Data Processing Addendum
This applies when you embed our widget on your own site. Your customers are your customers: for their data you are the controller and we are your processor. This sets out what we do with it and what we don't.
1. Roles
You (the studio) are the controller of your customers' personal data. IARTSHOW CORP, trading as AIFRAMING, is the processor. For our own account data about you, we are the controller — see the Privacy Policy.
2. Scope of processing
| Item | Detail |
|---|---|
| Subject matter | Providing framing visualisation, pricing, production and fulfilment |
| Duration | For as long as your account is open, plus statutory retention |
| Categories of data | Name, email, phone, shipping address, artwork files, framing configurations |
| Data subjects | Your customers, and your own staff who use the dashboard |
3. Our obligations
- We process personal data only on your documented instructions — placing an order through the platform is such an instruction.
- Everyone with access is bound by confidentiality.
- We apply the measures described on our Security page.
- We assist you, as far as we reasonably can, with data-subject requests, breach notification and impact assessments.
- On termination we delete or return personal data, except what we are legally required to keep.
- We make available the information you need to verify our compliance.
4. Sub-processors
You authorise these sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel | Hosting | US |
| Supabase | Database, file storage | US |
| Stripe | Payments | US |
| Resend | Transactional email | US |
| Replicate | Image processing | US |
| EasyPost + carrier | Shipping and tracking | US |
| Production partners | Framing production and fulfilment | US |
We will give you notice before adding or replacing a sub-processor, and you may object on reasonable data-protection grounds.
5. Breach notification
If we become aware of a personal-data breach affecting your data we will tell you without undue delay and in any case within 72 hours, with what we know: what happened, which data, likely consequences, and what we are doing.
6. International transfers
Processing takes place in the United States. Where personal data is transferred from the EEA, UK or Switzerland, the EU Standard Contractual Clauses are incorporated by reference and apply to that transfer.
7. Audit
On reasonable notice, and no more than once a year unless a regulator requires otherwise, we will answer a security questionnaire or provide the documentation we hold. We do not currently hold a SOC 2 report; we would rather tell you that than point at someone else's.
8. Liability and precedence
This addendum is governed by, and its liability limits are those of, the Terms of Service. Where this addendum and the terms conflict on the processing of personal data, this addendum wins.
9. Accepting it
This addendum applies automatically to every approved studio account — you do not need to sign it. If your own compliance process needs a countersigned copy, email hello@aiframing.com and we will send one.