dodamai
Create account
All documents

Data Processing Addendum (summary)

When a customer puts its own customers' personal data into Dodam AI, the customer is the controller and VanillaX Inc. is the processor. This summarises the roles, instructions, security measures, sub-processors, deletion and incident handling that then apply.

Effective
Last revised
Version
1.0
한국어로 읽기

Article 1 (Parties and roles)

(1) In this document "Controller" means the customer using the Service and "Processor" means VanillaX Inc..

Who plays which role
  • Data
    Account data of the customer's staff (email, name)
    Controller
    Not applicable
    Processor
    VanillaX Inc. (as controller)
    Document that applies
    Privacy Policy
  • Data
    Third-party personal data inside uploaded product images or copy
    Controller
    The customer
    Processor
    VanillaX Inc.
    Document that applies
    This document
  • Data
    The customer's own customers' data sent through the API
    Controller
    The customer
    Processor
    VanillaX Inc.
    Document that applies
    This document

(2) For its own account and organization data the Company acts as a controller under the Privacy Policy; for third-party personal data the customer supplies, it acts as a processor under this document.

(3) This is a summary. Customers who need a signed processing agreement can request the standard contract at admin@vanillax.co. Once signed, that contract prevails over this document.

Article 2 (Subject matter and purpose)

Processing overview
  • Item
    Purpose
    Detail
    Running listing inspections, producing findings, applying approved automatic fixes, re-inspecting, and creating and delivering reports and outputs
  • Item
    Duration
    Detail
    While the customer uses the Service. Immediate on deleting an individual inspection; within 30 days of the agreement ending
  • Item
    Nature of processing
    Detail
    Collection, storage, retrieval, analysis, transformation (automatic fixing), destruction
  • Item
    Categories of data subjects
    Detail
    People appearing in the customer's product images or copy (models, staff, reviewers) and the customer's own customers
  • Item
    Categories of data
    Detail
    Faces, contact details or addresses inside images; names or contact details inside product copy — whatever the customer supplies

Article 3 (Instructions and the Processor's duties)

(1) The Processor processes personal data only on the Controller's documented instructions — this document, the Terms of Service, and requests made through the Service screens and the API.

(2) The Processor does not use personal data beyond the entrusted purpose and does not disclose it to third parties. In particular it does not use it to train, fine-tune or evaluate AI models.

(3) The Processor limits the staff who handle personal data to the minimum and binds them to confidentiality.

(4) If the Processor considers an instruction unlawful, it tells the Controller without delay and may suspend that instruction.

(5) The Controller is responsible for having a lawful basis for collection and handles data subject requests in the first instance. The Processor cooperates to a reasonable extent on request.

Article 4 (Security measures)

The Processor maintains the following.

Measures in place
  • Area
    Access control
    Measure
    Per-organization data isolation with row-level security, separated roles (owner, admin, member, viewer), uploads stored in a private bucket
  • Area
    Encryption
    Measure
    TLS 1.2 or above in transit, encryption at rest, one-way hashing of passwords and API keys
  • Area
    Administrative access
    Measure
    The smallest possible number of console accounts, multi-factor authentication enforced
  • Area
    Logging
    Measure
    Access logs of the personal-data processing system kept for at least 3 months and protected against tampering
  • Area
    Operations
    Measure
    An internal management plan, at least annual training for staff who handle personal data, a documented incident procedure
  • Area
    Development
    Measure
    Production data is never copied into development or test environments

Article 5 (Sub-processors)

(1) The Processor uses the following sub-processors to the extent needed to run the Service. By accepting this document the Controller authorises them.

Processors engaged by Dodam AI
  • Processor
    Supabase Inc.
    Purpose of the entrusted work
    Database, account authentication and uploaded-file storage
    Processing location
    Seoul region (ap-northeast-2), Republic of Korea; operational support accesses remotely from the United States
    Retention
    Until the processing agreement ends, or within 30 days of account deletion
  • Processor
    Vercel Inc.
    Purpose of the entrusted work
    Web application hosting, request routing, access logging
    Processing location
    United States (global edge network)
    Retention
    Until the processing agreement ends. Access logs for up to 30 days
  • Processor
    Google LLC (Gemini API)
    Purpose of the entrusted work
    Analysis of product images and product copy to enrich inspection results
    Processing location
    United States
    Retention
    Deleted as soon as the request is served. Not used to train models
  • Processor
    OpenAI, L.L.C.
    Purpose of the entrusted work
    Generation of example images for fix suggestions
    Processing location
    United States
    Retention
    Deleted as soon as the request is served. Not used to train models
  • Processor
    Brave Software, Inc. (Brave Search API)
    Purpose of the entrusted work
    Search for marketplace rule sources
    Processing location
    United States
    Retention
    Only the search query is sent; no personal data or uploaded content is sent

(2) The Processor imposes obligations equivalent to this document on each sub-processor and remains directly liable to the Controller for their processing.

(3) Before adding or changing a sub-processor the Processor updates this document 30 days in advance and emails organization owners and admins. The Controller may object on reasonable grounds within 14 days; if no agreement is reached, it may terminate without penalty.

Article 6 (Cross-border transfers)

(1) Of the sub-processors, Vercel, Google, OpenAI and Brave process in the United States; Supabase stores in the Seoul region of Korea with operational access from the United States. Full detail is in the cross-border transfer table in Article 7 of the Privacy Policy.

(2) The Controller is responsible for reflecting these transfers in its own privacy policy and, where required, for informing data subjects or obtaining their consent.

Article 7 (Personal data breach)

(1) The Processor notifies the Controller without delay, and in any case within 24 hours, of becoming aware of a breach or a suspected breach.

(2) The notification includes, so far as known: the categories and volume of data affected, when and how it happened, the harm identified, what the Processor has done, what the Controller can do, and a contact point.

(3) The Processor provides the material the Controller needs to meet its own notification and reporting duties under Article 34 of PIPA, and cooperates with them.

Article 8 (Supervision and evidence)

(1) Once a year the Controller may ask the Processor for evidence that these protections are in place; the Processor provides it in writing within 30 days.

(2) Where a supervisory authority investigates or a serious incident occurs, the Processor cooperates without that annual limit.

(3) On-site audits are agreed in advance as to scope, timing and cost, and are conducted so that no other customer's data is exposed.

Article 9 (Return and deletion)

(1) The Controller can delete an individual inspection in the Service or through the API, which destroys the related uploads and results immediately.

(2) When the agreement ends the Processor returns or destroys personal data at the Controller's choice. If no return is requested, it destroys the data within 30 days of the end date.

(3) Return is provided as output downloads (report, images, JSON) and must be requested within 30 days of the end date.

(4) Copies remaining on backup media expire once the backup retention cycle (up to 30 days) passes. Data that must be retained by law is kept with restricted access for that period.

(5) The Processor confirms completion of destruction in writing on request.

Article 10 (Liability)

(1) Where a data subject suffers loss because the Processor breached this document, the Processor is treated as an employee of the Controller and bears liability under Article 26(6) of PIPA.

(2) As between the Controller and the Processor, the liability cap in Article 17 of the Terms of Service applies, except for a breach caused by the Processor's wilful misconduct or gross negligence.

(3) The Controller bears the loss arising from entering personal data without a lawful basis for collecting it.

Addendum

This document takes effect on 2026-09-03. To request the standard signed processing agreement, write to admin@vanillax.co.

  • Version 1.0First published

Other terms and policies that apply together with this document.

Questions

Send questions or correction requests about these documents to the address below. We reply within 3 business days.

admin@vanillax.co

VanillaX Inc. · Room 801, 8F Woochang Plaza, 295 Cheonho-daero, Dongdaemun-gu, Seoul, Republic of Korea