Data Processing Agreement
How PurifyAI handles personal data under the GDPR and UK GDPR, what we process, who our sub-processors are, and the rights you can exercise.
The short version
- Your media is never processed by us โ it is handled entirely in your browser, so it is outside this agreement by design.
- We process only account data: your email, a password hash, and subscription status.
- Three sub-processors: Stripe (payments), Vercel (hosting), and our transactional email provider.
- You can export or delete all of your data at any time, and we respond within 30 days.
1. Roles
For account data (registration, billing, support correspondence) PurifyAI Studio is the data controller. Where you use the service on behalf of an organisation and upload personal data into support tickets, we act as processor for that content and this agreement governs it.
2. The critical exclusion: your media
Media you scrub is never transmitted to us. Processing happens with JavaScript running in your own browser tab, and there is no upload endpoint. We therefore never become a controller or processor of the personal data contained in your images and video. This materially reduces your own compliance exposure when handling client media, and you can verify it by inspecting network traffic during a scrub.
3. Categories of data we do process
Limited to what is required to run an account:
- Identity and contact โ name and email address you provide at registration.
- Authentication โ a salted password hash. We never store plaintext passwords.
- Subscription โ plan, quota usage counters, and billing status from Stripe.
- Support โ the content of messages you send us, retained for 24 months.
- Technical โ server logs including IP address and user agent, retained for 30 days.
4. Purposes and lawful basis
Account data is processed to perform our contract with you (Article 6(1)(b)). Security logging and abuse prevention rely on legitimate interests (Article 6(1)(f)). Marketing email, where you receive it, relies on your consent (Article 6(1)(a)) and can be withdrawn at any time.
5. Sub-processors
We use the following sub-processors, and will give 30 days notice before adding any new one so you can object:
- Stripe โ payment processing and invoicing. Handles card data directly; we never receive card numbers.
- Vercel โ application hosting and edge delivery.
- Transactional email provider โ account verification, password reset and billing receipts.
6. International transfers
Where personal data leaves the EEA or UK, transfers are covered by the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, plus supplementary technical measures including encryption in transit and at rest.
7. Security measures
TLS 1.3 in transit, encryption at rest, salted password hashing, least-privilege access controls with audit logging, and a documented incident response process. We notify you without undue delay, and within 72 hours where feasible, of any breach affecting your personal data.
8. Retention and deletion
Account data is retained for the life of your account. On deletion, personal data is erased within 30 days except where retention is legally required โ invoices, for example, are kept for the statutory period. Backups age out within 90 days.
9. Your rights
Under the GDPR and UK GDPR you have the right to access, rectify, erase, restrict and port your data, to object to processing, and to withdraw consent. Exercise any of these at privacy@purifyai.app โ we respond within 30 days at no cost. You may also complain to your national supervisory authority.
10. Audit and signed copies
Enterprise and Agency customers may request a countersigned DPA and reasonable audit information. Contact legal@purifyai.app.