These Data Processing Terms are a separate document incorporated into the Autopix Terms and Conditions (the "Terms") by clause 10.3 of the Terms. They are presented with the Terms and accepted in the same click. Together with the Terms they constitute the contract required by Art. 28(3) GDPR between Autopix AS, organisation number 926 408 763, Gaustadalléen 21, 0349 Oslo, Norway ("Autopix", the processor) and each Customer (the controller) for personal data in Customer Content.
Three mechanics, stated up front:
A.1.1 These Data Processing Terms govern all processing of personal data in Customer Content by Autopix on the Customer's behalf. The Customer is the controller; Autopix is the processor (Art. 4(7)–(8), Art. 28 GDPR).
A.1.2 Autopix is established in Norway. Norway is a party to the Agreement on the EEA, so the GDPR applies to Autopix through the EEA Agreement. The competent supervisory authority for Autopix is Datatilsynet, the Norwegian Data Protection Authority.
A.1.3 "Personal data", "processing", "sub-processor" and "personal data breach" have the meanings in Art. 4 GDPR.
Art. 28(3) — mandatory particulars.
Subject matter
Personal data in Customer Content, processed to deliver the Platform services — ingest, storage, the image pipeline, QC, delivery, sharing, invitations, exports and related support
Duration
While the Customer uses the Platform, plus the deletion period in clause A.12
Nature
Hosting and storage; programmatic preprocessing; AI segmentation; machine-learning computer vision; programmatic alignment; compositing onto templates; optional human editing and QC by a sub-processor; transmission to integrations the Customer has connected
Purpose
Producing edited images and running the related order, QC, distribution and account workflow, only on the Customer's documented instructions (Art. 28(3)(a))
Types of personal data
Vehicle images and original file names; vehicle identification numbers ("VIN") and registration plates (personal data under Art. 4(1)); order metadata; organisation and location records; invitation recipient email addresses; share recipient email addresses (used transiently to send mail and never stored)
Categories of data subjects
The Customer's staff and other Users, in the content they create; individuals appearing indirectly in Customer Content — for example vehicle buyers, sellers and owners — in identifiers, image content, file names or free text; invitation and share recipients
Special categories
None. The Customer must not upload special category data (clause 4.2 of the Terms), and Autopix performs no face detection, classification or matching of individuals — Art. 9 GDPR is not engaged
A.3.1 Autopix processes Customer personal data only on the Customer's documented instructions, including for transfers to a third country, unless required to process by EEA or Norwegian law — in which case Autopix informs the Customer of that legal requirement before processing, unless the law prohibits that on important grounds of public interest (Art. 28(3)(a)).
A.3.2 Documented instructions are: the Terms, including these Data Processing Terms; the package and storage terms the Customer accepts; configuration and elections made in the Platform by the Customer's authorised Users; and written instructions (including email) from the Customer.
A.3.3 Autopix informs the Customer immediately if, in Autopix's opinion, an instruction infringes the GDPR or other applicable data protection law (Art. 28(3), final paragraph).
Autopix does not use Customer Content or Output to train machine-learning models for its own purposes.
A.5.1 Autopix implements the following technical and organisational measures, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing (Art. 32(1)):
A.5.2 Autopix will not materially reduce the overall level of security described in this clause during a paid term (clause 2.7 of the Terms).
Autopix ensures that every person authorised to process Customer personal data has committed themselves to confidentiality in writing before access is granted (Art. 28(3)(b)).
A.7.1 The Customer gives Autopix general written authorisation (Art. 28(2)) to engage the sub-processors listed in Schedule 1 Part A, and to engage further sub-processors under clause A.7.3.
A.7.2 Autopix imposes on each sub-processor data-protection obligations equivalent to those in these Data Processing Terms, so far as they apply to that sub-processor's processing (Art. 28(4)).
A.7.3 Changes. Autopix may add or replace a sub-processor by updating Schedule 1 Part A and giving account holders at least 30 days' notice by email before the new sub-processor begins processing Customer personal data. The Customer may object on reasonable data-protection grounds within that notice period. If the parties cannot resolve the objection, the Customer may terminate the affected service as its sole remedy under this clause.
A.8.1 Primary hosting and processing is in the EEA (AWS eu-central-1, Frankfurt), in Autopix's own AWS account.
A.8.2 Where Customer personal data leaves the EEA — or a third-country entity has remote access that counts as a transfer under EDPB Guidelines 05/2021 — Autopix relies on a Chapter V GDPR mechanism: an adequacy decision (Art. 45), Standard Contractual Clauses ("SCCs", Art. 46(2)(c)), or the EU–US Data Privacy Framework. The mechanism for each sub-processor is stated in Schedule 1 Part A.
A.9.1 Taking into account the nature of the processing, Autopix assists the Customer by appropriate technical and organisational measures in fulfilling the Customer's obligations to respond to data subject requests under Arts. 12–23 GDPR (Art. 28(3)(e)). Assistance is normally provided within 10 business days of the Customer's request. The Platform also provides per-user self-service export and a company-level export for company administrators.
A.9.2 If a data subject contacts Autopix directly about personal data in Customer Content, Autopix refers the request to the Customer without undue delay and does not answer it on the Customer's behalf, except on the Customer's instruction or where required by law.
A.10.1 Autopix notifies the affected Customer without undue delay, and in any event within 24 hours, after becoming aware of a personal data breach affecting Customer personal data (Art. 33(2)), with the information reasonably available at that time, supplemented as further information becomes known.
A.10.2 Autopix assists the Customer with the Customer's obligations under Arts. 33–34 GDPR — notification to the supervisory authority and communication to data subjects — taking into account the nature of the processing and the information available to Autopix (Art. 28(3)(f)).
Autopix provides reasonable assistance with data protection impact assessments and prior consultation of the supervisory authority (Arts. 35–36 GDPR), taking into account the nature of the processing and the information available to Autopix (Art. 28(3)(f)).
A.12.1 During the term, Customer Content is deleted on the plan-based schedule in clause 6.2 of the Terms. Deletion is genuine: image files, including thumbnails and variants, are permanently deleted from storage, and database records are hard-deleted.
A.12.2 At the end of services, Autopix's default is to delete the Customer's personal data. The Customer has 30 days from the effective end of services to instruct Autopix in writing to return a copy first (using the Platform's export routes), after which deletion proceeds.
A.12.3 Deleted data ages out of database backups within 7 days of the deletion running, because backups are retained for 7 days.
A.12.4 Retention required by law. Autopix retains: the immutable billing ledger (5 years, bokføringsloven § 13); agreement documents and acceptance evidence (end of contract + 5 years, for the establishment, exercise or defence of legal claims — Art. 17(3)(e)); and audit logs (2 years). Retained data remains protected under these Data Processing Terms.
A.12.5 Deletion under this clause covers all Customer personal data, including company assets such as logos, plate images and reference images.
A.13.1 Autopix makes available to the Customer the information necessary to demonstrate compliance with Art. 28 GDPR. The default route is documentation and written responses to a reasonable security and privacy questionnaire.
A.13.2 The Customer (or an independent auditor bound by confidentiality) may audit or inspect, on these conditions:
A.14.1 Liability under these Data Processing Terms is subject to clause 12 of the Terms, except that nothing limits liability that cannot be limited under applicable law.
A.14.2 On any matter of personal data protection under Art. 28 GDPR, these Data Processing Terms prevail over the body of the Terms (clause 1.6 of the Terms).
Art. 28(2) and 28(4). Twelve rows. This is the same list as the Autopix privacy policy, section 7.
Autopix does not use a third-party application performance or error-tracking product (for example Sentry, Bugsnag or Flare). API observability, including capture of error responses in API payloads, is provided by Treblle (row 8).
Informational. These are not Autopix sub-processors under Art. 28 GDPR.