Data Processing Addendum

Last updatedJune 26, 2026

Draft for legal review. This Data Processing Addendum is a starting template. Have qualified counsel review and adapt it (including the SCC modules, governing law, and liability terms) before offering it to customers. It is not legal advice.

1. Introduction and Scope

This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer," "Controller") and ICVR LLC, operator of Craftology ("Craftology," "Processor"), governing the processing of personal data by Craftology on the Customer's behalf in connection with the Craftology service (the "Agreement"). Where there is a conflict between this DPA and the Agreement on data protection, this DPA controls.

2. Definitions

Terms such as "personal data," "processing," "controller," "processor," "data subject," and "supervisory authority" have the meanings given in the EU General Data Protection Regulation (GDPR) and, where applicable, the UK GDPR and other applicable data protection laws.

3. Roles of the Parties

The Customer is the Controller (or a processor acting on behalf of a third-party controller) and Craftology is the Processor. Craftology processes personal data only on documented instructions from the Customer, including those set out in the Agreement and this DPA.

4. Processing Details

  • Subject matter: Provision of the Craftology AI creative-production platform.
  • Duration: For the term of the Agreement plus any retention period set out herein.
  • Nature and purpose: Hosting, storage, processing, and AI-assisted generation of content as directed by the Customer.
  • Types of personal data: Account data (name, email), user-generated content, usage data, and any personal data the Customer chooses to submit.
  • Categories of data subjects: The Customer's users, employees, collaborators, and individuals depicted in submitted content.

5. Obligations of Craftology (Processor)

Craftology will:

  • Process personal data only on the Customer's documented instructions;
  • Ensure persons authorized to process personal data are bound by confidentiality;
  • Implement appropriate technical and organizational security measures (Section 7);
  • Respect the conditions for engaging subprocessors (Section 6);
  • Assist the Customer, insofar as possible, in responding to data-subject requests;
  • Assist the Customer with security, breach notification, data protection impact assessments, and prior consultations;
  • At the Customer's choice, delete or return personal data at the end of the services (Section 9);
  • Make available information necessary to demonstrate compliance and allow for audits (Section 10).

6. Subprocessors

The Customer provides general authorization for Craftology to engage subprocessors listed at craftology.io/subprocessors. Craftology will impose data-protection obligations on each subprocessor that are no less protective than this DPA, and remains liable for their performance. Craftology will give notice of intended changes to subprocessors and allow the Customer a reasonable period to object on legitimate data-protection grounds.

7. Security Measures

Craftology maintains technical and organizational measures appropriate to the risk, including encryption of data in transit and at rest, access controls and least-privilege, logging and monitoring, secure software development, vulnerability management, and personnel confidentiality and training. A current summary is described in our Trust Center.

8. Personal Data Breach

Craftology will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, and will provide information reasonably necessary to enable the Customer to meet its breach-notification obligations.

9. Return and Deletion

Upon termination or expiry of the Agreement, Craftology will, at the Customer's choice, delete or return all personal data and delete existing copies, except to the extent retention is required by applicable law.

10. Audits

Craftology will make available to the Customer information necessary to demonstrate compliance with this DPA and will contribute to audits, including by providing relevant third-party certifications or reports (such as SOC 2, once available) in satisfaction of audit requests where appropriate.

11. International Transfers

To the extent Craftology processes personal data subject to the GDPR or UK GDPR in a country without an adequacy decision, the parties agree that the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum) are incorporated by reference and apply, with Craftology acting as data importer.

12. Liability and Governing Law

The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA is governed by the law specified in the Agreement, except where applicable data protection law requires otherwise.

13. Contact

To execute this DPA or for any data-protection questions, contact privacy@craftology.io.