0. How this DPA applies
This Data Processing Addendum (the "DPA") is incorporated into and forms part of the developer agreement between Art Shop AI LLC d/b/a Snowcone, a Delaware limited liability company (file number 7347980), with registered office at 611 South DuPont Highway, Suite 102, Dover, Delaware 19901, USA (the "Processor"), and the entity using the Snowcone developer API (the "Customer", which is the "Controller" with respect to personal data submitted to the API). The DPA applies to all personal data the Processor processes on behalf of the Customer in connection with the developer API. In the event of any conflict between the developer agreement and this DPA, this DPA controls in respect of personal-data processing. The Customer accepts this DPA by an authorised representative calling POST /compliance/dpa/accept; counter- signed paper copies are available on request from legal@snowcone.app.
1. Definitions
Capitalised terms used and not otherwise defined in this DPA have the meaning given in the developer agreement or, where applicable, the meaning given in GDPR Article 4. In addition:
- "Applicable Data Protection Law" means GDPR; UK GDPR + DPA 2018; CCPA / CPRA; the privacy laws of CO, CT, VA, UT, TX, OR, MT, IA, TN, IN, DE, NH, NJ, MN, MD, KY; Quebec Law 25; PIPEDA; LFPDPPP; and any other data-protection law applicable to the Customer's processing.
- "Customer Personal Data" means personal data the Customer (or any of its end users) submits to the Snowcone developer API, that the Processor processes on the Customer's behalf.
- "Sub-processor" means a third party engaged by the Processor to process Customer Personal Data on the Processor's behalf.
- "SCCs" means the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, as set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, incorporating the UK Addendum (the "ICO IDTA") for UK transfers as applicable.
2. Subject matter, duration, nature, and purpose of processing
- Subject matter: the provision of the Snowcone developer API services described in the developer agreement.
- Duration: the term of the developer agreement, plus any post-termination period set out in Section 11.
- Nature of processing: hosting, storage, retrieval, transformation (including AI inference where the Customer enables it), routing to fulfillment partners, and deletion of Customer Personal Data on the Customer's documented instructions.
- Purpose: enabling the Customer to use the Snowcone developer API to provide its own products and services to its end users.
3. Types of personal data and categories of data subjects
Types of personal data the Processor may process: identifiers (name, email, username), contact information (shipping address, phone), device and usage information (IP address, browser metadata), order metadata (line items, transaction amount, fulfillment events), uploaded artwork and design files, AI prompts and AI-generated outputs, and any other personal data the Customer chooses to submit.
Categories of data subjects: the Customer's end users (consumers using the Customer's product), the Customer's personnel, and any other natural person whose data the Customer submits.
Special categories of data: the Customer agrees not to submit special categories of personal data (GDPR Art 9), criminal-conviction data (Art 10), or sensitive personal information (CPRA §1798.140(ae); LFPDPPP Art 3-VI) through the developer API, except (a) photographs that may depict identifiable individuals where the Customer has obtained the necessary consent, and (b) any other category for which the Customer has obtained a prior written exception.
4. Roles and scope
- Roles. The Customer is the controller (and for CCPA purposes the "business"), and the Processor is the processor (and for CCPA purposes a "service provider"). Where the Customer's end users are themselves controllers, the Customer represents that it is authorised to enter into this DPA on the relevant controllers' behalf.
- Documented instructions. The Processor will process Customer Personal Data only on the documented instructions of the Customer, including those instructions that are inherent in the developer agreement, in the API specification at developers.snowcone.app, and in this DPA. The Processor will inform the Customer if, in its opinion, a Customer instruction infringes Applicable Data Protection Law.
- No sale, no sharing, no own-purpose use. The Processor will not (a) sell Customer Personal Data, (b) share Customer Personal Data for cross-context behavioral advertising, or (c) retain, use, or disclose Customer Personal Data outside of the direct business relationship between the Customer and the Processor or for any purpose other than performing the developer agreement (CCPA §1798.140(ag)).
- No AI training on Customer Data — the broad commitment. The Processor does not use any data the Customer submits via the developer API — Customer Personal Data, the Customer's non-personal business data, AI prompts the Customer submits, or AI outputs the Processor generates for the Customer — to train, fine-tune, or improve the Processor's artificial-intelligence models. This is a deliberately broader commitment than the consumer-facing Privacy Policy permits for direct-Snowcone-consumer data: the Customer is the controller of its end-user data and the Customer's instruction to us is "process for the Customer's business purposes only." Sub-processors that route inference (fal.ai, Runware, Google Vertex AI, Modal) are bound by contract to the same no-training commitment for Customer Data.
5. Confidentiality
The Processor will ensure that personnel authorised to process Customer Personal Data are bound by appropriate written or statutory confidentiality obligations, and that access to Customer Personal Data is limited on a need-to-know basis.
6. Security of processing
Taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing, the Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of Customer Personal Data in transit (TLS 1.2 or higher) and at rest.
- Role-based access control with least-privilege defaults.
- Audit logging of administrative and access events, retained for at least 18 months.
- Periodic security reviews, vulnerability scanning, and patch management for systems handling Customer Personal Data.
- Documented incident-response procedures; an internal breach runbook; on-call coverage.
- Vendor due-diligence for new Sub-processors before onboarding, including a written processing agreement with flow-down obligations consistent with this DPA.
7. Sub-processors
- General authorisation. The Customer grants the Processor a general authorisation under GDPR Art 28(2) to engage Sub-processors, subject to the conditions in this Section.
- Current Sub-processor list. The Processor maintains an up-to-date list at /legal/sub-processors. The list constitutes Annex II to this DPA.
- Notice of changes. The Processor will publish intended changes at least 30 days before they take effect, with concurrent notice by email and via the RSS feed at /legal/sub-processors/changelog.xml.
- Right to object. The Customer may object to a new Sub-processor on reasonable grounds related to data protection within 30 days of notice. If the parties cannot agree on a remedy within a further 30 days, the Customer may terminate the affected portion of the developer agreement without penalty.
- Flow-down obligations. The Processor will impose on each Sub-processor data-protection obligations no less protective than those in this DPA.
- Liability. The Processor remains fully liable to the Customer for the performance of Sub-processors' obligations.
8. Assistance with data-subject rights
Taking into account the nature of the processing, the Processor will assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligations to respond to data-subject requests under Applicable Data Protection Law (GDPR Articles 15–22, equivalent rights under UK GDPR, Quebec Law 25, CCPA / CPRA, and LFPDPPP).
The Processor provides Customer-facing endpoints in the developer API to read, export, rectify, restrict, and delete Customer Personal Data the Processor holds. Where a data subject contacts the Processor directly with a request related to Customer Personal Data, the Processor will refer the data subject to the Customer without acting on the request, except where the Processor is required by law to respond.
9. Personal-data breach notification
The Processor will notify the Customer of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 48 hours after the Processor becomes aware of the breach. The notification will include, to the extent then known: the nature of the breach; the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it; and a contact point for further information. The Processor will provide further information as it becomes available, on a continuing basis until the matter is closed.
Breach notifications go to the Customer's designated security contact (provided through the developer console). For Snowcone, breach reports may be sent to security@snowcone.app.
10. Audit and assistance with DPIAs
- Records. The Processor maintains records of processing activities under Art 30 in respect of Customer Personal Data and will make them available on reasonable request.
- Audit rights. The Customer may, at its own expense and on at least 30 days' written notice, audit the Processor's compliance with this DPA no more than once per calendar year. The Processor may satisfy an audit request by providing its then-current third-party security audit reports (such as SOC 2 Type II when available) and responding to a reasonable security questionnaire. On-site audits are limited to systems and personnel materially involved in processing Customer Personal Data.
- DPIA assistance. The Processor will provide reasonable assistance to the Customer in fulfilling its obligations under Article 35 (DPIAs) and Article 36 (prior consultation) GDPR.
11. Deletion or return on termination
On termination of the developer agreement, and at the Customer's choice, the Processor will (a) return all Customer Personal Data in a commonly used machine-readable format, or (b) delete all Customer Personal Data, in each case within 30 days of termination, unless retention is required by applicable law (in which case the Processor will continue to protect the retained data in accordance with this DPA for as long as it is retained). The Processor will certify the completion of deletion on the Customer's written request. Encrypted backups containing Customer Personal Data are overwritten on a 35-day cycle following deletion.
12. International transfers
Where the Processor (or any of its Sub-processors) transfers Customer Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country that does not benefit from an adequacy decision, the Standard Contractual Clauses (Module 2 — controller-to-processor) are incorporated into this DPA by reference and apply to the transfer. For UK transfers, the UK Addendum to the SCCs published by the ICO is also incorporated.
Annex I.A (parties) is populated by reference to the signature block of the developer agreement; Annex I.B (description of transfer) by reference to Sections 2 and 3 above; Annex II (technical and organisational measures) by reference to Section 6; and Annex III (Sub-processors) by reference to /legal/sub-processors. The competent supervisory authority under Clause 13 is the supervisory authority of the EU member state where the Customer's lead establishment is located, or, where the Customer is established outside the EEA, the supervisory authority of the EU member state where the data subjects whose personal data is transferred are located.
The Processor maintains transfer-impact assessments (per Schrems II, CJEU C-311/18, 16 July 2020) for material transfers and provides them on the Customer's reasonable request.
13. California (CCPA / CPRA) service-provider provisions
Where the Processor processes the personal information of California consumers on the Customer's behalf, the Processor is a "service provider" within the meaning of CCPA §1798.140(ag), and the Processor:
- Will not sell or share the personal information.
- Will not retain, use, or disclose the personal information for any purpose other than the specific purpose of performing the developer agreement.
- Will not combine the personal information that the Processor receives from the Customer with personal information from another source, except to perform a business purpose permitted by the regulations under the CCPA / CPRA.
- Will, on the Customer's written instruction, comply with a consumer request to delete the consumer's personal information that the Processor processes on the Customer's behalf, and forward the request to any of the Processor's Sub-processors that hold the same personal information (CCPA §1798.105(c)).
14. Quebec Law 25 mandator-mandatary provisions
Where the Processor processes the personal information of Quebec residents on the Customer's behalf, the parties acknowledge that the Customer is the mandator and the Processor is the mandatary within the meaning of Quebec's An Act respecting the protection of personal information in the private sector. This DPA constitutes the written agreement required by section 18.3 of that Act. The Processor will notify the Customer of any confirmed personal-information breach involving Quebec residents in accordance with Section 9 above.
15. Mexico (LFPDPPP) encargado provisions
Where the Processor processes the personal data of Mexican residents on the Customer's behalf, the Processor is the "encargado" within the meaning of LFPDPPP Article 50, and the Processor will (i) process the data only on the Customer's instructions, (ii) not transfer the data except to Sub-processors authorised under Section 7 above, (iii) maintain confidentiality, and (iv) on termination, delete or return the data and any copies in accordance with Section 11 above.
16. Liability
Each party's liability under this DPA is subject to the limitations of liability set out in the developer agreement, except that nothing in this DPA limits a party's liability for (a) personal injury or death caused by negligence, (b) fraud, (c) any liability that cannot be limited under Applicable Data Protection Law (including under GDPR Article 82), or (d) any amounts payable to a data subject in respect of a claim brought directly by that data subject.
17. Governing law and survival
This DPA is governed by the law specified in the developer agreement, except that any provision of this DPA that is required to be governed by the law of a particular jurisdiction under Applicable Data Protection Law (in particular, the SCCs) is governed by that law as required. Sections 5 (Confidentiality), 11 (Deletion or return), 13–15 (regional provisions), and 16 (Liability) survive termination of the developer agreement.
18. Versioning and acceptance
The Processor may publish updated versions of this DPA from time to time. Material changes are notified to the Customer at least 30 days before they take effect; the Customer's continued use of the developer API after the effective date constitutes acceptance, and the new version is recorded in the Processor's dpa_acceptances table. Historical versions are reachable at /legal/dpa-api/v<version>.
19. Notices
- Privacy + DPA matters: privacy@snowcone.app.
- Security incidents + breach notifications: security@snowcone.app.
- Service of process / regulatory notices (DSA Art 11): legal@snowcone.app.
Last updated . Previous versions available on request.
View Annex II — sub-processor list →
