An agency that is AI Early access

Data Processing Addendum (DPA)

Studio58, Inc. · Last updated 5 August 2026 · Version 1.3

This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between Studio58, Inc. ("Kaldune," "we," "us," or "our") and the business customer ("Customer") that submits personal data through the Kaldune service. It applies only where, and to the extent that, Customer submits personal data of third parties (for example, Customer's own customers, users, or staff) through the Service and Studio58, Inc. processes that data on Customer's behalf. If the Agreement and this DPA conflict on the processing of personal data, this DPA governs.

1. Definitions

Terms not defined here have the meaning given in the Agreement or in applicable data protection law. "Applicable Data Protection Law" means all laws governing the processing of personal data that apply to a party, including the EU General Data Protection Regulation (2016/679) ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws including the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"). "Customer Personal Data" means personal data contained in the Customer Content that Studio58, Inc. processes on Customer's behalf. "Sub-processor" means a third party engaged by Studio58, Inc. to process Customer Personal Data. "Controller," "Processor," "Data Subject," "Processing," and "Personal Data Breach" have the meanings in the GDPR (and their equivalents under other Applicable Data Protection Law).

2. Roles of the parties

2.1. Controller and processor. As to Customer Personal Data, Customer is the Controller (or itself a processor acting for a third-party controller) and Studio58, Inc. is the Processor. Studio58, Inc. processes Customer Personal Data only to provide and operate the Service and only on Customer's documented instructions, including as set out in the Agreement and this DPA.

2.2. Studio58, Inc. as controller of other data. For account, billing, and Service-usage data that Studio58, Inc. determines the purposes and means of processing, Studio58, Inc. is an independent Controller; that processing is governed by the Privacy Policy, not this DPA.

2.3. CCPA/CPRA. As to personal data subject to the CCPA/CPRA, Studio58, Inc. acts as a service provider. Studio58, Inc. will not sell or share Customer Personal Data, will not retain, use, or disclose it for any purpose other than performing the Service (or as permitted by the CCPA/CPRA), and will not combine it with data from other sources except as the CCPA/CPRA permits. Studio58, Inc. certifies it understands and will comply with these restrictions.

3. Processing of Customer Personal Data

3.1. Instructions. Studio58, Inc. processes Customer Personal Data only on Customer's documented instructions (including to provide the Service, and as otherwise agreed in writing), unless required by law, in which case Studio58, Inc. will, where legally permitted, inform Customer first.

3.2. Subject matter, duration, nature, and purpose; categories; data subjects. These are set out in Schedule 1 (Details of Processing).

3.3. Confidentiality. Studio58, Inc. ensures that personnel authorized to process Customer Personal Data are bound by confidentiality obligations.

3.4. No reading in the normal course. Consistent with the Agreement and the Privacy Policy, Studio58, Inc. does not access the contents of Customer Content in the normal course. Support personnel access Customer Personal Data only at Customer's (or an authorized user's) request, for the stated purpose, and each access is logged.

4. Sub-processors

4.1. Authorization. Customer grants Studio58, Inc. general authorization to engage the Sub-processors listed in Schedule 3, including the AI provider that powers the Service. Studio58, Inc. imposes on each Sub-processor data protection obligations at least as protective as those in this DPA and remains responsible for each Sub-processor's performance.

4.2. Change notice and objection. Studio58, Inc. will give Customer at least 30 days' advance notice before a new Sub-processor begins processing Customer Personal Data, during which Customer may object on reasonable data-protection grounds. If the parties cannot resolve the objection, Customer may terminate the affected Service and receive a refund of unused paid credits and a pro-rata refund of any prepaid subscription fees.

4.3. The AI provider. The AI provider (currently Anthropic, PBC; Anthropic Ireland, Limited for EEA/UK/Swiss data) is a Sub-processor. Under the provider's commercial terms and DPA, verified on 2026-07-17, the provider processes data as a processor, does not train its models on content submitted through its commercial offering, and relies on Standard Contractual Clauses for onward transfers to its own infrastructure sub-processors (Google Cloud, Amazon Web Services, Microsoft Azure, Cloudflare; worldwide). Customer acknowledges this downstream chain.

5. International transfers

5.1. Mechanism. Where Studio58, Inc. transfers Customer Personal Data of EEA, UK, or Swiss data subjects to a country without an adequacy decision, the transfer is made under the EU Standard Contractual Clauses (Module Two, controller-to-processor; and Module Three, processor-to-processor, for onward transfers), the UK International Data Transfer Addendum, and the Swiss Addendum, each incorporated into this DPA by reference and completed by Schedule 3 and the party details in Schedule 1. Where equivalent clauses with one of Studio58, Inc.'s own Sub-processors are still being completed, this Section states the standard Studio58, Inc. applies to that transfer in the meantime.

5.2. Transfer impact. The parties will cooperate to complete any transfer-impact assessment reasonably required by Applicable Data Protection Law.

6. Security

6.1. Measures. Studio58, Inc. maintains appropriate technical and organizational measures to protect Customer Personal Data, described in Schedule 2, including encryption in transit and at rest, access controls on a least-privilege basis, and logging of support access to Customer Content.

6.2. Sub-processor security. The AI provider maintains, as verified on 2026-07-17, AES-256 encryption at rest, TLS 1.2+ in transit, MFA and role-based access control, annual third-party audit/penetration testing, and SOC 2, ISO 27001, and ISO 42001 certifications. Studio58, Inc. will require comparable measures of its other Sub-processors.

7. Personal Data Breach

7.1. Notice. Studio58, Inc. will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, with the information Customer reasonably needs to meet its own notification obligations.

7.2. Cooperation. Studio58, Inc. will reasonably assist Customer in investigating and mitigating the breach.

8. Assistance to Customer

8.1. Data-subject requests. Taking into account the nature of the processing, Studio58, Inc. will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to data-subject requests to exercise rights under Applicable Data Protection Law (access, rectification, erasure, restriction, portability, objection). Where a data subject contacts Studio58, Inc. directly, Studio58, Inc. will refer them to Customer.

8.2. DPIAs and consultation. Studio58, Inc. will provide Customer reasonable assistance with data-protection impact assessments and prior consultations with supervisory authorities, taking into account the information available to Studio58, Inc.

9. Return and deletion

On termination or expiry of the Agreement, Studio58, Inc. will, at Customer's choice, return and/or delete Customer Personal Data from its active systems within 30 days, except copies in encrypted backups which are deleted on the backup rotation cycle no later than 90 days after active-system deletion, and except where retention is required by law. Backup copies remain subject to this DPA's protections until deleted. The 90-day backup figure is a protective ceiling: if the measured rotation period is shorter, deletion happens sooner, and this DPA's commitment is the outer bound either way.

10. Audit

Studio58, Inc. will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor Customer mandates, on reasonable prior notice, subject to confidentiality and no more than once per year absent cause. Studio58, Inc. may satisfy this obligation by providing relevant third-party audit reports (its own or its Sub-processors', such as the AI provider's SOC 2 report).

11. General

This DPA is governed by the governing law of the Agreement (State of Delaware), except that the SCCs are governed by the law they specify (Ireland, for EEA transfers). If any provision of this DPA conflicts with the SCCs, the SCCs prevail as to the transfer they govern. This DPA takes effect when the Agreement does and terminates with it, except provisions that by their nature survive.


Schedule 1: Details of processing

| Item | Detail | |---|---| | Subject matter | Provision of the Kaldune AI studio service to Customer. | | Duration | The term of the Agreement, plus the return/deletion period in Section 9. | | Nature and purpose | Storing Customer Content and generating AI-assisted work in response to Customer's briefs; account, security, and support operations. | | Categories of personal data | Any personal data Customer chooses to include in its Inputs or that appears in Outputs; Customer account and contact data. Customer controls what personal data it submits. | | Special categories | Not intended. Customer should not submit special-category data unless it has a lawful basis and has configured its use accordingly; Studio58, Inc. does not require it to operate the Service. | | Data subjects | As determined by Customer: e.g. Customer's own customers, users, staff, or contacts represented in the Customer Content. | | Controller | Customer (Schedule 1 party details to be completed by Customer). | | Processor | Studio58, Inc. (operating Kaldune), a Delaware corporation. Notices via hello@kaldune.ai; registered-agent address on file with the Delaware Division of Corporations. |

Schedule 2: Security measures (Studio58, Inc.)

Schedule 3: Sub-processors

Studio58, Inc. imposes on each Sub-processor data protection obligations at least as protective as those in this DPA (Section 4.1), and gives 30 days' advance notice before a new Sub-processor begins processing Customer Personal Data (Section 4.2).

| Sub-processor | Purpose | Location | |---|---|---| | Anthropic, PBC (Anthropic Ireland, Limited for EEA/UK/Swiss customers) | AI model inference for the work in a brief, via commercial API | US (Ireland entity for EEA/UK/CH contracting); onward infra worldwide (GCP, AWS, Azure, Cloudflare) | | Google Cloud Platform | Infrastructure and hosting; stores Customer Content and encrypted backups | US (us-central1) | | Google (Gemini API) | AI model inference for the work in a brief | US | | fal.ai | Image, video, and media model inference | US | | ElevenLabs | Audio generation, on briefs that include audio | US | | Stripe, Inc. | Payment processing for wallet credits and subscriptions (card data collected and processed by Stripe; not received or stored by Studio58, Inc.) | US | | Resend | Transactional email: sign-in codes, receipts, account notices | US | | Error-monitoring provider (to be named) | Crash and error diagnostics | US |