This Addendum applies when Affichr processes client personal data on behalf of an artist or studio using Affichr.
The artist or studio is the controller for client personal data they collect, enter, import, review, or manage for their own services. Affichr acts as processor/service provider for that client data. Affichr remains an independent controller for account administration, platform security, billing, subscriptions, internal analytics, fraud prevention, abuse detection, legal compliance, support, and records Affichr must keep for its own obligations.
Affichr processes client data only to provide and secure the platform, including booking requests, appointment management, reminders, consent workflows, design sharing, client notes, imports, exports, support, abuse prevention, and retention workflows. The artist's use of the platform and these Terms are the artist's documented instructions.
Client data may include identifiers, contact details, appointment records, booking descriptions, reference files, design files, communications, consent records, health questionnaire answers, location preferences, payment/deposit metadata, and communication preferences. Health and consent data may be special-category or sensitive data under applicable law.
Affichr maintains technical and organizational measures including TLS in transit, database row-level security, role-based access, private storage buckets, short-lived signed URLs for private files, audit logging, rate limiting, credential controls, and retention cleanup for selected telemetry and workflow records.
Affichr may use subprocessors listed in the Privacy Policy, including Supabase, Stripe, Twilio, Resend, Daily.co, Google, PostHog, Groq, Gemini, Browserless.io, Shorebird, and deployment-controlled AI endpoints where configured. Affichr will require subprocessors to protect personal data under written terms appropriate to their processing role.
Where EEA/UK client personal data is transferred to a country without an adequacy decision, Affichr relies on appropriate transfer safeguards where required, including EU Standard Contractual Clauses, the UK International Data Transfer Addendum or equivalent UK transfer mechanism, and provider Data Privacy Framework certification where available and applicable.
Affichr will provide reasonable assistance for data subject requests, security obligations, data protection impact assessments, and regulator consultations where required by applicable data protection law and where the request relates to Affichr's processing. Affichr will notify affected artists without undue delay after becoming aware of a personal data breach affecting client data processed on their behalf.
On account closure or verified deletion request, Affichr will delete, anonymize, return, or export eligible client data according to platform capabilities and applicable retention rules. Records required for legal, tax, health, security, fraud-prevention, dispute, or chargeback purposes may be retained for the required period with access restricted.
Affichr may satisfy audit obligations by providing security summaries, subprocessors, retention documentation, and reasonable written responses. Direct audits require advance written notice, confidentiality, reasonable scope, and controls to protect other customers and platform security.