Kaldune Back to Kaldune

Document 06 · Legal & Privacy

Data Processing Addendum

The processing terms for business customers who submit personal data through Kaldune: roles, sub-processors, transfers, security, breach notice, and return or deletion of data.

Last updated 17 July 2026 · For business customers

This Data Processing Addendum ("DPA") forms part of the Terms & Conditions (the "Agreement") between Studio58, Inc. ("Kaldune," "we," "us," or "our") and the business customer ("Customer") that submits personal data through the Kaldune service. It applies only where, and to the extent that, Customer submits personal data of third parties (for example, Customer's own customers, users, or staff) through the Service and Studio58, Inc. processes that data on Customer's behalf. If the Agreement and this DPA conflict on the processing of personal data, this DPA governs.

1. Definitions

Terms not defined here have the meaning given in the Agreement or in applicable data protection law. "Applicable Data Protection Law" means all laws governing the processing of personal data that apply to a party, including the EU General Data Protection Regulation (2016/679) ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws including the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"). "Customer Personal Data" means personal data contained in the Customer Content that Studio58, Inc. processes on Customer's behalf. "Sub-processor" means a third party engaged by Studio58, Inc. to process Customer Personal Data. "Controller," "Processor," "Data Subject," "Processing," and "Personal Data Breach" have the meanings in the GDPR (and their equivalents under other Applicable Data Protection Law).

2. Roles of the parties

2.1. Controller and processor. As to Customer Personal Data, Customer is the Controller (or itself a processor acting for a third-party controller) and Studio58, Inc. is the Processor. Studio58, Inc. processes Customer Personal Data only to provide and operate the Service and only on Customer's documented instructions, including as set out in the Agreement and this DPA.

2.2. Studio58, Inc. as controller of other data. For account, billing, and Service-usage data that Studio58, Inc. determines the purposes and means of processing, Studio58, Inc. is an independent Controller; that processing is governed by the Privacy Policy, not this DPA.

2.3. CCPA/CPRA. As to personal data subject to the CCPA/CPRA, Studio58, Inc. acts as a service provider. Studio58, Inc. will not sell or share Customer Personal Data, will not retain, use, or disclose it for any purpose other than performing the Service (or as permitted by the CCPA/CPRA), and will not combine it with data from other sources except as the CCPA/CPRA permits. Studio58, Inc. certifies it understands and will comply with these restrictions.

3. Processing of Customer Personal Data

3.1. Instructions. Studio58, Inc. processes Customer Personal Data only on Customer's documented instructions (including to provide the Service, and as otherwise agreed in writing), unless required by law, in which case Studio58, Inc. will, where legally permitted, inform Customer first.

3.2. Subject matter, duration, nature, and purpose; categories; data subjects. These are set out in Schedule 1 (Details of Processing).

3.3. Confidentiality. Studio58, Inc. ensures that personnel authorized to process Customer Personal Data are bound by confidentiality obligations.

3.4. No reading in the normal course. Consistent with the Agreement and the Privacy Policy, Studio58, Inc. does not access the contents of Customer Content in the normal course. Support personnel access Customer Personal Data only at Customer's (or an authorized user's) request, for the stated purpose, and each access is logged.

4. Sub-processors

4.1. Authorization. Customer grants Studio58, Inc. general authorization to engage the Sub-processors listed in Schedule 3, including the AI provider that powers the Service. Studio58, Inc. imposes on each Sub-processor data protection obligations at least as protective as those in this DPA and remains responsible for each Sub-processor's performance.

4.2. Change notice and objection. Studio58, Inc. will give Customer at least 30 days' advance notice before a new Sub-processor begins processing Customer Personal Data, during which Customer may object on reasonable data-protection grounds. If the parties cannot resolve the objection, Customer may terminate the affected Service and receive a pro-rata refund of prepaid, unused fees.

4.3. The AI provider. The AI provider (currently Anthropic, PBC; Anthropic Ireland, Limited for EEA/UK/Swiss data) is a Sub-processor. Under the provider's commercial terms and DPA, verified on 2026-07-17, the provider processes data as a processor, does not train its models on content submitted through its commercial offering, and relies on Standard Contractual Clauses for onward transfers to its own infrastructure sub-processors (Google Cloud, Amazon Web Services, Microsoft Azure, Cloudflare, worldwide). Customer acknowledges this downstream chain.

5. International transfers

5.1. Mechanism. Where Studio58, Inc. transfers Customer Personal Data of EEA, UK, or Swiss data subjects to a country without an adequacy decision, the transfer is made under the EU Standard Contractual Clauses (Module Two, controller-to-processor; and Module Three, processor-to-processor, for onward transfers), the UK International Data Transfer Addendum, and the Swiss Addendum, each incorporated into this DPA by reference and completed by Schedule 3 and the party details in Schedule 1.

5.2. Transfer impact. The parties will cooperate to complete any transfer-impact assessment reasonably required by Applicable Data Protection Law.

6. Security

6.1. Measures. Studio58, Inc. maintains appropriate technical and organizational measures to protect Customer Personal Data, described in Schedule 2, including encryption in transit and at rest, access controls on a least-privilege basis, and logging of support access to Customer Content.

6.2. Sub-processor security. The AI provider maintains, as verified on 2026-07-17, AES-256 encryption at rest, TLS 1.2+ in transit, MFA and role-based access control, annual third-party audit/penetration testing, and SOC 2, ISO 27001, and ISO 42001 certifications. Studio58, Inc. will require comparable measures of its other Sub-processors.

7. Personal Data Breach

7.1. Notice. Studio58, Inc. will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, with the information Customer reasonably needs to meet its own notification obligations.

7.2. Cooperation. Studio58, Inc. will reasonably assist Customer in investigating and mitigating the breach.

8. Assistance to Customer

8.1. Data-subject requests. Taking into account the nature of the processing, Studio58, Inc. will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to data-subject requests to exercise rights under Applicable Data Protection Law (access, rectification, erasure, restriction, portability, objection). Where a data subject contacts Studio58, Inc. directly, Studio58, Inc. will refer them to Customer.

8.2. DPIAs and consultation. Studio58, Inc. will provide Customer reasonable assistance with data-protection impact assessments and prior consultations with supervisory authorities, taking into account the information available to Studio58, Inc.

9. Return and deletion

On termination or expiry of the Agreement, Studio58, Inc. will, at Customer's choice, return and/or delete Customer Personal Data from its active systems within 30 days, except copies in encrypted backups which are deleted on the backup rotation cycle no later than 90 days after active-system deletion, and except where retention is required by law. Backup copies remain subject to this DPA's protections until deleted. (The 90-day backup figure is a protective ceiling pending confirmation of the true rotation period; see Schedule 4.)

10. Audit

Studio58, Inc. will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor Customer mandates, on reasonable prior notice, subject to confidentiality and no more than once per year absent cause. Studio58, Inc. may satisfy this obligation by providing relevant third-party audit reports (its own or its Sub-processors', such as the AI provider's SOC 2 report).

11. General

This DPA is governed by the governing law of the Agreement (State of Delaware), except that the SCCs are governed by the law they specify (Ireland, for EEA transfers). If any provision of this DPA conflicts with the SCCs, the SCCs prevail as to the transfer they govern. This DPA takes effect when the Agreement does and terminates with it, except provisions that by their nature survive.


Schedule 1 — Details of processing

ItemDetail
Subject matterProvision of the Kaldune AI studio service to Customer.
DurationThe term of the Agreement, plus the return/deletion period in Section 9.
Nature and purposeStoring Customer Content and generating AI-assisted work in response to Customer's briefs; account, security, and support operations.
Categories of personal dataAny personal data Customer chooses to include in its Inputs or that appears in Outputs; Customer account and contact data. Customer controls what personal data it submits.
Special categoriesNot intended. Customer should not submit special-category data unless it has a lawful basis and has configured its use accordingly; Studio58, Inc. does not require it to operate the Service.
Data subjectsAs determined by Customer, e.g. Customer's own customers, users, staff, or contacts represented in the Customer Content.
ControllerCustomer (Schedule 1 party details to be completed by Customer).
ProcessorStudio58, Inc. (operating Kaldune), c/o Corporation Service Company, 251 Little Falls Drive, Wilmington, New Castle County, DE 19808.

Schedule 2 — Security measures (Studio58, Inc.)

Schedule 3 — Sub-processors

Sub-processorPurposeLocationStatus
Anthropic, PBC (Anthropic Ireland, Limited for EEA/UK/Swiss customers)AI models powering the room, via commercial APIUS (Ireland entity for EEA/UK/CH contracting); onward infra worldwide (GCP, AWS, Azure, Cloudflare)verified
Cloud hosting provider (to be named)App hosting, database, encrypted storage and backupsUS or EU per customer (region to be confirmed)pending
Stripe, Inc.Payment processing for prepaid top-ups (card data collected and processed by Stripe; not received or stored by Studio58, Inc.)USconfirmed
Transactional email provider (to be named)Account emails, notifications, password resetsUSpending
Product analytics provider (to be named)Aggregate, privacy-respecting usage analyticsEU or US (protective: EU-hosted, cookieless)pending
Error-monitoring provider (to be named)Crash and error diagnosticsUSpending
Customer-support tooling (to be named)Handling Get Help requestsUSpending

Schedule 4 — Open items to be confirmed before this DPA is executed

These are the values still being confirmed. Each is locked identically across the Privacy Policy, this DPA, and the Terms before publication.

ItemThis DPA's default
True backup rotation period (Section 9; currently "no later than 90 days")90 days, protective ceiling
Hosting provider and region (Schedule 3)Unnamed; US/EU protective
Email, analytics, error-monitoring, support vendors (Schedule 3)Unnamed defaults
Payments vendor (Schedule 3)Resolved: Stripe, Inc.
Studio58, Inc. SCCs executed with each non-AI Sub-processor (Section 5.1)Stated as intended posture
Sub-processor change-notice window (Section 4.2)30 days
Postal address of processor (Schedule 1)c/o Corporation Service Company, 251 Little Falls Drive, Wilmington, New Castle County, DE 19808
Back to Kaldune

Kaldune is a product of Studio58, Inc.