Skip to content

Legal

Data processing agreement

The terms on which we process personal data you put into a workspace. Readable here, without a sales call.

Last updated

This agreement forms part of the terms of service and applies where your use of Kinoplate involves us processing personal data on your behalf under Article 28 of the GDPR. Where it and the terms conflict on data protection, this document governs.

1. Roles

You are the controller of personal data contained in the content you put into a workspace - a customer list you render name badges from, a photograph of a person in a template. We are the processor of it and act only on your documented instructions, which are these terms plus what you do in the product and over the API.

We are the controller of the account data we need to run the service - who you are, how you sign in, what you spent. The privacy notice covers that, and it is not what this agreement is about.

2. Subject matter, duration, nature and purpose

We process the personal data in your workspace content in order to store it, render it into images and documents, deliver the results to you, and keep the service working. Processing lasts as long as your account does, plus any retention you configure.

3. Categories of data and data subjects

Whatever you choose to put in. In practice that is names, contact details, images and commercial data belonging to your customers, staff or contacts. We do not require any special category data and the product is not designed for it; if you send some, you are responsible for having a lawful basis.

4. Our obligations

  • Process only on your documented instructions, including on transfers.
  • Keep the people who process it under a duty of confidence, and limit access to those who need it.
  • Implement the measures in section 6.
  • Engage sub-processors only as set out in section 5.
  • Help you respond to a data subject's request, and help with your obligations under Articles 32 to 36, taking into account what we know and can see.
  • Tell you without undue delay if we become aware of a personal data breach affecting your data.
  • Delete or return the data at the end of the service, at your choice, except where the law requires us to keep it.
  • Make available the information needed to demonstrate compliance, and allow audits.

5. Sub-processors

You give general authorisation for the sub-processors listed on the sub-processor page. That page is the list; it names each one, what it does and where it is.

We will announce a new or replacement sub-processor before it starts processing, and you may object on reasonable data protection grounds - in which case we will work with you on an alternative, and if there is none you may terminate the affected part of the service.

Every sub-processor is bound by terms no less protective than these, and we remain liable to you for what they do.

6. Security

These are the measures the system actually implements, not a list of aspirations:

  • Encryption in transit, and encryption at rest for the database and object storage.
  • Workspace isolation enforced twice - in the application and again by Postgres row-level security, so a query without workspace context returns nothing rather than everything. That is asserted by a test suite on every change.
  • Credentials stored as hashes only. An API key's secret cannot be re-derived, and no secret, key hash or storage configuration appears in an API response, a log line or a client bundle.
  • Scoped API keys with per-key spend caps, and immediate revocation. Optional two-factor authentication on every plan, and an organisation-wide requirement an owner can turn on.
  • Rendering runs in a sandboxed browser with no network access beyond an allow-list, and every outbound fetch - a remote image, a webhook, your own storage - passes an egress guard.
  • Access to production limited to those who need it, with audited change control.

7. International transfers

Storage, rendering, the database and identity are in the European Union. There is no US region.

One exception, named rather than implied away: the AI features use United States sub-processors. Where you use them, an AI prompt and the specific image being processed are transferred to those sub-processors under the appropriate transfer mechanism; your template files and rendered artwork are not. The sub-processor list says which is which. If you do not use those features, no personal data in your workspace leaves the EU.

8. Data subject requests

If a data subject contacts us about data you control, we will refer them to you and will not respond on your behalf except on your instruction. We will help you meet the deadline.

9. Deletion and return

You can delete workspace content at any time from within the product. On termination we delete it, or return it first if you ask. Backups age out on their own schedule and are not restored selectively.

10. Audit

We will answer a reasonable written request for the information needed to demonstrate compliance with this agreement, and will accommodate an audit no more than once a year, or after a breach affecting your data, on reasonable notice and without disrupting the service for others.

Contact

privacy@kinoplate.com. Tell us if you need this signed; the terms are the same either way.