Legal

Data Processing Addendum

Last updated: September 23, 2026

The terms on which NOLGIA processes personal data on behalf of business customers. Each section starts with a short summary where it helps; the full text is what counts.

1. About this Addendum

In short: When NOLGIA processes personal data for a business customer, this Addendum sets the rules. It is part of your agreement with us.

This Data Processing Addendum (the "Addendum") is between Nolgia Inc., a Delaware corporation ("NOLGIA", "we"), and the business customer that uses the Service ("you"). It forms part of our Terms of Service or any other agreement you have with us for the Service (the "Agreement"), and applies whenever we process Customer Personal Data on your behalf.
It does not cover personal data we process for our own purposes as a controller, such as account, billing, security and product analytics data. Our Privacy Policy covers that.
If this Addendum conflicts with the Agreement, this Addendum controls for personal data. If the Standard Contractual Clauses apply and conflict with this Addendum, the Standard Contractual Clauses control. A signed copy is available on request.

2. Definitions

  • Data Protection Laws: the laws on personal data that apply to the processing, including the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act.
  • Customer Personal Data: personal data in the content you and your users submit to the Service or create with it (Inputs and Outputs), and in your organization's workspace, that we process on your behalf.
  • Subprocessor: a third party we engage that processes Customer Personal Data.
  • Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
  • Controller, processor, data subject, processing and supervisory authority have the meanings given in the GDPR. Under US state laws, "processor" includes "service provider".

3. Roles and instructions

In short: You decide what happens to your data. We process it only to provide the Service and on your instructions.

You are the controller of Customer Personal Data (or a processor acting for your own customers), and we are your processor (or subprocessor). Annex 1 describes the processing.
We process Customer Personal Data only on your documented instructions. The Agreement, this Addendum and your use and configuration of the Service, including the models, agents, sharing and connections you choose, are your instructions. We tell you if we believe an instruction breaks Data Protection Laws, unless the law prevents us from doing so.
We do not sell Customer Personal Data or share it for cross-context behavioral advertising, do not use it to train AI models, and do not use or disclose it for any purpose other than providing the Service and the other purposes allowed by this Addendum or the law. We do not combine it with personal data we receive from other sources except as needed to provide the Service.
You are responsible for having a lawful basis for the processing, for the notices you give, and for the consents you obtain, including from people whose images or voices appear in your content.

4. Confidentiality

We make sure everyone we authorize to process Customer Personal Data is bound by confidentiality, and give access only to those who need it to provide, support or secure the Service.

5. Security

In short: We protect your data with the technical and organizational measures in Annex 2.

We implement and maintain appropriate technical and organizational measures to protect Customer Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing and its risks. Annex 2 describes them. We may update them as long as the overall level of protection does not decrease.

6. Subprocessors

In short: You authorize us to use subprocessors. We tell you before adding one and you can object.

You give general authorization for us to engage Subprocessors. Our principal Subprocessors are listed on our Subprocessors page. Other model providers and hosting partners that run specific models receive Customer Personal Data only when you or your users choose one of those models.
We impose data protection obligations on each Subprocessor that are no less protective than this Addendum, and we remain responsible for their performance.
We give notice of a new principal Subprocessor by updating the Subprocessors page at least 15 days before it starts processing Customer Personal Data, and by email if you ask us for notices at contact@nolgia.ai. Where we need to replace a Subprocessor urgently to keep the Service running, we give notice as soon as we can. You may object on reasonable data protection grounds within 10 days of the notice. We will then work with you in good faith on a solution; if we cannot find one, you may terminate the affected part of the Service.

7. Helping you meet your obligations

Taking into account the nature of the processing, we help you respond to requests from data subjects to exercise their rights, mainly through the Service's own features for finding, exporting and deleting content. If we receive a request directly that relates to your data, we refer the person to you and do not respond ourselves unless the law requires it.
We give you reasonable information and help with data protection impact assessments and prior consultations with supervisory authorities, where they concern our processing.
If a public authority asks us for Customer Personal Data, we tell you before disclosing it, unless the law prevents us, and we disclose only what we are legally required to.

8. Personal data breaches

In short: If a breach affects your data, we tell you without undue delay and help you respond.

We notify you without undue delay after becoming aware of a Personal Data Breach, and where feasible within 72 hours. The notice describes, as far as we then know, the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, and the measures taken or proposed. We add information as it becomes available, take reasonable steps to contain the breach, and help you meet your own notification obligations. Notifying you is not an admission of fault.

9. Deletion or return at the end

In short: When the Service ends, you can export your content first, and then we delete it.

Until the Service ends, you can export or delete your content through the Service. When the account or organization that holds Customer Personal Data is deleted, we delete that Customer Personal Data within 30 days, including from backups and logs. We keep only records we must keep by law, such as for tax and accounting, with personal data removed where we can; we keep them confidential and use them only for that purpose.

10. Information and audits

We make available the information reasonably needed to show that we meet this Addendum, including answers to reasonable security questionnaires. If that information is not enough, you (or an independent auditor you appoint who is bound by confidentiality) may audit our compliance no more than once a year, or after a Personal Data Breach, on at least 30 days' written notice, during business hours, at your cost, and in a way that does not disrupt the Service or expose other customers' data. Where an independent audit report covering the processing is available, we may provide it instead.

11. International transfers

In short: We store data in the United States. For transfers out of the EU, UK or Switzerland, the Standard Contractual Clauses apply.

We store Customer Personal Data in the United States, and some Subprocessors process it in other countries. Where Data Protection Laws require a transfer mechanism:
  • EU: the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914 are incorporated into this Addendum, using Module Two (controller to processor) and, where you are a processor, Module Three (processor to processor). Clause 7 does not apply; under Clause 9, Option 2 applies with the notice period in the Subprocessors section of this Addendum; the optional wording in Clause 11 does not apply; under Clause 13, the supervisory authority is the one competent for you; under Clauses 17 and 18, the law and courts of Ireland apply. Annexes 1 to 3 of this Addendum complete the Annexes of the Clauses.
  • UK: the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner applies, with the details above completing its tables, and either party may end it as its Part 2 allows.
  • Switzerland: the Standard Contractual Clauses apply with the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority, and references to the GDPR read as references to the Swiss Federal Act on Data Protection.
We make sure Subprocessors that receive Customer Personal Data in countries without an adequacy decision are bound by an appropriate transfer mechanism.

12. Liability and general terms

Each party's liability under this Addendum is subject to the limitations and exclusions of liability in the Agreement, except where Data Protection Laws or the Standard Contractual Clauses do not allow them. This Addendum lasts as long as we process Customer Personal Data on your behalf. We may update it to reflect changes in the law or the Service; material changes that reduce your protection apply only with notice as described in the Agreement.

13. Annex 1: Details of the processing

Details of the processing
ItemDetails
PartiesData exporter: you, the customer, contactable through your account. Data importer and processor: Nolgia Inc., 8549 Wilshire Blvd, Suite 1180, Beverly Hills, CA 90211, United States, contact@nolgia.ai.
Subject matter and durationProviding the Service under the Agreement, for its term and until deletion as described in this Addendum.
Nature and purposeHosting and storing content; generating images, video, audio and other Outputs, including sending Inputs to the model providers you choose; running NOLGIA Agent for your users; sharing content at your direction; support; and security.
Data subjectsYour authorized users; people whose images, voices or other personal data appear in content submitted to or created with the Service; and people mentioned in agent chats.
Personal dataUsers' names, email addresses, roles and activity within your organization's workspace; any personal data in prompts, uploads, reference photos, voice clips, chats and Outputs.
Special categoriesYou decide what content is submitted. The face identity check processes face templates only for reference photos a user has agreed to have checked, as described in our Privacy Policy. Do not submit other special category data unless it is necessary.
FrequencyContinuous, while the Service is in use.

14. Annex 2: Security measures

  • Encryption of data in transit and at rest.
  • Content kept in private storage and shown to users only through short-lived access links.
  • Separation of each customer's data within the Service, with access checked on every request.
  • Access to production systems limited to authorized staff who need it, with access to customer chats recorded.
  • Passwords and access tokens stored only in hashed form, and credentials for customer-connected storage encrypted.
  • Databases reachable only on a private network.
  • Regular backups with limited retention, and the ability to restore service.
  • Software and dependencies kept up to date, with changes reviewed and tested before release.
  • An incident response process for investigating and containing security events and notifying customers.
  • Due diligence on Subprocessors and written data protection terms with them.
  • For the face identity check: processing only with consent, on our own systems, with face templates never stored.

15. Annex 3: Subprocessors

Our principal Subprocessors, what we use each for and where they process data are listed on our Subprocessors page. Other model providers and hosting partners that run specific models receive the Inputs needed for those models, under the same rules.

16. Contact

Questions about this Addendum, requests for a signed copy, or subprocessor notices: email contact@nolgia.ai or write to Nolgia Inc., Attn: Privacy, 8549 Wilshire Blvd, Suite 1180, Beverly Hills, CA 90211, United States.
  • September 23, 2026: First published.