Data Processing Agreement

Annex 2 to the Terms of Service. In force from 24 August 2026. It binds both sides from the moment the Terms are accepted — no separate signature needed.

Annex 2 to the ConverterSEO Terms of Service

§ 1. Parties and nature of this agreement

  1. This agreement is Annex 2 to the Terms of Service and binds the parties from the moment the Terms are accepted. No separate signature is required.
  2. The controller of the data entrusted under this agreement is the Customer.
  3. The processor is DESEO DESIGN sp. z o.o., al. Korfantego 125a, 40-156 Katowice, Poland, KRS 0000975111 (the Processor).
  4. This agreement fulfils the obligation under Article 28(3) of Regulation 2016/679 (GDPR).

§ 2. Separation of roles

  1. Only the data contained in the image files submitted by the Customer for processing, together with the address of the website the request comes from, are entrusted under this agreement.
  2. In relation to the Customer's own data — email address, company name, Business profile, Licence keys, subscription data and usage statistics — the Processor acts as an independent controller, not as a processor. The Privacy Policy governs how those are processed.
  3. The distinction in paragraphs 1 and 2 matters: the same regulation imposes different obligations on a controller and on a processor.

§ 3. Subject, purpose and scope

  1. Purpose: generating metadata for an image file — a title, alt text, a description and a proposed file name.
  2. Categories of data: personal data that may be present in the content of image files, in particular images of natural persons, and data contained in file metadata where the Customer has not removed it.
  3. Categories of data subjects: persons visible in the image files submitted by the Customer, including the Customer's employees, customers and business partners.
  4. Nature of processing: transmission, reading and analysis of the image, transfer to the sub-processor, return of the result. Processing is one-off and transient.
  5. Duration of processing: the time it takes to complete a single request. The Processor neither saves nor stores the submitted image files — not in a database, not on disk, not in logs.
  6. The Customer is under no obligation to submit files containing personal data. What is submitted is entirely the Customer's decision.

§ 4. Obligations of the Processor

The Processor undertakes to:

  1. process the data only on the Customer's documented instruction, being each request sent from the Plugin or the panel;
  2. not use the entrusted data for its own purposes, in particular not to use submitted files to train models or to build datasets;
  3. ensure that access to the data is limited to authorised persons bound by confidentiality;
  4. apply technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS), authentication of requests by Licence key, and restricted access to servers;
  5. assist the Customer in meeting the obligations under Articles 32–36 GDPR, in particular when notifying breaches and carrying out data protection impact assessments;
  6. assist the Customer in responding to data subject requests — noting that because image files are not stored, the Processor holds no data it could produce, rectify or erase;
  7. notify the Customer of a breach affecting the entrusted data without undue delay and no later than within 48 hours of detecting it;
  8. delete all entrusted data on completion of the services — an obligation met as each request completes, because the data is not stored;
  9. make available to the Customer the information needed to demonstrate compliance and allow audits on the terms in § 7.

§ 5. Obligations of the Customer

  1. The Customer declares that it has a legal basis for processing the data contained in the files submitted and holds the rights to those files.
  2. The Customer is responsible for meeting the information obligation towards data subjects, including informing them about the use of ConverterSEO where required.
  3. The Customer does not submit files containing special categories of data (Article 9 GDPR) or data relating to criminal convictions, unless separate terms have been agreed with the Processor beforehand.

§ 6. Sub-processors

  1. The Customer gives general authorisation for the use of sub-processors.
  2. As at the date of this agreement the Processor uses:
EntityRolePlace of processing
Anthropic PBCimage analysis and metadata generationUnited States
Cyber_Folks S.A.hosting of the application serverPoland
  1. The Processor informs the Customer of an intended change to the list of sub-processors at least 30 days before it takes effect, by publishing the information in the Service and sending it by email. The Customer may object, in which case it may terminate the service contract with immediate effect and at no cost.
  2. The Processor imposes on sub-processors data protection obligations no less protective than those in this agreement and is liable for their acts as for its own.

§ 7. Transfers outside the European Economic Area

  1. Image analysis takes place at a sub-processor established in the United States, which constitutes a transfer to a third country.
  2. The transfer is based on the standard contractual clauses adopted by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, set out in the Data Processing Addendum of Anthropic PBC, which forms part of the Processor's agreement with that entity.
  3. Because the Processor acts as a processor towards the Customer, Module Three of the clauses applies — processor to processor transfers.
  4. Anthropic PBC does not rely in that document on certification under the EU–US Data Privacy Framework. The transfer basis remains the contractual clauses referred to in paragraph 2.
  5. Anthropic PBC publishes its current list of further sub-processors at trust.anthropic.com/subprocessors.
  6. All other processing operations take place on a server in Poland.

§ 8. Audit

  1. The Customer has the right to verify how this agreement is performed.
  2. An audit is announced at least 14 days in advance and no more than once per calendar year, except for an audit following a personal data breach, which may be carried out immediately.
  3. An audit may not infringe the Processor's business secrets or the protection of other customers' data.
  4. The Processor may demonstrate compliance by presenting the results of its own audits or technical documentation.

§ 9. Liability

  1. Each party is liable for damage caused by processing that infringes the GDPR, on the terms of Article 82 GDPR.
  2. The limitation of liability in § 13 of the Terms applies to this agreement as well, to the extent permitted by law.

§ 10. Duration and final provisions

  1. This agreement applies for as long as the ConverterSEO service contract is in force and expires together with it.
  2. Changes to this agreement follow the rules for changing the Terms (§ 15 of the Terms).
  3. Matters not covered here are governed by the GDPR and by Polish law.
  4. This agreement takes effect on 24 August 2026.