← Back to Home

Legal

Data Processing Addendum

Binding processing terms for business customer data, security, subprocessors, assistance and deletion.

Last updated: September 14, 2026

Data Processing Addendum

Effective September 14, 2026. This Addendum is part of the Aslax Terms of Service between Aslax, LLC (Processor) and the business customer identified by the applicable account or order (Customer). It applies only when Aslax processes personal data on Customer’s behalf. Customer acts as controller, or as a processor authorised by its controller. A person accepting for Customer must have authority to bind it. No separate handwritten signature is required where the underlying agreement is validly accepted electronically.

Aslax separately acts as controller for account administration, billing, fraud prevention and its own legal obligations, as described in the Privacy Policy. This Addendum prevails over conflicting general terms for Customer processing; a signed negotiated DPA or mandatory transfer clauses prevail where applicable.

1. Processing instructions and confidentiality

Aslax processes Customer data only on documented instructions in the agreement, product settings and authorised requests, including instructions about international transfers. If law requires other processing, Aslax informs Customer before processing unless legally prohibited. Aslax promptly informs Customer if an instruction appears to infringe applicable data-protection law and may pause that instruction while it is resolved.

Customer is responsible for lawful collection, notices, instructions and required permissions. Aslax limits access to authorised people bound by confidentiality and does not use private Customer inputs or outputs to train its own general-purpose models. Instructions cannot override the applicable Acceptable Use Policy or make an unapproved upstream processing arrangement lawful.

2. Security and incident assistance

Taking account of processing risk, Aslax implements appropriate technical and organisational safeguards, including authenticated access, least privilege, encrypted transport, protected service credentials, separation of customer permissions, controlled changes, incident handling and restoration procedures. The Security Statement describes the service; it does not represent a certification or a guarantee of uninterrupted service.

Aslax notifies Customer without undue delay after becoming aware of a personal-data breach affecting Customer data and supplies available information about its nature, affected data, likely consequences and mitigation. Further information may follow in phases. Aslax assists Customer with security, breach notifications and required impact assessments and regulator consultations, taking account of the nature of processing and information available. Aslax does not make Customer’s regulatory notification decision on Customer’s behalf unless instructed or legally required.

3. Subprocessors and transfers

Customer generally authorises the subprocessors applicable to its selected features and agreed processing configuration, identified in the provider register and any order annex. Aslax binds subprocessors to data-protection obligations providing equivalent protection for delegated processing and remains responsible to Customer for their performance.

Aslax gives at least 30 days’ advance notice of a proposed new or replacement subprocessor for Customer data, except urgent security or service-continuity changes, when notice is given as soon as practicable. Customer may object on reasonable data-protection grounds. The parties will seek a workable alternative; if none is available, Customer may discontinue the affected processing and receive a proportionate refund of prepaid unused affected service. An objection does not authorise unsafe routing while unresolved.

Transfers outside the EEA, UK or another protected jurisdiction require the applicable lawful mechanism and safeguards. This Addendum is not by itself an adequacy decision or completed Standard Contractual Clauses. Where needed, the parties must complete the applicable transfer instrument, modules and annexes before the restricted transfer. Business customers should contact aslan@aslax.eu to document destinations, vendor retention, transfer terms or a restricted provider configuration before submitting regulated or sensitive data. A model being listed does not mean its processing terms are approved for every Customer use.

4. Rights requests, return and deletion

Aslax assists Customer with data-subject requests using appropriate technical and organisational measures. Requests received directly concerning Customer-controlled data are referred to Customer unless law requires otherwise. Customer may export data using available account tools and request additional assistance through support@aslax.eu.

At the end of applicable processing, Aslax returns or deletes Customer data at Customer’s choice and deletes remaining copies unless applicable law requires retention. Customer settings and documented instructions determine the active retention period. Retained legal records are restricted to that purpose. Backup copies follow the documented provider rotation, remain protected from ordinary use, and deletion decisions are reapplied on restoration. Aslax provides the relevant deletion scope and completion information on request and identifies any lawful retention exception rather than representing a partial deletion as complete.

5. Accountability and audits

Aslax makes available information reasonably necessary to demonstrate compliance with this Addendum and permits and contributes to Customer or independent-auditor assessments, including inspections where required. The parties coordinate reasonable notice, scope, confidentiality and security to protect other customers. These arrangements do not prevent urgent investigations, regulator access, or mandatory audit rights. Each party keeps applicable processing records and cooperates with competent authorities.

Annex A — Processing description

ItemScope
Subject and durationHosted creative AI generation, editing, storage, collaboration and support for the agreement term and documented return/deletion period.
Nature and purposeReceiving, organising, transmitting to authorised providers, generating, editing, storing, retrieving, sharing on instruction and deleting data to deliver Customer’s selected service.
Data subjectsCustomer staff, contractors, clients and individuals lawfully depicted or referenced in submitted content.
Data categoriesNames and business contact details, account/workspace identifiers, prompts, authorised media and likenesses, outputs, project context, technical metadata and support information.
Sensitive dataNot authorised by default. Special-category, biometric-identification, health, government-ID or other regulated processing requires a lawful basis, appropriate safeguards and an expressly agreed supported configuration.
Customer instructions and contactsThe account/order, authorised settings and written instructions identify the Customer and its contact. Aslax privacy contact: Aslan Al-Abdali, aslan@aslax.eu, Aslax, LLC, 1111B S Governors Ave, Suite 52762, Dover, DE 19904, United States.

Related: Provider register · Privacy · Security · Terms