1. Scope
This agreement is part of the terms of service between the customer (you, the controller) and Pwnera SAS (we, the processor). It applies to personal data in the content you put in Artbucket Cloud: people in photos and videos, names and credits in metadata, the members and guests you invite, and anything else you upload. An Enterprise agreement may replace it with a signed version.
2. The processing
| Subject matter | Hosting, organizing, transforming and serving your content through the Service |
|---|---|
| Duration | As long as you use the Service, plus the deletion periods in section 8 |
| Nature and purpose | Storage, indexing, rendering sizes and formats, access control, sharing through portals, BrandHub, the API and MCP, as you configure them |
| Data subjects | Your people, guests, portal visitors, and people who appear in or are named by your content |
| Categories of data | Names, emails, roles, images and likenesses, credits and other metadata, and whatever else your content holds. The Service is not meant for special categories of data; if you upload them, you are responsible for having a basis to |
3. Our commitments
- We process your personal data only on your documented instructions, which are these terms and how you configure the Service, unless the law requires otherwise; we tell you if we think an instruction breaks the law.
- People who can access it are bound by confidentiality.
- We take the security measures in section 5.
- We help you answer data subjects' requests, largely through the Service itself (edit, delete, export), and with security, breach notification and impact assessments where you need us.
- We make available what you need to show we meet this agreement, and allow audits by you or an auditor you choose, bound by confidentiality, with 30 days' notice, at most once a year unless a regulator or a breach requires it.
- We never use your content for our own purposes, never sell it, and never train models on it.
4. Subprocessors
You authorize the subprocessors listed on the trust page. We bind each to data protection terms at least as protective as these. We give at least 30 days' notice of a new subprocessor by updating that list and emailing organization admins; you may object on reasonable grounds, and if we cannot address the objection, you may terminate and receive a refund of the unused prepaid period. We remain responsible for our subprocessors.
5. Security
- Hosting in the EU: the application, the database and stored files in Frankfurt, Germany.
- Encryption in transit (TLS) and at rest.
- Access control inside the Service down to a single asset, single sign-on on paid plans, and an audit log for admins.
- Production access limited to the people who run the Service.
- Infrastructure changes reviewed and deployed from version control; rate limits and isolation of uploaded files.
- The core is open source, so its security can be inspected; vulnerabilities are handled under a published disclosure policy.
6. Personal data breaches
We notify you without undue delay, and within 48 hours, of becoming aware of a breach affecting your personal data, with what we know, its likely consequences and what we are doing, and keep you updated.
7. Transfers
We store your content in the EU. Where a subprocessor outside the EEA processes personal data, the transfer relies on an adequacy decision (including the EU-US Data Privacy Framework) or on the European Commission's standard contractual clauses, which are incorporated here by reference where needed.
8. End of processing
When you delete content or your organization, or the contract ends, we delete your personal data: stored files and records are purged within 30 days and backups expire within a further 30, unless the law requires us to keep them. You can export your content before then.
9. Precedence
On data protection, this agreement prevails over the rest of the terms. The liability terms of the terms of service apply to it.