Data Processing Addendum

Data Processing Addendum

Last updated: July 30, 2026

This Data Processing Addendum ("DPA") forms part of the Lithiq Studios Terms of Service (the "Agreement") between Lithiq Studios ("Processor," "we," "us") and the customer entity that has subscribed to the Service ("Controller," "you"). This DPA applies to the extent the Processor processes Personal Data on behalf of the Controller in connection with the Service and is governed by data protection law, including the General Data Protection Regulation (Regulation (EU) 2016/679) and the UK GDPR, where applicable.

1. Definitions

Capitalized terms not defined here have the meaning set forth in the Agreement or in applicable data protection law.

  • "Controller" — the entity that determines the purposes and means of processing Personal Data. For the purposes of this DPA, you (the customer) are the Controller.
  • "Processor" — the entity that processes Personal Data on behalf of the Controller. For the purposes of this DPA, Lithiq Studios is the Processor.
  • "Personal Data" — any information relating to an identified or identifiable individual processed under this DPA.
  • "Processing" — any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
  • "Sub-processor" — any Processor engaged by Lithiq Studios to process Personal Data on behalf of the Controller.
  • "Data Protection Law" — all applicable laws and regulations relating to the processing, privacy, and security of Personal Data, including the GDPR, UK GDPR, and all state data protection laws applicable to the Controller.

2. Roles and Responsibilities

2.1 Roles

You are the Controller of Personal Data you upload to or enter into the Service, including client names, contact details, job addresses, and any personal information contained in project notes or uploaded files. We are the Processor of that Personal Data and process it solely on your behalf and in accordance with your documented instructions.

2.2 Controller Responsibilities

You are responsible for ensuring that you have a lawful basis to process Personal Data in connection with your use of the Service, and that such processing complies with Data Protection Law. You will provide us with all instructions required for us to perform our obligations under this DPA.

3. Details of Processing

3.1 Subject Matter and Duration

The subject matter of the processing is Personal Data provided by you in connection with your use of the Service, including client and customer information, job and project information, and related operational data. The duration of the processing continues until the termination of the Agreement and the expiration of applicable data retention periods.

3.2 Nature and Purpose

The processing is performed for the purpose of providing, operating, and maintaining the Service, including job management, quoting and estimating, layout and nesting, inventory tracking, invoicing, accounting integration, and customer support.

3.3 Categories of Data Subjects

Data subjects include your clients, customers, team members, and any other individuals whose Personal Data you provide to the Service.

3.4 Categories of Personal Data

Categories of Personal Data may include names, contact information (email, phone, address), job and project details, and any other personal information you choose to store in the Service.

4. Processor Obligations

We shall:

  • Process Personal Data only on documented instructions from you, unless required to do so by law (in which case we will inform you of that requirement before processing, unless law prohibits such notification)
  • Ensure that persons authorized to process Personal Data have committed themselves to confidentiality
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in the Security section of our Privacy Policy
  • Not sell, rent, or otherwise commercially exploit Personal Data, and not use Personal Data for any purpose other than providing the Service
  • Not use Personal Data to build or augment profiles of data subjects for purposes other than providing the Service
  • Assist you, to the extent possible, in fulfilling your obligations to respond to data subject requests exercising their rights under Data Protection Law
  • Make available to you information necessary to demonstrate compliance with this DPA

5. Sub-processors

5.1 Authorized Sub-processors

You generally authorize us to engage the following categories of Sub-processors to process Personal Data in connection with the Service:

  • Vercel Inc. — application hosting and edge delivery
  • Neon — PostgreSQL database hosting
  • Cloudflare, Inc. — file storage (R2), content delivery, and security
  • Stripe, Inc. — payment processing and subscription management
  • QuickBooks / Intuit — accounting synchronization when you connect your account
  • Upstash — Redis-based rate limiting
  • OpenStreetMap / Nominatim — geocoding of addresses for distance calculations

5.2 Notification and Objection

We will provide you with at least 30 days' notice of any new Sub-processor or changes to our Sub-processor list, including by updating this DPA and the Privacy Policy. If you object to a new Sub-processor, you may terminate the Agreement in accordance with its terms. Where we engage a Sub-processor, we will impose on it data protection obligations substantially equivalent to those set out in this DPA.

6. International Data Transfers

To the extent that the processing of Personal Data involves transfers outside the European Economic Area, the United Kingdom, or other restricted territories, we will ensure that such transfers are made in accordance with Data Protection Law, including through the use of appropriate safeguards such as Standard Contractual Clauses adopted by the European Commission or the UK Information Commissioner's Office, or an adequacy decision where applicable.

7. Security

We will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data, including the measures described in the "Data Security" section of our Privacy Policy.

8. Data Breach Notification

We will notify you without undue delay after becoming aware of any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed under this DPA ("Data Breach"). The notification will include, to the extent available: the nature of the Data Breach, the categories and approximate number of data subjects and records affected, and the measures taken or proposed to mitigate the Data Breach. You are responsible for notifying supervisory authorities and data subjects as required by Data Protection Law.

9. Data Subject Rights

To the extent required by Data Protection Law, we will reasonably assist you in responding to requests by data subjects to exercise their rights of access, correction, deletion, restriction, portability, objection, and any other rights conferred by applicable law. You may submit data subject requests to us at privacy@lithiqstudios.com. Where you are unable to resolve a data subject request directly, we will cooperate with you to address the request.

10. Deletion and Return

On termination of the Agreement, or upon your request, we will delete or return Personal Data in our possession, subject to applicable legal and regulatory retention obligations (including tax and accounting record retention). Upon your deletion of specific Personal Data through the Service, we will take reasonable steps to delete or anonymize that data in accordance with our retention policies.

11. Audit Rights

Upon reasonable notice and no more than once per calendar year, and provided that such audit does not interfere with our operations or expose confidential information of our other customers, you may, at your expense, request information reasonably necessary to verify our compliance with this DPA. We will provide a summary of relevant certifications, audit reports, and security documentation available to us.

12. Liability

Each party's liability arising out of or related to this DPA will be subject to the limitations of liability set forth in the Agreement. We shall be liable for damages caused by processing only where we have failed to comply with this DPA or have acted outside or contrary to your documented instructions.

13. Governing Law

This DPA is governed by the laws of the State of Washington, United States, and any dispute arising out of or relating to this DPA shall be resolved in accordance with the dispute resolution provisions of the Agreement.

14. Contact Information

If you have any questions about this DPA or our data processing practices, please contact us at privacy@lithiqstudios.com.

Lithiq is a product of Lithiq Studios.