Legal
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Terms of Service and the services agreement between Aeuix LLC (“Aeuix”, the “processor”) and each client company (the “Client”, the “controller”) for whom Aeuix processes personal data through aeuix one. It applies automatically; no signature is needed. If your company needs a signed copy or specific wording, email will@aeuix.com.
1. Definitions
“Personal data”, “processing”, “controller”, “processor”, “data subject” and “supervisory authority” have the meanings given in applicable data protection law, including the GDPR, the UK GDPR, and US state privacy laws such as the CCPA/CPRA (where “business”, “service provider” and “consumer” correspond).
2. Roles and scope
The Client is the controller of personal data about its employees, contractors, customers and other people that it or Aeuix adds to the portal on the Client’s behalf (“Client Data”). Aeuix is the processor of Client Data and processes it only to provide the Service. Aeuix is an independent controller for its own team members’ accounts, billing records and the security logs it keeps for the Service, and the creative work it produces and may keep as its own body of work (see Section 4).
3. Details of processing
| Subject matter | Providing the aeuix one portal: project management, calendars, file storage, photo libraries, notes, notifications and billing. |
|---|---|
| Duration | The term of the services agreement plus the retention periods in the Privacy Policy. |
| Nature and purpose | Storage, display, transmission, search indexing, preview generation, face grouping in photo shoots, notification delivery, activity logging and backup. |
| Types of personal data | Names, email addresses, job titles, phone numbers, addresses, profile photos, messages, notes, files and their contents, photographs and, where the Client uses face grouping, face templates derived from photographs (biometric data). |
| Data subjects | The Client’s staff and contractors, people who appear in the Client’s photographs, and people referenced in the Client’s content. |
4. Aeuix’s obligations
- Process Client Data only on the Client’s documented instructions, which are the Terms, this DPA and the Client’s use of the Service, unless the law requires otherwise (in which case Aeuix will tell the Client first where allowed).
- Not sell Client Data, share it for advertising, combine it with data from other clients, or use it for any purpose other than providing the Service.
- Ensure everyone with access is bound by confidentiality.
- Maintain the technical and organisational measures described on the Security page, including encryption in transit and at rest, row-level access control, logging, backups and incident response.
- Help the Client respond to data-subject requests (access, correction, deletion, portability, objection) within the legal deadlines; many can be completed directly in the portal.
- Help the Client with data protection impact assessments and consultations with supervisory authorities where the processing requires it, taking into account the information available to Aeuix.
- Notify the Client without undue delay, and within 72 hours of confirming, of any personal data breach affecting Client Data, with the information the Client needs to meet its own obligations.
- Delete or return all Client Data at the end of the services agreement, at the Client’s choice, and delete remaining copies within 30 days after the hand-over period, unless the law requires retention. Backups are overwritten within seven days. This does not apply to the creative work Aeuix produced for the Client (photographs, video, designs and other deliverables), which Aeuix and the Client own jointly under the Terms of Service and which Aeuix may keep, at its discretion, as an independent controller of its own business records; personal details of the Client’s staff (profiles, contact details, personal notes, face templates) are deleted regardless.
- Make available the information needed to demonstrate compliance, and allow audits by the Client or an independent auditor it appoints, at reasonable intervals and on reasonable notice, at the Client’s cost. Provider compliance reports (SOC 2) satisfy this where they cover the relevant systems.
5. Subprocessors
The Client gives general authorisation for the subprocessors listed at aeuix.com/subprocessors. Aeuix will give at least 30 days’ notice of additions on that page and by email to clients who request it. The Client may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Client may terminate the affected part of the Service without penalty. Aeuix remains responsible for its subprocessors’ performance.
6. International transfers
Aeuix and its subprocessors process data in the United States. For Client Data from the EEA, UK or Switzerland, the parties rely on the European Commission’s Standard Contractual Clauses (Module 2, controller to processor) and the UK Addendum, which are incorporated by reference, together with the subprocessors’ own transfer safeguards. Aeuix will provide completed copies on request.
7. Biometric data
Face grouping is an optional feature. The Client instructs Aeuix to generate and store face templates only for shoots the Client has asked Aeuix to process, confirms it has provided the notices and obtained the consents required by applicable law (including Illinois BIPA, Texas CUBI and Washington’s biometric law) from the people photographed, and may withdraw that instruction for any shoot or person at any time. Aeuix will destroy face templates as the Face Data Notice describes.
8. US state privacy laws
Where the CCPA/CPRA or a similar law applies, Aeuix is a service provider or processor. Aeuix certifies that it understands and will comply with the restrictions in Section 4, will notify the Client if it can no longer meet its obligations, and grants the Client the right to take reasonable steps to stop and remediate unauthorised use.
9. Liability and precedence
The limitation of liability in the Terms of Service applies to this DPA. If this DPA conflicts with the Terms or the services agreement, this DPA prevails for data protection matters. Where a Client requires additional or different terms by law, the parties will agree them in writing.
10. Contact
Data protection questions: will@aeuix.com, Aeuix LLC, Scottsdale, Arizona.