Data Processing Agreement

Data Processing Agreement

Last updated July 13, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Senova Systems LLC, a New Jersey limited liability company (contact: legal@senova.studio) ("Senova"), and the customer entity that has agreed to Senova's Terms of Service or another written agreement governing Senova's services ("Customer") (such agreement, the "Agreement"). This DPA applies where and to the extent Senova processes Customer Personal Data (defined below) on behalf of Customer in the course of providing the Services.

This DPA is effective on the later of the date the Agreement takes effect and the date this DPA is executed or accepted by Customer (the "Effective Date": July 13, 2026).

How to execute: Customers who require a signed DPA may complete the signature block and Annex I below and send a copy to legal@senova.studio. The DPA becomes binding when countersigned by Senova or, where Senova makes this DPA available for acceptance within the Services or by reference in the Agreement, upon such acceptance.

On this page

  1. Definitions
  2. Scope, roles, and responsibilities
  3. Details of processing
  4. Processing on documented instructions
  5. Confidentiality of personnel
  6. Security
  7. Sub-processing
  8. Assistance with Data Subject rights
  9. Assistance with Articles 32–36
  10. Personal Data Breach notification
  11. Return and deletion of Customer Personal Data
  12. Audits and information rights
  13. International transfers
  14. CCPA — Service Provider terms
  15. Liability
  16. Term, precedence, and general
  17. Signature block
  18. Annex I — Details of Processing
  19. Annex II — Security Measures
  20. Annex III — Sub-processors

1. Definitions

1.1 "Data Protection Laws" means all laws applicable to the processing of Customer Personal Data under the Agreement, including as applicable: (a) Regulation (EU) 2016/679 (the "GDPR"); (b) the GDPR as incorporated into United Kingdom law by the Data Protection Act 2018 and the European Union (Withdrawal) Act 2018 (the "UK GDPR"); (c) the Swiss Federal Act on Data Protection ("FADP"); (d) the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020, and its regulations (the "CCPA"); and (e) other applicable data protection or privacy laws — in each case as amended, replaced, or superseded.

1.2 "Customer Personal Data" means Personal Data that Customer or its Authorized Users submit to the Services and that Senova processes on Customer's behalf — including Personal Data contained in Customer Content (prompts, uploaded inputs and reference material, and generated outputs) — as further described in Annex I. Customer Personal Data does not include Account Data (defined in Section 2.4).

1.3 "Personal Data", "Controller", "Processor", "Data Subject", "Processing" (and "process"), "Personal Data Breach", and "Supervisory Authority" have the meanings given in the GDPR or, where applicable, equivalent meanings under other Data Protection Laws. "Business", "Service Provider", "Sell", "Share", and "Business Purpose" have the meanings given in the CCPA.

1.4 "EU SCCs" means the standard contractual clauses for the transfer of personal data to third countries annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

1.5 "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0) issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, in force 21 March 2022.

1.6 "Sub-processor" means any third party engaged by Senova (or by another Sub-processor) to process Customer Personal Data on Customer's behalf.

1.7 "Services" means Senova's AI image and video generation services and related services provided under the Agreement.

1.8 Capitalized terms not defined in this DPA have the meanings given in the Agreement.

2. Scope, roles, and responsibilities

2.1 Roles. As between the parties, Customer is the Controller (or, where Customer acts on behalf of a third-party controller, a Processor) of Customer Personal Data, and Senova is a Processor (or Sub-processor, as applicable) acting on Customer's behalf. Where Customer is itself a Processor, Customer warrants that its instructions to Senova, including appointment of Senova as a sub-processor, are authorized by the relevant controller.

2.2 Customer responsibilities. Customer is responsible for: (a) the accuracy, quality, and lawfulness of Customer Personal Data and the means by which it was acquired; (b) having a lawful basis for the processing and providing all required notices to, and obtaining all required consents from, Data Subjects; (c) its instructions to Senova complying with Data Protection Laws; and (d) not submitting to the Services any Personal Data whose processing under this DPA would be unlawful, and not submitting special categories of data (Article 9 GDPR), criminal-offence data (Article 10 GDPR), or comparably sensitive data under other laws, unless the parties have expressly agreed in writing to such processing and to any additional required measures.

2.3 Compliance. Each party will comply with its obligations under Data Protection Laws in respect of Customer Personal Data.

2.4 Account Data carve-out. Senova processes certain data as an independent controller for its own legitimate business purposes — such as account registration and administration data, billing and payment records, usage telemetry, support communications, and security logs ("Account Data") — as described in Senova's Privacy Policy. Account Data is not subject to this DPA.

3. Details of processing

The subject matter, duration, nature and purpose of the processing, the categories of Data Subjects, and the categories of Personal Data are set out in Annex I. In summary: Senova processes Customer Personal Data to provide, secure, and support the Services — i.e., to generate images and videos from Customer's prompts and inputs, to store inputs and outputs, and to operate related account features — for the duration of the Agreement plus the deletion period in Section 11.

4. Processing on documented instructions

4.1 Senova will process Customer Personal Data only on Customer's documented instructions, including with regard to transfers of Customer Personal Data to a third country or international organisation, unless required to do otherwise by law to which Senova is subject; in that case, Senova will inform Customer of that legal requirement before processing, unless the law prohibits doing so on important grounds of public interest.

4.2 Customer's complete and documented instructions consist of: (a) the Agreement and this DPA; (b) Customer's and its Authorized Users' use of the Services and their features and settings; and (c) any additional written instructions agreed between the parties. Senova may charge a reasonable fee for compliance with additional instructions that require materially different or additional processing beyond the Services.

4.3 Senova will immediately inform Customer if, in Senova's opinion, an instruction infringes the GDPR, the UK GDPR, or other Data Protection Laws. Senova may suspend performance of such an instruction until it is confirmed or modified.

4.4 No training. Senova will not use Customer Personal Data to train, retrain, or improve machine-learning or AI models (whether Senova's own or any third party's), and will contractually require the same of its Sub-processors that process Customer Personal Data for model inference, except with Customer's prior written consent.

5. Confidentiality of personnel

Senova will ensure that all persons it authorizes to process Customer Personal Data (including employees and contractors) are bound by written or statutory obligations of confidentiality, are informed of the confidential nature of the Customer Personal Data, and receive appropriate training on their responsibilities. Access is limited to personnel who need it to perform the Services.

6. Security

6.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Senova will implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR, including as appropriate the measures described in Annex II.

6.2 Senova may update the measures in Annex II from time to time, provided the updates do not materially reduce the overall level of protection of Customer Personal Data during the term of the Agreement.

7. Sub-processing

7.1 General authorization. Customer grants Senova general written authorization to engage Sub-processors to process Customer Personal Data, subject to this Section 7. The Sub-processors engaged as of the Effective Date are listed in Annex III and on Senova's published Subprocessors page at senova.studio/subprocessors (the "Subprocessors Page"), which forms part of this DPA.

7.2 Notice of changes. Senova will update the Subprocessors Page and provide Customer with notice (via the Subprocessors Page notification mechanism, email to Customer's account or designated contact, or in-app notice) at least 30 days before authorizing any new Sub-processor to process Customer Personal Data. Customer is responsible for subscribing to the notification mechanism where offered.

7.3 Right to object. Customer may object to a new Sub-processor on reasonable, data-protection-related grounds by notifying privacy@senova.studio in writing within 30 days of Senova's notice. The parties will discuss the objection in good faith and Senova will use reasonable efforts to offer an alternative (for example, a configuration change avoiding the Sub-processor). If no resolution is reached within 30 days of the objection, Customer may, as its sole remedy, terminate the affected Services (or, if they cannot be separated, the Agreement) on written notice, and Senova will refund any prepaid fees for the period after the effective date of termination.

7.4 Flow-down and liability. Senova will enter into a written contract with each Sub-processor imposing data protection obligations that are, in substance, no less protective of Customer Personal Data than those in this DPA (including as required by Article 28(4) GDPR), to the extent applicable to the services the Sub-processor provides. Senova remains fully liable to Customer for the performance of each Sub-processor's obligations.

8. Assistance with Data Subject rights

8.1 Taking into account the nature of the processing, Senova will assist Customer, by appropriate technical and organizational measures and insofar as this is possible, in fulfilling Customer's obligation to respond to Data Subjects' requests to exercise their rights (including access, rectification, erasure, restriction, portability, and objection, and equivalent rights under the CCPA and other Data Protection Laws). In the first instance, Customer can retrieve, correct, and delete Customer Content through the Services' standard functionality.

8.2 If Senova receives a request from a Data Subject that identifies Customer Personal Data, Senova will promptly forward it to Customer and will not respond to it except to acknowledge receipt and direct the Data Subject to Customer, unless required by law.

9. Assistance with Articles 32–36

Taking into account the nature of processing and the information available to Senova, Senova will provide reasonable assistance to Customer in ensuring compliance with Customer's obligations under Articles 32 to 36 GDPR (and equivalent provisions of other Data Protection Laws), including security of processing, Personal Data Breach notification to Supervisory Authorities and Data Subjects, data protection impact assessments, and prior consultation with Supervisory Authorities. Senova may charge a reasonable fee for assistance that is materially beyond the standard functionality and documentation of the Services, and will notify Customer of any such fee in advance.

10. Personal Data Breach notification

10.1 Senova will notify Customer without undue delay, and in any event no later than 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notice will be sent to the email address(es) associated with Customer's account or designated in Annex I.

10.2 The notification will, to the extent then known (and supplemented as information becomes available): (a) describe the nature of the breach, including where possible the categories and approximate number of Data Subjects and records concerned; (b) provide the name and contact details of Senova's point of contact; (c) describe the likely consequences of the breach; and (d) describe the measures taken or proposed to address the breach and mitigate its possible adverse effects.

10.3 Senova will take reasonable steps to contain, investigate, and remediate the breach, will document it as required by Article 33(5) GDPR, and will cooperate with Customer's reasonable requests for information. Senova's notification of, or response to, a Personal Data Breach is not an acknowledgment of fault or liability. As between the parties, Customer is responsible for any legally required notifications to Supervisory Authorities and Data Subjects, unless otherwise agreed.

11. Return and deletion of Customer Personal Data

11.1 During the term, Customer may retrieve or delete Customer Content through the Services' standard functionality.

11.2 Upon termination or expiry of the Agreement, Senova will, at Customer's choice, delete or return all Customer Personal Data, and delete existing copies, unless applicable law requires storage of the Personal Data (in which case Senova will isolate and protect it from further processing except as required by that law). Absent a written election by Customer within 30 days of termination, Senova will delete Customer Personal Data.

11.3 Deletion will be completed within 60 days of termination (or of Customer's deletion instruction), with residual copies in encrypted backups deleted on Senova's standard backup rotation and in any event within a further 35 days. On request, Senova will confirm deletion in writing.

12. Audits and information rights

12.1 Senova will make available to Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer.

12.2 The parties agree that audit rights will in the first instance be satisfied by Senova providing, on written request: (a) this DPA and the current Annexes; (b) the Subprocessors Page; (c) summaries of Senova's security measures, policies, and any available third-party audit reports or certifications (which are Senova's Confidential Information); and (d) written responses to reasonable security questionnaires (no more than once per 12-month period).

12.3 If the information in Section 12.2 is not reasonably sufficient to demonstrate compliance, or where an audit is required by a Supervisory Authority or Data Protection Laws, Customer may conduct an audit subject to the following: (a) at least 30 days' prior written notice (except where a Supervisory Authority requires otherwise); (b) no more than once per 12-month period, except following a Personal Data Breach affecting Customer Personal Data or where required by a Supervisory Authority; (c) during normal business hours, without unreasonable disruption to Senova's operations, and subject to Senova's reasonable security and confidentiality requirements; (d) not extending to other customers' data or to Sub-processors' facilities (Sub-processor compliance being addressed through Senova's own audit and diligence rights); and (e) each party bearing its own costs, provided Senova may charge reasonable fees for audit support exceeding one business day of personnel time. Customer will provide Senova a copy of audit findings relevant to Senova.

13. International transfers

13.1 Senova will not transfer Customer Personal Data originating in the EEA, the UK, or Switzerland to a country not recognized as providing an adequate level of protection unless a valid transfer mechanism under Data Protection Laws is in place.

13.2 EU SCCs. To the extent Customer Personal Data is transferred from the EEA to Senova in a third country without an adequacy decision, the EU SCCs are incorporated into this DPA and apply as follows:

13.3 UK Addendum. To the extent Customer Personal Data is transferred from the UK to Senova in a third country without UK adequacy regulations, the UK Addendum is incorporated and amends the EU SCCs as it specifies: Table 1 is completed with the parties' details in Annex I.A; Table 2 refers to the EU SCCs as completed in Section 13.2; Table 3 refers to Annexes I–III of this DPA; and for Table 4, either party may end the UK Addendum as set out in Section 19 of the UK Addendum.

13.4 Switzerland. To the extent the FADP applies to a transfer, the EU SCCs apply as adapted: references to the GDPR are understood as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; the term "member state" is not interpreted to exclude Swiss Data Subjects from enforcing their rights in Switzerland; and the EU SCCs also protect the data of legal entities where and until required by the FADP.

13.5 Order of application. If the EU SCCs or UK Addendum conflict with this DPA or the Agreement, the EU SCCs or UK Addendum prevail to the extent of the conflict. If a transfer mechanism relied on under this Section 13 is invalidated or superseded, the parties will cooperate in good faith to implement a valid replacement mechanism promptly.

14. CCPA — Service Provider terms

To the extent the CCPA applies to Customer Personal Data, the parties agree that Customer discloses Customer Personal Data to Senova solely for the Business Purposes described in Annex I and the Agreement, and that Senova acts as a Service Provider. Senova will not, and certifies that it understands the restrictions in this Section 14 and will not:

(a) Sell or Share Customer Personal Data;

(b) retain, use, or disclose Customer Personal Data for any purpose other than the Business Purposes specified in the Agreement and this DPA (including retaining, using, or disclosing it for a commercial purpose other than providing the Services), or as otherwise permitted for service providers under the CCPA;

(c) retain, use, or disclose Customer Personal Data outside of the direct business relationship between Senova and Customer; or

(d) combine Customer Personal Data with personal information received from or on behalf of another person, or collected from Senova's own interactions with consumers, except as permitted for service providers under the CCPA.

Senova will: comply with applicable obligations under the CCPA and provide the same level of privacy protection as required of Businesses; notify Customer promptly if it determines it can no longer meet its obligations under the CCPA; grant Customer the right, upon reasonable notice, to take reasonable and appropriate steps to ensure Senova uses Customer Personal Data consistently with Customer's CCPA obligations and to stop and remediate any unauthorized use; and reasonably assist Customer in responding to verifiable consumer requests. The parties acknowledge that the disclosure of Customer Personal Data to Senova is not part of, and is not exchanged for, any monetary or other valuable consideration.

15. Liability

Each party's and its affiliates' aggregate liability arising out of or relating to this DPA (including the EU SCCs and UK Addendum, to the extent permitted by them), whether in contract, tort, or otherwise, is subject to the exclusions and limitations of liability set out in the Agreement, and any such liability counts toward (and does not enlarge) the liability cap in the Agreement. Nothing in this Section 15 limits: (a) liability that cannot be limited under applicable law; or (b) a Data Subject's rights against either party, including under Clause 12 of the EU SCCs and Article 82 GDPR.

16. Term, precedence, and general

16.1 Term. This DPA takes effect on the Effective Date and remains in force for as long as Senova processes Customer Personal Data under the Agreement, and thereafter until deletion or return under Section 11 is complete.

16.2 Order of precedence. In case of conflict regarding the processing of Customer Personal Data: (1) the EU SCCs and UK Addendum prevail over (2) this DPA, which prevails over (3) the Agreement and any other terms. In all other respects the Agreement remains unchanged and in full force.

16.3 Updates for legal compliance. Senova may update this DPA where reasonably necessary to reflect changes in Data Protection Laws or approved transfer mechanisms, provided the updates do not materially reduce the protections for Customer Personal Data; Senova will give notice of material updates.

16.4 Severability. If any provision of this DPA is held invalid or unenforceable, the remainder remains in effect, and the invalid provision will be replaced by a valid one that most closely reflects its intent.

16.5 Governing law. This DPA is governed by the laws governing the Agreement — the State of New Jersey, United States — except where the EU SCCs or UK Addendum mandatorily require otherwise (see Sections 13.2 and 13.3).

Signature block

AGREED by the parties' authorized representatives:

Customer
Legal entity name: ______________________________
Signature: ______________________________
Name: ______________________________
Title: ______________________________
Date: ______________________________
Notice email for breach and Sub-processor notices: ______________________________

Senova
Signature: ______________________________
Name: ______________________________
Title: Senova (authorized signatory)
Date: ______________________________

Annex I — Details of Processing

A. List of parties

Data exporter (Customer):

Data importer (Senova):

B. Description of processing / transfer

Categories of Data Subjects:

Categories of Personal Data:

Special categories of data: none intended. Customer must not submit special categories of Personal Data (Article 9 GDPR), criminal-offence data, or comparably sensitive data unless expressly agreed in writing with additional safeguards (see Section 2.2). Note also the restrictions in Senova's Acceptable Use Policy, including on uploading other people's likenesses without permission.

Frequency of the transfer/processing: continuous, for the duration of the Agreement, as initiated by Customer's use of the Services.

Nature and purpose of the processing: collection, storage, retrieval, transmission to model-inference Sub-processors, generation of derived media outputs, hosting and making available to Customer, deletion — solely to provide, secure, maintain, and support the Services under the Agreement.

Duration of processing and retention: the term of the Agreement, plus the deletion period in Section 11 of the DPA.

Transfers to Sub-processors: as described in Annex III and the Subprocessors Page; the subject matter, nature, and duration of Sub-processor processing correspond to the function each Sub-processor performs (payment processing, model inference, hosting/compute, object storage, network/DNS/email services) for the duration above.

C. Competent Supervisory Authority

The Supervisory Authority determined in accordance with Clause 13 of the EU SCCs: the competent supervisory authority determined under the SCCs. For UK transfers, the UK Information Commissioner's Office.

Annex II — Technical and Organizational Security Measures

Senova implements and maintains, and requires its infrastructure Sub-processors to maintain, the following measures, in each case as appropriate to the risk and updated per Section 6.2:

  1. Encryption. Encryption of Customer Personal Data in transit using TLS 1.2 or higher; encryption at rest for databases and object storage.
  2. Access control. Role-based access on a least-privilege, need-to-know basis; unique accounts; multi-factor authentication required for access to production infrastructure and administrative systems; timely revocation of access on role change or departure.
  3. Network and infrastructure security. Segregated production environment; firewalling and restricted ingress; hardened configurations; secrets management (no credentials in code).
  4. Logging and monitoring. Logging of administrative and production access and security-relevant events; monitoring and alerting for anomalous activity.
  5. Vulnerability management and secure development. Dependency and vulnerability scanning; timely patching prioritized by severity; code review for changes to production systems.
  6. Data segregation. Logical separation of Customer data from other customers' data via per-account identifiers and access controls.
  7. Backups and resilience. Regular encrypted backups; documented restore procedures; hosting on providers with redundant infrastructure (see Annex III).
  8. Incident response. A documented incident response process covering detection, escalation, containment, remediation, and the notification obligations in Section 10.
  9. Personnel. Confidentiality obligations for all personnel (Section 5); security and privacy training; background screening where permitted by law and proportionate to role.
  10. Vendor management. Risk-based diligence of Sub-processors, written data protection terms (Section 7.4), and periodic review of Sub-processors' security documentation and certifications.
  11. Physical security. Physical and environmental security of data centers is provided by Senova's cloud infrastructure Sub-processors (Annex III), which maintain industry-standard certifications for their facilities.
  12. Data minimization and deletion. Retention limited per Annex I.B and Section 11; standard tooling for Customer-initiated deletion of Customer Content.

Annex III — Sub-processors

Senova's current, authoritative list of Sub-processors — including entity names, functions, and processing locations — is published and kept up to date at senova.studio/subprocessors, which is incorporated into this DPA. As of the Effective Date, the Sub-processors are:

Sub-processorFunctionLocation
StripePayment processing (payment data is collected directly by Stripe)United States
fal.aiAI model inference (processing of prompts and inputs to generate outputs)United States
AnthropicAI processing of prompt text (prompt classification, planning, and content moderation)United States
Fly.ioApplication hosting and computeUnited States
Tigris DataObject storage (uploaded inputs and generated outputs)United States
CloudflareDNS, content delivery, network security, and email routingGlobal (edge network)

Mechanisms for notice of changes and Customer's objection rights are set out in Sections 7.2 and 7.3 of this DPA.