Data Processing Addendum

Effective: August 25, 2026

1. Parties, Scope, and Incorporation

This Data Processing Addendum (“DPA”) is entered into between the merchant or other business customer using HomeVisioner (“Merchant”) and Ayyüce Turan, trading as HomeVisioner, Petersstr. 59-61, 47809 Krefeld, Germany (“HomeVisioner”).

This DPA forms part of the HomeVisioner Terms and any other agreement governing the Merchant’s use of HomeVisioner. It applies where HomeVisioner processes Personal Data on behalf of the Merchant. If this DPA conflicts with the main agreement on the processing of Personal Data, this DPA prevails.

“Applicable Data Protection Law” includes the GDPR and applicable national laws, the UK GDPR where applicable, the Australian Privacy Act 1988 (Cth) and Australian Privacy Principles where applicable, and other privacy laws applicable to this processing.

2. Roles and Documented Instructions

For Personal Data processed through a Merchant’s store, the Merchant is the controller or business and HomeVisioner is the processor or service provider. HomeVisioner processes that data only on documented instructions contained in the agreement, this DPA, the Merchant’s service configuration, and lawful support requests.

HomeVisioner may process merchant account, billing, security, fraud-prevention, and legal compliance data as an independent controller under the HomeVisioner Privacy Policy. That independent processing is outside the processor obligations in this DPA.

HomeVisioner will inform the Merchant if it believes an instruction infringes Applicable Data Protection Law, unless legally prohibited from doing so.

3. Merchant Responsibilities

The Merchant is responsible for:

  • lawful, fair, and transparent instructions and an appropriate legal basis;
  • providing required privacy information to its customers;
  • presenting optional marketing consent separately and lawfully;
  • not instructing customers to upload images containing people, children, or sensitive information; and
  • using generated visualizations in accordance with Applicable Data Protection Law.

4. HomeVisioner Obligations

HomeVisioner will:

  • process Personal Data only on documented instructions and for agreed purposes;
  • ensure authorised personnel are subject to confidentiality obligations;
  • maintain the technical and organisational measures in Annex 2;
  • reasonably assist with data-subject requests, security obligations, impact assessments, and regulatory consultations where required;
  • notify the Merchant without undue delay after becoming aware of a Personal Data Breach affecting Merchant Personal Data;
  • make information reasonably necessary to demonstrate compliance available to the Merchant; and
  • delete or return Merchant Personal Data when required under section 10.

5. Data-Subject Requests and Anonymous Images

HomeVisioner will reasonably assist with requests to access, correct, delete, restrict, or export Personal Data processed on the Merchant’s behalf. Unless legally required to respond directly, HomeVisioner will direct the requester to the relevant Merchant.

The Shopify integration can be used anonymously. A share link, job identifier, or another reliable technical identifier may therefore be required to locate a particular image. A name or email address alone may not identify an anonymous upload.

6. Confidentiality, Security, and AI Training

HomeVisioner restricts access to authorised persons and service providers that require access for the agreed purposes and applies the measures in Annex 2.

HomeVisioner does not use Merchant Personal Data to train or improve AI models and does not authorise its subprocessors, including Google Cloud and Google AI services, to do so.

7. Subprocessors

The Merchant grants HomeVisioner general authorisation to use the subprocessors in Annex 3. HomeVisioner requires subprocessors through written terms to provide protection appropriate to the processing and remains responsible for its processor obligations.

HomeVisioner may update Annex 3 as the service changes. Where required by law, reasonable advance notice of a material new subprocessor will be provided through the service, by email, or through the published schedule. A reasonable data-protection objection may be sent to [email protected].

8. International Transfers

Where Personal Data is transferred outside a jurisdiction requiring transfer safeguards, HomeVisioner and its subprocessors use an applicable lawful mechanism, such as an adequacy decision or Standard Contractual Clauses, together with supplementary safeguards where required.

Where Australian Personal Data is processed outside Australia, HomeVisioner applies contractual, technical, and organisational safeguards and reasonably assists the Merchant with applicable Australian privacy obligations.

9. Audits and Compliance Information

On reasonable written request, HomeVisioner will provide information reasonably necessary to demonstrate compliance with this DPA. If that information is insufficient, the Merchant may request an audit limited to the relevant processing, subject to reasonable notice, confidentiality, security, proportionality, and cost arrangements. An audit must not expose another merchant’s data or compromise service security.

10. Return, Deletion, and Term

HomeVisioner deletes image files according to the retention periods in the Privacy Policy. At the end of the service or following a valid instruction, HomeVisioner will delete or return Merchant Personal Data as required by Applicable Data Protection Law, unless retention is required by law. Protected backups are deleted according to the applicable backup lifecycle.

This DPA remains effective while HomeVisioner processes Personal Data on the Merchant’s behalf. The governing-law and dispute terms of the main agreement apply without limiting mandatory data-protection rights.

Privacy and DPA enquiries may be sent to [email protected].

Annex 1 — Processing Description

  • Subject matter: Providing the HomeVisioner visualisation service for the Merchant.
  • Duration: The service term plus applicable retention and deletion periods.
  • Nature: Collection, transmission, validation, storage, retrieval, AI processing, generation, display, support, security monitoring, and deletion.
  • Purposes: Requested product visualisations; merchant features; optional lead collection; analytics and order attribution where enabled; support; security; and legal compliance.
  • Data subjects: Merchant personnel, store visitors, shoppers, customers, and persons contacting support.
  • Personal Data: Room and product images; product information; generated visualisations; optional email and customer identifier; shop and account data; visualisation and product events; order-attribution information; IP address, browser, device, language, timestamps, authentication, security, and error-log data.
  • Sensitive data: Not intentionally requested. Customers are instructed not to upload images containing people, children, or sensitive information.
  • Image retention: Uploaded room images and generated visualisations are automatically deleted within the Privacy Policy period, currently a maximum of 30 days.

Annex 2 — Technical and Organisational Measures

  • Private object storage rather than public image buckets.
  • Encryption in transit and provider-managed encryption at rest.
  • Time-limited signed URLs for authorised image access.
  • Server-side credentials and authenticated server-to-server AI-service access.
  • Role-based access controls and separation between merchant tenants.
  • Merchant Gallery restrictions exposing generated outputs but not original room uploads.
  • Automated image-retention and deletion controls.
  • Automated upload controls designed to reject room images where a human face is detected.
  • Logging, monitoring, abuse prevention, error handling, and incident-response procedures.
  • Data minimisation, confidentiality, access review, and secure software-change practices.
  • Provider due diligence and contractual data-protection safeguards.

Automated face detection is a preventive safety control. It is not used to identify individuals, perform facial recognition, or create biometric identifiers, and it cannot guarantee detection of every person or identifying detail.

Annex 3 — Current Subprocessor Schedule

  • Google Cloud: AI processing, application compute, infrastructure, security, and operational logging. Primary HomeVisioner application infrastructure is operated in EU regions; other processing locations are subject to Google Cloud’s terms and transfer safeguards.
  • Supabase: Database, authentication, and private object storage. The primary HomeVisioner project is hosted in an EU region.
  • Resend: Transactional and service-related email delivery. Room images are not included in routine merchant emails.
  • Crisp: Merchant support communications. Room images are processed there only if a user or merchant chooses to provide one in a support conversation.
  • Cloudflare: Network security, traffic protection, and content delivery.
  • Stripe: Payments for direct HomeVisioner services where used. Shopify app billing is handled through Shopify.

Shopify provides the commerce platform and app environment under its own relationship with the Merchant. Shopify’s independent processing is governed by the Merchant’s agreement with Shopify.

Schedule effective: August 25, 2026.

© 2026 HomeVisioner. All rights reserved.Support and inquiries are handled exclusively via the contact page.
Powered by Google Cloud
Data Processing Addendum | HomeVisioner