Legal

Data Processing Addendum

Last updated:

This is a template for review by legal counsel before launch — not legal advice.

This Data Processing Addendum ("DPA") forms part of the agreement between NoShot ("Processor") and the customer ("Controller") for use of the Service. It applies where NoShot processes personal data on the Controller's behalf and reflects the requirements of the GDPR and similar laws.

Roles of the parties

The Controller determines the purposes and means of processing the personal data it submits to the Service. NoShot acts as Processor and processes that personal data only on the Controller's documented instructions, including as set out in the agreement and this DPA.

Details of the processing

  • Subject matter — provision of AI on-model image generation.
  • Duration — the term of the agreement, plus the deletion period below.
  • Nature and purpose — hosting, processing, and generating imagery from the Controller's Input.
  • Types of personal data — account contact details and any personal data contained in Input the Controller chooses to upload (for example, images that include identifiable people).
  • Categories of data subjects — the Controller's staff and any individuals depicted in the Controller's Input.

Controller instructions

NoShot will process personal data only on the Controller's instructions and will tell the Controller if, in its opinion, an instruction breaches data protection law — unless it is prohibited from doing so.

Confidentiality

NoShot ensures that personnel authorised to process personal data are bound by confidentiality and are trained on their obligations.

Security measures

NoShot implements appropriate technical and organisational measures — including encryption in transit and at rest, access controls, network protection, logging, and regular testing — to protect personal data against accidental or unlawful loss, access, or disclosure.

Subprocessors

The Controller authorises NoShot to engage subprocessors — such as cloud hosting, image processing, payment, analytics, and email vendors — to support the Service. NoShot imposes data protection terms on each subprocessor no less protective than this DPA, remains responsible for their performance, and will give notice of intended changes so the Controller can object.

Data subject requests

Taking into account the nature of the processing, NoShot will assist the Controller with appropriate measures to respond to requests from data subjects exercising their rights, and will promptly forward any such request it receives directly.

Personal data breach

NoShot will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide the information reasonably required to help the Controller meet its own notification obligations.

International transfers

Where personal data is transferred across borders, the parties rely on an approved transfer mechanism such as the Standard Contractual Clauses, which are incorporated by reference where they apply.

Audits

NoShot will make available the information reasonably necessary to demonstrate compliance with this DPA and will allow for audits, including inspections, by the Controller or an auditor it mandates, on reasonable notice and subject to confidentiality.

Return and deletion of data

On termination, NoShot will — at the Controller's choice — delete or return the personal data it processes and delete existing copies within 90 days, unless the law requires it to retain them.

Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the agreement.

Contact us

To exercise any right under this DPA or to request our current subprocessor list, email hello@piktor.co.