Legal
Data Processing Addendum
Last updated: July 17, 2026
1. Parties and scope
This Data Processing Addendum ("DPA") forms part of the agreement between you ("Client", acting as data controller for your own business data) and Aikagra Technologies, operating as Chiselo ("we", "us", acting as data processor), under our Terms of Service. It applies wherever we process personal data on your behalf in the course of delivering the service described in our Privacy Policy. Where this DPA and the Terms conflict on the processing of personal data, this DPA controls.
2. Subject matter and duration
Subject matter: our provision of 3D-asset conversion services against the product photography, dimensions, and catalog data you submit. Duration: this DPA applies for as long as we process personal data on your behalf — from your first order until your account is closed and the deletion or return process in Section 10 is complete.
3. Nature and purpose of processing
We process the data you submit strictly to produce and deliver your converted 3D assets: ingesting your reference images and specs, running them through our generation pipeline, routing outputs through human review, and delivering finished files via a token-gated delivery link. We do not process your data for any purpose beyond operating the service you ordered, and we do not use it to train models for other clients or for our own unrelated purposes.
4. Categories of data subjects
The business contacts you designate to work with us — the people who submit orders, receive delivery notifications, or correspond with our support team. As a B2B service, we do not knowingly process personal data belonging to your own end consumers.
5. Categories of personal data
- Business contact details of the people you designate (name, work email, company, phone if provided)
- Any personal data incidentally present within the product photography, spec sheets, or catalog metadata you submit — for example, if a reference image happens to include a person, or a spec sheet includes an internal contact name. We don't request this, don't use it separately from your submission, and don't knowingly seek out end-consumer personal data as part of your catalog data.
6. Sub-processors
We rely on a small set of third-party sub-processors, grouped by category — cloud infrastructure & hosting, 3D generation, retexturing, communications, and analytics & performance monitoring — disclosed on our Vendor Disclosure page. We don't name specific vendors in public documentation; identities and data-flow detail are shared directly with you as part of executing this DPA. We remain responsible for each sub-processor's compliance with the obligations set out here.
We will give you at least 30 days' notice — via an update to the Vendor Disclosure page and, for material changes, directly to your account contact — before adding a new sub-processor category. If you reasonably object to a new sub-processor on data-protection grounds, notify us within that 30-day window and we will work with you in good faith to address the concern, which may include using an alternative sub-processor where feasible or, if we cannot reach a resolution, allowing you to terminate the affected services without penalty.
7. Security measures
Technical and organizational measures are described in full on our Security page and incorporated here by reference. In summary:
- Third-party API credentials encrypted at rest via Supabase Vault (
pgsodium), write-once and never displayed as plaintext - Row-Level Security enabled on every production table, deny-by-default where no policy exists
- Audit and financial tables that reject updates and deletes at the database level
- Inbound webhooks verified against a per-account HMAC signature, with no fall-open path
- Encryption at rest and in transit via our infrastructure providers
- Per-order credit reservation and per-account isolation preventing cross-client interference
- A fixed set of error classifications so failures surface rather than fail silently
8. Assistance with data subject rights
If an individual whose data we process on your behalf contacts us directly to exercise a data subject right (access, correction, deletion, portability), we will forward the request to you and give reasonable assistance so you can respond, since you remain the controller of that data. We will not respond to such a request on your behalf without your instruction, except where required by law.
9. Personal data breach notification
Consistent with our Security page, if we confirm a security breach affecting personal data we process on your behalf, we will notify you within 72 hours of confirmation, including — to the extent known at the time — the nature of the breach, the categories and approximate number of data subjects and records affected, and the measures taken or proposed in response.
10. Deletion or return of data on termination
On termination of your account, or on your written request, we will delete or return — at your election — the personal data we process on your behalf, except where retention is required by law. Absent a contrary instruction, uploaded source files and intermediate processing data are deleted within 60 days of final delivery, matching our standard retention practice described in our Privacy Policy. Delivered 3D assets and the records needed to support your delivery link are retained until you revoke that link or close your account.
11. International data transfers
Aikagra Technologies is based in India and our sub-processors operate globally, which means personal data may be transferred between India, the United States, and other jurisdictions in the course of delivering the service. We rely on our vendors' standard contractual protections and take reasonable measures to ensure data transferred internationally receives a comparable level of protection to that described in this DPA. If your organization requires Standard Contractual Clauses or another GDPR Chapter V transfer mechanism executed specifically between us, contact us and we'll work through that as part of finalizing this DPA for your engagement.
12. Audit and compliance
We do not currently hold SOC 2, ISO 27001, or other third-party compliance certifications. We will provide reasonable information necessary to demonstrate compliance with this DPA on request, and will discuss a mutually agreeable audit approach with clients who require one as part of their vendor review.
13. Liability
Each party's liability arising under this DPA is subject to the limitation of liability set out in our Terms of Service.
14. Governing law
This DPA is governed by the laws of India. Disputes are handled per the dispute resolution terms in our Terms of Service, including arbitration under the Arbitration and Conciliation Act, 1996, seated in India.
15. Changes
We may update this DPA from time to time. The date above reflects the most recent revision. Material changes will be communicated to clients with an active account.
16. Executing this DPA
This page is a starting point covering our standard processing terms — it isn't a countersigned instrument. To execute a DPA specific to your engagement, or to work through any client-specific terms (including transfer mechanisms under Section 11), email support@chiselo.design or get in touch.
17. Contact
Aikagra Technologies — support@chiselo.design