Data Processing Agreement
Document: DOC 2
Version: 2.0
Effective date: 3 August 2026
Background
(A) The Artist uses the Stoodio platform to publish and operate a professional website (the Artist Website) accessible to the public. In the course of operating that website, personal data belonging to visitors, prospective buyers, and other third parties (Visitor Data) is collected and processed.
(B) In relation to Visitor Data, the Artist is the data controller and STOODIO LTD (trading as Stoodio) acts as a data processor, processing that data on the Artist's behalf and in accordance with the Artist's instructions, as set out in this Agreement.
(C) This Data Processing Agreement (DPA) is entered into in accordance with Article 28 of the UK General Data Protection Regulation (UK GDPR) and forms part of the Terms and Conditions of Service (DOC 1) agreed between the parties. Where the Artist Website is accessed by visitors located in the European Economic Area, this DPA is also intended to satisfy the requirements of Article 28 of EU GDPR (Regulation (EU) 2016/679), the content of which is materially identical to UK GDPR Article 28. In the event of any conflict between this DPA and DOC 1, this DPA shall prevail in respect of the processing of personal data.
(D) Both parties acknowledge that Stoodio also processes certain Artist Data in its own capacity as an independent data controller, for the purposes described in Clauses 9 and 9A of DOC 1. That processing falls outside the scope of this DPA, which applies exclusively to Stoodio's processing of Visitor Data on the Artist's behalf.
(E) Stoodio intends, in a future phase of its product development, to process certain Visitor Data in its own capacity as an independent data controller for the purpose of generating aggregated and anonymised market intelligence for sharing with Art Sector Partners (as defined in DOC 1). When that processing commences, Stoodio will notify the Artist and, where required by applicable law, update this DPA or enter into a separate agreement to reflect the dual-controller relationship. Until such notification is given, this DPA applies exclusively to Stoodio's processing of Visitor Data on the Artist's behalf as set out herein.
1. Definitions
In this DPA, the following definitions apply. Terms not defined here have the meaning given to them in DOC 1 or in UK GDPR.
"Controller" means the Artist, who determines the purposes and means of the processing of Visitor Data.
"Processor" means STOODIO LTD (trading as Stoodio), Company No. 14071912, which processes Visitor Data on behalf of the Controller.
Registered office: Roberts Court, 45 Barkston Gardens, London SW5 0ES
"Visitor Data" means any personal data relating to visitors to the Artist Website, including but not limited to: names, email addresses, and other contact information submitted via inquiry forms, contact forms, or newsletter sign-up forms; IP addresses and device identifiers collected via cookies or analytics tools; browsing behaviour data (pages visited, artworks viewed, session duration, referral source); purchase and transaction-related information submitted in the course of buying an artwork; and any other personal data submitted by visitors in the course of interacting with the Artist Website.
"Processing" has the meaning given in UK GDPR and includes any operation performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.
"Sub-processor" means any third party engaged by Stoodio to carry out processing activities in respect of Visitor Data on the Controller's behalf.
"Security Incident" means any confirmed or reasonably suspected accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Visitor Data.
"UK GDPR" means the UK General Data Protection Regulation as incorporated into UK law by the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018. References in this DPA to UK GDPR shall, where the context requires, also be read as references to EU GDPR (Regulation (EU) 2016/679) in respect of the processing of personal data of individuals located in the European Economic Area.
2. Scope and Duration
This DPA applies to all processing of Visitor Data carried out by Stoodio in the course of operating the Artist Website and providing the associated services described in DOC 1.
This DPA commences on the date of Account registration and remains in force for the duration of the Artist's active Account. Upon termination of the Artist's Account, Stoodio shall cease processing Visitor Data on the Artist's behalf, subject to the retention and deletion obligations in Clause 8.
This DPA does not apply to processing Stoodio carries out as an independent controller: (a) the Artist Data processing described in Clauses 9 and 9A of DOC 1; and (b) where a visitor has separately opted in on an Artist Website form, the processing of that visitor's contact details for Stoodio's own purposes, as described in the Stoodio Privacy Policy (DOC 7, Section 9).
3. Nature, Purpose, and Legal Basis of Processing
3.1 Nature of processing
Stoodio processes Visitor Data by: collecting it via forms and tracking technologies embedded in the Artist Website; storing it on secure servers; making it accessible to the Artist via the dashboard; generating analytics and performance metrics from it; and, where applicable, transmitting it to Sub-processors for the purposes described below.
3.2 Purposes of processing
Stoodio processes Visitor Data on the Artist's behalf, subject to the carve-out in Clause 2, and for the following purposes:
- Operating and delivering the Artist Website and its interactive features (contact forms, inquiry forms, newsletter sign-up, artwork browsing, and checkout).
- Enabling the Artist to receive, manage, and respond to inquiries and purchase requests from visitors.
- Generating website analytics and performance data (visitor counts, geographic distribution, artwork engagement metrics, session behaviour) accessible to the Artist via the dashboard.
- Processing payments initiated by visitors, via the Third-Party Payment Processor connected by the Artist, solely to the extent of passing transaction data to that processor and receiving status notifications in return.
- Facilitating newsletter and marketing communications sent by the Artist to visitors who have subscribed.
- Complying with applicable legal obligations.
3.3 Processing on documented instructions only
Stoodio shall process Visitor Data only on the documented instructions of the Artist as set out in this DPA and in the configuration options available within the Platform. Stoodio shall not process Visitor Data for any other purpose without the prior documented agreement of the Artist, communicated via the Account Settings or in writing, except where required to do so by applicable law, in which case Stoodio shall inform the Artist of that legal requirement before processing (unless prohibited from doing so by law).
The Artist, as Controller, is responsible for ensuring that there is a valid legal basis under UK GDPR for each processing activity carried out on their behalf, including the collection of Visitor Data via inquiry forms, the use of analytics cookies, and any marketing communications.
The Artist instructs Stoodio to present, on the Artist Website's contact and subscription forms, a separate optional opt-in through which a visitor may ask Stoodio to keep in touch with them directly. Data collected under that opt-in is processed by Stoodio as an independent controller and falls outside this DPA.
4. Obligations of Stoodio as Processor
4.1 Confidentiality
Stoodio shall ensure that all personnel authorised to process Visitor Data are bound by appropriate confidentiality obligations, whether contractual or statutory.
4.2 Security
Stoodio shall implement and maintain appropriate technical and organisational security measures to protect Visitor Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, taking into account the nature, scope, context, and purposes of processing and the risks to the rights and freedoms of natural persons. These measures include, as a minimum:
- Encryption of Visitor Data in transit (TLS) and at rest.
- Access controls limiting access to Visitor Data to authorised personnel only.
- Regular testing and evaluation of the effectiveness of security measures.
- Procedures for regularly backing up data and restoring availability following a technical incident.
4.3 Sub-processors
The Artist grants Stoodio general authorisation to engage Sub-processors for the purposes of this DPA. The Sub-processors engaged by Stoodio as of the effective date of this DPA are listed in Schedule B. Stoodio shall:
- Notify the Artist of any intended addition or replacement of Sub-processors at least fourteen (14) days before the change takes effect. The Artist may object in writing within that fourteen (14) day period. If no written objection is received within fourteen (14) days of notification, the Artist shall be deemed to have accepted the new or replacement Sub-processor. Where the Artist raises a legitimate and documented objection, the parties shall discuss in good faith; if no resolution is reached, the Artist may terminate this DPA on written notice. Where the objection concerns a sub-processor used for Stoodio's Assistive AI, Stoodio will, on the Artist's legitimate and documented objection, suspend transmission of that Artist's Content to the objected-to provider and disable the dependent optional features; termination is the last resort, not the only remedy.
- Impose data protection obligations on each Sub-processor that are no less protective than those set out in this DPA.
- Remain fully liable to the Artist for the performance of each Sub-processor's obligations to the extent that such Sub-processor fails to fulfil its data protection obligations.
4.4 Assistance to the Controller
Taking into account the nature of the processing, Stoodio shall provide reasonable assistance to the Artist in fulfilling the Artist's obligations to respond to requests from data subjects exercising their rights under UK GDPR (including the rights of access, rectification, erasure, restriction, portability, and objection).
Stoodio shall also provide reasonable assistance to the Artist in ensuring compliance with the Artist's obligations relating to security of processing, notification of Security Incidents to the relevant supervisory authority, and, where applicable, data protection impact assessments.
4.5 Security Incidents
Stoodio shall notify the Artist without undue delay, and in any event within 72 hours of becoming aware of a confirmed Security Incident affecting Visitor Data. Such notification shall include, to the extent known at the time: a description of the nature of the incident; the categories and approximate number of data subjects affected; the categories and approximate volume of Visitor Data affected; the likely consequences of the incident; and the measures taken or proposed to address the incident.
4.6 Deletion and return of data
Upon termination of this DPA, or upon written request by the Artist, Stoodio shall (at the Artist's election) delete or return all Visitor Data processed on the Artist's behalf, and shall delete all existing copies no later than ninety (90) days following termination, unless applicable law requires longer retention. The Artist may request earlier deletion at any time; Stoodio shall comply within thirty (30) days of such request and confirm completion in writing.
Notwithstanding the above, Stoodio may retain anonymised or aggregated data derived from Visitor Data indefinitely, provided that such data cannot be used to re-identify any individual.
4.7 Audit rights
Stoodio shall make available to the Artist all information reasonably necessary to demonstrate compliance with the obligations set out in this DPA. Where Stoodio holds a current and relevant security certification (including without limitation ISO 27001, SOC 2 Type II, or equivalent), provision of that certification shall be deemed sufficient to satisfy the audit and inspection obligation in respect of the matters covered by the certification. Where no such certification is in place, or where the Artist reasonably requires verification beyond the scope of any certification, Stoodio shall allow for and contribute to audits or inspections conducted by the Artist or an auditor appointed by the Artist, provided that: (a) the Artist gives at least thirty (30) days' prior written notice; (b) audits are conducted during normal business hours and in a manner that does not unreasonably disrupt Stoodio's operations; and (c) the parties agree in good faith on the scope and cost of any audit before it commences. Each party shall bear its own costs in connection with any audit.
5. Obligations of the Artist as Controller
The Artist, as Controller, is solely responsible for:
- Ensuring that all processing of Visitor Data instructed to Stoodio has a valid legal basis under UK GDPR.
- Providing visitors to the Artist Website with a compliant privacy notice (as made available by Stoodio in standardised form and published on the Artist Website) that accurately describes the processing of their personal data. Stoodio is responsible for its own transparency obligations in respect of the processing it carries out as an independent controller.
- Obtaining any necessary consents from visitors prior to the collection of their personal data, including consent to the use of non-essential cookies where required.
- Ensuring that any personal data submitted to the Platform is accurate, adequate, and not excessive for the purposes for which it is collected.
- Notifying the relevant supervisory authority (the Information Commissioner's Office in the UK) of any Security Incident in accordance with Article 33 UK GDPR, using the information provided by Stoodio under Clause 4.5.
- Notifying affected data subjects of any Security Incident where required under Article 34 UK GDPR.
6. International Transfers
Stoodio shall not transfer Visitor Data outside the United Kingdom or the European Economic Area without ensuring that an appropriate transfer mechanism is in place in accordance with UK GDPR, including (where applicable) Standard Contractual Clauses (UK Addendum), adequacy decisions, or other approved safeguards.
Where Sub-processors are located outside the UK or EEA, Stoodio shall ensure that transfers to such Sub-processors are covered by an appropriate transfer mechanism. Details of Sub-processor locations and applicable transfer mechanisms are set out in Schedule B.
7. Liability
Each party's liability under this DPA is subject to the limitations set out in Clause 12 of DOC 1. Nothing in this DPA restricts or excludes liability that cannot be excluded under applicable law.
If Stoodio processes Visitor Data otherwise than in accordance with the Artist's documented instructions or the terms of this DPA, Stoodio shall bear liability as a controller in respect of that non-compliant processing.
8. Term and Termination
This DPA is effective from the date of Account registration and remains in force for as long as Stoodio processes Visitor Data on the Artist's behalf. It terminates automatically upon termination of the Artist's Account under DOC 1.
Upon termination, Stoodio shall delete or return Visitor Data as described in Clause 4.6. Clauses 4.1 (confidentiality), 4.6 (deletion), 7 (liability), and this Clause 8 shall survive termination.
9. General
This DPA is governed by the laws of England and Wales. Any dispute arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales.
If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.
This DPA constitutes the entire agreement between the parties with respect to the processing of Visitor Data by Stoodio on the Artist's behalf, and supersedes all prior agreements or understandings on the same subject matter.
Schedule A. Description of Processing Activities
Controller: The Artist (individual or entity registered on the Stoodio platform).
Processor: STOODIO LTD (trading as Stoodio).
Categories of data subjects
- Visitors to the Artist Website (members of the public, prospective buyers, collectors, gallery representatives, press, and other individuals accessing the Artist Website).
- Individuals who submit an inquiry or contact form on the Artist Website.
- Individuals who subscribe to the Artist's newsletter or mailing list.
- Individuals who purchase artwork via the Artist Website (Pro Plan only).
Categories of personal data processed
- Identity data: first name, last name, display name.
- Contact data: email address, telephone number (where provided).
- Transactional data: purchase records and transaction status notifications (sensitive payment credentials are not processed by Stoodio; see DOC 1, Clause 6).
- Behavioural and analytics data: IP address, device type and browser, pages visited, artworks viewed and engagement duration, session duration, referral source, geographic location (country/city level derived from IP).
- Communication data: content of messages submitted via inquiry or contact forms.
- Marketing preferences: newsletter subscription status, opt-in and opt-out records.
- Discovery data: how the visitor found the Artist (where voluntarily provided via form fields).
- Budget and interest data: budget range and acquisition interest type (where voluntarily provided via inquiry form).
Sensitive data
No special category data (as defined in Article 9 UK GDPR) is intentionally collected via the Artist Website. The Artist is responsible for ensuring that their inquiry and contact forms do not solicit special category data from visitors.
Nature of processing
Collection, storage, organisation, retrieval, use, display, transmission, and deletion of Visitor Data, carried out via the Stoodio platform infrastructure.
Purpose of processing
As set out in Clause 3.2 of this DPA.
Duration of processing
For the duration of the Artist's active Account. Following termination or upon written request by the Artist, Stoodio retains Visitor Data for a period of up to ninety (90) days, after which it is deleted or permanently anonymised, unless a shorter retention period is requested by the Artist or required by applicable law. Anonymised and aggregated analytical data, from which no individual can be re-identified, may be retained indefinitely.
Schedule B. Approved Sub-processors
The following Sub-processors are authorised by the Artist as of the effective date of this DPA. Stoodio will notify the Artist of any changes to this list in accordance with Clause 4.3.
Database, storage, and authentication provider: Supabase, Inc.
Purpose: hosting of the Platform database, media storage, and authentication.
Location: United States (infrastructure region: European Union). Transfer mechanism: Standard Contractual Clauses (UK Addendum).
Hosting and delivery provider: Vercel Inc.
Purpose: server infrastructure and delivery network for the Artist Website and Platform.
Location: United States. Transfer mechanism: Standard Contractual Clauses (UK Addendum).
Email delivery provider: Resend, Inc.
Purpose: delivery of transactional email (inquiry notifications, subscription confirmations).
Location: United States. Transfer mechanism: Standard Contractual Clauses (UK Addendum).
Payment processing (subscription billing): Stripe, Inc.
Purpose: processing of the Artist's subscription payments. Visitor payment data is not processed by Stoodio (DOC 1, Clause 6).
Location: United States / European Union. Transfer mechanism: Standard Contractual Clauses (UK Addendum).
Assistive AI provider (when engaged): a provider contractually bound as described in DOC 1, Clause 9A.3
Purpose: operation of Stoodio's internal, non-generative Assistive AI. Providers are engaged only on terms that prohibit training their own models on Stoodio inputs and that require deletion within a limited retention period.
Location and transfer mechanism: notified per Clause 4.3 before engagement.
Acceptance
This Data Processing Agreement is incorporated by reference into the Stoodio Terms and Conditions of Service (DOC 1) and is accepted by the Artist upon registration of a Stoodio Account. No separate signature is required. It is accepted together with DOC 1 by the affirmative act described in DOC 1, Clause 2.
STOODIO LTD · Registered in England and Wales · stoodio.io