HYPERTURE
ExamplesHow it worksCustomersTrustPricing
ExamplesHow it worksCustomersTrustPricingGet started
HYPERTURE
TermsPrivacyDPA
Back to siteGet started

Legal · Data processing addendum

The terms for processing your team's data on your behalf.

This Data Processing Addendum ("DPA") governs how HYPERTURE processes personal data as your processor under the GDPR. It forms part of the agreement between your organization and HYPERZ AI B.V.

Effective 30 June 2026Version 1.0
Terms of servicePrivacy policyData processing addendum

On this page

01Scope & relationship02Definitions03Roles & responsibilities04Processing instructions05Confidentiality06Security measures07Sub-processors08Data subject requests09Personal data breaches10DPIA & prior consultation11International transfers12Return & deletion13Audits14Liability & precedenceAnnex ADetails of processingAnnex BSecurity measuresAnnex CSub-processors

In short

When HYPERTURE processes your team's photos and account data, your organization is the controller and we are the processor. This DPA sets out our obligations under Article 28 of the GDPR - instructions, confidentiality, security, sub-processors, transfers, breach notification, and deletion - with the specifics in Annexes A-C. It applies automatically alongside the Terms of Service; no signature is required unless you ask for a counter-signed copy.

01

Scope & relationship

This DPA applies where HYPERZ AI B.V. ("HYPERTURE", "Processor") processes personal data on behalf of a customer organization ("Customer", "Controller") in connection with the HYPERTURE service. It supplements and forms part of the agreement between the parties.

Where this DPA refers to the GDPR, it means Regulation (EU) 2016/679 and any national implementing laws, as well as equivalent data protection laws that apply to the processing.

02

Definitions

Terms such as "controller", "processor", "personal data", "processing", "data subject", "personal data breach", and "sub-processor" have the meanings given to them in the GDPR.

"Customer Personal Data" means personal data that HYPERTURE processes on behalf of the Customer under the agreement, as described in Annex A.

03

Roles & responsibilities

The Customer is the controller of Customer Personal Data and HYPERTURE is the processor. The Customer is responsible for the lawful basis of the processing, including obtaining and maintaining each individual's consent for their photos to be processed and for the resulting headshots to be used.

HYPERTURE will process Customer Personal Data only as a processor, in accordance with this DPA and the Customer's documented instructions.

04

Processing instructions

HYPERTURE processes Customer Personal Data only on the Customer's documented instructions, including those given through the service's configuration, the agreement, and this DPA. If we are required by law to process beyond those instructions, we will inform the Customer in advance unless the law prohibits it.

We will promptly inform the Customer if, in our opinion, an instruction infringes applicable data protection law. We are not obliged to monitor the Customer's compliance with the law.

05

Confidentiality

HYPERTURE ensures that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and are trained on their data protection responsibilities. Access is granted on a need-to-know, least-privilege basis.

06

Security measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, and risks of the processing, HYPERTURE implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex B.

Given that Customer Personal Data includes facial images, we apply heightened controls to the storage, access, and deletion of source photos and per-person models.

07

Sub-processors

The Customer provides general authorization for HYPERTURE to engage sub-processors to support the service. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. A current list is set out in Annex C.

We will give the Customer prior notice of any intended addition or replacement of a sub-processor, allowing the Customer to object on reasonable data protection grounds.

08

Data subject requests

Taking into account the nature of the processing, HYPERTURE assists the Customer with appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights under the GDPR. Where a data subject contacts us directly about Customer Personal Data, we will promptly refer them to the Customer.

09

Personal data breaches

HYPERTURE notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provides the information reasonably available to assist the Customer in meeting its own notification obligations. We will take reasonable steps to mitigate the effects and to minimize any damage.

10

DPIA & prior consultation

HYPERTURE provides reasonable assistance to the Customer with any data protection impact assessment and any prior consultation with a supervisory authority that the Customer is required to carry out, in each case in relation to the processing under this DPA and taking into account the information available to us.

11

International transfers

HYPERTURE hosts Customer Personal Data on infrastructure in the European Union. Where any transfer of Customer Personal Data outside the European Economic Area takes place, it is carried out under an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses, which are incorporated by reference, together with any supplementary measures required.

12

Return & deletion

On termination of the service, or on the Customer's request, HYPERTURE deletes or returns Customer Personal Data and deletes existing copies, unless retention is required by law. Source photos and per-person models are deleted within 30 days of generating a set in the ordinary course, and on request at any time.

13

Audits

HYPERTURE makes available to the Customer information reasonably necessary to demonstrate compliance with Article 28 of the GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates. Audits are subject to reasonable notice, confidentiality, and frequency limits, and may be satisfied through up-to-date certifications or third-party reports where available.

14

Liability & precedence

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the agreement. In the event of a conflict between this DPA and the agreement on the subject of data protection, this DPA prevails. Where Standard Contractual Clauses apply, they prevail over this DPA to the extent of any conflict.

This DPA remains in effect for as long as HYPERTURE processes Customer Personal Data.

Annex A

Details of processing

Subject matterGeneration, verification, and management of professional headshots for the Customer's team using the HYPERTURE service.
DurationFor the term of the agreement, plus the retention periods set out in this DPA.
Nature & purposeCollection, storage, hosting, AI-based generation, likeness verification, provenance signing, delivery, and deletion of headshots.
Categories of dataFacial images (which may be biometric / special-category data), name, work email, role, team and company details, and usage data.
Data subjectsThe Customer's administrators, employees, and other team members who upload photos.

Annex B

Security measures

HYPERTURE maintains technical and organizational measures including, at a minimum:

  • Encryption of personal data in transit (TLS) and at rest.
  • Role-based access controls, multi-factor authentication for internal access, and least-privilege provisioning.
  • Audit logging of access to source photos and generated sets.
  • Network segmentation, hardened infrastructure, and regular patching.
  • Secure software development practices and dependency monitoring.
  • Backup, resilience, and tested restoration procedures.
  • Personnel confidentiality obligations and data protection training.
  • Defined retention and secure deletion of source photos and per-person models.
  • An incident response process for detecting, reporting, and handling personal data breaches.

Annex C

Sub-processors

HYPERTURE engages the following categories of sub-processor to deliver the service. The current named list is available on request at privacy@hyperture.ai.

CategoryPurposeLocation
Cloud hostingApplication and data storageEU
GPU computeAI image generationEU
Email deliveryTransactional & account emailEU / SCCs
PaymentsBilling & subscription managementEU / SCCs
Product analyticsUsage measurement & supportEU / SCCs
HYPERZ AI B.V. - Data protectionRegulusweg 5, 2516 AC The Hague, Netherlandsprivacy@hyperture.ai
HYPERTURE

Studio-grade headshots for every team member. Consistent, on-brand and ready in minutes.

Product

ExamplesHow it worksTrust & compliancePricing

Company

Customer storiesCareersContact us

Legal

Privacy policyData processing addendumTerms of service
© 2026 HYPERTURE. All Rights Reserved.
HYPERTURE

Studio-grade headshots for every team member. Consistent, on-brand and ready in minutes.

Product

ExamplesHow it worksTrust & compliancePricing

Company

Customer storiesCareersContact us

Legal

Privacy policyData processing addendumTerms of service
© 2026 HYPERTURE. All Rights Reserved.