Data Processing Agreement
Last updated: 31 August 2026
This Data Processing Agreement ("DPA") is entered into between the platform client (the "Controller") and Tjarks and Tjarks Design LLC, a limited liability company organized under the laws of the State of Illinois (File No. 05330912), with its principal place of business at 111 West Jackson Blvd, Chicago, IL 60604 (the "Processor"). It forms part of the Terms of Service and sets out the terms required by Article 28 of the EU GDPR and the UK GDPR in respect of personal data processed by the Processor on the Controller's behalf through the PIXEL platform and the PhotoPod™ production service. Terms defined in the Terms of Service have the same meaning here.
1. Roles and scope
In relation to Client Personal Data the Controller is the controller and the Processor is the processor. The Controller warrants that it has a lawful basis for the processing it instructs, that it has provided all required information to data subjects, and that its instructions comply with data protection law. Each party shall comply with its own obligations under Regulation (EU) 2016/679 ("EU GDPR"), the UK GDPR and the Data Protection Act 2018, and any other applicable data protection or privacy law, including applicable US state privacy laws (together, "Data Protection Laws").
2. Subject matter, duration, nature and purpose
Subject matter: the provision of AI-driven product photography services, comprising brief intake, capture management, image generation and editing, range production, print finalization and delivery.
Duration: from the commencement of the Terms of Service until the later of termination of the Terms and the completion of deletion or return under clause 10.
Nature and purpose: collection, recording, organization, storage, adaptation, retrieval, transmission to authorized subprocessors for AI inference, use, transfer, restriction, erasure and destruction of personal data, in each case solely to provide the services and to comply with law.
3. Categories of data and data subjects
Categories of personal data: identification and business contact data (name, business email address, telephone number, job role, employer); account credentials and authentication metadata; project content including briefs, comments, approvals and audit-trail records attributed to named users; product imagery and captures supplied by the Controller, which may incidentally contain images of individuals such as hands or reflections; billing contact data; and technical data such as IP address, device and browser information and access logs.
Categories of data subjects: the Controller's employees, contractors and agency personnel who are authorized users of the platform; the Controller's commercial and billing contacts; and any individuals incidentally depicted in or identifiable from Controller-supplied imagery.
Special category data: none is required or requested. The Controller shall not submit special category or criminal-offence data to the platform, and the Processor's security measures are not designed for it.
4. Documented instructions
The Processor shall process Client Personal Data only on the documented instructions of the Controller. The Terms of Service, this DPA, the applicable Order and the Controller's configuration of and use of the platform (including uploads, approvals and deletion requests) constitute the Controller's complete documented instructions. The Processor shall not process Client Personal Data for its own purposes, and shall not sell it or use it to train foundation models. Where the Processor is required by law to process Client Personal Data otherwise than on instruction, it shall inform the Controller before processing unless legally prohibited. If the Processor considers an instruction to infringe Data Protection Laws it shall inform the Controller without undue delay and may suspend the affected processing.
6. Security measures (Annex summary)
Having regard to Article 32 UK GDPR, the Processor implements and maintains the following technical and organizational measures:
- encryption of personal data in transit using TLS, and encryption at rest for databases, object storage and backups;
- role-based access control on a least-privilege basis, with individual named accounts and multi-factor authentication for administrative and production access;
- row-level security enforced in the database so that each client's records are logically isolated and accessible only to authorized identities;
- audit logging of authentication events, administrative actions and significant production actions, including the prompt, references, model and cost recorded against generated imagery;
- segregation of development, staging and production environments, with no use of production personal data in development;
- managed secret storage, with credentials never held in source code, and key rotation on personnel change;
- encrypted automated backups with defined retention and periodic restoration testing, and documented recovery objectives;
- vulnerability and dependency monitoring with timely patching, and security review of changes before release;
- hardened, hosted infrastructure operated by providers certified to recognized standards such as ISO/IEC 27001 or SOC 2;
- documented internal procedures for the detection, escalation, investigation and reporting of personal data breaches;
- secure deletion procedures for the removal of personal data on expiry of retention periods or on instruction.
The Processor may update these measures from time to time provided that the level of protection is not reduced. A current description is available on request.
7. Subprocessors
The Controller grants the Processor general written authorization to engage subprocessors for the provision of the services. The Processor maintains a list of the subprocessors engaged, identifying each by name and category, which is available to the Controller on request to orchestrator@shootpixel.ai. The current categories are: cloud hosting and application platform; object storage and content delivery; AI model and inference providers; database, logging and error-monitoring services; backup services; email delivery; and payment and accounting services.
The Processor shall give the Controller at least thirty (30) days' notice before adding or replacing a subprocessor that processes Client Personal Data. The Controller may object on reasonable data protection grounds within that period, in which case the parties shall discuss the objection in good faith; if it cannot be resolved, the Controller may terminate the affected part of the services without penalty, save that fees for services already provided remain payable. The Processor shall impose on each subprocessor data protection obligations no less protective than those in this DPA and remains fully liable to the Controller for the performance of each subprocessor's obligations.
8. International transfers
The Processor is established in the United States, so processing under this DPA involves the transfer of Client Personal Data out of the EEA and the United Kingdom. Such transfers are made only where an appropriate safeguard under Article 46 EU GDPR / UK GDPR is in place. The parties agree that the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference and apply to transfers of EEA personal data, and that the UK International Data Transfer Addendum (or the UK IDTA) applies to transfers of UK personal data, in each case supported by a transfer risk assessment and appropriate supplementary measures. Onward transfers to subprocessors are made on equivalent terms; the Controller authorizes the Processor to enter into such transfer mechanisms with subprocessors on the Controller's behalf where necessary, and copies shall be made available to the Controller on request.
9. Assistance: data subject requests, Articles 32 to 36
The Processor shall notify the Controller without undue delay if it receives a request from a data subject relating to Client Personal Data, and shall not respond to that request itself except to confirm that it acts as a processor and to refer the data subject to the Controller. Taking into account the nature of the processing, the Processor shall provide reasonable assistance, by appropriate technical and organizational measures and insofar as possible, to enable the Controller to respond to requests for access, rectification, erasure, restriction, portability and objection.
The Processor shall also provide the Controller with reasonable assistance in ensuring compliance with the Controller's obligations under Articles 32 to 36 EU GDPR / UK GDPR, including security of processing, breach notification to the competent supervisory authority (the ICO in the United Kingdom) and to data subjects, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to the Processor. The Processor may charge its reasonable costs for assistance that goes materially beyond the standard functionality of the platform.
10. Personal data breach notification
The Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a personal data breach affecting Client Personal Data. The notification shall describe, to the extent then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it and mitigate its effects, and a contact point for further information. The Processor shall provide further information as the investigation progresses and shall co-operate with the Controller in its own notification obligations. The Processor shall not make any public statement identifying the Controller in connection with a breach without the Controller's prior written consent, unless required by law.
11. Deletion or return on termination
On termination or expiry of the services, and at the Controller's election, the Processor shall return Client Personal Data in a commonly used machine-readable format or delete it, together with existing copies, within thirty (30) days of the Controller's written instruction. Absent instruction, the Processor shall delete Client Personal Data within twelve (12) months of termination. Deletion from routine encrypted backups occurs on the ordinary backup expiry cycle, normally within thirty-five (35) days of deletion from live systems, during which time the data remains protected by the measures in clause 6. The Processor may retain Client Personal Data to the extent and for so long as required by law, in which case it shall continue to protect it and shall process it only for the purpose of that legal requirement.
12. Audits and information
The Processor shall make available to the Controller, on reasonable written request and no more than once in any twelve-month period (unless a personal data breach or a regulator's requirement makes a further request necessary), the information reasonably necessary to demonstrate compliance with this DPA, including its security-measures description and any third-party certifications or audit reports held by it or by its infrastructure providers. Where such information is insufficient, the Controller may conduct an audit, on at least thirty (30) days' notice, during business hours, subject to confidentiality undertakings, without unreasonable disruption to the Processor's operations, and without access to other customers' data. The Controller shall bear the costs of any on-site audit unless it reveals material non-compliance.
13. Liability
The liability of each party under or in connection with this DPA is subject to the exclusions and limitations set out in the Terms of Service, which apply as if set out in full here, save that nothing in this DPA limits any liability which cannot lawfully be limited or any liability of either party directly to a data subject or a supervisory authority under Data Protection Laws.
14. General and governing law
In the event of conflict between this DPA and the Terms of Service, this DPA prevails in respect of the processing of personal data. This DPA takes effect on acceptance of the Terms of Service and requires no separate signature, though the Processor will execute a counterpart on request. This DPA, and any dispute or claim arising out of or in connection with it, is governed by the laws of the State of Illinois, United States, in line with the governing law of the Terms of Service, and the state and federal courts located in Cook County, Illinois shall have exclusive jurisdiction — except that, where the EU GDPR, the UK GDPR or the incorporated Standard Contractual Clauses mandate the law or the forum of an EU member state or of the United Kingdom, that mandated law and forum take precedence over this clause for the matters concerned.
Data protection contact for both parties' notices under this DPA: orchestrator@shootpixel.ai.
PIXEL™ and PhotoPod™ are trademarks of Tjarks and Tjarks Design LLC. All rights reserved. © 2026 Tjarks and Tjarks Design LLC.