This Data Processing Agreement ("DPA") forms part of the Agreement between:
(1) Threadmind AI Limited, a company registered in England and Wales with company number 17218646, registered office at Xeinadin South East Limited, Office 5, Rayleigh Road, Hutton, Brentwood, Essex, England, CM13 1AB ("Threadmind AI", the "Processor"); and
(2) the customer identified in the Agreement (the "Customer", the "Controller").
Background. The Processor provides the ViZO Studio platform (the "Service") to the Controller under the Terms of Service (the "Agreement"). In providing the Service, the Processor processes Personal Data on behalf of the Controller. This DPA sets out the terms on which that processing is carried out, as required by Article 28 of the UK GDPR. If there is any conflict between this DPA and the Agreement in respect of data protection, this DPA prevails.
1.1 Terms used in this DPA have the meanings given to them in the Agreement. In addition:
"UK GDPR" means the United Kingdom General Data Protection Regulation and the Data Protection Act 2018 ("DPA 2018"), and any successor or amending legislation.
"Data Protection Laws" means the UK GDPR, the DPA 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), and all other applicable laws relating to the processing of Personal Data.
"Controller", "Processor", "Data Subject", "Personal Data", "Special Category Data", "Processing", "Personal Data Breach" and "Supervisory Authority" have the meanings given in the UK GDPR.
"Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
"Processing Instructions" means the Controller's documented instructions to the Processor regarding the processing of Personal Data, as set out in this DPA, the Agreement and the Controller's use of the Service.
2.1 The parties agree that, in respect of Personal Data contained within the Controller's Input Content, any Digital Twin, and other content the Controller submits to the Service, the Controller is the controller and the Processor is the processor.
2.2 In respect of the Processor's own account, billing, website and usage data, the Processor acts as a controller in its own right, as described in its Privacy Policy; that processing is outside the scope of this DPA.
2.3 The subject-matter, duration, nature and purpose of the processing, the types of Personal Data and categories of Data Subjects are set out in Annex 1.
2.4 The Controller warrants that it has a valid lawful basis (and, for Special Category Data including any biometric data in a Digital Twin, a valid Article 9 condition and any necessary explicit consent) for the processing it instructs the Processor to carry out, and that its instructions comply with Data Protection Laws.
The Processor shall:
3.1 (a) Documented instructions. Process the Personal Data only on the Controller's documented Processing Instructions, including with regard to international transfers, unless required to do otherwise by applicable law; in which case the Processor will inform the Controller of that legal requirement before processing, unless the law prohibits it on important grounds of public interest. If the Processor believes an instruction infringes Data Protection Laws, it will inform the Controller.
3.2 (b) Confidentiality. Ensure that persons authorised to process the Personal Data are bound by an appropriate duty of confidence.
3.3 (c) Security. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the nature of the data and the risks to Data Subjects, as described in Annex 2. These measures include, where appropriate, encryption, pseudonymisation, resilience, and regular testing. Heightened measures apply to any Special Category Data, including biometric data within Digital Twins.
3.4 (d) Sub-processors. Not engage a Sub-processor without the Controller's prior general written authorisation. The Controller provides general authorisation for the Sub-processors listed in Annex 3. The Processor will inform the Controller of any intended addition or replacement of a Sub-processor, giving the Controller a reasonable opportunity to object. Where the Processor engages a Sub-processor, it will impose data protection obligations equivalent to those in this DPA by written contract, and remains fully liable to the Controller for the Sub-processor's compliance.
3.5 (e) Assistance with Data Subject rights. Taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights under the UK GDPR (including access, rectification, erasure, restriction, portability and objection). Where a Data Subject contacts the Processor directly regarding data the Processor holds on the Controller's behalf, the Processor will refer the request to the Controller.
3.6 (f) Assistance with compliance. Taking into account the nature of processing and the information available to it, assist the Controller in ensuring compliance with its obligations regarding security of processing (Article 32), notification of Personal Data Breaches (Articles 33–34), data protection impact assessments (Article 35) and prior consultation (Article 36). The parties acknowledge that the Digital Twin feature involves Special Category/biometric data and is likely to require a DPIA by the Controller.
3.7 (g) Breach notification. Notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting the Controller's Personal Data, and provide information reasonably available to assist the Controller in meeting its breach-notification obligations.
3.8 (g) End-of-contract. At the Controller's choice, delete or return all Personal Data to the Controller at the end of the provision of the Service, and delete existing copies unless applicable law requires storage. The Controller is responsible for exporting its data before termination; the Processor's standard retention and deletion practices are described in the Privacy Policy.
3.9 (h) Audits and information. Make available to the Controller all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates. Audits will be on reasonable prior notice, no more than once per year (save following a Personal Data Breach or where required by a Supervisory Authority), during business hours, subject to confidentiality, and conducted so as to minimise disruption.
3.10 No training. Consistent with the Agreement, the Processor does not use the Controller's Input Content or Output (including Personal Data within them) to train its AI models.
4.1 The Processor shall not transfer the Controller's Personal Data outside the United Kingdom unless it has taken appropriate safeguards in accordance with Data Protection Laws, such as transfer to a jurisdiction subject to UK adequacy regulations, or the use of the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with any necessary supplementary measures.
4.2 Certain Sub-processors are located outside the UK — in particular Cloudflare, Inc. and Web3Forms (United States), and Microsoft 365 (European Union). For any such transfer, the relevant safeguard (UK adequacy, IDTA, or the UK Addendum to the EU SCCs, with any necessary supplementary measures) is put in place. Details of safeguards are available to the Controller on request.
5.1 Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
5.2 This DPA does not relieve the Processor of any obligations or liabilities imposed on it directly as a processor under the UK GDPR.
6.1 This DPA takes effect on the same date as the Agreement and continues for as long as the Processor processes Personal Data on the Controller's behalf. The obligations that by their nature should survive (including confidentiality, deletion/return, and audit) survive termination.
7.1 In the event of conflict between this DPA and the Agreement on data protection matters, this DPA prevails. In all other respects the Agreement continues in full force.
7.2 This DPA is governed by the law of England and Wales and is subject to the jurisdiction provisions of the Agreement.
Subject-matter: processing of Personal Data to provide the ViZO Studio Service (AI fashion image generation, batch processing, and where available video generation).
Duration: for the term of the Agreement and until deletion/return of Personal Data.
Nature and purpose: hosting, storage, generation, processing and delivery of imagery and related Output from the Controller's Input Content, and provision of support.
Types of Personal Data: images that may contain identifiable individuals (e.g. on-model photographs); Digital Twin data, which may include biometric/Special Category Data of the Controller or its consenting personnel; names and contact details where included in submitted content.
Categories of Data Subjects: the Controller's personnel; models or individuals depicted in the Controller's Input Content; subjects of Digital Twins (the Controller itself or its consenting staff).
Special Category Data: potentially biometric data within Digital Twins (Article 9), processed on the basis of the Controller's lawful basis and the explicit consent it has obtained.
Encryption of data in transit (and at rest where appropriate); access controls and least-privilege access; authentication controls; network and application security; logical separation of customer data; secure development practices; staff confidentiality and training; logging and monitoring; backup and resilience; vendor/sub-processor due diligence; incident-response and breach-notification procedures; and heightened controls for Special Category/biometric data (Digital Twins).
The Processor’s current Sub-processors are listed below. The Controller is notified of intended changes under clause 3.4.
| Sub-processor | Purpose | Location |
|---|---|---|
| Tom & Co. Ltd. (company no. 07557895), 38 Shad Thames, London, SE1 2YD | Builds, hosts and operates the ViZO platform (app) | United Kingdom |
| Cloudflare, Inc. | Hosts the ViZO marketing website | United States |
| Stripe Payments UK Ltd | Subscription payment processing | United Kingdom |
| Web3Forms | Website contact-form submissions | United States |
| Microsoft (Microsoft 365 / Microsoft Ireland Operations Ltd.) | Email hosting | European Union |