1. Roles
1.1 You decide why and how the personal data in your content is processed; we process it for you, on your instructions. If you are yourself a processor for another business, we are your sub-processor and you confirm that your instructions are authorised.
1.2 Under India’s Digital Personal Data Protection Act 2023, you are the Data Fiduciary and we are the Data Processor, and this DPA is the contract required by its section 8(2).
1.3 For the personal data of the person who holds your account, and for our own business contacts with you, we are a separate controller; our privacy notice covers that. Clauses 9.1 and 9.2 say how that data is protected when it comes to us from the EU or the UK.
2. Definitions
The words used in the GDPR and the UK GDPR (“personal data”, “processing”, “controller”, “processor”, “sub-processor”, “personal data breach”, “supervisory authority”) have the same meaning here. “Your content” means the photos, backgrounds, vehicle details and instructions you send us, and the images we make from them (what section 1.6 of our terms of service calls your content and your images). “The standard contractual clauses” (or “the clauses”) are the European Commission’s standard contractual clauses for transfers of personal data to third countries (Commission Implementing Decision (EU) 2021/914 of 4 June 2021). “The UK Addendum” is the UK Information Commissioner’s International Data Transfer Addendum to them (version B1.0, in force 21 March 2022).
3. Your instructions (GDPR Art. 28(3)(a))
3.1 We process personal data only on your documented instructions. Your instructions are: our agreement; your orders; the settings you choose in the app; your API calls; and anything else you tell us in writing.
3.2 We tell you at once if we think an instruction breaks data protection law, and we may pause that processing until you confirm or change it.
3.3 If EU or Member State law (or UK law, for UK data) requires us to process your personal data in another way, we tell you first unless that law forbids it. Requests under other laws are handled under clause 9.4.
4. What we process (Annex 1)
Annex 1 describes the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of people.
5. Our people (Art. 28(3)(b))
Everyone at TunePixel who can open your content is bound to keep it confidential, and opens it only to do the work: checking images, fixing them, supporting you and keeping the service secure.
6. Security (Art. 28(3)(c) and Art. 32)
6.1 We keep in place the measures in Annex 2 and we review them at least once a year. We do not process your personal data until each measure Annex 2 marks with * is in place.
6.2 We may change the measures, but never so that they protect your data less.
7. Sub-processors (Art. 28(2) and (4))
7.1 You authorise the sub-processors in Annex 3A (by category) and Annex 3B (by name, confidential).
7.2 We give you at least 30 days’ notice by email before we add or replace a sub-processor, with its name, what it does and where. If a sub-processor adds or replaces one of its own sub-processors, we send you its notice the day we receive it. That notice may be shorter than 30 days (Annex 3B gives each period), and clause 7.3 applies.
7.3 You may object during that period on reasonable data protection grounds. We then talk, and if we cannot meet your objection, you may end the part of the service that would use the new sub-processor and we refund any fees paid in advance for it.
7.4 We bind every sub-processor by written contract to data protection obligations that are, in substance, the same as this DPA’s, including that it processes your personal data only on our instructions, to provide its part of the service. We remain responsible to you for its work. Annex 3B shows, for each sub-processor, where its terms differ in form (notice of its own sub-processors, breach-notice time, audits by report, liability), and any right they give it to keep de-identified or aggregated data for its own use.
7.5 If we have factually disappeared, ceased to exist in law or become insolvent, you may instruct the person named in Annex 3B to end our sub-processors’ processing of your data and to have it erased or returned.
8. Helping you with people’s rights (Art. 28(3)(e))
8.1 You can ask us at any time to delete a vehicle and everything made from it. Once our API is open to you, you can also do it there.
8.2 If someone asks us directly about your content, we pass the request to you no later than 5 working days after we receive it, and we do not answer it ourselves unless you ask us to.
8.3 We help you answer requests to see, correct, delete, restrict or move personal data, as far as we reasonably can.
9. International transfers (Chapter V GDPR; UK GDPR)
9.1 We are in India, which has no adequacy decision from the EU or the UK. Where the GDPR applies to the personal data you send us (for example, because you are established in the European Economic Area), the standard contractual clauses are part of this DPA. You are the data exporter and we are the data importer, and:
- Module 2 (controller to processor) applies to the personal data in your content;
- Module 3 (processor to processor) applies instead where you process that data for another business, which is its controller; you pass on to that business what the clauses ask you to pass on;
- Module 1 (controller to controller) applies to the personal data we receive as a separate controller (clause 1.3), such as the name and work email of the person who holds your account.
These are the choices the clauses leave to us:
- Clause 7 (docking clause): included. Each of your group companies that sends us personal data from the European Economic Area accedes to the clauses as a data exporter when your order lists it with its details for Annex 1.A and you accept for it.
- Clause 9(a), in Modules 2 and 3: option 2 (general written authorisation), with the notice periods in clause 7.2: 30 days; for a sub-processor’s own sub-processors, the notice it gives us, at least 15 days.
- Clause 11(a): the optional language is not included.
- Clause 13: the supervisory authority in Annex 1.C.
- Clause 17 (option 1) and Clause 18(b): the law and the courts of Ireland, unless your order names another EU Member State whose law allows third-party beneficiary rights.
- Annexes I, II and III of the clauses: this DPA’s Annex 1 (with Annex 5), Annex 2, and Annexes 3A and 3B.
9.2 Where the UK GDPR applies to the personal data you send us, the UK Addendum applies, with its Tables 1 to 4 completed in Annex 7. In it, the Information Commissioner takes the place of the supervisory authority, and the law and the courts of England and Wales apply. If you prefer, we sign the UK’s International Data Transfer Agreement (version A1.0) with you instead, completed from the same annexes. Where the Swiss Federal Act on Data Protection applies, the clauses apply with these changes: the Federal Data Protection and Information Commissioner is the competent supervisory authority for those transfers; references to the GDPR are read as references to that Act; and “Member State” is read so that people in Switzerland can bring claims where they habitually live.
9.3 We transfer your personal data onward only to the sub-processors you have authorised (Annexes 3A and 3B), only under a written contract that gives, in substance, the same protection as the clauses, and only where the transfer is covered by an adequacy decision (for example, for a United States organisation that has joined the EU-US Data Privacy Framework), by the clauses or by another safeguard the law accepts.
9.4 Annex 4 summarises our assessment of the laws and practices of India, and of the other countries where our sub-processors handle your data, that could affect these transfers (Clause 14 of the clauses). We give you the full assessment with Annex 3B, and we review it at least once a year and whenever something it relies on changes. If a public authority asks us for your content or your personal data, or we learn that one has reached it directly:
- we tell you at once, unless the law forbids it; if it does, we ask the authority to let us tell you, and we keep a record of each attempt;
- we ask the authority to go to you;
- we check that the request is lawful, and we challenge it, and appeal, where there are reasonable grounds to think it is not;
- we give only the minimum the request requires;
- once a year, and whenever you ask, we tell you how many requests we received and what they were for, as far as the law allows.
We have not built any back door or other means for an authority to reach your content, and we will tell you if a law ever requires one.
9.5 The standard contractual clauses (with the modules and choices in clause 9.1) and the UK Addendum (with Annex 7) are part of this DPA, in the text published by the European Commission and the UK Information Commissioner. We send you that text, completed, with this DPA. When you accept this DPA (by email, or by clicking where we offer that), they bind you and us, with their Annex 1.A, just as our signatures would.
10. Personal data breaches (Art. 28(3)(f) and Art. 33(2))
10.1 We tell you without undue delay, and in any case no later than 48 hours after becoming aware, of a personal data breach affecting your personal data.
10.2 We tell you what we know at the time: what happened, what kind of data and roughly how many people and records, the likely consequences, what we have done and will do, and who you can contact. We add to it as we learn more.
10.3 We help you notify regulators and people where you must. We notify no one about your data on your behalf unless you ask us to, or a law requires us to report the incident ourselves. (India’s CERT-In Directions require us to report certain cyber incidents to CERT-In no later than 6 hours after noticing them; if we do, we tell you.)
11. Assessments (Art. 28(3)(f))
We give you the information you reasonably need for a data protection impact assessment or a consultation with a regulator about our service.
12. Deleting and returning data (Art. 28(3)(g))
12.1 While our agreement runs, we keep your content only for the periods in Annex 5, unless you set other periods in writing (Annex 6). Deletion is real: files and database records, not a flag. Copies at sub-processors are deleted within the periods in Annex 5.
12.2 When our agreement ends, you choose: we delete your content at once, or we give you 30 days to download it and then delete it no later than 30 days after that. If you do not choose, you get the 30 days. Either way, we keep nothing unless EU or UK law, or another law that the standard contractual clauses allow, requires us to keep it. We confirm the deletion in writing if you ask. Our backups expire no later than 35 days after they are made.
12.3 We keep a record that a deletion happened, with counts but no photos and no vehicle names, for 2 years, so that we can show it was done.
13. Information and audits (Art. 28(3)(h))
13.1 We make available the information you need to check that we meet this DPA: this DPA, Annex 2, the sub-processor list, our transfer assessment (Annex 4), the relevant part of our record of processing, and a summary of our latest security review. We answer your reasonable requests for information about how we meet this DPA.
13.2 If that is not enough, or a regulator asks, or after a breach, you (or an independent auditor bound to confidentiality) may audit us, with 30 days’ notice, in working hours, remotely where possible, at your cost, and no more than once a year otherwise.
14. AI and your content
14.1 We don’t use your photos to train AI models without your written permission. Such a permission says what we may use, for what and for how long; for that use we become a separate controller, and we first remove or blur number plates and people. Each sub-processor processes your personal data only on our instructions, to provide its part of the service; Annex 3B shows any right its terms give it to keep de-identified or aggregated data for its own use (clause 7.4).
14.2 We do not use your content to develop, test or improve our studios or features without your written permission. Such a permission never covers code repositories or AI assistants. We may use service records that contain no personal data (for example which checks an image failed) to run and improve the service.
14.3 A person checks every image before it is delivered.
14.4 The information we write into delivered files says how the image was made and contains no personal data. We do not copy your photo’s metadata (including its location) into delivered images.
14.5 On request we remove number plates in AI studio images.
15. California (CCPA/CPRA)
Where the California Consumer Privacy Act applies to you, we are your service provider, and:
- we process personal information only for the business purposes in Annex 1 (making, checking, delivering and storing vehicle images, and supporting and securing that service);
- we do not sell or share it, and we do not retain, use or disclose it for any other purpose, or outside our direct business relationship with you, except as the CCPA allows;
- we do not combine it with personal information from other sources, except as the CCPA allows;
- we comply with the CCPA and give the same level of protection it requires, and we tell you if we can no longer do so;
- you may take reasonable steps to make sure we use it as the CCPA requires, and to stop and fix any unauthorised use;
- we help you answer consumers’ requests, through the deletion tools in clause 8.
16. Australia
Where the Australian Privacy Act 1988 applies to you, we handle personal information you disclose to us consistently with the Australian Privacy Principles, as if they applied to us, including APP 8 (overseas disclosure) and APP 11 (security). We tell you no later than 48 hours after we suspect an eligible data breach, and we help you assess and notify it. For your own privacy policy, Annex 3A lists the countries where we and our sub-processors handle your data.
17. India
For personal data of people in India, we take the reasonable security safeguards that the DPDP Act and its Rules require (Rule 6), help you meet your breach-intimation duties (Rule 7), and erase personal data when you instruct us (section 8(7)(b)). If Indian law requires us to keep personal data or logs of processing for longer than this DPA’s periods, we keep only what that law requires, for only as long as it requires, use it only for that purpose, and tell you that this applies.
18. Liability and order of documents
18.1 Each of us is liable under this DPA within the limits of our main agreement, except that nothing in our agreement limits either party’s liability under the standard contractual clauses, the UK Addendum or the UK’s International Data Transfer Agreement, towards each other or towards the people they protect, or any liability the law does not allow to be limited.
18.2 If documents conflict: the standard contractual clauses (and the UK Addendum) win; then this DPA; then the rest of our agreement.
19. Term and law
19.1 This DPA lasts as long as we process personal data for you.
19.2 It follows the law and disputes clause of our main agreement, except that the standard contractual clauses follow clause 9.1, and the UK Addendum follows the law of England and Wales.
Annexes
Annex 1: Details of the processing and the transfers (Annex I of the clauses)
Annex 1.A: The parties
| Party | Details |
|---|---|
| Data exporter | You: the business that accepts this DPA, with the legal name, address and contact person (name, position and email) that your order or your acceptance email gives, and your data protection officer or representative in the EU, if you have one. Also each group company that accedes under clause 9.1. Activities relevant to the transfers: selling or marketing vehicles, for which you send us photos and details of vehicles. Role: controller (Modules 1 and 2), or processor (Module 3). |
| Data importer | TunePixel, with the name and address in section 1.1 of our terms of service. Contact person: Venkatesh Gandham, Founder and CEO, privacy@tunepixelstudio.com. Activities relevant to the transfers: making, checking, delivering and storing studio images of vehicles, and running your account. Role: processor (Modules 2 and 3), and controller (Module 1). |
| Signature and date | your acceptance of this DPA, and our sending it to you, on the day you accept it (clause 9.5) |
Annex 1.B: Description of the processing and the transfers
| Item | Details |
|---|---|
| Categories of people | people visible in photos (customers, staff, passers-by, people reflected in paint or glass, and children who appear by chance: please leave people out of your photos); registered keepers or owners of vehicles, identifiable from number plates or VINs; your staff named in vehicle notes |
| Types of personal data | images of people; number plates; VINs and stock numbers typed as vehicle names; anything visible inside a vehicle (papers, screens); location and device metadata in uploaded photos, which we keep in the stored original, remove before a photo goes to the AI image-generation services that TunePixel AI runs on, and remove before it goes to our real-photo engine (except that, if that removal step fails, the engine receives the original), and which we never copy into a delivered image |
| Special categories | none intended; please do not send them. If a photo shows any by chance, it gets the same protection as the rest of your content, and we use it for nothing but your images. |
| Frequency | continuous, as you upload |
| Subject matter | making, checking, delivering and storing studio images of vehicles from your photos |
| Nature | receiving uploads; converting file formats; turning photos upright and removing their metadata before rendering (the types of personal data above say when that step can fail); cutting out the vehicle and rendering a studio (real-photo studio); generating a studio image with TunePixel AI (AI studio); making 360° spins, if you order them; human review; editing; packaging and delivery; storage; deletion |
| Purpose of the transfers and the further processing | to provide the service you ordered: making, checking, delivering and storing your images, and supporting and securing that service; nothing else (clause 14) |
| Duration | the term of our agreement, then deletion under clause 12 |
| Retention | Annex 5, or your periods in Annex 6 |
| Transfers to sub-processors | subject matter and nature: Annex 3A (by category) and Annex 3B (by name); duration: as long as each one’s part of the work takes, then the periods in Annex 5 |
| Personal data we receive as a separate controller (Module 1) | people: the person who holds your account, and your staff who write to us. Data: name, work email and role; when the account was created and last used; a security record of important actions; our emails with you. Purpose: running your account, securing the service and our relationship with you, as our privacy notice says. Frequency: when you ask us to set up an account, and whenever you write to us. Retention: the periods in our privacy notice. |
Annex 1.C: Competent supervisory authority (Clause 13 of the clauses)
- If you are established in the European Economic Area: the supervisory authority responsible for your compliance with the GDPR for these transfers (your lead supervisory authority, if you have one).
- If you are not established in the European Economic Area, but the GDPR applies to you under its Article 3(2) and you have appointed a representative under its Article 27(1): the supervisory authority of the Member State where your representative is established.
- If you are not established in the European Economic Area, the GDPR applies to you under its Article 3(2), and you do not need a representative (Article 27(2)): the supervisory authority of the Member State, among those where the people whose data is transferred are, that your order names.
- For personal data from the UK: the Information Commissioner (the UK Addendum does not use Annex I.C).
- For personal data from Switzerland: the Federal Data Protection and Information Commissioner.
Annex 2: Technical and organisational measures (Annex II of the clauses)
In place (checked on 6 October 2026):
- Access: our staff accounts and your account have separate roles; each account sees only its own vehicles (another account’s vehicle answers “not found”); deactivating an account ends its sessions and its API keys at once; an account on a temporary password can only change it, or sign out, until it does.
- Sign-in: passwords stored only as bcrypt hashes; sessions use a cookie that scripts cannot read, and end after a day without use; while the app is open, the page also holds the session token in memory; repeated failed sign-ins locked out by network address, by account and by browser.
- API: keys shown once, stored only as hashes, limited to the scopes given and revocable at once; each upload link works once and for one hour; webhooks signed with HMAC-SHA256, sent only to public HTTPS addresses and checked again at each delivery; webhook signing secrets stored encrypted.
- Uploads: checked by what the file contains, not by its name; at most 50 MB; HEIC and AVIF photos converted.
- Minimisation: a photo’s hidden data, including its location, is removed before the photo goes to the AI image-generation services that TunePixel AI runs on, and if it cannot be removed the photo is not sent; that data is never copied into a delivered image; the provenance information in delivered files contains no personal data.
- TunePixel AI’s image-generation services: every request tells the service we contract with not to store the request’s record (since 6 October 2026).
- Isolation: our rendering engine is never reachable from browsers; its access key stays on our server; results are copied off the engine as soon as they are made; our rendering engine deletes each photo and result once it is 48 hours old: it checks every hour while its server runs, and 15 minutes after each start.
- Retention and deletion: our server deletes data automatically once it passes the periods in Annex 5 (it checks once a day while it runs). It does not yet reach files left behind when a vehicle or photo was deleted with an older function of our app; we are deleting those files and extending the check to them. Deletion on request removes files first and then records. A deletion still unfinished after a day is flagged in our server’s log.
- Records: an append-only log of important actions, such as deleting a vehicle or creating an API key, with no photos in it, kept 2 years.
- People: our founder is the only person who works on your content, and he is bound to keep it confidential (clause 5).
- Assurance: on 29 September 2026 we reviewed our app’s source code for security flaws (injection, access between accounts, server-side request forgery, secrets, uploads) with automated, AI-assisted tools. It found no high-severity flaw, and we fixed its five medium findings. It did not cover our computers, providers or operations, and it was not an independent audit or penetration test; none has been done yet. Automated tests run on every merge into our main code line.
Not yet in place. We will not process your personal data until each item marked * is in place:
- * Encryption in transit on every link, including the link to our rendering engine.
- * The service we contract with for TunePixel AI set to delete your photo and the images it makes no later than 48 hours after the request (Annex 5), and the period for which the maker of the AI model it runs keeps them confirmed in writing.
- * Our rendering engine’s copies of your photos deleted before its server is stopped.
- * Full-disk encryption of every computer that holds your data, with a strong sign-in, automatic locking, and no other user.
- * An encrypted backup with a tested restore, each backup deleted 35 days after it is made.
- * Multi-factor sign-in for our staff and administrator accounts.
- * A written incident-response procedure.
- * A written procedure for requests from public authorities, with a register of requests (Annex 4).
- * Your content used only in the systems in Annex 3: never in developing or testing our software unless you allow it in writing under clause 14, and never in a code repository or in the AI assistants we use for software work, whatever the permission.
- * Data processing agreements, with the standard contractual clauses where needed, with every sub-processor in Annex 3B.
- * Old domain records that point at services we no longer use removed, and keys that have travelled unencrypted replaced.
Planned:
- Hosting in a cloud data centre, with encryption at rest.
- Location and device data removed from every photo when it is stored, and our rendering engine refusing a photo that still carries it.
- Security logs kept for at least 180 days.
- The incident-response procedure tested once a year.
- A separate sign-in for each person at your dealership.
- Written confidentiality undertakings from anyone who joins us.
Annex 3A: Sub-processors, by category
We handle your content in India. Our sub-processors handle it in the countries below, and Annex 3B names each of them.
| Category | What it does with your content | Where it processes | Named in Annex 3B |
|---|---|---|---|
| Cloud GPU computing | runs our real-photo studio’s rendering engine, which deletes each photo and result once it is 48 hours old: it checks every hour while its server runs, and 15 minutes after each start | United States | yes |
| AI image generation for TunePixel AI (two companies: the service that runs the model for us, and the maker of the model, which receives your photo from that service) | makes AI studio images from your photo (sent without its metadata) and the studio image | United States (the service’s delivery network may also hold copies of files in data centres in other countries, near where they are downloaded) | yes (confidential) |
| AI video generation (two companies: the service that runs the model for us, and the maker of the model) | makes 360° spins from your delivered AI studio images, only if you order spins | United States (the service); the maker of the model stores data in Singapore, and its group companies in other countries may reach it | yes (confidential) |
| Business email | holds our email with you, including folder links and any photos you attach | India (the provider’s staff in other countries may access it to fix errors and check spam) | yes |
| File transfer | will host the download links by which we send your images back by email | not chosen yet: we name it in Annex 3B, with where it processes, before we send you a link | yes, once chosen |
Our app, and the photos and images it stores, run on our own computer in Hyderabad, India.
Our website’s providers (website delivery, form email, bot check) do not handle your content; our privacy notice lists them.
Annex 3B: Confidential schedule of sub-processors
We give you Annex 3B, which names every sub-processor with its address, privacy contact, location, transfer safeguard, terms and its own list of sub-processors, and names the person in clause 7.5, when you accept this DPA. It is our confidential information under section 10 of our terms of service. You may show it to your regulators, auditors and advisers, and to a person exercising their rights where the law requires it.
Annex 4: Transfer impact assessment (summary)
We give you the full assessment, with its sources, together with Annex 3B. It was prepared by TunePixel and has not yet been reviewed by a lawyer. In short, as of 7 October 2026:
- What we assessed: the transfers of your personal data to us in India under the clauses, the UK Addendum and the Swiss changes, and onward to the sub-processors in Annex 3A. We followed the European Data Protection Board’s six steps (Recommendations 01/2020) and, for the UK, the Information Commissioner’s guidance on transfer risk assessments.
- The data: vehicle photos that may show number plates, people who appear by chance and VINs, and the work contact details of the person who holds your account. No special categories. Small volumes, kept for short periods (Annex 5).
- Indian law: public authorities can order the interception, monitoring or decryption of information held on a computer (Information Technology Act 2000, section 69, and its 2009 rules); require information from service providers (the IT intermediary rules of 2021 and, from 13 May 2027, the Digital Personal Data Protection Act 2023, section 36); order documents for a criminal investigation (Bharatiya Nagarik Suraksha Sanhita 2023, section 94); intercept messages on telecom networks (Telecommunications Act 2023, section 20); and require cyber incident information and logs (CERT-In Directions of 2022). Interception and information orders come from government officials, not judges, and the person concerned is not told. In our assessment these laws do not meet all of the European Essential Guarantees, and India has no adequacy decision from the EU or the UK.
- In practice: we have received no request from any public authority for any customer’s data, and we know of no direct access. Your data has no evident value to an authority. We have no reason to believe that these laws will be applied to it, or to us, in practice.
- Measures: encryption in transit on every link, so that interception on a network yields nothing readable; encryption at rest; photo metadata removed before AI processing; short retention and deletion on request; access only by the person who does the work; the commitments in clause 9.4; and a written procedure and register for requests from authorities. We process none of your personal data until the measures Annex 2 marks with * are in place.
- Onward to the United States: we rely on the clauses, or on the EU-US Data Privacy Framework for a provider that has joined it. Our transfers to the United States leave from India. The limits that US law sets on signals intelligence apply to everyone, whatever their nationality, but the US redress mechanism covers only data sent to the United States from the countries designated for it (the EU and the European Economic Area, the UK and Switzerland), and India is not one. So for these transfers we do not rely on that redress: we rely on sending only what the work needs and keeping it for short periods (Annex 5). We follow the legal challenges to the framework.
- Conclusion: with the measures in Annex 2, the clauses and the UK Addendum can be relied on for these transfers. No technical measure can stop a lawful order to us, because we must see your photos in clear. The conclusion rests on there being no reason to believe these laws will be applied to this data. The remaining risk is low, but not nil. If a request ever comes, clause 9.4 and the clauses apply, and you may suspend the transfers (Clause 14(f) of the clauses). We review this assessment at least once a year.
Annex 5: Retention schedule
| What | Kept for | Counted from |
|---|---|---|
| your uploaded photos | 90 days; while work on the vehicle is under way or a re-edit you asked for is open, until that is done | when the image finished (a photo never finished: from upload) |
| editing layers made from a photo | 90 days | same |
| finished images and the vehicle record | 1 year | the vehicle’s last finished image |
| editing history | 1 year | when the image finished |
| copies on our rendering engine | 48 hours; deleted at the engine’s next hourly check while its server runs (Annex 2) | the job |
| copies at the AI image-generation services that TunePixel AI runs on | at the service we contract with, 48 hours; at the maker of the AI model it runs, the period its terms set, which we confirm in writing, and state here, before we send them any of your photos | the request |
| copies at the AI video service and its model’s maker (spins only) | the periods their terms set, which we confirm in writing, and state here, before we send them any of your images | the spin |
| photos or files you email us | deleted from our mailbox no later than 30 days after we load them into our app, and never later than 90 days after we receive them, or at once when you ask | as the period says |
| our backups | 35 days | when the backup is made |
| records of updates sent to your systems | 30 days (90 days if undelivered) | delivery or event |
| the record that a deletion happened (no photos, no names) | 2 years | the deletion |
Annex 6: Your settings
Your order, or an email from you, can set these. Until you do, the defaults apply.
| Setting | Default |
|---|---|
| Retention periods (photos, editing layers, finished images, editing history) | Annex 5 |
| Studios you use (AI studio, real-photo studio) | as your order or the pilot terms say |
| Number-plate removal by default (AI studio) | off |
| Contact for breach notices | the person who holds your account |
| Contact for sub-processor notices | the person who holds your account |
Annex 7: The UK Addendum’s tables
The UK Addendum (version B1.0, in force 21 March 2022) is completed as follows. Its Part 2, the Mandatory Clauses, is the Information Commissioner’s: those of the template Addendum B1.0 laid before Parliament on 2 February 2022, as revised under its Section 18.
Table 1: Parties
| Item | Exporter (who sends the Restricted Transfer) | Importer (who receives the Restricted Transfer) |
|---|---|---|
| Start date | the day you accept this DPA | the day you accept this DPA |
| The parties’ details | you: your full legal name, trading name (if different), main address and company number, as your order or your acceptance email gives them | TunePixel: the full legal name, trading name, main address and (once registered) company number in section 1.1 of our terms of service |
| Key contact | the person your order or your acceptance email names, with job title and email | Venkatesh Gandham, Founder and CEO, privacy@tunepixelstudio.com |
| Signature | not needed: accepting this DPA makes the Addendum binding on both of us (its Section 2) | the same |
Table 2: Selected SCCs, Modules and Selected Clauses
The Approved EU SCCs, including the Appendix Information, with only these modules and options in effect:
| Module | In operation | Clause 7 (docking clause) | Clause 11 (option) | Clause 9a (prior or general authorisation) | Clause 9a (time period) | Personal data received from the Importer combined with personal data collected by the Exporter? |
|---|---|---|---|---|---|---|
| 1 | yes | yes | not used | not in Module 1 | not in Module 1 | applies to Module 4 only |
| 2 | yes | yes | not used | general authorisation | 30 days; for a sub-processor’s own sub-processors, the notice it gives us, at least 15 days | applies to Module 4 only |
| 3 | yes | yes | not used | general authorisation | 30 days; for a sub-processor’s own sub-processors, the notice it gives us, at least 15 days | applies to Module 4 only |
| 4 | no | not used | not used | not used | not used | not used |
Table 3: Appendix Information
- Annex 1A (List of Parties): Annex 1.A of this DPA.
- Annex 1B (Description of Transfer): Annex 1.B of this DPA, with Annex 5.
- Annex II (Technical and organisational measures, including those to ensure the security of the data): Annex 2 of this DPA.
- Annex III (List of sub-processors, Modules 2 and 3 only): Annexes 3A and 3B of this DPA.
Table 4: Ending this Addendum when the Approved Addendum changes
Which parties may end this Addendum as set out in Section 19: neither party.