eveli All legal documents

Data Processing Addendum

Effective: August 11, 2026
Version: 1.2

This Data Processing Addendum (“DPA”) forms part of the agreement between Eveli, Inc. (“EVELI”) and a business customer (“Customer”) when EVELI processes personal data on Customer's behalf through the Service.

1. Roles and scope

Customer is the controller or processor that determines the lawful instructions for Customer Personal Data. EVELI is Customer's processor or subprocessor. EVELI remains an independent controller for account administration, billing, security, fraud prevention, legal compliance and its own business records as described in the Privacy Notice.

“Data Protection Law” means applicable EU GDPR, UK GDPR, Data Protection Act 2018, U.S. state privacy law and other binding data-protection law. Terms including controller, processor, personal data, processing, data subject and supervisory authority have their statutory meanings.

2. Documented instructions

EVELI will process Customer Personal Data only to provide, secure, troubleshoot and support the contracted Service in accordance with the agreement, Customer's documented use and lawful instructions, unless law requires otherwise. Product improvement for EVELI's independent purposes is outside these processor instructions unless Customer gives a separate documented instruction or the parties document another lawful role. EVELI will inform Customer if an instruction appears to violate Data Protection Law, unless prohibited.

Customer is responsible for lawful collection, notices, consents, rights, data accuracy, minimization and instructions. Customer will not submit an identifiable real-person or minor image, special-category or biometric data, or personal data prohibited by the agreement, and will not use EVELI for biometric identification, special-category inference or high-impact decisions.

3. Confidentiality and personnel

EVELI ensures that authorized personnel are bound by confidentiality, receive appropriate privacy and security training and access Customer Personal Data only on a need-to-know basis.

4. Security

EVELI implements the technical and organizational measures in Annex II and may update them without materially reducing overall protection. Customer is responsible for configuring its account, permissions, devices and exports securely.

5. Subprocessors

Customer gives general authorization for the subprocessors on EVELI's published list. EVELI will impose data-protection obligations providing materially equivalent protection and remains responsible for subprocessor performance as required by law.

EVELI will provide at least 15 days' advance notice of a new subprocessor that will process Customer Personal Data. Customer may object on reasonable data-protection grounds during that period. The parties will work in good faith on a solution. If no reasonable solution exists, Customer may terminate the affected Service without penalty and receive any refund required by the agreement or law.

Subprocessors may not use private Customer Personal Data to train their own generalized models. EVELI will not use Customer Personal Data for EVELI generalized model training without Customer's separate written instruction and all required data-subject authority.

For U.S. state privacy laws, EVELI will not sell or share Customer Personal Data, retain/use/disclose it outside the direct business relationship or permitted purposes, or combine it with personal data received from another source except as legally permitted. EVELI provides the same level of privacy protection required of a contracted service provider/processor, will notify Customer if it can no longer comply and grants Customer the right to take reasonable steps to stop and remediate unauthorized use.

6. Data-subject requests

Taking into account the nature of processing, EVELI will provide reasonable technical and organizational assistance for Customer to respond to rights requests. If EVELI receives a request concerning Customer-controlled data, it will direct the person to Customer or notify Customer, unless law requires EVELI to respond.

7. Security incidents

EVELI will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide information reasonably available about nature, likely consequences, affected data, mitigation and contact, supplementing it in phases if necessary. Notification is not an admission of fault. Customer is responsible for controller notifications unless law assigns them to EVELI.

8. DPIAs and consultation

EVELI will provide reasonable information needed for Customer's data-protection impact assessment or prior consultation concerning the Service, taking into account processing and information available. Additional custom assistance may be subject to reasonable fees unless required because of EVELI's breach.

9. Deletion and return

During the term, Customer may export supported data. At Customer's choice, on termination or written instruction EVELI will delete or return Customer Personal Data and delete existing copies within the verified retention periods, unless law requires retention. On request, EVELI will certify completion. Backup copies remain isolated and protected and are deleted through the ordinary verified backup cycle.

10. Information and audits

EVELI will make available information reasonably necessary to demonstrate compliance, including current independent reports or questionnaires when available. No more than once annually, Customer may request an audit after first using available documentation, except after a material incident, a regulator request or credible evidence of material noncompliance. Audits must be scoped, confidential, non-disruptive, conducted by an independent qualified auditor, and at Customer's cost unless they reveal a material EVELI breach. Audits may not expose other customers' data, security secrets or privileged material.

11. International transfers

Where a restricted transfer occurs:

  1. the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914 (“EU SCCs”) are incorporated by reference;
  2. Module Two applies to controller-to-processor transfers and Module Three to processor-to-processor transfers;
  3. the optional docking clause applies; Clause 9 uses Option 2 with the notice period in Section 5; Clause 11 does not apply unless mandatory; and Clause 17 and 18 use the law and courts of Ireland unless mandatory law requires another eligible forum;
  4. Annex I of this DPA supplies Annex I to the EU SCCs and Annex II supplies the security measures;
  5. for UK restricted transfers, the then-current UK International Data Transfer Addendum to the EU SCCs is incorporated: Table 1 is completed by Annex I's party details; Table 2 selects the applicable Module Two or Three EU SCCs and the options in this Section; Table 3 is completed by Annexes I and II; in Table 4, either party may end the Addendum as its mandatory terms permit; England and Wales are the governing law and forum unless mandatory law requires another eligible choice; and
  6. an applicable adequacy decision or certified framework may be used instead where valid.

If a transfer mechanism becomes invalid, the parties will cooperate to adopt a valid replacement. EVELI will provide information reasonably necessary for transfer-risk assessments.

For transfers protected by Swiss law, references in the EU SCCs to the GDPR and Member State law include the Swiss Federal Act on Data Protection as applicable; “Member State” is interpreted to allow Swiss data subjects to exercise their rights; and the competent authority and courts are those of Switzerland where required.

12. Liability and conflict

Liability under this DPA is subject to the agreement's lawful liability limits, except to the extent Data Protection Law prohibits limitation. If this DPA conflicts with the agreement on personal-data processing, this DPA controls. The incorporated transfer terms control over inconsistent DPA terms.

Annex I — Processing details

Parties: Customer as exporter/controller or processor; Eveli, Inc., 16192 Coastal Highway, Lewes, Delaware 19958, United States, legal@eveli.ai, as importer/processor or subprocessor.

Data subjects: Customer users, personnel, clients, contractors and other adults connected with permitted Customer Inputs. Identifiable depicted people and minors are prohibited at launch.

Data: account identifiers; permitted synthetic images; project metadata; text and selections; generation inputs and outputs; technical identifiers; support data; and other non-prohibited personal data Customer lawfully submits.

Special categories and biometric data: prohibited. EVELI does not use images to infer special categories or uniquely identify people.

Operations: collection, hosting, storage, organization, retrieval, transmission to generation providers, transformation/generation, logging, support, security, deletion and export.

Purpose: provide, secure, troubleshoot and support the contracted AI-production Service.

Frequency: continuous or as initiated by Customer during the term.

Duration: agreement term plus the published deletion and backup periods, subject to lawful retention.

Competent authority: determined under applicable Data Protection Law and the incorporated transfer terms.

Annex II — Technical and organizational measures

The August 11, 2026 implementation includes:

Before processing Customer Personal Data through live generation, EVELI will add and verify fal.ai payload non-retention and restricted short-lived media controls described in the Subprocessor page. Before a Customer order incorporates this DPA, EVELI will record the applicable provider account regions, administrator access, incident contacts, deletion/backup settings and current vendor transfer contracts in the Customer/vendor register. Those account-specific records supplement this Annex without weakening the controls above.

Effective: August 11, 2026Version: 1.2

Permanent link to this exact version: /legal/v1.2/dpa