12ui Data Processing Addendum

Last updated 4 August 2026

This Data Processing Addendum ("Addendum") forms part of the Terms of Service (the "Terms") between Peter Industries Pty Ltd ABN 13 588 984 088, trading as 12ui ("12ui"), and Customer. It applies where 12ui processes personal information or personal data contained in Customer Content on behalf of Customer as a processor, service provider, contractor, or similar role under applicable privacy or data protection laws, including EU/UK, Australian, and applicable US state privacy laws.

12ui does not require personal information to provide the Service. 12ui processes personal information only to the extent it appears in Customer Content - the images, prompts, LayerDocs, and configuration Customer submits to the Service. In the typical case this means screenshots that incidentally show names, email addresses, usernames, avatars, or account details.

If the parties sign a separate data processing agreement, that separate agreement controls to the extent of any conflict.

Roles

For Customer Content processed through the Service:

  • Customer is the controller, business, or equivalent party that determines the purposes and means of processing.
  • 12ui is the processor, service provider, contractor, or equivalent party that processes Customer Content on Customer's behalf.

For 12ui account administration, security, support, and business operations data, 12ui may act as an independent controller or business as described in the Privacy Policy.

Subject matter and duration

The subject matter is 12ui's provision of the Service. The duration is the period during which the Terms remain in effect, plus up to 30 days after the relevant processing purpose ends for deletion, return, legal compliance, dispute resolution, security, or legitimate business records, unless a longer period is required or permitted by law.

In the ordinary course, most processing of Customer Content is short-lived: conversion artifacts, including uploaded images and generated outputs, are removed from operational storage by automated cleanup once they are no longer needed to provide the Service, as described in section 13.

Nature and purpose of processing

12ui may collect, receive, record, host, store, transmit, retrieve, organise, structure, adapt, analyse, transform, disclose to authorised subprocessors, delete, de-identify, and otherwise process Customer Content to provide, secure, support, improve, and maintain the Service; generate outputs such as LayerDocs, exports, and generated images; comply with Customer's documented instructions; and comply with law. Any processing of personal information is incidental to this purpose and limited to personal information that appears in Customer Content.

Categories of data subjects

Data subjects may include Customer's users, customers, employees, contractors, and other individuals whose information is visible in content submitted to the Service, as well as Customer's account holders and personnel who operate the Service on Customer's behalf.

Categories of personal data

Personal data may include identifiers such as names, email addresses, usernames, avatars, and account details, and any other information embedded in submitted images or text; account identifiers; and usage metadata such as timestamps, filenames, media types, and request records.

Customer instructions

12ui will process Customer Content only on Customer's documented instructions, including the Terms, account settings, API calls, submitted configuration, and support requests, unless required by law. If 12ui believes an instruction violates applicable law, 12ui may notify Customer and may suspend the relevant processing.

Confidentiality

12ui will ensure that personnel authorised to process Customer Content are subject to appropriate confidentiality obligations.

Security measures

12ui will maintain reasonable administrative, technical, and organisational measures designed to protect Customer Content, taking into account the nature of the data, processing risks, available technology, implementation costs, and the Service's functionality.

These measures may include, as appropriate: access controls; least-privilege permissions; encryption in transit and strict transport security; encryption at rest where supported; signed, expiring artifact URLs; scoped, revocable API keys; automated deletion of conversion artifacts; logging and monitoring; vulnerability management; segregation of customer environments or logical access controls; secure development practices; incident response processes; personnel confidentiality; and vendor management.

Subprocessors

Customer authorises 12ui to use subprocessors to provide the Service, including cloud hosting, storage, compute, AI model inference, image processing, bot protection, security, and monitoring providers.

12ui will impose written obligations on subprocessors designed to protect Customer Content to a standard materially consistent with this Addendum. 12ui remains responsible for subprocessors' processing of Customer Content to the extent required by applicable law.

12ui will maintain a list of material subprocessors at /subprocessors or make it available on request. Customer may object to a new subprocessor on reasonable data protection grounds within 10 days after notice, and the parties will work in good faith to resolve the objection.

International transfers

Customer authorises 12ui and its subprocessors to process Customer Content in Australia, the United States, the United Kingdom, the European Economic Area, and other locations where 12ui or its subprocessors operate.

Where GDPR, UK GDPR, Swiss data protection law, Australian privacy law, or other cross-border transfer rules require safeguards, the parties will use appropriate transfer mechanisms, such as standard contractual clauses, UK addenda, contractual safeguards, data processing terms, or other lawful mechanisms.

Assistance with rights and compliance

Taking into account the nature of processing and information available to 12ui, 12ui will provide reasonable assistance to Customer to respond to data subject requests and meet applicable obligations relating to security, breach notification, data protection impact assessments, prior consultation, deletion, access, correction, and portability.

12ui may charge reasonable fees for assistance that is not included in the Service or that results from Customer's failure to use available Service functionality.

Security incidents

12ui will notify Customer without undue delay after confirming a Security Incident involving Customer Content. A Security Incident means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Content processed by 12ui.

Notification of a Security Incident is not an admission of fault or liability. Customer is responsible for determining whether regulatory, customer, or individual notification is required, except where 12ui has a direct legal obligation.

Deletion and return

Conversion artifacts, including uploaded images and generated outputs, are removed from 12ui's operational storage by automated cleanup once they are no longer needed to provide the Service, and on verified request at any time. Durable usage records that outlive artifacts - account identifiers, salted IP hashes, and cost and usage ledgers - persist for security, quota enforcement, and business records. Copies of uploaded images and generated outputs retained in 12ui's internal evaluation corpus, as described in the Privacy Policy, are deleted on verified request to support@12ui.com.

Upon Customer's request after termination or expiry of the Terms, 12ui will delete or return Customer Content in its possession or control within 30 days, unless and to the extent retention is required by law or reasonably necessary for security, dispute resolution, or legal compliance. These exceptions do not limit the deletion commitment in the first paragraph of this section: copies of uploaded images and generated outputs retained in the internal evaluation corpus are deleted on verified request.

Audits

Customer may request information reasonably necessary to demonstrate 12ui's compliance with this Addendum. Unless required by law, audits are limited to written questionnaires and review of available policies or summaries no more than once per year. On-site audits require reasonable notice, confidentiality, scope controls, and must not compromise 12ui's systems, security, other customers, or confidential information.

US state privacy law service provider terms

To the extent Customer Content is personal information subject to US state privacy laws and 12ui acts as a service provider, contractor, or processor, 12ui will not sell or share Customer Content, retain, use, or disclose Customer Content outside the business purposes of providing the Service, or combine Customer Content with personal information from other sources except as permitted by applicable law.

12ui certifies that it understands and will comply with the restrictions in this section. Customer may take reasonable and appropriate steps to help ensure 12ui uses Customer Content consistently with Customer's obligations, and 12ui will notify Customer if 12ui determines it can no longer meet its obligations.

Sensitive data

Customer must not submit sensitive or regulated data unless permitted by the Terms of Service or a written addendum. 12ui does not perform biometric identification and does not use Customer Content to identify individuals.

Conflict

If this Addendum conflicts with the Terms, this Addendum controls only for the processing of Customer Content as personal data. The Terms control for all other matters.