How these terms bind

These Data Processing Terms are a separate document incorporated into the Autopix Terms and Conditions (the "Terms") by clause 10.3 of the Terms. They are presented with the Terms and accepted in the same click. Together with the Terms they constitute the contract required by Art. 28(3) GDPR between Autopix AS, organisation number 926 408 763, Gaustadalléen 21, 0349 Oslo, Norway ("Autopix", the processor) and each Customer (the controller) for personal data in Customer Content.

Three mechanics, stated up front:

  1. Definitions carry over. "Customer", "User", "Customer Content",
    "Output", "Platform", "QC", "EEA" and "GDPR" have the meanings given in clause 1.7 of the Terms. References to numbered clauses "of the Terms" are to the Terms and Conditions.
  2. Numbering. Clauses here are numbered A.1 to A.14, and the
    sub-processor list is Schedule 1. The "A." prefix is kept so that references from the Terms and the privacy policy are unambiguous.
  3. Precedence and overrides. On any matter of personal data
    protection under Art. 28 GDPR, these Data Processing Terms prevail over the body of the Terms (clause 1.6 of the Terms). Where Autopix and a Customer have entered into a separately signed agreement covering the processing of personal data, that agreement prevails over these Data Processing Terms for that Customer (clause 10.4 of the Terms). Changes to these Data Processing Terms follow clause 13 of the Terms; changes to the sub-processor list follow clause A.7.3.

A.1 Scope and roles

A.1.1 These Data Processing Terms govern all processing of personal data in Customer Content by Autopix on the Customer's behalf. The Customer is the controller; Autopix is the processor (Art. 4(7)–(8), Art. 28 GDPR).

A.1.2 Autopix is established in Norway. Norway is a party to the Agreement on the EEA, so the GDPR applies to Autopix through the EEA Agreement. The competent supervisory authority for Autopix is Datatilsynet, the Norwegian Data Protection Authority.

A.1.3 "Personal data", "processing", "sub-processor" and "personal data breach" have the meanings in Art. 4 GDPR.

A.2 Details of the processing

Art. 28(3) — mandatory particulars.

Subject matter

Personal data in Customer Content, processed to deliver the Platform services — ingest, storage, the image pipeline, QC, delivery, sharing, invitations, exports and related support

Duration

While the Customer uses the Platform, plus the deletion period in clause A.12

Nature

Hosting and storage; programmatic preprocessing; AI segmentation; machine-learning computer vision; programmatic alignment; compositing onto templates; optional human editing and QC by a sub-processor; transmission to integrations the Customer has connected

Purpose

Producing edited images and running the related order, QC, distribution and account workflow, only on the Customer's documented instructions (Art. 28(3)(a))

Types of personal data

Vehicle images and original file names; vehicle identification numbers ("VIN") and registration plates (personal data under Art. 4(1)); order metadata; organisation and location records; invitation recipient email addresses; share recipient email addresses (used transiently to send mail and never stored)

Categories of data subjects

The Customer's staff and other Users, in the content they create; individuals appearing indirectly in Customer Content — for example vehicle buyers, sellers and owners — in identifiers, image content, file names or free text; invitation and share recipients

Special categories

None. The Customer must not upload special category data (clause 4.2 of the Terms), and Autopix performs no face detection, classification or matching of individuals — Art. 9 GDPR is not engaged

A.3 Instructions

A.3.1 Autopix processes Customer personal data only on the Customer's documented instructions, including for transfers to a third country, unless required to process by EEA or Norwegian law — in which case Autopix informs the Customer of that legal requirement before processing, unless the law prohibits that on important grounds of public interest (Art. 28(3)(a)).

A.3.2 Documented instructions are: the Terms, including these Data Processing Terms; the package and storage terms the Customer accepts; configuration and elections made in the Platform by the Customer's authorised Users; and written instructions (including email) from the Customer.

A.3.3 Autopix informs the Customer immediately if, in Autopix's opinion, an instruction infringes the GDPR or other applicable data protection law (Art. 28(3), final paragraph).

A.4 Purpose limitation

Autopix does not use Customer Content or Output to train machine-learning models for its own purposes.

A.5 Security (Art. 32)

A.5.1 Autopix implements the following technical and organisational measures, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing (Art. 32(1)):

  1. Encryption. TLS 1.2 minimum in transit on all endpoints;
    encryption at rest for object storage, cache and databases, with encrypted database snapshots (AWS-managed keys); field-level encryption of integration credentials.
  2. Storage. Private object storage with no public objects; upload
    and download by time-limited presigned links only (upload links: 15 minutes).
  3. Integrity. Inbound webhooks verified with HMAC-SHA256
    signatures, timestamp and event-ID replay protection; rate limits across the API surface.
  4. Logging. Audit logging of security-relevant actions carrying
    actor, IP address and user agent, retained for two years; privileged access to Customer Content is logged; resolution of QC and public share links is logged.
  5. Backups. Encrypted database snapshots retained for 7 days, with
    a documented restore procedure that has been tested.
  6. Vulnerability management. Dependency scanning (`composer
    auditandnpm audit`) on every deploy; patching of critical vulnerabilities within 7 days and high-severity vulnerabilities within 30 days; a pre-go-live security review.
  7. Personnel. Written confidentiality undertakings (clause A.6);
    a documented access-removal procedure with explicit token revocation when personnel leave or change role; Customer Content handled on company-owned machines only, with local copies deleted when the task is done and in any case within 14 days of download.

A.5.2 Autopix will not materially reduce the overall level of security described in this clause during a paid term (clause 2.7 of the Terms).

A.6 Confidentiality of personnel

Autopix ensures that every person authorised to process Customer personal data has committed themselves to confidentiality in writing before access is granted (Art. 28(3)(b)).

A.7 Sub-processors

A.7.1 The Customer gives Autopix general written authorisation (Art. 28(2)) to engage the sub-processors listed in Schedule 1 Part A, and to engage further sub-processors under clause A.7.3.

A.7.2 Autopix imposes on each sub-processor data-protection obligations equivalent to those in these Data Processing Terms, so far as they apply to that sub-processor's processing (Art. 28(4)). 

A.7.3 Changes. Autopix may add or replace a sub-processor by updating Schedule 1 Part A and giving account holders at least 30 days' notice by email before the new sub-processor begins processing Customer personal data. The Customer may object on reasonable data-protection grounds within that notice period. If the parties cannot resolve the objection, the Customer may terminate the affected service as its sole remedy under this clause.

A.8 International transfers

A.8.1 Primary hosting and processing is in the EEA (AWS eu-central-1, Frankfurt), in Autopix's own AWS account.

A.8.2 Where Customer personal data leaves the EEA — or a third-country entity has remote access that counts as a transfer under EDPB Guidelines 05/2021 — Autopix relies on a Chapter V GDPR mechanism: an adequacy decision (Art. 45), Standard Contractual Clauses ("SCCs", Art. 46(2)(c)), or the EU–US Data Privacy Framework. The mechanism for each sub-processor is stated in Schedule 1 Part A.

A.9 Data subject requests

A.9.1 Taking into account the nature of the processing, Autopix assists the Customer by appropriate technical and organisational measures in fulfilling the Customer's obligations to respond to data subject requests under Arts. 12–23 GDPR (Art. 28(3)(e)). Assistance is normally provided within 10 business days of the Customer's request. The Platform also provides per-user self-service export and a company-level export for company administrators.

A.9.2 If a data subject contacts Autopix directly about personal data in Customer Content, Autopix refers the request to the Customer without undue delay and does not answer it on the Customer's behalf, except on the Customer's instruction or where required by law.

A.10 Personal data breaches

A.10.1 Autopix notifies the affected Customer without undue delay, and in any event within 24 hours, after becoming aware of a personal data breach affecting Customer personal data (Art. 33(2)), with the information reasonably available at that time, supplemented as further information becomes known.

A.10.2 Autopix assists the Customer with the Customer's obligations under Arts. 33–34 GDPR — notification to the supervisory authority and communication to data subjects — taking into account the nature of the processing and the information available to Autopix (Art. 28(3)(f)).

A.11 Impact assessments

Autopix provides reasonable assistance with data protection impact assessments and prior consultation of the supervisory authority (Arts. 35–36 GDPR), taking into account the nature of the processing and the information available to Autopix (Art. 28(3)(f)).

A.12 Deletion and return (Art. 28(3)(g))

A.12.1 During the term, Customer Content is deleted on the plan-based schedule in clause 6.2 of the Terms. Deletion is genuine: image files, including thumbnails and variants, are permanently deleted from storage, and database records are hard-deleted.

A.12.2 At the end of services, Autopix's default is to delete the Customer's personal data. The Customer has 30 days from the effective end of services to instruct Autopix in writing to return a copy first (using the Platform's export routes), after which deletion proceeds.

A.12.3 Deleted data ages out of database backups within 7 days of the deletion running, because backups are retained for 7 days.

A.12.4 Retention required by law. Autopix retains: the immutable billing ledger (5 years, bokføringsloven § 13); agreement documents and acceptance evidence (end of contract + 5 years, for the establishment, exercise or defence of legal claims — Art. 17(3)(e)); and audit logs (2 years). Retained data remains protected under these Data Processing Terms.

A.12.5 Deletion under this clause covers all Customer personal data, including company assets such as logos, plate images and reference images.

A.13 Information and audit (Art. 28(3)(h))

A.13.1 Autopix makes available to the Customer the information necessary to demonstrate compliance with Art. 28 GDPR. The default route is documentation and written responses to a reasonable security and privacy questionnaire.

A.13.2 The Customer (or an independent auditor bound by confidentiality) may audit or inspect, on these conditions:

  1. at least 30 days' prior written notice, unless a competent
    supervisory authority or a documented personal data breach requires shorter notice;
  2. not more than once in any 12-month period, unless Autopix has
    suffered a notifiable personal data breach affecting the Customer's data, or is in material breach of these Data Processing Terms;
  3. during Autopix's normal business hours, conducted so as not to
    unreasonably disrupt operations, with remote or virtual review preferred where it meets the Customer's purpose;
  4. limited in scope to the processing of the Customer's personal data
    under these Data Processing Terms, with no access to other customers' data;
  5. Autopix may require a reasonable confidentiality undertaking before
    access;
  6. each party bears its own costs, unless the audit reveals a material
    breach of these Data Processing Terms by Autopix, in which case Autopix bears the Customer's reasonable audit costs;
  7. where Autopix holds a current independent third-party security or
    privacy report covering the relevant controls, that report may satisfy the request to the extent of its coverage.

A.14 Liability and precedence

A.14.1 Liability under these Data Processing Terms is subject to clause 12 of the Terms, except that nothing limits liability that cannot be limited under applicable law.

A.14.2 On any matter of personal data protection under Art. 28 GDPR, these Data Processing Terms prevail over the body of the Terms (clause 1.6 of the Terms).

Schedule 1 — Sub-processors and other recipients

Part A — Authorised sub-processors

Art. 28(2) and 28(4). Twelve rows. This is the same list as the Autopix privacy policy, section 7.

1
#
Sub-processor
What it does
Location
Transfer mechanism
Amazon Web Services (AWS)
Compute, image storage, databases, CDN, transactional email (SES)
Frankfurt, EEA
— (EEA processing)
2
Laravel Vapor
Deployment platform, with access to Autopix's AWS account
US entity
US entity
3
3sixtyfactory Inc.
Manual editing, QC and support; editors may download images to local disk; no further processors
Philippines
SCCs (Art. 46(2)(c), Module 3)
4
Kaleido AI (remove.bg)
Background removal (≤ 60 minutes retention); may add vendor-generated shadows
EU, EEA
-
5
OpenAI
Image classification and QC only (gpt-4o-mini; JSON labels, no image output)
United States
EU–US Data Privacy Framework and/or SCCs
6
Mailgun
Transactional email (primary route; AWS SES is the secondary route)
EU endpoint, EEA
-
7
Treblle Inc.
API observability; captures API request and response payloads (JSON only, no images); passwords, keys and named sensitive fields are masked before data leaves Autopix's servers; data is committed to Treblle's EU ingress endpoint
US contracting entity (operating HQ Zagreb, Croatia)
Chapter V engaged by third-country entity access (EDPB Guidelines 05/2021); EU ingress configured by Autopix
8
Vumo AI
Automated AI image processing for vehicle visualisation
Poland, EEA
-
9
Pusher Limited
Channels (real-time updates; EU cluster, AWS Ireland) and Beams (push transport holding device tokens and the FCM / APNS credentials; receives notification title, body and entity identifiers — no images)
United Kingdom (Beams hosted in London)
UK adequacy as incorporated into the EEA Agreement
10
Google (Firebase Cloud Messaging, "FCM")
Android push delivery — an onward recipient via Pusher Beams; Autopix does not call FCM directly
United States
EU–US Data Privacy Framework and/or SCCs
11
Apple (Apple Push Notification service, "APNS")
iOS push delivery — an onward recipient via Pusher Beams; Autopix does not call APNS directly
United States / Ireland
SCCs
12
Google (Google Analytics 4 and Tag Manager)
Web analytics, only where the user consents (see the privacy policy)
Google Ireland Limited is the contracting entity; analytics data reaches Google LLC, United States, through Google's own chain
EU–US Data Privacy Framework and/or SCCs

Autopix does not use a third-party application performance or error-tracking product (for example Sentry, Bugsnag or Flare). API observability, including capture of error responses in API payloads, is provided by Treblle (row 8).

Part B — Recipients that are not sub-processors

Informational. These are not Autopix sub-processors under Art. 28 GDPR.

Recipient
Role
Location
Billink
Client-authorised integration endpoint at the Customer's election (clause 7 of the Terms); the Customer holds its own account and contract; Autopix transmits on the Customer's documented instruction
Norway, EEA
Carweb
As above
Norway, EEA
Drive
As above
Norway, EEA
Wayke
As above
Sweden, EEA
PowerOffice Go
Processor of Autopix's own accounting records (Autopix's controller activity under Norwegian bookkeeping law); never processes Customer Content
Norway
Brønnøysundregistrene / Bolagsverket
Public registers queried server-side for company lookups (clause 7.5 of the Terms); not processors for Autopix
Norway / Sweden
Autopix-operated systems
The Automation Platform, the Legacy Platform and the thumbnail service run in Autopix's own AWS account; they are Autopix systems, not third parties
Frankfurt, EEA