Data Processing Addendum

Terms governing Codifiq LLC’s processing of personal data on behalf of customers, including EEA and UK transfers.

Version 2026-07-27 · Effective 27 July 2026

Scope and roles

This Data Processing Addendum (the Addendum) forms part of the Terms of Service between Codifiq LLC (Processor) and the customer organisation (Controller) and applies whenever we process personal data on the Controller’s behalf in Sartoria.

No signature needed. This Addendum applies automatically when the Controller accepts the Terms. A countersigned copy is available on request to legal@codifiq.com for customers whose procurement process requires one.

What it covers. It governs personal data contained in Customer Content — the material the Controller and its users put into a workspace. It does not govern account data about the Controller’s administrators and users, for which we are an independent controller and our Privacy Policy applies.

Applicable law. Data Protection Law means the EU General Data Protection Regulation 2016/679, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended, each as applicable to the processing.

California. For the CCPA, we are a service provider. We will not sell or share personal information, will not retain, use or disclose it for any purpose other than performing the Service or as otherwise permitted by the CCPA, and will not combine it with information received from other sources except as the CCPA permits. We certify that we understand and will comply with these restrictions.

Details of processing (Annex I)

Subject matter
Provision of the Sartoria product lifecycle management service, including AI-assisted image generation, to the Controller.
Duration
For the term of the Terms of Service, plus the retention periods set out in “Return and deletion”.
Nature and purpose
Hosting, storage, transmission, display, backup, generation of derivative images from Controller inputs, security monitoring, and support performed on the Controller’s instructions.
Personal data
Names and email addresses of the Controller’s personnel and invitees as they appear in workspace records; identifiers of designers and reviewers attached to styles; review notes and free-text fields; and any personal data the Controller chooses to include in uploaded images, reference photographs, prompts or documents.
Special categories
None requested or required. The Terms prohibit uploading sensitive categories of personal data, and the Service is not designed for them.
Data subjects
The Controller’s employees, contractors and invited partners, and any individual depicted or identified in material the Controller uploads.
Frequency
Continuous, for as long as the Controller uses the Service.
Recipients
The subprocessors listed on our subprocessors page.

Our obligations as processor

  • We process personal data only on the Controller’s documented instructions, which comprise the Terms, this Addendum, the Controller’s configuration and use of the Service, and any further written instruction we agree to.
  • We will tell the Controller if we believe an instruction infringes Data Protection Law, and may suspend that processing until it is resolved.
  • If law requires us to process beyond the Controller’s instructions, we will inform the Controller first unless that law prohibits it.
  • We do not use personal data contained in Customer Content for our own purposes, and specifically not to train or improve machine learning models.
  • We make available the information reasonably necessary to demonstrate compliance with these obligations.

Confidentiality of personnel

We limit access to personal data to personnel who need it to provide or support the Service, bind them to written confidentiality obligations that survive their engagement, and ensure they are informed of the confidential nature of the data. Access to production systems is restricted and credentialed.

Security measures (Annex II)

We implement appropriate technical and organisational measures under Article 32, taking account of the state of the art, the cost of implementation, and the risk to data subjects. As of the date of this Addendum they include:

  • Encryption. TLS for all data in transit; encryption at rest for the database, file storage and backups, provided by our infrastructure providers.
  • Tenant isolation. Database row-level security keyed to the organisation, enforced by the database itself rather than application code alone, so a defect in one query cannot expose another customer’s data.
  • Storage access control. Uploaded and generated files are held in a private bucket with no public access, addressed by tenant-scoped paths, and served only through signed links that expire after one hour.
  • Authentication. Credentials are managed by a specialist provider and stored only as hashes; email verification is required for signup, invitation and password reset; sessions are validated server-side on each request.
  • Least privilege. Privileged service credentials are held server-side only, never exposed to the browser, and separated from the keys used by client sessions.
  • Availability. Managed, encrypted backups of the database, operated by our infrastructure provider.
  • Change control. Version-controlled code and reviewed database migrations.
  • Vendor management. Written data processing terms with every subprocessor listed on our subprocessors page.

We may update these measures as the Service evolves, provided the level of protection is not reduced.

Subprocessors

General authorisation. The Controller gives general authorisation for us to engage subprocessors. Our current subprocessors, with the purpose and data categories for each, are published on our subprocessors page, which forms part of this Addendum.

Terms we impose. We enter a written agreement with each subprocessor imposing data protection obligations no less protective than those in this Addendum, and we remain fully liable to the Controller for their performance.

Changes and objection. We will give the Controller at least thirty (30) days’ notice by email before adding or replacing a subprocessor. The Controller may object on reasonable data protection grounds within that period; we will work in good faith to offer an alternative, and if we cannot, the Controller may terminate the affected part of the Service without penalty.

Data subject requests

Taking account of the nature of the processing, we will assist the Controller with appropriate technical and organisational measures, so far as possible, in fulfilling requests to exercise data subject rights. The Service itself lets administrators access, correct and delete most workspace content directly. If we receive a request directly from a data subject about Customer Content, we will not respond substantively but will forward it to the Controller without undue delay.

Personal data breach

We will notify the Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting personal data processed under this Addendum. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, the measures taken or proposed, and a contact point for more information.

We will assist the Controller in meeting its own notification obligations. Notification is not an acknowledgement of fault.

Impact assessments and prior consultation

Taking account of the nature of the processing and the information available to us, we will provide reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority that the Controller must carry out under Articles 35 and 36 of the GDPR.

Return and deletion

On termination, and at the Controller’s choice, we will return or delete personal data processed under this Addendum. Unless the Controller instructs otherwise, we will make Customer Content available for export for thirty (30) days after termination and then delete it from active systems within a reasonable period. Copies in encrypted backups are deleted as those backups expire on their rolling schedule.

We may retain personal data where required by law, and records evidencing acceptance of the Terms, as described in our Privacy Policy. Any retained data remains subject to this Addendum.

Audits and information

We will make available to the Controller the information reasonably necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates. Audits will be at the Controller’s expense, on at least thirty (30) days’ written notice, no more than once a year unless required by a supervisory authority or following a breach, during business hours, subject to confidentiality, and conducted so as not to disrupt the Service or the data of other customers. Where available, we may satisfy an audit request by providing current third-party reports or completed security questionnaires.

International transfers

Personal data processed under this Addendum is transferred to and processed in the United States.

Standard Contractual Clauses. Where the GDPR applies to a transfer, the European Commission’s Standard Contractual Clauses of 4 June 2021, Module Two (controller to processor), are incorporated into this Addendum by reference and apply, with Annex I completed by the “Details of processing” section above, Annex II by the “Security measures” section, and Annex III by our subprocessors page. The optional docking clause applies; the governing law and forum are those of Ireland where the Clauses require a Member State.

United Kingdom. Where the UK GDPR applies, the International Data Transfer Addendum issued by the Information Commissioner applies to the Clauses, with the tables completed using the corresponding information in this Addendum.

Switzerland. Where Swiss law applies, references in the Clauses are read to give equivalent effect under the Federal Act on Data Protection, and the Federal Data Protection and Information Commissioner is the competent authority.

Liability and precedence

Each party’s liability under this Addendum is subject to the exclusions and limitations of liability in the Terms of Service.

If there is a conflict, the Standard Contractual Clauses prevail over this Addendum, and this Addendum prevails over the rest of the Terms of Service, in each case only to the extent of the conflict and only in respect of the processing of personal data.

Contact

Processor
Codifiq LLC
Data protection
privacy@codifiq.com
Legal notices
legal@codifiq.com
Address
[Codifiq LLC registered address — to be completed]