Data Processing Addendum

Last updated: July 1, 2026

Contents

This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Autorender Terms of Service or other written agreement (the "Agreement") between Autorender, Inc. ("Autorender," "Processor") and the customer agreeing to the Agreement ("Customer," "Controller"). It governs Autorender's processing of Personal Data on Customer's behalf in connection with the Service. Where the Customer distributes or accesses the Service through a marketplace (such as Shopify, WordPress, or WooCommerce), this DPA also governs personal data of the Customer's own end customers processed through that integration.

In the event of a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls.

1. Definitions

  • "Applicable Data Protection Laws" means all data protection and privacy laws applicable to the processing of Personal Data under the Agreement, including, as applicable, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, and India's Digital Personal Data Protection Act, 2023 ("DPDP").
  • "Controller," "Processor," "Data Subject," "Personal Data," "Processing," and "Personal Data Breach" have the meanings given in the GDPR; "Business," "Service Provider," "Sell," "Share," and "Consumer" have the meanings given in the CCPA. For clarity, Customer is the Controller/Business and Autorender is the Processor/Service Provider.
  • "Customer Personal Data" means Personal Data contained in Customer Content or otherwise processed by Autorender on Customer's behalf under the Agreement.
  • "Sub-processor" means any third party engaged by Autorender to process Customer Personal Data.
  • "Standard Contractual Clauses" ("SCCs") means the clauses approved by the European Commission (Decision 2021/914) and, for the UK, the UK Addendum issued by the ICO.

2. Roles and scope of processing

2.1 Roles. Customer is the Controller (or a processor acting on behalf of a third-party controller) and Autorender is the Processor. Where CCPA applies, Autorender is a Service Provider processing Customer Personal Data on Customer's behalf.

2.2 Customer instructions. Autorender will process Customer Personal Data only (a) to provide, secure, and support the Service; (b) in accordance with Customer's documented lawful instructions (including through configuration and use of the Service); and (c) as required by applicable law, in which case Autorender will, where legally permitted, inform Customer first. Autorender will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Laws.

2.3 Customer responsibilities. Customer is responsible for the accuracy and lawfulness of Customer Personal Data and for having an appropriate legal basis and any required notices or consents for Autorender to process it as contemplated.

2.4 Details of processing. The subject matter, duration, nature and purpose of processing, types of Personal Data, and categories of Data Subjects are set out in Annex I.

3. Autorender obligations

3.1 Confidentiality. Autorender ensures that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and process it only as needed to perform their duties.

3.2 Security. Autorender implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data, as described in Annex II, taking into account the state of the art, the costs of implementation, and the risks to Data Subjects.

3.3 Data-subject requests. Taking into account the nature of the processing, Autorender will provide reasonable assistance (including appropriate technical and organizational measures) to help Customer respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws. If Autorender receives such a request directly, it will, where legally permitted, refer the Data Subject to Customer.

3.4 Assistance. Autorender will provide reasonable assistance to Customer with data protection impact assessments, prior consultations with supervisory authorities, and security-and-breach obligations, taking into account the information available to Autorender.

3.5 Personal Data Breach. Autorender will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to help Customer meet its notification obligations.

4. Sub-processors

4.1 General authorization. Customer provides general authorization for Autorender to engage Sub-processors to process Customer Personal Data. Autorender's current Sub-processors are listed at its Sub-processors page, which is incorporated by reference (see Annex III).

4.2 Notice and objection. Autorender will give Customer reasonable prior notice — at least fourteen (14) days where practicable — of any intended addition or replacement of a Sub-processor (by updating the Sub-processors page and/or notifying Customer). Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, Customer may terminate the affected portion of the Service.

4.3 Flow-down and liability. Autorender imposes data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains liable for the acts and omissions of its Sub-processors as if performed by Autorender.

5. CCPA service-provider terms

Where Autorender processes Customer Personal Data that is subject to the CCPA as a Service Provider, Autorender will not: (a) sell or share such Personal Data; (b) retain, use, or disclose it for any purpose other than the business purposes specified in the Agreement, or as otherwise permitted by the CCPA; (c) retain, use, or disclose it outside the direct business relationship between the parties; or (d) combine it with Personal Data received from other sources, except as permitted by the CCPA. Autorender certifies that it understands and will comply with these restrictions.

6. International data transfers

6.1 Autorender processes Customer Personal Data primarily in the United States. Where Autorender processes Personal Data subject to GDPR or UK GDPR and transfers it from the EEA, UK, or Switzerland to a country not deemed adequate, the SCCs (with the UK Addendum where applicable) are incorporated by reference and apply to that transfer, with Customer as data exporter and Autorender as data importer. Module Two (Controller-to-Processor) applies; where Customer is itself a processor, Module Three applies.

6.2 The parties agree that the details required by the SCCs are supplied by Annexes I–III of this DPA, and Autorender will provide the technical and organizational measures set out in Annex II.

7. Deletion or return

Upon termination or expiry of the Agreement, and at Customer's choice, Autorender will delete or return Customer Personal Data, and delete existing copies, within the timeframes described in the Agreement's retention terms (Customer Content and associated Personal Data deleted within thirty (30) days; routine backups purged within a further ninety (90) days), except to the extent applicable law requires continued storage.

8. Audits

Autorender will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written request and subject to confidentiality, will allow for and contribute to audits conducted by Customer or an independent auditor, no more than once per year absent a specific regulatory requirement or a Personal Data Breach.

9. Liability

Each party's liability under this DPA is subject to the exclusions and limitations of liability set out in the Agreement.

10. General

This DPA takes effect on the effective date of the Agreement and remains in force while Autorender processes Customer Personal Data. If any provision is invalid, the remainder remains in effect. This DPA is governed by the law and dispute-resolution terms of the Agreement, except as required by Applicable Data Protection Laws or the SCCs.

Annex I — Details of processing

  • Roles: Customer = Controller/Business; Autorender = Processor/Service Provider.
  • Subject matter: Autorender's provision of the media transformation, optimization, and delivery Service.
  • Duration: For the term of the Agreement, plus the deletion periods in §7.
  • Nature and purpose: Hosting, storing, transmitting, transforming, optimizing, analyzing, and delivering Customer Content and related media, including AI-assisted operations the Customer invokes, and providing associated account, workspace, analytics, and support functions.
  • Types of Personal Data: Account and contact data (names, usernames, email addresses); authentication identifiers; usage and log data (including IP address and user-agent); Personal Data contained within Customer Content (e.g., images or video depicting or identifying individuals, and derived metadata); and, for marketplace integrations, limited end-customer data made available by the marketplace (e.g., for Shopify, Protected Customer Data).
  • Categories of Data Subjects: Customer's authorized users and personnel; and individuals whose Personal Data appears in Customer Content or is made available through a marketplace integration (e.g., the Customer's own end customers).
  • Special categories: Not intended; Customer should not submit special-category data except as expressly agreed.

Annex II — Technical and organizational measures

Autorender maintains measures including: encryption in transit (TLS) and application-level encryption at rest for sensitive stored credentials (AES-256-GCM); Argon2id password hashing; hashed API keys and access tokens; role- and workspace-scoped access controls with limited staff access to production data; network and application security controls (including a web application firewall and rate limiting); logical separation of customer data in a multi-tenant environment; monitoring, logging, and error tracking; and an incident-response process for security events. These measures may be updated as the Service evolves, provided the level of protection is not materially decreased.

Annex III — Sub-processors

Autorender's current Sub-processors are listed on its Sub-processors page, incorporated here by reference, and updated in accordance with §4.