Skip to main content

Legal

Data Processing Agreement

Last updated: September 21, 2026

This Data Processing Agreement (DPA) forms part of the Terms of Service between you (the Customer) and PrismLabs OÜ (PrismPoster) whenever PrismPoster processes personal data on your behalf. It applies automatically to every account, including free accounts; no separate signature is required. Business customers who need a countersigned copy for their records can request one at the address in section 12.

1. Parties and roles

For personal data contained in the prompts, reference media, uploaded footage, audio, lyrics, and project files you submit to the Service (together, Customer Content), you are the controller and PrismLabs OÜ, registry code 17538933, Sepapaja tn 6, 15551 Tallinn, Harju County, Estonia, is the processor within the meaning of Article 4 of Regulation (EU) 2016/679 (the GDPR) and the UK GDPR.

For account, billing, security, and usage data that PrismPoster needs to run the Service itself, PrismPoster acts as an independent controller. That processing is described in our Privacy Policy and is outside this DPA.

2. Details of the processing

  • Subject matter: generation, editing, storage, rendering, and export of images, video, and music from Customer Content using the Service.
  • Duration: the term of your account, plus the deletion periods in section 9.
  • Nature and purpose: receiving Customer Content, transmitting it to the AI generation and rendering sub-processors listed in Annex III, storing the inputs and outputs in your Library, and returning finished exports to you. There is no other purpose.
  • Categories of data subjects: you, your staff and contractors who use the account, and any individual who appears in or is described by Customer Content (for example a person in uploaded footage or a reference photo).
  • Categories of personal data: names, likenesses, voices, and any other personal data you choose to include in Customer Content.

3. No model training on your content

PrismPoster does not use Customer Content, generated outputs, or prompts to train, fine-tune, or otherwise improve any machine-learning model, and there is no setting that enables it. We do not build or train models. Customer Content is sent to a generation provider only to produce the output you requested, and the result is stored only for you.

The generation sub-processors we rely on are bound by their own terms to the same restriction. Google Cloud states that it will not use customer data to train or fine-tune any AI/ML model without the customer’s prior permission or instruction, and BytePlus’ AI Services terms provide that it will not use customer data to train the foundation models underlying its AI services. The music generation provider is licensed to process your inputs solely to operate its service and deletes generated files from its systems 14 days after generation. The current provider list and each provider’s role are maintained on our Sub-Processors page.

We may use aggregated, de-identified operational metrics (such as counts of generations per model or average render time) to run and improve the Service. These metrics never contain Customer Content.

4. Processor obligations

PrismPoster will:

  • process Customer Content only on your documented instructions, which are the Terms of Service, this DPA, and the actions you take in the product; and inform you if we believe an instruction infringes data-protection law;
  • ensure that every person authorised to process Customer Content is bound by a duty of confidentiality;
  • implement the technical and organisational measures in Annex II and keep them appropriate to the risk;
  • engage sub-processors only under section 6;
  • assist you, taking into account the nature of the processing, in responding to data-subject requests (section 8) and in meeting your obligations under Articles 32 to 36 of the GDPR, including data-protection impact assessments;
  • delete or return Customer Content at the end of the service under section 9; and
  • make available the information necessary to demonstrate compliance with Article 28 and allow for audits under section 10.

5. Security

PrismPoster maintains the measures described in Annex II and on our Security page, including TLS 1.3 in transit, encryption at rest with every storage provider, scoped credentials, row-level access control on the database, rate limiting, origin checks, and audit logging. We will not reduce the overall level of protection during the term of this DPA.

6. Sub-processors

You give general written authorisation for PrismPoster to engage the sub-processors listed on the Sub-Processors page (Annex III). Each is bound by a written contract imposing data-protection obligations at least as protective as this DPA, and PrismPoster remains fully liable to you for their performance.

We will update that page at least 30 days before a new sub-processor begins processing Customer Content. If you object on reasonable data-protection grounds within that period, we will work with you in good faith on an alternative; if none is available, you may terminate the affected part of the Service and receive a pro-rata refund of any prepaid, unused fees for it.

7. International transfers

Customer Content is stored in the European Union (database in Ireland; object storage with Cloudflare R2). Generation providers process it in the locations shown on the Sub-Processors page. Where a transfer leaves the EEA or the United Kingdom, PrismPoster relies on an adequacy decision (including the EU-US Data Privacy Framework where the provider is certified) or on the European Commission’s Standard Contractual Clauses (Module 3, processor to processor) and the UK International Data Transfer Addendum, together with a transfer impact assessment.

8. Data-subject requests and breach notice

If we receive a request from a data subject concerning Customer Content, we will forward it to you without responding, unless the law requires us to respond directly. You can serve most requests yourself with the export and deletion controls in Settings.

We will notify you without undue delay, and in any case within 72 hours of becoming aware of a personal-data breach affecting Customer Content, with the information available to us at that time, and we will keep you updated as the investigation proceeds.

9. Deletion and return

You can export or delete any project, generation, or Library item at any time. When you delete your account, Customer Content is deleted from the live systems as part of the deletion workflow and from backups on their normal rotation, generally within 30 days. Generation providers retain inputs only for the short operational windows shown on the Sub-Processors page. PrismPoster keeps only what the law requires it to keep (billing and legal records), which does not include Customer Content.

10. Audit

Once per year, or after a breach affecting your data, you may request written evidence of our compliance with this DPA, including our current security measures, sub-processor contracts (redacted for confidentiality), and the results of any third-party assessment we hold. Where that evidence is not sufficient to satisfy a legal obligation on your side, you may conduct an audit on reasonable notice, during business hours, at your cost, and without disrupting the Service or exposing other customers’ data.

11. Liability, term, and law

Each party’s liability under this DPA is subject to the limitation of liability in the Terms of Service, except where the GDPR does not permit that limitation. This DPA lasts as long as PrismPoster processes Customer Content for you. It is governed by the law of Estonia, and where this DPA and the Terms conflict on a data-protection matter, this DPA prevails.

12. Countersigned copies and contact

This DPA is incorporated by reference into the Terms of Service and binds both parties from the moment you use the Service. If your procurement or compliance process needs a dated, countersigned PDF, email dpo@prismposter.com with your legal entity name and address and we will return one. Data-protection questions go to privacy@prismposter.com.

Annex I — Processing details

As set out in section 2 above.

Annex II — Technical and organisational measures

  • Transport encryption: HTTPS with TLS 1.3 for every request.
  • Encryption at rest: database (Supabase), object storage (Cloudflare R2), and cache (Upstash) are encrypted at rest by the respective providers.
  • Access control: row-level security on every customer table; scoped, per-service credentials; least-privilege API tokens; founder-only administrative access.
  • Application security: CSRF protection, per-request Content Security Policy on authenticated routes, origin checks, rate limiting, and server-side ownership checks on every media operation.
  • Monitoring: error and performance telemetry with EU data residency; audit logging of administrative actions.
  • Resilience: append-only, content-addressed archive of customer media in a separate private bucket with dedicated credentials; no deletion lifecycle.
  • Deletion: external storage objects are removed before the database forgets them; account deletion workflow with backup purge on rotation.
  • Vulnerability handling: coordinated disclosure via the address on the Security page.

Annex III — Sub-processors

The authorised sub-processors, their purpose, and their processing locations are listed on the Sub-Processors page, which forms part of this DPA.