Business Data Processing Addendum
Effective date: 31 August 2026
This Business Data Processing Addendum (“DPA”) supplements the Terms of Service and Public Offer or another written agreement under which a business customer (“Customer”) uses SolidFrame Studio and submits personal data for processing on its behalf.
1. Parties and roles
The paid service is sold by AG PLUS LLC, the contractual seller and merchant of record. The technical platform is supplied and operated by Solidframe Technologies OÜ.
For Customer Personal Data processed solely to provide Customer-requested project, media or production functions, the Customer is controller and Solidframe is processor. AG PLUS is not a processor of project content merely because it sells credits. AG PLUS acts as an independent controller for billing, transaction, tax, fraud-prevention and contractual records.
If the Customer acts as processor for another controller, Solidframe acts as the Customer’s subprocessor and the Customer confirms that it has authority to appoint Solidframe.
2. Definitions
“Customer Personal Data” means personal data contained in Customer prompts, uploads, projects, source material or other content processed by Solidframe solely on Customer’s documented instructions.
“Applicable Data Protection Law” means personal-data law applicable to the processing, including the GDPR where it applies and the law of Uzbekistan where relevant.
“Subprocessor” means another processor engaged by Solidframe to process Customer Personal Data.
Terms such as controller, processor, personal data, processing and data subject have the meanings given by Applicable Data Protection Law.
3. Processing details
Subject matter: browser-based storage, editing, generation, media processing, export, security and support requested by Customer.
Duration: the term of the Customer’s use plus deletion, backup and legal-retention periods described below.
Nature: collection, recording, organisation, storage, retrieval, transmission to selected providers, transformation, generation, consultation, restriction and deletion.
Purposes: providing, securing, troubleshooting and supporting the Customer-requested Service.
Data subjects: Customer users, employees, contractors, clients, talent, speakers, performers and other persons appearing in Customer content.
Data types: identifiers, account details, images, video, voice, correspondence, prompts, project metadata and other personal data chosen by Customer. Special-category or biometric data is not required and should not be submitted unless Customer has a lawful basis and has confirmed that the Service is appropriate.
4. Customer instructions
Solidframe will process Customer Personal Data only on documented instructions, including the Terms, Customer’s configuration and commands, support requests and this DPA, unless law requires otherwise. If legally permitted, Solidframe will inform Customer before legally required processing.
Solidframe will notify Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law. Solidframe may suspend the affected instruction while the parties resolve the concern.
Customer is responsible for the lawfulness, accuracy and quality of Customer Personal Data; notices and consents; rights in source material; instructions; and responding as controller to data subjects.
5. Confidentiality and personnel
Solidframe will ensure that persons authorised to process Customer Personal Data are bound by confidentiality and receive access only as necessary for their duties. Access will be reviewed and withdrawn when no longer needed.
6. Security
Solidframe will maintain measures appropriate to the risk, including as applicable:
- access control and least-privilege permissions;
- authentication and credential protection;
- encryption in transit and at rest where appropriate;
- logging, monitoring and incident-response procedures;
- backup, resilience and restoration procedures;
- vulnerability, patch and supplier management;
- separation of customer environments where technically appropriate; and
- periodic assessment of the effectiveness of safeguards.
Customer is responsible for secure account administration, authorised-user management, lawful configuration and backups or exports within its control.
7. Subprocessors
Customer gives general authorisation for the subprocessors needed to provide the Service. The current categories and confirmed providers are described in the Subprocessor and Third-Party Provider Disclosure.
Solidframe will impose data-protection obligations appropriate to the processing on each Subprocessor. Solidframe remains responsible for its Subprocessor’s performance to the extent required by Applicable Data Protection Law.
Where a business feature provides update notifications, Solidframe will give reasonable advance notice of a material new Subprocessor. Customer may object on reasonable data-protection grounds within 15 days. The parties will seek a practical alternative; if none is reasonably available, Customer may stop the affected feature and obtain an appropriate remedy for the unused affected paid portion.
8. International transfers
Solidframe will use a lawful transfer mechanism for restricted international transfers. Where Customer Personal Data subject to the GDPR is transferred to a country without an adequacy decision, the applicable European Commission Standard Contractual Clauses are incorporated by reference as follows unless the parties sign another lawful mechanism:
- Module Two applies where Customer is controller and Solidframe is processor;
- Module Three applies where Customer is processor and Solidframe is subprocessor;
- the docking clause applies;
- optional general written authorisation for subprocessors applies;
- the supervisory authority and governing-law selections follow the Customer’s competent EU/EEA establishment or, if none, the competent authority determined by the GDPR;
- Annex I is completed by this DPA and the parties’ corporate and account details;
- Annex II is completed by Section 6; and
- Annex III is completed by the current Subprocessor Disclosure.
The parties will implement supplementary safeguards where reasonably required by a transfer assessment.
Transfers subject to Uzbekistan law will comply with applicable localisation and cross-border-transfer requirements.
9. Data-subject requests
Taking into account the nature of processing, Solidframe will reasonably assist Customer with access, correction, deletion, restriction, portability and objection requests. If Solidframe receives a request concerning Customer Personal Data, it will direct the requester to Customer unless law permits or requires Solidframe to respond directly.
Customer will reimburse extraordinary assistance costs agreed in advance, except where assistance is required because of Solidframe’s breach.
10. Personal-data breaches
Solidframe will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. The notice will provide available information about the nature of the breach, affected data and subjects, likely consequences, measures taken or proposed and a contact point. Information may be provided in phases as the investigation continues.
Solidframe’s notice is not an admission of fault. Customer is responsible for regulatory and data-subject notifications as controller, with Solidframe’s reasonable assistance.
11. DPIAs and consultations
Solidframe will provide information reasonably available to assist Customer with a data-protection impact assessment or prior regulatory consultation concerning the Service. Customer remains responsible for determining whether an assessment or consultation is required.
12. Audit and information rights
On reasonable written request, Solidframe will provide information necessary to demonstrate compliance, including relevant independent certifications or summaries where available. If that information is insufficient, Customer may request an audit no more than once per year, unless a breach or regulator requires more frequent review.
Audits must be proportionate, scheduled with reasonable notice, protect other customers and security, and be conducted by an independent auditor bound by confidentiality. Customer bears its audit costs unless the audit identifies a material breach by Solidframe.
13. Return and deletion
During the account term, Customer should use available export tools. On termination and written request, Solidframe will return or delete Customer Personal Data within a reasonable period, unless law requires retention. Data in backups will be isolated from ordinary use and deleted according to the backup cycle.
AG PLUS may retain independent billing, tax, fraud and contract records as controller even after project data is deleted.
14. Liability and order of precedence
Liability under this DPA is subject to the liability provisions of the governing customer agreement, except to the extent Applicable Data Protection Law requires otherwise. If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA prevails. Applicable Standard Contractual Clauses prevail over both for matters they govern.
15. Contacts and signatures
Data-processing contact for Solidframe: info@solidframe.io. Billing-controller contact for AG PLUS: info@4teen.me.
This DPA becomes binding when incorporated into a Customer order or accepted electronically by an authorised Customer representative. Upon request, the parties may execute a signature page identifying the Customer and account.
This DPA is issued in English. A Russian translation may be provided for convenience. If the translations differ, the English version prevails, subject to mandatory law and the Standard Contractual Clauses.