Company content is not provided for provider training or unrelated use under this DPA.
Data Processing Addendum
This agreement explains how we handle personal data for business customers. Your Order Form specifies the approved services, providers, storage periods and any regional commitments.
SCCs, UK transfer terms or another lawful mechanism where required.
Your Order Form records the approved services and any regional commitments.
Accept the business terms and DPA in your company account before submitting real company data. Review the named register before acceptance. The public recipient overview describes processing categories. Your account provides the named register and a downloadable copy of your accepted agreement.
1. Scope and roles
This Data Processing Addendum (“DPA”) is included in the business agreement accepted by an authorised owner or admin in the company account, or in a separately signed Order Form. The acceptance record identifies the Customer. Código Solidário Lda, NIPC 519431553, Rua da Arriba, N.º 18-Ac, Condomínio Vigias da Arriba, 2560-046 A dos Cunhados, Torres Vedras, Lisboa, Portugal, operates DeepfakePolicy and is the Processor.
The Customer decides why and how Customer Personal Data is used and is its controller. If acting for another controller, the Customer confirms it can appoint us as a subprocessor. We separately act as controller for our own account administration, security, billing, tax and legal records, as explained in the privacy policy.
2. Instructions and purpose limitation
We use Customer Personal Data to provide, protect and support the agreed service, following the Customer’s settings and documented instructions, or as required by law. If an instruction appears to break data-protection law, we will tell the Customer and may pause that processing until the issue is resolved.
Ordinary Customer Content is not sold, used for behavioural advertising, or used to train or improve a general-purpose or third-party model. Research use needs a separate, specific agreement. A personal checkbox does not give permission to use company content for research.
3. Customer responsibilities
The Customer must have a lawful basis and the required permissions, tell affected people how their data is used and give instructions limited to what the service needs. A person must review important decisions. Reports are estimates and can be wrong; identity, authorship, authenticity, fraud and intent need supporting evidence.
Contracts, invoices, financial records and confidential business documents are within scope when necessary for the agreed service. For children’s data, criminal-offence data, special-category data or biometric data for unique identification, the Customer must document the lawful basis and satisfy all additional legal conditions, notices, permissions and safeguards before processing. The selected service and its providers must support that processing under the required agreements. Do not submit data where these conditions are not met; accepting this DPA alone does not establish compliance.
4. Confidentiality and security
Authorised personnel must keep Customer Personal Data confidential and access it only as needed. We use security measures appropriate to the service and risk: encrypted connections, server-side secrets, hashed passwords and API keys, workspace permissions, signed webhooks, private temporary storage and scheduled deletion. Report saving and research are separate choices; analytics is restricted on sensitive pages.
OpenAI calls disable response storage with store: false. This does not mean all OpenAI records are deleted immediately. Our security page describes the measures in use and their limits.
5. Assistance and data-subject requests
We will reasonably help with people’s data-rights requests, security assessments, breach notifications, data-protection impact assessments and regulator consultations, taking account of the processing and information available. Requests received directly about Customer Personal Data are forwarded to the Customer unless the law requires a different response.
The Customer remains responsible for its legal decisions and replies. Substantial custom assistance may be charged at an agreed rate, except where required because we breached this DPA.
6. Personal data breaches
We will notify the Customer without undue delay after learning of a personal data breach affecting Customer Personal Data. We will share what is known about the incident, affected data, likely consequences, protective action and a contact for updates. Further information may follow in stages.
We will preserve relevant evidence and cooperate with a reasonable investigation. We contact affected people or regulators on the Customer’s behalf only when instructed or legally required.
7. Subprocessors
The Customer gives general written authorisation for the named providers in the register saved with its electronic acceptance or separately signed Order Form. The public recipient overview describes services and recipient categories and does not replace that named list. Before a provider receives Customer Personal Data, the required written processing and transfer terms must be in place. Confirmation of a general service arrangement does not expand a Customer’s agreed scope.
We will email the recorded privacy contact at least 30 days before a new or replacement subprocessor receives Customer Personal Data. The Customer may object on data-protection grounds during that period. If no reasonable alternative resolves the objection, the Customer may end the affected service without penalty. An urgent change requires specific prior authorisation or suspension of the affected processing.
8. International transfers
We are based in Portugal and use international services. EU-only processing or a specific region is promised only if the Order Form says so. Transfers outside protected jurisdictions must use a valid mechanism, such as an adequacy decision, EU Standard Contractual Clauses or UK transfer terms.
For a transfer from us as an EEA processor to a non-EEA subprocessor, Module Three of the EU clauses normally applies. UK transfers also need the UK Addendum or another valid UK mechanism. Required party details, annexes and transfer assessments must be completed before the clauses take effect.
9. Return, deletion and retention
Product controls let the Customer delete saved reports and time-limited API results. When the agreement ends, or on a valid written instruction, we will return or delete Customer Personal Data, subject to legally required retention and protected backup cycles. See the retention schedule and applicable Order Form.
Data retained by law is restricted to that purpose. Provider copies follow their agreements; deleting our copy does not itself erase a provider’s copy before its deletion cycle.
10. Information and audits
We provide information reasonably needed to demonstrate compliance. Review starts with documentation, questionnaires and available independent evidence. If this is not enough, the Customer may arrange one reasonable audit every 12 months by an independent auditor bound to confidentiality. The audit must not expose other customers’ data or unreasonably disrupt the service.
The frequency limit does not apply after a material breach, credible security concern or regulator request. We do not claim SOC 2, ISO 27001 or independent certification unless a current report covers Código Solidário Lda and this service.
11. United States state privacy terms
Where US state privacy law treats us as a service provider or contractor, we will not sell Customer Personal Data, share it for cross-context behavioural advertising, use it outside the contracted business purpose or direct business relationship, or combine it with other personal data except as the law permits.
We will provide the required level of protection, notify the Customer if we can no longer do so and allow reasonable steps to stop and remedy unauthorised use. These terms do not change our separate roles for billing, security, fraud prevention or legal records.
12. Liability, term and governing law
The main agreement governs liability, subject to mandatory law. If terms conflict, mandatory EU or UK transfer terms take priority, then this DPA, then the main agreement, then general website terms. This DPA applies for as long as we process Customer Personal Data.
Portuguese law and courts apply unless the agreement lawfully provides otherwise. Mandatory data-protection law and transfer clauses remain unaffected.
Schedule 1: Processing details
| Subject matter | Media and content verification, report generation, workspace administration, security, support and agreed integrations. |
|---|---|
| Duration | The Agreement term plus the verified deletion periods in the public retention schedule and applicable Order Form. |
| Data subjects | Authorised users; personnel and customers of the Customer; people depicted, heard, named or referenced in submitted content; authors and recipients of documents; support contacts. |
| Data | Account and workspace identifiers; images, audio, video, text, documents, URLs and metadata; analysis outputs and reports; case labels and notes; security and support records. |
| Frequency | Customer-initiated through supported interactive, organisation or approved API workflows. |
| Special data | May include sensitive personal data where lawful, necessary and supported by the agreed processing arrangements. Clause 3 conditions apply. |
Schedule 2: Current technical and organisational measures
- HTTPS enforcement, HSTS, baseline browser protections including frame denial and MIME-sniffing protection, and no-store handling on private routes.
- Cryptographically random sessions and API keys; passwords and recoverable credentials are not stored in plain text.
- Server-enforced organisation roles, scoped records and an audit trail for casework actions.
- Private object storage for retained sources; temporary provider-transfer objects use short TTL metadata, an immediate deletion attempt and a scheduled expired-object sweep for retry.
- Company browser batch results and report thumbnails expire seven days after completion. Source deletion follows the same post-processing and retry rules as the API. Customer downloads and existing workspace case records follow their separate retention arrangements.
- Evidence API sources are targeted for deletion after processing; failed deletion remains pending for scheduled retry. Report retention is customer-selected from one hour to seven days.
- Signed webhooks, bounded retries and one-time display of webhook secrets.
- Separate controls for analysis, report saving and research contribution; research-file deletion is scheduled 180 days after consent or requested earlier by verified withdrawal. Unconfirmed deletion remains pending and the source is excluded from research use while retry continues.
- OpenAI Responses calls use
store: false; optional Clarity session analytics is excluded from scanner, report, authentication and account routes. - First-party marketing events expire after 90 days; user-linked provider telemetry expires after 180 days; authentication-attempt hashes expire after 24 hours.
Adding this DPA to your agreement
Accept standard business terms in your company account. If your processing needs additional safeguards, regional commitments or a different scope, send your requirements to deepfakepolicy@proton.me. Custom processing starts only after the additional scope is agreed in writing.