Article 1 (Parties and roles)
(1) In this document "Controller" means the customer using the Service and "Processor" means VanillaX Inc..
- Data
- Account data of the customer's staff (email, name)
- Controller
- Not applicable
- Processor
- VanillaX Inc. (as controller)
- Document that applies
- Privacy Policy
- Data
- Third-party personal data inside uploaded product images or copy
- Controller
- The customer
- Processor
- VanillaX Inc.
- Document that applies
- This document
- Data
- The customer's own customers' data sent through the API
- Controller
- The customer
- Processor
- VanillaX Inc.
- Document that applies
- This document
| Data | Controller | Processor | Document that applies |
|---|---|---|---|
| Account data of the customer's staff (email, name) | Not applicable | VanillaX Inc. (as controller) | Privacy Policy |
| Third-party personal data inside uploaded product images or copy | The customer | VanillaX Inc. | This document |
| The customer's own customers' data sent through the API | The customer | VanillaX Inc. | This document |
(2) For its own account and organization data the Company acts as a controller under the Privacy Policy; for third-party personal data the customer supplies, it acts as a processor under this document.
(3) This is a summary. Customers who need a signed processing agreement can request the standard contract at admin@vanillax.co. Once signed, that contract prevails over this document.
Article 2 (Subject matter and purpose)
- Item
- Purpose
- Detail
- Running listing inspections, producing findings, applying approved automatic fixes, re-inspecting, and creating and delivering reports and outputs
- Item
- Duration
- Detail
- While the customer uses the Service. Immediate on deleting an individual inspection; within 30 days of the agreement ending
- Item
- Nature of processing
- Detail
- Collection, storage, retrieval, analysis, transformation (automatic fixing), destruction
- Item
- Categories of data subjects
- Detail
- People appearing in the customer's product images or copy (models, staff, reviewers) and the customer's own customers
- Item
- Categories of data
- Detail
- Faces, contact details or addresses inside images; names or contact details inside product copy — whatever the customer supplies
| Item | Detail |
|---|---|
| Purpose | Running listing inspections, producing findings, applying approved automatic fixes, re-inspecting, and creating and delivering reports and outputs |
| Duration | While the customer uses the Service. Immediate on deleting an individual inspection; within 30 days of the agreement ending |
| Nature of processing | Collection, storage, retrieval, analysis, transformation (automatic fixing), destruction |
| Categories of data subjects | People appearing in the customer's product images or copy (models, staff, reviewers) and the customer's own customers |
| Categories of data | Faces, contact details or addresses inside images; names or contact details inside product copy — whatever the customer supplies |
Article 3 (Instructions and the Processor's duties)
(1) The Processor processes personal data only on the Controller's documented instructions — this document, the Terms of Service, and requests made through the Service screens and the API.
(2) The Processor does not use personal data beyond the entrusted purpose and does not disclose it to third parties. In particular it does not use it to train, fine-tune or evaluate AI models.
(3) The Processor limits the staff who handle personal data to the minimum and binds them to confidentiality.
(4) If the Processor considers an instruction unlawful, it tells the Controller without delay and may suspend that instruction.
(5) The Controller is responsible for having a lawful basis for collection and handles data subject requests in the first instance. The Processor cooperates to a reasonable extent on request.
Article 4 (Security measures)
The Processor maintains the following.
- Area
- Access control
- Measure
- Per-organization data isolation with row-level security, separated roles (owner, admin, member, viewer), uploads stored in a private bucket
- Area
- Encryption
- Measure
- TLS 1.2 or above in transit, encryption at rest, one-way hashing of passwords and API keys
- Area
- Administrative access
- Measure
- The smallest possible number of console accounts, multi-factor authentication enforced
- Area
- Logging
- Measure
- Access logs of the personal-data processing system kept for at least 3 months and protected against tampering
- Area
- Operations
- Measure
- An internal management plan, at least annual training for staff who handle personal data, a documented incident procedure
- Area
- Development
- Measure
- Production data is never copied into development or test environments
| Area | Measure |
|---|---|
| Access control | Per-organization data isolation with row-level security, separated roles (owner, admin, member, viewer), uploads stored in a private bucket |
| Encryption | TLS 1.2 or above in transit, encryption at rest, one-way hashing of passwords and API keys |
| Administrative access | The smallest possible number of console accounts, multi-factor authentication enforced |
| Logging | Access logs of the personal-data processing system kept for at least 3 months and protected against tampering |
| Operations | An internal management plan, at least annual training for staff who handle personal data, a documented incident procedure |
| Development | Production data is never copied into development or test environments |
Article 5 (Sub-processors)
(1) The Processor uses the following sub-processors to the extent needed to run the Service. By accepting this document the Controller authorises them.
- Processor
- Supabase Inc.
- Purpose of the entrusted work
- Database, account authentication and uploaded-file storage
- Processing location
- Seoul region (ap-northeast-2), Republic of Korea; operational support accesses remotely from the United States
- Retention
- Until the processing agreement ends, or within 30 days of account deletion
- Processor
- Vercel Inc.
- Purpose of the entrusted work
- Web application hosting, request routing, access logging
- Processing location
- United States (global edge network)
- Retention
- Until the processing agreement ends. Access logs for up to 30 days
- Processor
- Google LLC (Gemini API)
- Purpose of the entrusted work
- Analysis of product images and product copy to enrich inspection results
- Processing location
- United States
- Retention
- Deleted as soon as the request is served. Not used to train models
- Processor
- OpenAI, L.L.C.
- Purpose of the entrusted work
- Generation of example images for fix suggestions
- Processing location
- United States
- Retention
- Deleted as soon as the request is served. Not used to train models
- Processor
- Brave Software, Inc. (Brave Search API)
- Purpose of the entrusted work
- Search for marketplace rule sources
- Processing location
- United States
- Retention
- Only the search query is sent; no personal data or uploaded content is sent
| Processor | Purpose of the entrusted work | Processing location | Retention |
|---|---|---|---|
| Supabase Inc. | Database, account authentication and uploaded-file storage | Seoul region (ap-northeast-2), Republic of Korea; operational support accesses remotely from the United States | Until the processing agreement ends, or within 30 days of account deletion |
| Vercel Inc. | Web application hosting, request routing, access logging | United States (global edge network) | Until the processing agreement ends. Access logs for up to 30 days |
| Google LLC (Gemini API) | Analysis of product images and product copy to enrich inspection results | United States | Deleted as soon as the request is served. Not used to train models |
| OpenAI, L.L.C. | Generation of example images for fix suggestions | United States | Deleted as soon as the request is served. Not used to train models |
| Brave Software, Inc. (Brave Search API) | Search for marketplace rule sources | United States | Only the search query is sent; no personal data or uploaded content is sent |
(2) The Processor imposes obligations equivalent to this document on each sub-processor and remains directly liable to the Controller for their processing.
(3) Before adding or changing a sub-processor the Processor updates this document 30 days in advance and emails organization owners and admins. The Controller may object on reasonable grounds within 14 days; if no agreement is reached, it may terminate without penalty.
Article 6 (Cross-border transfers)
(1) Of the sub-processors, Vercel, Google, OpenAI and Brave process in the United States; Supabase stores in the Seoul region of Korea with operational access from the United States. Full detail is in the cross-border transfer table in Article 7 of the Privacy Policy.
(2) The Controller is responsible for reflecting these transfers in its own privacy policy and, where required, for informing data subjects or obtaining their consent.
Article 7 (Personal data breach)
(1) The Processor notifies the Controller without delay, and in any case within 24 hours, of becoming aware of a breach or a suspected breach.
(2) The notification includes, so far as known: the categories and volume of data affected, when and how it happened, the harm identified, what the Processor has done, what the Controller can do, and a contact point.
(3) The Processor provides the material the Controller needs to meet its own notification and reporting duties under Article 34 of PIPA, and cooperates with them.
Article 8 (Supervision and evidence)
(1) Once a year the Controller may ask the Processor for evidence that these protections are in place; the Processor provides it in writing within 30 days.
(2) Where a supervisory authority investigates or a serious incident occurs, the Processor cooperates without that annual limit.
(3) On-site audits are agreed in advance as to scope, timing and cost, and are conducted so that no other customer's data is exposed.
Article 9 (Return and deletion)
(1) The Controller can delete an individual inspection in the Service or through the API, which destroys the related uploads and results immediately.
(2) When the agreement ends the Processor returns or destroys personal data at the Controller's choice. If no return is requested, it destroys the data within 30 days of the end date.
(3) Return is provided as output downloads (report, images, JSON) and must be requested within 30 days of the end date.
(4) Copies remaining on backup media expire once the backup retention cycle (up to 30 days) passes. Data that must be retained by law is kept with restricted access for that period.
(5) The Processor confirms completion of destruction in writing on request.
Article 10 (Liability)
(1) Where a data subject suffers loss because the Processor breached this document, the Processor is treated as an employee of the Controller and bears liability under Article 26(6) of PIPA.
(2) As between the Controller and the Processor, the liability cap in Article 17 of the Terms of Service applies, except for a breach caused by the Processor's wilful misconduct or gross negligence.
(3) The Controller bears the loss arising from entering personal data without a lawful basis for collecting it.
Addendum
This document takes effect on 2026-09-03. To request the standard signed processing agreement, write to admin@vanillax.co.
Revision history
- Version 1.0First published
Read alongside
Other terms and policies that apply together with this document.
Questions
Send questions or correction requests about these documents to the address below. We reply within 3 business days.
VanillaX Inc. · Room 801, 8F Woochang Plaza, 295 Cheonho-daero, Dongdaemun-gu, Seoul, Republic of Korea