to the subprocessor notice list at [email protected].
  • You may object on reasonable data-protection grounds. If we cannot offer a workable alternative, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees for it.
If you route model work through your own provider agreements — an Enterprise option — those providers are your subprocessors, not ours, and this clause does not cover them.

5.Data subject rights

The product gives you direct control: you can access, export, correct and delete content in your workspace, which is how most requests are satisfied without involving us. Where you need more, we will assist you in responding to a data subject request, and we will not respond directly to a data subject about your content except to direct them to you.

6.Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the nature of the breach, the categories and approximate volume of data involved, the likely consequences, and the measures taken or proposed. We will provide further information as the investigation develops.

7.Return and deletion

On termination you may export your content for 90 days, after which we delete it. On written request we will delete it sooner, except where we are required by law to retain a copy — in which case we will tell you what we must keep and for how long.

8.Audits and information

We will make available the information reasonably necessary to demonstrate compliance with this addendum, and respond to a reasonable security questionnaire once in any twelve-month period.

Be aware, in assessing us: we hold no third-party security certification or audit report — no SOC 2, ISO 27001 or equivalent. We cannot substitute an attestation for an audit, so we answer questionnaires directly. See Security.

9.International transfers

Our infrastructure is hosted in the United States by default, and several model providers operate outside the EEA and the UK — so using Accentor involves transferring personal data internationally. EU or APAC data residency is available on Enterprise.

The transfer mechanism — Standard Contractual Clauses, the UK Addendum, and the accompanying transfer impact assessment — will be attached to the executed version of this addendum and confirmed on legal review. If you require SCCs in place before you begin processing, contact [email protected] and we will execute them with you rather than have you rely on this page.

10.Precedence

Order of precedence

Where this addendum conflicts with the Terms of Service on the processing of personal data, this addendum prevails. A signed order form or a negotiated agreement prevails over both.


Questions about this document? [email protected]