Terms of service

Last Updated: September 18, 2026

This Data Processing Addendum ("DPA") is entered into between CandorLight LLC ("Processor," "we," "us") and the Business Customer identified in the applicable ImageFlow-AI account or order form ("Controller," "you"), and is incorporated into and forms part of the ImageFlow-AI Terms of Service (the "Agreement"). Capitalized terms not defined here have the meaning given in the Agreement.

1. Definitions

1.1. "Personal Data" means any information relating to an identified or identifiable natural person that is processed by CandorLight on the Controller's behalf under the Agreement, including End User photos and inquiry-form submissions (full name, email, company name, company website, phone number, and message).

1.2. "Data Subject," "Processing," "Controller," "Processor," and "Sub-processor" have the meanings given under applicable Data Protection Law.

1.3. "Data Protection Law" means all data protection and privacy laws applicable to the Processing of Personal Data under this DPA, including, to the extent applicable, the EU General Data Protection Regulation ("GDPR"), the UK GDPR, Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA"), and applicable US state privacy laws.

2. Roles of the Parties

2.1. As between the parties, the Controller is the Controller of End User Personal Data, and CandorLight is the Processor, acting only on the Controller's documented instructions as set out in the Agreement, this DPA, and the Controller's configuration and use of the Service.

2.2. CandorLight will not Process Personal Data for any purpose other than providing the Service, except as required by applicable law — in which case CandorLight will inform the Controller of that legal requirement before Processing, unless the law prohibits such notice.

3. Details of Processing

Set out in Annex 1.

4. Confidentiality

CandorLight will ensure that personnel authorized to Process Personal Data are subject to a duty of confidentiality (whether contractual or statutory).

5. Security Measures

CandorLight will implement appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, or damage, as described in Annex 3.

6. Sub-processors

6.1. The Controller authorizes CandorLight to engage the Sub-processors listed in Annex 2. CandorLight will impose data protection obligations on each Sub-processor that are substantially no less protective than those in this DPA.

6.2. CandorLight will notify the Controller before adding or replacing a Sub-processor within 30 days, giving the Controller the opportunity to object on reasonable data-protection grounds. If the Controller objects and the parties can't resolve it either party may terminate the affected part of the Service.

7. International Data Transfers

7.1. Personal Data is currently Processed and stored in "United States".

7.2. If CandorLight transfers Personal Data outside the country or region in which it was collected in a manner that requires a specific legal transfer mechanism under Data Protection Law, CandorLight will implement that mechanism (such as Standard Contractual Clauses) before the transfer occurs. [CONFIRM/FLAG: this clause is written to activate once you expand to Europe — before any EU Personal Data is actually processed, this section needs the specific mechanism named, not a placeholder.]

8. Assistance with Data Subject Rights

Taking into account the nature of the Processing, CandorLight will provide reasonable assistance to the Controller, by appropriate technical and organizational measures, to help the Controller respond to requests from Data Subjects to exercise their rights under Data Protection Law (such as access, correction, deletion, or portability requests), including by providing an export of the relevant Personal Data on request, consistent with Section 13 of the Agreement.

9. Personal Data Breach Notification

CandorLight will notify the Controller without undue delay, and in any event within [CONFIRM: window — 72 hours is the GDPR benchmark and a reasonable default if you don't have a different operational target] of becoming aware of a Personal Data breach affecting the Controller's End User Personal Data, and will provide reasonably available information to help the Controller meet its own notification obligations.

10. Deletion and Return of Data

Consistent with Section 13 of the Agreement, upon termination of the Agreement, CandorLight will provide an export of the Controller's Personal Data on request and will delete or anonymize retained Personal Data within twelve (12) months, except to the extent retention is required by law.

11. Audit Rights

11.1. CandorLight will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA. [CONFIRM: whether you're willing to support a more formal audit right — an annual questionnaire is common and much less operationally burdensome than allowing on-site or third-party audits; many early-stage SaaS companies limit this to information requests plus independent certifications/reports if and when you have any (e.g., a future SOC 2), rather than open-ended audit access.]

12. Liability

Each party's liability arising under this DPA is subject to the limitations of liability set out in Section 11 of the Agreement.

13. Term

This DPA remains in effect for as long as CandorLight Processes Personal Data on the Controller's behalf under the Agreement.


Annex 1 — Details of Processing

Subject matter Provision of the ImageFlow-AI visual product search widget and lead-capture service
Duration For the term of the Agreement, plus the retention period in Section 13
Nature and purpose Matching End User-submitted photos against the Controller's product catalog; capturing and delivering inquiry-form submissions to the Controller as sales leads
Categories of Data Subjects End Users (visitors to the Controller's website who use the widget)
Categories of Personal Data Photos submitted for matching; full name, email address, company name, company website, phone number, and message text submitted via the inquiry form
Special categories of data None. The Service is not designed to collect or process special categories of Personal Data, and Controllers should not configure the widget or catalog to invite Data Subjects to submit such data.

Annex 2 — Sub-processors

Sub-processor Purpose Location
Microsoft Azure Hosting and infrastructure USA
[CONFIRM] [Any payment processor used for billing — e.g., Stripe — wasn't covered in our Terms/Privacy work. If one exists, it processes Business Customer billing data, which is a separate Personal Data flow from End User data and belongs in this list.]

Annex 3 — Technical and Organizational Security Measures

[CONFIRM: this section needs your actual practices, not a generic list — a Business Customer's security reviewer will ask follow-up questions on whatever's stated here. Starting points to confirm or correct:]

  • Encryption of Personal Data in transit (e.g., TLS) and at rest, to the extent provided by Azure's underlying services
  • Access controls limiting Personal Data access to personnel who need it to provide the Service
  • [CONFIRM: do you have any of — regular access reviews, logging/monitoring, a written incident response process, employee confidentiality agreements, background checks? List only what's actually true today; an inflated list here is worse than a short accurate one.]

 

ImageFlow-AI is a product of CandorLight LLC.

© 2026 ImageFlow-AI.com. All rights reserved.