Palette
Product
GenerateEditStoryboardCharacters
Models
ByteDance Seedance 2.0Google Veo 3.1Kling 3.0 ProMiniMax Hailuo 02LTX Video
Company
About usSecurityContact
Book a Demo

Data Processing Addendum

Last updated: June 29, 2026

This document is a starter template provided for convenience. It is not legal advice and must be reviewed and adapted by qualified legal counsel before you rely on it.

This addendum governs how Palette processes personal data on behalf of our customers. It is structured to meet GDPR Article 28 and to support Standard Contractual Clauses for international transfers.

1. Scope and Roles

This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Controller") and Palette Technology, Inc. ("Processor", "Palette") for the provision of the services. It applies where Palette processes personal data on the Controller's behalf and is intended to meet the requirements of Article 28 of the GDPR and comparable laws.

The Controller determines the purposes and means of processing Customer Data. Palette processes that data only on the Controller's documented instructions, including those set out in the agreement and this DPA, unless required to do otherwise by law, in which case it will inform the Controller where permitted.

2. Nature and Purpose of Processing

Palette processes Customer Data to provide the AI-native HR platform and related services, including hosting, configuration, support, and generating AI outputs. The subject matter, duration, nature, purpose, categories of data, and categories of data subjects are described in the Annexes below.

3. Confidentiality

Palette ensures that personnel authorized to process Customer Data are bound by appropriate confidentiality obligations and are trained on their responsibilities. Access is limited to those who need it to provide the services.

4. Security Measures

Palette implements appropriate technical and organizational measures to protect Customer Data, taking into account the state of the art and the risks of processing. These measures are described in Annex II and on our security page, and include encryption in transit and at rest, access controls, tenant isolation, logging, and a tested incident response process.

5. Sub-processors

The Controller authorizes Palette to engage sub-processors to provide the services. Palette imposes data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible for their performance. A current list of sub-processor categories is published on our subprocessor page. Palette will give notice of intended changes and allow the Controller to object on reasonable data protection grounds.

6. International Transfers

Where processing involves transfer of personal data outside the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the parties incorporate the European Commission's Standard Contractual Clauses, and the UK Addendum or Swiss amendments where applicable, which are deemed completed with the details in the Annexes. Palette applies supplementary measures where needed.

7. Data Subject Rights

Taking into account the nature of the processing, Palette assists the Controller with appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects to exercise their rights. If Palette receives such a request directly, it will, where permitted, refer the data subject to the Controller.

8. Assistance and Breach Notification

Palette assists the Controller in ensuring compliance with its obligations regarding security, breach notification, data protection impact assessments, and prior consultation, taking into account the information available to Palette. Palette notifies the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data, and provides information reasonably needed to meet the Controller's notification obligations.

9. AI Processing Commitments

Where the services use AI to process Customer Data, Palette processes prompts and context only to provide the services. Palette does not use Customer Data to train public foundation models, and requires its AI sub-processors not to use Customer Data to train their general models. This processing is subject to the same instructions, security, and confidentiality terms as the rest of this DPA.

10. Audit Rights

Palette makes available information reasonably necessary to demonstrate compliance with this DPA and allows for audits, including inspections, conducted by the Controller or an auditor it mandates. To minimize disruption, Palette may satisfy audit requests by providing current certifications, reports, and questionnaire responses, with on-site audits limited to reasonable scope, frequency, and notice.

11. Return and Deletion of Data

On termination of the services, Palette will, at the Controller's choice, return or delete Customer Data, and delete existing copies, within the period described in the agreement, unless retention is required by law. Backup copies are deleted in line with our backup retention cycle.

12. Annexes

Annex I describes the parties, the subject matter, duration, nature and purpose of processing, categories of data subjects, and categories of personal data, including HR and employee records. Annex II describes the technical and organizational security measures. Annex III lists sub-processors. These Annexes are completed in the agreement and on the referenced pages, and may be updated as the services evolve.

13. Contact

To execute this DPA or request our standard form, contact us at founders@palettetechnology.com or (408) 889-1158.

Palette

The creative engine for multimodal content.

One generation layer for teams creating across audiences, formats, and contexts.

Product

  • Generate
  • Edit
  • Storyboard
  • Models
  • Characters

Company

  • About
  • Contact
  • Book a call

Trust

  • Security
  • Subprocessors

Legal

  • Privacy
  • Terms
  • DPA

© 2026 Palette Technology, Inc.

LinkedInTwitterEmail