Document 06 · Legal & Privacy
Data Processing Addendum
The processing terms for business customers who submit personal data through Kaldune: roles, sub-processors, transfers, security, breach notice, and return or deletion of data.
This Data Processing Addendum ("DPA") forms part of the Terms & Conditions (the "Agreement") between Studio58, Inc. ("Kaldune," "we," "us," or "our") and the business customer ("Customer") that submits personal data through the Kaldune service. It applies only where, and to the extent that, Customer submits personal data of third parties (for example, Customer's own customers, users, or staff) through the Service and Studio58, Inc. processes that data on Customer's behalf. If the Agreement and this DPA conflict on the processing of personal data, this DPA governs.
1. Definitions
Terms not defined here have the meaning given in the Agreement or in applicable data protection law. "Applicable Data Protection Law" means all laws governing the processing of personal data that apply to a party, including the EU General Data Protection Regulation (2016/679) ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws including the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"). "Customer Personal Data" means personal data contained in the Customer Content that Studio58, Inc. processes on Customer's behalf. "Sub-processor" means a third party engaged by Studio58, Inc. to process Customer Personal Data. "Controller," "Processor," "Data Subject," "Processing," and "Personal Data Breach" have the meanings in the GDPR (and their equivalents under other Applicable Data Protection Law).
2. Roles of the parties
2.1. Controller and processor. As to Customer Personal Data, Customer is the Controller (or itself a processor acting for a third-party controller) and Studio58, Inc. is the Processor. Studio58, Inc. processes Customer Personal Data only to provide and operate the Service and only on Customer's documented instructions, including as set out in the Agreement and this DPA.
2.2. Studio58, Inc. as controller of other data. For account, billing, and Service-usage data that Studio58, Inc. determines the purposes and means of processing, Studio58, Inc. is an independent Controller; that processing is governed by the Privacy Policy, not this DPA.
2.3. CCPA/CPRA. As to personal data subject to the CCPA/CPRA, Studio58, Inc. acts as a service provider. Studio58, Inc. will not sell or share Customer Personal Data, will not retain, use, or disclose it for any purpose other than performing the Service (or as permitted by the CCPA/CPRA), and will not combine it with data from other sources except as the CCPA/CPRA permits. Studio58, Inc. certifies it understands and will comply with these restrictions.
3. Processing of Customer Personal Data
3.1. Instructions. Studio58, Inc. processes Customer Personal Data only on Customer's documented instructions (including to provide the Service, and as otherwise agreed in writing), unless required by law, in which case Studio58, Inc. will, where legally permitted, inform Customer first.
3.2. Subject matter, duration, nature, and purpose; categories; data subjects. These are set out in Schedule 1 (Details of Processing).
3.3. Confidentiality. Studio58, Inc. ensures that personnel authorized to process Customer Personal Data are bound by confidentiality obligations.
3.4. No reading in the normal course. Consistent with the Agreement and the Privacy Policy, Studio58, Inc. does not access the contents of Customer Content in the normal course. Support personnel access Customer Personal Data only at Customer's (or an authorized user's) request, for the stated purpose, and each access is logged.
4. Sub-processors
4.1. Authorization. Customer grants Studio58, Inc. general authorization to engage the Sub-processors listed in Schedule 3, including the AI provider that powers the Service. Studio58, Inc. imposes on each Sub-processor data protection obligations at least as protective as those in this DPA and remains responsible for each Sub-processor's performance.
4.2. Change notice and objection. Studio58, Inc. will give Customer at least 30 days' advance notice before a new Sub-processor begins processing Customer Personal Data, during which Customer may object on reasonable data-protection grounds. If the parties cannot resolve the objection, Customer may terminate the affected Service and receive a pro-rata refund of prepaid, unused fees.
4.3. The AI provider. The AI provider (currently Anthropic, PBC; Anthropic Ireland, Limited for EEA/UK/Swiss data) is a Sub-processor. Under the provider's commercial terms and DPA, verified on 2026-07-17, the provider processes data as a processor, does not train its models on content submitted through its commercial offering, and relies on Standard Contractual Clauses for onward transfers to its own infrastructure sub-processors (Google Cloud, Amazon Web Services, Microsoft Azure, Cloudflare, worldwide). Customer acknowledges this downstream chain.
5. International transfers
5.1. Mechanism. Where Studio58, Inc. transfers Customer Personal Data of EEA, UK, or Swiss data subjects to a country without an adequacy decision, the transfer is made under the EU Standard Contractual Clauses (Module Two, controller-to-processor; and Module Three, processor-to-processor, for onward transfers), the UK International Data Transfer Addendum, and the Swiss Addendum, each incorporated into this DPA by reference and completed by Schedule 3 and the party details in Schedule 1.
5.2. Transfer impact. The parties will cooperate to complete any transfer-impact assessment reasonably required by Applicable Data Protection Law.
6. Security
6.1. Measures. Studio58, Inc. maintains appropriate technical and organizational measures to protect Customer Personal Data, described in Schedule 2, including encryption in transit and at rest, access controls on a least-privilege basis, and logging of support access to Customer Content.
6.2. Sub-processor security. The AI provider maintains, as verified on 2026-07-17, AES-256 encryption at rest, TLS 1.2+ in transit, MFA and role-based access control, annual third-party audit/penetration testing, and SOC 2, ISO 27001, and ISO 42001 certifications. Studio58, Inc. will require comparable measures of its other Sub-processors.
7. Personal Data Breach
7.1. Notice. Studio58, Inc. will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, with the information Customer reasonably needs to meet its own notification obligations.
7.2. Cooperation. Studio58, Inc. will reasonably assist Customer in investigating and mitigating the breach.
8. Assistance to Customer
8.1. Data-subject requests. Taking into account the nature of the processing, Studio58, Inc. will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to data-subject requests to exercise rights under Applicable Data Protection Law (access, rectification, erasure, restriction, portability, objection). Where a data subject contacts Studio58, Inc. directly, Studio58, Inc. will refer them to Customer.
8.2. DPIAs and consultation. Studio58, Inc. will provide Customer reasonable assistance with data-protection impact assessments and prior consultations with supervisory authorities, taking into account the information available to Studio58, Inc.
9. Return and deletion
On termination or expiry of the Agreement, Studio58, Inc. will, at Customer's choice, return and/or delete Customer Personal Data from its active systems within 30 days, except copies in encrypted backups which are deleted on the backup rotation cycle no later than 90 days after active-system deletion, and except where retention is required by law. Backup copies remain subject to this DPA's protections until deleted. (The 90-day backup figure is a protective ceiling pending confirmation of the true rotation period; see Schedule 4.)
10. Audit
Studio58, Inc. will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor Customer mandates, on reasonable prior notice, subject to confidentiality and no more than once per year absent cause. Studio58, Inc. may satisfy this obligation by providing relevant third-party audit reports (its own or its Sub-processors', such as the AI provider's SOC 2 report).
11. General
This DPA is governed by the governing law of the Agreement (State of Delaware), except that the SCCs are governed by the law they specify (Ireland, for EEA transfers). If any provision of this DPA conflicts with the SCCs, the SCCs prevail as to the transfer they govern. This DPA takes effect when the Agreement does and terminates with it, except provisions that by their nature survive.
Schedule 1 — Details of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Kaldune AI studio service to Customer. |
| Duration | The term of the Agreement, plus the return/deletion period in Section 9. |
| Nature and purpose | Storing Customer Content and generating AI-assisted work in response to Customer's briefs; account, security, and support operations. |
| Categories of personal data | Any personal data Customer chooses to include in its Inputs or that appears in Outputs; Customer account and contact data. Customer controls what personal data it submits. |
| Special categories | Not intended. Customer should not submit special-category data unless it has a lawful basis and has configured its use accordingly; Studio58, Inc. does not require it to operate the Service. |
| Data subjects | As determined by Customer, e.g. Customer's own customers, users, staff, or contacts represented in the Customer Content. |
| Controller | Customer (Schedule 1 party details to be completed by Customer). |
| Processor | Studio58, Inc. (operating Kaldune), c/o Corporation Service Company, 251 Little Falls Drive, Wilmington, New Castle County, DE 19808. |
Schedule 2 — Security measures (Studio58, Inc.)
- Encryption of Customer Content in transit (TLS 1.2+) and at rest.
- Access control on a least-privilege basis; multi-factor authentication for administrative access.
- Support access to Customer Content only on request, scoped to the item and purpose requested, and logged (who, when, why), with the log available to the customer on request.
- Segregation of Customer environments; secured, encrypted backups on a fixed rotation.
- Error-monitoring configured to scrub Customer Content from diagnostic payloads.
- Vendor due diligence and data-protection terms with each Sub-processor.
Schedule 3 — Sub-processors
| Sub-processor | Purpose | Location | Status |
|---|---|---|---|
| Anthropic, PBC (Anthropic Ireland, Limited for EEA/UK/Swiss customers) | AI models powering the room, via commercial API | US (Ireland entity for EEA/UK/CH contracting); onward infra worldwide (GCP, AWS, Azure, Cloudflare) | verified |
| Cloud hosting provider (to be named) | App hosting, database, encrypted storage and backups | US or EU per customer (region to be confirmed) | pending |
| Stripe, Inc. | Payment processing for prepaid top-ups (card data collected and processed by Stripe; not received or stored by Studio58, Inc.) | US | confirmed |
| Transactional email provider (to be named) | Account emails, notifications, password resets | US | pending |
| Product analytics provider (to be named) | Aggregate, privacy-respecting usage analytics | EU or US (protective: EU-hosted, cookieless) | pending |
| Error-monitoring provider (to be named) | Crash and error diagnostics | US | pending |
| Customer-support tooling (to be named) | Handling Get Help requests | US | pending |
Schedule 4 — Open items to be confirmed before this DPA is executed
These are the values still being confirmed. Each is locked identically across the Privacy Policy, this DPA, and the Terms before publication.
| Item | This DPA's default |
|---|---|
| True backup rotation period (Section 9; currently "no later than 90 days") | 90 days, protective ceiling |
| Hosting provider and region (Schedule 3) | Unnamed; US/EU protective |
| Email, analytics, error-monitoring, support vendors (Schedule 3) | Unnamed defaults |
| Payments vendor (Schedule 3) | Resolved: Stripe, Inc. |
| Studio58, Inc. SCCs executed with each non-AI Sub-processor (Section 5.1) | Stated as intended posture |
| Sub-processor change-notice window (Section 4.2) | 30 days |
| Postal address of processor (Schedule 1) | c/o Corporation Service Company, 251 Little Falls Drive, Wilmington, New Castle County, DE 19808 |
Kaldune is a product of Studio58, Inc.