Data Processing Agreement
Version 2.2 · 14 August 2026
Status: In force. Version 2.2 posted 14 August 2026, effective 13 September 2026, superseding version 1.1. Forms part of the Pixop Terms of Service, as in effect from time to time, in accordance with §16.
Parties: Customer (Controller) and Pixop ApS (Processor).
Incorporates: Pixop Terms of Service (the “Agreement”).
1. Scope, roles, and precedence
1.1 This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the Pixop Terms of Service between Pixop ApS (“Pixop”) and the customer accepting those terms (“Customer”) (the “Agreement”). It applies whenever Pixop processes Personal Data on the Customer’s behalf in connection with the Pixop Platform Service. It does not apply to Pixop Prime supplied under a negotiated Master Service Agreement, which is governed by the data-processing annex to that agreement.
1.2 Roles. For the processing under this DPA, the Customer is the Controller (or, where the Customer is itself a processor for a third-party controller, the Customer is that processor) and Pixop is the Processor. This DPA governs only Pixop’s processing of Personal Data as Processor on the Customer’s behalf (principally Personal Data contained in the Customer Content). Personal Data that Pixop processes to operate its own business - including account, billing, security, audit, and compliance data - is processed by Pixop as Controller under the Pixop Privacy Policy, not under this DPA.
1.3 Precedence. In the event of a conflict between this DPA and the rest of the Agreement regarding the processing of Personal Data, this DPA prevails. Where the Customer and Pixop have executed a separate, negotiated data processing agreement, that agreement prevails over this DPA to the extent of any conflict.
1.4 Processing environment. How this DPA applies depends on where the processing occurs:
(a) Processing in Pixop’s environment (managed Service). Where the Customer Content is copied into and processed within Pixop’s own cloud environment (for example, Pixop’s AWS account) to produce the Output, Pixop hosts and processes that Customer Content as Processor, and the full obligations of this DPA apply to it, including security (Section 6), the engagement of the cloud infrastructure provider and other Sub-processors (Section 7), international transfers (Section 12), and deletion or return (Section 11).
(b) Customer-controlled storage. Where the Customer provides its own storage for ingestion or delivery (for example, its own S3 buckets or HTTPS endpoints), that storage, and the content held in it, remain under the Customer’s control. Pixop reads from and writes to that storage to perform the requested processing but does not retain the Customer Content in it. The Customer is responsible for the security, access controls, and configuration of its own storage, and for any international transfer arising from its choice of storage region.
2. Definitions
Capitalised terms not defined here have the meaning given in the Agreement. “Controller”, “Processor”, “Personal Data”, “Processing”, “Data Subject”, “Personal Data Breach”, “Sub-processor”, and “Supervisory Authority” have the meanings given in the GDPR. “GDPR” means Regulation (EU) 2016/679. “Data Protection Law” means all data protection and privacy laws applicable to the processing under the Agreement, including the GDPR. “Customer Content” and “Service” have the meanings given in the Agreement.
3. Processing on documented instructions
3.1 Pixop will process the Customer’s Personal Data only on the Customer’s documented instructions, including as to international transfers, unless required to do otherwise by Union or Member State law (in which case Pixop will inform the Customer of that legal requirement before processing, unless the law prohibits it). The Agreement, this DPA, and the Customer’s configuration and use of the Service (including the content it submits and the processing it requests through the API or web application) constitute the Customer’s documented instructions.
3.2 Pixop will promptly inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
3.3 Pixop will not sell the Personal Data, and will not process it for any purpose other than providing and supporting the Service under the Agreement, except as required by law.
4. Details of the processing (Article 28(3) GDPR)
Item | Description |
|---|---|
Subject matter | Pixop’s processing of Personal Data contained in Customer Content, and support or diagnostic material supplied by Customer, to provide and support the Service under the Agreement. |
Duration | The term of the Agreement, plus the retention periods in Section 11. |
Nature and purpose | Ingestion, hosting, processing (enhancement, restoration, format and colour conversion), storage and delivery of Customer Content; and receipt, storage and analysis of support or diagnostic material supplied by Customer - in each case on Customer’s documented instructions to provide and support the Service. |
Categories of Data Subjects | Individuals appearing in or otherwise identifiable from Customer Content (for example, persons depicted or heard in video or audio), and individuals identifiable from support or diagnostic material supplied by Customer. |
Categories of Personal Data | Personal Data contained in Customer Content (for example, images, likenesses and voices of individuals, and personal data in associated metadata or subtitles), and Personal Data contained in support or diagnostic material supplied by Customer. |
Special categories | Special categories of personal data may appear incidentally within general audiovisual Customer Content (for example, data that may reveal health, racial or ethnic origin, or biometric characteristics of individuals shown or heard). The Customer must not intentionally use the Service to process special categories as a distinct dataset, or other highly sensitive information, unless expressly agreed with Pixop in writing (Terms of Service §5.4). |
5. Confidentiality
Pixop will ensure that persons authorised to process the Personal Data are bound by an appropriate obligation of confidentiality (contractual or statutory) and are limited to those who need access to provide the Service.
6. Security (Article 32 GDPR)
6.1 Pixop will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including, as appropriate: encryption of Personal Data in transit and at rest; measures to ensure the ongoing confidentiality, integrity, availability, and resilience of the Service; the ability to restore availability and access to Personal Data in a timely manner after an incident; and a process for regularly testing and evaluating the effectiveness of those measures.
6.2 These measures are described in Section 10 (Security) of the Agreement and summarised in Annex A (Technical and organisational measures). Pixop may update its measures from time to time provided the overall level of protection is not materially reduced.
7. Sub-processors
7.1 Authorised Sub-processors. The Customer grants Pixop general authorisation to engage the Sub-processors identified on Pixop’s current Sub-processor List, available at https://www.pixop.com/sub-processors. The list identifies each Sub-processor’s legal entity, service and processing purpose, location or region, and applicable transfer mechanism.
Pixop’s video enhancement is performed by Pixop’s own machine-learning models running on its cloud infrastructure; Pixop does not use any third-party artificial-intelligence service to process the Customer Content.
7.2 Changes to Sub-processors. Pixop will give the Customer at least thirty (30) days’ prior notice of an intended addition or replacement of a Sub-processor by email, account notice or another durable electronic notice. The Customer may object within that period on reasonable and documented data-protection grounds.
The parties will work in good faith to resolve the objection. If the objection cannot reasonably be resolved before the proposed change takes effect, the Customer may terminate the affected part of the Service as its exclusive remedy.
Where the Customer terminates the affected part of the Service under this Section, Pixop will refund any prepaid fees attributable to the terminated part of the Service for the period after termination. Fees for Usage already incurred, services already provided, or other amounts already due are non-refundable. Where the Service was purchased through a Marketplace or Partner Platform, any refund will be processed through the applicable channel in accordance with the Agreement.
An update to the Sub-processor List does not otherwise amend this DPA.
7.3 Pixop will impose on each Sub-processor data-protection obligations that are, in substance, no less protective than those in this DPA, and remains liable for the acts and omissions of its Sub-processors to the same extent as if performed by Pixop.
Service providers used solely for Pixop’s own Controller activities - including payment processing, account administration, fraud prevention, security, audit and compliance - are not Sub-processors under this DPA and are described in the Pixop Privacy Policy.
7.4 Providers acting in different roles. A service provider may process different categories of Personal Data in different capacities. Where a provider processes Personal Data on Pixop’s behalf in connection with processing performed for the Customer under this DPA, that provider acts as a Sub-processor and is identified on the Sub-processor List.
The same provider may separately provide services to Pixop in relation to Personal Data for which Pixop determines the purposes and means of processing and acts as Controller. Such Controller-side processing is outside the scope of this DPA and is described, where applicable, in the Pixop Privacy Policy.
8. Assistance to the Controller
Taking into account the nature of the processing and the information available to it, Pixop will assist the Customer, by appropriate technical and organisational measures and insofar as reasonably possible, in fulfilling the Customer’s obligations to: (a) respond to requests from Data Subjects exercising their rights under Articles 12-23 GDPR; and (b) ensure compliance with its obligations under Articles 32-36 GDPR (security, breach notification, and data protection impact assessments and prior consultation).
9. Personal Data Breach
Pixop will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting the Customer’s Personal Data, and will provide the Customer with the information reasonably available to enable the Customer to meet any breach-notification obligations under Data Protection Law. Pixop’s notification is not an acknowledgement of fault or liability.
10. Data Subject requests
Pixop will, to the extent legally permitted, promptly notify the Customer if it receives a request from a Data Subject in respect of Personal Data processed under this DPA, and will not respond to that request itself except on the Customer’s documented instructions or as required by law.
11. Deletion or return
11.1 On termination or expiry of the Agreement, Pixop will delete the Customer’s Personal Data, or return it to the Customer if the Customer so requests in writing before deletion, and delete existing copies, unless Union or Member State law requires continued storage. Where return is requested, it is provided through the Service’s export functionality or another mutually agreed secure method, in a commonly used, machine-readable format. Pixop will permanently delete remaining Customer Content and Output from its active systems no later than thirty (30) days after termination, and may delete earlier, subject to the backup cycle in Section 11.3.
11.2 Support and diagnostic data containing Personal Data is deleted or anonymised within a period not exceeding ninety (90) days after closure of the related support matter.
11.3 Backups. Personal Data may persist in Pixop’s routine backups after deletion from active systems. Such backups are retained on a rolling basis and are overwritten or deleted in the ordinary backup cycle, in any event within a period not exceeding thirty (30) days. Personal Data in backups is not returned to active use except as part of a service-recovery operation, and remains subject to this DPA until deleted.
11.4 Security and audit logs. For the avoidance of doubt, and consistent with §1.2, this Section 11 does not require Pixop to delete or return security or audit logs. Pixop processes the Personal Data contained in those logs - such as identifiers, IP addresses and timestamps - as controller, for security, abuse prevention, incident investigation and compliance, and retains them in accordance with the Pixop Privacy Policy.
12. International transfers
Customer Content is hosted and processed by default in AWS Europe (Ireland), eu-west-1, within the EEA. An EEA hosting region does not by itself eliminate an international transfer: access to Personal Data processed under this DPA by Pixop personnel or a Sub-processor from outside the EEA is treated as a transfer and is made under a valid transfer mechanism, including the EU Standard Contractual Clauses together with any necessary supplementary measures. For transfers originating in the United Kingdom, the UK International Data Transfer Addendum applies; for transfers originating in Switzerland, the applicable Swiss amendments apply. Where such a transfer occurs, Pixop will assess it and apply supplementary measures where required. Transfers relating solely to Personal Data that Pixop processes as Controller are outside this DPA and are described in the Pixop Privacy Policy.
13. Audits
Pixop will make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 GDPR and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, in relation to Pixop’s processing of Personal Data under this DPA.
Audits require reasonable prior written notice, will be conducted during normal business hours, and must be performed in a manner that does not unreasonably disrupt Pixop’s operations or compromise the security, confidentiality, or rights of other customers or third parties.
Unless required by a Supervisory Authority, applicable Data Protection Law, or reasonably necessary following a material Personal Data Breach or where the Customer has reasonable and documented grounds to suspect a material breach of this DPA, the Customer may conduct no more than one audit in any twelve (12)-month period.
Pixop may satisfy an audit request, where reasonably appropriate, by providing relevant documentation, completing a questionnaire, conducting a remote review, or providing an available third-party audit report or certification. An on-site inspection may be conducted where the information available through those methods is not reasonably sufficient to demonstrate compliance.
Each party will bear its own costs relating to an audit. Where an audit requires material assistance from Pixop beyond the information and cooperation reasonably required under Article 28 GDPR, Pixop may charge the Customer its reasonable costs for that additional assistance, provided that Pixop will not charge such additional costs where the audit identifies a material breach of this DPA by Pixop.
Information disclosed in connection with an audit is Confidential Information of Pixop.
14. Liability and governing law
The liability of the parties under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA is governed by, and construed in accordance with, the governing law of the Agreement (the laws of England and Wales), and disputes are resolved as provided in the Agreement.
15. Term
This DPA takes effect on the Customer’s acceptance of the Agreement and remains in effect for as long as Pixop processes the Customer’s Personal Data on its behalf.
16. Changes to this DPA
Pixop may update this DPA from time to time. An updated version takes effect thirty (30) days after Pixop posts it at https://www.pixop.com/data-processing-agreement or notifies the Customer under the Agreement, whichever is earlier, except that an update made in response to a change in applicable law, or required by a Supervisory Authority, takes effect on the date stated in it.
No update applies retroactively to Processing already carried out.
Where an update is materially adverse to the Customer, the Customer may, before the update takes effect, terminate the affected part of the Service by written notice, and Pixop will refund any prepaid fees attributable to the terminated part of the Service for the period after termination. That right is the Customer’s exclusive remedy in respect of the update.
Pixop maintains a version history of this DPA, stating each version and the period during which it was in effect, at the address above.
Annex A - Technical and organisational measures (Article 32 GDPR)
Pixop’s current measures include the following, which it may update provided the overall level of protection is not materially reduced:
Personal Data is protected in transit using secure protocols appropriate to the interface concerned, and is encrypted at rest where the relevant cloud service and configuration support it.
Separation of customer data. Customer data is held in shared database tables and is separated by a team identifier. Separation is enforced in Pixop’s application layer, which scopes each request to the teams of which the requesting user is a member; a user may be a member of more than one team and has access to the data of each. Separation is therefore a property of the application rather than of the infrastructure: Pixop does not operate a separate database, schema or cloud environment for each customer.
Network access to the production environment is restricted using the cloud provider’s controls, including private networking and security-group restrictions. These restrict access to the environment as a whole; they are not the mechanism by which one customer’s data is separated from another’s.
Access to Personal Data is restricted to authorised personnel on a need-to-know basis. Human access is assigned to identifiable individual users wherever the relevant system supports individual accounts; where a shared technical or service account is operationally necessary, its permissions are restricted and its credentials protected.
Privileged access is protected by strong authentication, including multi-factor authentication where the relevant system supports it and it is configured.
Permissions are adjusted when responsibilities change, and accounts, credentials, keys and cloud permissions are removed when personnel leave or no longer require access.
Media assets in the Pixop-operated environment are not exposed publicly; access is granted through authenticated, authorisation-checked interfaces.
Hosting on established cloud infrastructure (AWS), using managed services for isolation, resilience and monitoring. AWS maintains its own security certifications and independent assurance reports; those are AWS’s and are not Pixop certifications.
Operational monitoring, health checks and alerting, and collection of operating-system, application and service logs for monitoring and investigation on the systems on which such logging is enabled.
Audit logging of security-relevant events.
Review of security advisories and relevant operating-system and application updates, with vulnerabilities remediated according to severity and risk.
An operational incident-response process covering detection, assessment, containment, remediation, recovery and follow-up.
Backup of persistent application and database data using the backup facilities of the relevant cloud service. Where Pixop processes Customer Content without persistently storing it, that content is not held in backups and service recovery is based on redeploying the application and its configuration.
Personnel and relevant contractors with access to Personal Data are bound by written confidentiality obligations; background screening is performed where appropriate and legally permitted; and new personnel receive security guidance during onboarding.
Changes are managed through source control, testing, and technical or peer review where appropriate.
Independent assurance. The technical and organisational measures described in this Annex reflect the safeguards currently implemented by Pixop. Pixop does not currently maintain an independent security certification such as ISO/IEC 27001 or SOC 2.
References to certifications, assurance reports, or security controls maintained by Pixop’s cloud or other service providers describe those providers’ controls and do not constitute certifications of Pixop itself.
Version history
Version | Posted | In effect |
|---|---|---|
v1.1 | 27 July 2026 | 27 July 2026 – 12 September 2026 |
v2.2 | 14 August 2026 | from 13 September 2026 |