Data Processing Addendum.
Effective date: 22 July 2026. This DPA forms part of the Terms of Service between the customer ("Customer", "you") and Sentez Inc. ("Looknish") whenever Looknish processes personal data on the Customer's behalf.
1. Roles
Customer is the controller (or a processor acting for another controller). Looknish is the processor for personal data contained in Customer content and workspace metadata.
2. Subject-matter and duration
Processing takes place for the term of the subscription and any wind-down period. Categories of data subjects: Customer's employees and end users. Categories of personal data: account identifiers, workspace metadata, uploaded images (which may include images of people), support communications.
3. Nature and purpose of processing
Hosting, storage, transmission, AI-based image generation, backups, security monitoring, and delivery of the Looknish service as documented at www.looknish.com.
4. Looknish obligations
Process personal data only on documented instructions from Customer (the Terms of Service constitute those instructions). Ensure personnel are bound by confidentiality. Implement the security measures described in §7. Assist Customer with data-subject requests, DPIAs and breach notifications. Delete or return personal data at the end of the subscription.
5. Subprocessors
Customer authorises Looknish to appoint subprocessors from the categories listed in the Privacy Policy (hosting, CDN, email, payments, AI inference). A current list is available on request. Looknish will announce material changes at least 14 days in advance; Customer may object on reasonable data-protection grounds.
6. International transfers
Where personal data leaves the EEA/UK, transfers rely on the EU Standard Contractual Clauses (Module 2, controller-to-processor) and the UK IDTA, which are incorporated by reference into this DPA.
7. Security measures
Encryption in transit (TLS 1.2+) and at rest, role-based access control, principle of least privilege, per-workspace isolation enforced by row-level security, audit logging, regular backups, dependency scanning, secure SDLC, incident-response procedures. Details available under NDA.
8. Breach notification
Looknish will notify Customer without undue delay, and no later than 72 hours after becoming aware, of any personal-data breach affecting Customer data.
9. Audit
Customer may request, at most once per year and at reasonable notice, information necessary to demonstrate compliance with this DPA. Where third-party audit reports (e.g. SOC 2, ISO 27001) exist, Looknish may provide those in lieu of an on-site audit.
10. Signing
This DPA is deemed executed when Customer subscribes to a paid plan. Customers requiring a counter-signed copy on their own paper can request one at privacy@looknish.com.