Data Processing Addendum
Last updated: 10 October 2026. This Data Processing Addendum (“DPA”) forms part of the IQ Deco Terms of Service between you (the “Customer”, controller) and MOZIX d.o.o. (“IQ Deco”, processor). It applies whenever you put personal data of others into the Service. It meets Article 28 of the EU GDPR and the UK GDPR.
1. Subject and duration
IQ Deco processes Client Data only to provide the Service to you, for as long as your account exists and until deletion under section 8.
| Item | Details |
|---|---|
| Nature and purpose | hosting, storing, displaying and transmitting data in your projects; showing brief and order-sheet pages you share; generating documents; AI processing you request |
| Data subjects | your customers and their contacts, venue contacts, your crew and subcontractors |
| Personal data | names, phone numbers, emails, postal addresses, tax numbers (optional), event details (date, venue, guests, budget, preferences), photos and images, notes |
| Special categories | none intended; you must not enter them unless strictly necessary and lawful |
Client details you enter for contracts and other documents may be saved in the project so you can reuse them; they are deleted together with the project.
2. Your instructions
We process Client Data only on your documented instructions: these Terms, this DPA and your use of the Service’s features. If we believe an instruction breaks data protection law, we will tell you. We process data otherwise only if EU or member-state law requires it, and then we inform you unless the law forbids it.
3. Confidentiality and security
Our staff with access are bound by confidentiality. We apply the technical and organisational measures in Annex 2 and may update them if the level of protection does not decrease.
4. Sub-processors
You give general authorisation to the sub-processors in Annex 1. We will notify you by email at least 30 days before adding or replacing one; you may object on reasonable data-protection grounds, and if we cannot resolve the objection you may terminate and receive a pro-rata refund. We bind each sub-processor to data-protection terms no less protective than this DPA and remain responsible for them.
5. International transfers
Where a sub-processor processes Client Data outside the EEA, Switzerland or the UK, we rely on an adequacy decision, the EU–US Data Privacy Framework, or the Standard Contractual Clauses (and the UK Addendum), with supplementary measures where needed.
6. Helping you
Taking into account the nature of the processing, we help you to answer data-subject requests (you can view, export, edit and delete Client Data in the Service yourself), and with security, breach notification, impact assessments and consultations with authorities. Requests we receive directly from your customers we forward to you without undue delay.
7. Personal data breaches
We notify you without undue delay, and where feasible within 48 hours, after becoming aware of a breach affecting Client Data, with the information reasonably available to help you meet your notification duties.
8. Deletion and return
When you delete a project or your account, or your account is deleted under the Terms, we delete the Client Data in it from live systems within 7 days and from backups within 30 days, unless law requires us to keep it. Before deletion you can download your documents and images from the Service.
9. Audits
We make available the information needed to show compliance with this DPA, in the first place through written answers and this documentation. On reasonable notice and at most once a year, you may audit us through an independent auditor bound by confidentiality, at your cost.
10. Liability and order of precedence
The liability limits of the Terms apply to this DPA. If this DPA conflicts with the Terms on data protection, this DPA prevails.
Annex 1 — Sub-processors
| Sub-processor | Service | Location of processing | Transfer safeguard |
|---|---|---|---|
| Infomaniak Network SA | hosting, database, email | Switzerland | adequacy decision |
| fal.ai (Features & Labels, Inc.) | AI image generation and background removal; model and moderation providers it uses | United States | Standard Contractual Clauses |
| Infomaniak Network SA (Swiss Backup) | encrypted backups | Switzerland | adequacy decision |
Paddle processes buyers’ payment data as an independent controller, not as our sub-processor.
Annex 2 — Security measures
- Encryption in transit (TLS) for all traffic; passwords stored as bcrypt hashes.
- Access to production limited to named staff, SSH keys only, no password logins.
- Email-code confirmation for account deletion, password and email changes.
- Rate limits and login-attempt monitoring against brute force and abuse.
- Public brief and order-sheet links use long random tokens, are excluded from search engines and never show the customer’s phone, budget or venue contact on the crew sheet.
- Images sent to AI providers are exposed through short-lived links and deleted from our side within 1 hour.
- Server logs kept 30 days; backups at most 30 days.
- Two separate application instances and tested rollback for availability.
