Data Processing Addendum
Last updated: 13 July 2026 · Mochic LTD (company no. 12405063) · Applies to enterprise and brand customers subject to UK/EU GDPR
This DPA forms part of the agreement between Mochic LTD ("Processor") and the enterprise or brand customer ("Controller") using SpecForm OS. It applies where we process personal data on your behalf and you are subject to the UK GDPR, Data Protection Act 2018, or EU GDPR. This DPA is incorporated into and subject to our Terms of Service and Privacy Policy.
1. Definitions
"Data Protection Laws" means the UK GDPR, Data Protection Act 2018, and, where applicable, EU GDPR. "Personal Data", "Controller", "Processor", "Data Subject", and "Processing" have the meanings given in those laws. "Sub-processor" means any third party engaged by us to process Personal Data.
2. Roles of the Parties
Controller: You are the Data Controller for personal data contained within your design workflows, uploaded assets, and account.
Processor: Mochic LTD acts as Data Processor and processes such data only on your documented instructions.
3. Scope and Purpose of Processing
We process Personal Data to provide, host, and support the SpecForm OS platform for the term of your agreement plus any legally required retention period. See our Privacy Policy for full details.
4. Our Obligations as Processor
We shall:
- Process Personal Data only on your documented instructions.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (see Annex 2).
- Assist you in responding to Data Subject rights requests.
- Notify you without undue delay of any personal data breach.
- Delete or return all Personal Data at the end of services, unless retention is required by law.
- Restrict access to creative content (designs, sketches, prompts, and generated outputs) to automated processing systems. Engineering or support personnel will not access or review creative content without your prior written consent and a documented support justification.
5. Sub-processors
You provide general authorisation for us to engage the Sub-processors listed in Annex 3. We impose equivalent data-protection obligations on each and remain responsible for their performance. We will give you notice of intended changes so you can object on reasonable data-protection grounds.
6. Security Measures
We maintain appropriate technical and organisational measures including: encryption in transit (TLS) and at rest; role-based access controls; secure hosting (Supabase / GCP); logging and monitoring; and vulnerability management. Full details in Annex 2.
7. International Transfers
Where we transfer Personal Data outside the UK or EEA, we ensure appropriate safeguards such as the UK IDTA or Addendum, EU SCCs, or an adequacy decision.
8–10. Data Subject Requests, Breach, and Audit
We will direct Data Subject requests to you and assist in responding. We will notify you without undue delay of any personal data breach. We will make available information to demonstrate compliance and allow audits subject to reasonable notice and confidentiality requirements.
11. Deletion and Return of Data
In-term deletion and backup purge. Where you or your authorised users delete individual files or assets during the term of the Service, those files are removed from active storage immediately. Automated backup copies are purged within 30 days of deletion. We do not retain deleted creative content beyond this window except where retention is required by applicable law.
On termination of the Service, we will, at your choice, delete or return all Personal Data and delete existing copies, unless applicable law requires continued storage.
12. Liability and Precedence
This DPA is subject to the limitation of liability in our Terms of Service. In the event of a conflict between this DPA and the Terms of Service regarding the processing of Personal Data, this DPA prevails.
Annex 1 — Description of Processing
- Subject matter: provision of the SpecForm OS platform and related services.
- Duration: the term of your agreement, plus any legally required retention period.
- Nature and purpose: hosting, storing, generating, and processing design and technical assets; account management; billing support; customer support.
- Types of Personal Data: account identifiers (name, email), authentication data, billing contact details, and any personal data included within design workflows or communications.
- Categories of Data Subjects: your authorised users, employees, collaborators, and contacts.
Annex 2 — Technical and Organisational Measures
- Encryption in transit (TLS) and at rest.
- Role-based access and authentication; least-privilege principle.
- Secure, production-grade hosting (Supabase / GCP).
- Activity logging, monitoring, and periodic security review.
- Measures to restore availability after physical or technical incidents.
- Contractual data-protection obligations flowed down to all Sub-processors.
Annex 3 — Sub-processor List
- Stripe — payment processing
- Supabase — database, authentication, and storage
- Google Cloud Platform (GCP) — hosting and storage
- Google (Gemini) and OpenAI — AI processing for technical asset generation (prohibited from using your data for their own model training)
13. Contact
For any DPA-related matter: hello@morchen.uk.