Data Processing Agreement

Last updated: April 15, 2026

For business customers who need a formal DPA for GDPR, CCPA/CPRA, or other data protection compliance.

When does this DPA apply? This Data Processing Agreement ("DPA") supplements the Terms of Service and Privacy Policy for My Pixie Suite. It applies when you (the "Customer" or "Controller") use the Service and CNG Studios LLC (the "Processor") processes personal data on your behalf. This DPA is automatically incorporated into your agreement with us when you use the Service to process personal data of your end users, customers, contacts, or employees.

Need a signed copy? If your organization requires a countersigned DPA for compliance purposes, contact us with "DPA Request" in the subject line and we will provide an executable version.

1. Definitions

In this DPA, the following terms have the meanings set out below. Capitalized terms not defined here have the meanings given in the Terms of Service.

2. Scope and Roles

Customer as Controller: You are the Controller of the Personal Data you submit to and process through the Service. You determine what Personal Data to process, why it is processed, and how long it is retained (within the capabilities of the Service).

CNG Studios as Processor: We act as your Processor when handling Personal Data on your behalf through the Service. We process Personal Data only according to your documented instructions (as expressed through your use of the Service and these Terms) and applicable Data Protection Laws.

Types of Personal Data processed through the Service may include:

Pixie ApplicationCategories of Personal DataData Subjects
EchoPixieSocial media account information, post content, engagement metrics, audience dataCustomer's social media followers and audience
HadesPixieVendor names, invoice details, receipt data, financial transaction recordsCustomer's vendors, clients, contractors
IrisPixieContact names, email addresses, phone numbers, company names, interaction history, lead scoresCustomer's leads, prospects, and contacts
AthenaPixieMarket research data, competitor information, sales analyticsMinimal personal data (primarily business data)
GaiaPixieChat transcripts, customer names, email addresses, support inquiriesCustomer's end users and support requesters
HermesPixieDelivery addresses, recipient names, phone numbers, shipment detailsCustomer's delivery recipients
CalliPixieAuthor names, contributor information, publishing metadataCustomer's authors and contributors
SirenPixieArtist names, contributor credits, release metadataCustomer's artists and collaborators

3. Processing Instructions

We will process Personal Data only in accordance with:

If we believe an instruction from you infringes applicable Data Protection Laws, we will inform you promptly before carrying out the instruction (unless prohibited by law from doing so).

We will not process Personal Data for any purpose other than providing the Service to you, unless required by applicable law, in which case we will inform you of that legal requirement before processing (unless the law prohibits such notification).

4. Confidentiality

We ensure that all persons authorized to process Personal Data on our behalf are bound by obligations of confidentiality. Access to Personal Data is limited to personnel who need it to provide the Service, and all such personnel have received appropriate training on data protection obligations.

5. Security Measures

We implement and maintain appropriate technical and organizational security measures to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include:

Technical Measures:

Organizational Measures:

6. Sub-Processors

We use the following Sub-Processors to assist in providing the Service. Each Sub-Processor receives only the minimum Personal Data necessary to perform its function:

Sub-ProcessorPurposeData ProcessedLocation
Stripe, Inc.Payment processingName, email, billing address, payment methodUnited States
Brevo (Sendinblue SAS)Transactional email deliveryEmail address, email contentEU (France) / United States
Cloudflare, Inc.CDN, DDoS protection, DNSIP address, request metadata (encrypted in transit)Global (edge nodes)

No third-party AI Sub-Processors: All AI features (content generation, OCR, analytics) are processed on our own self-hosted infrastructure. No Personal Data is sent to any third-party AI service.

Changes to Sub-Processors: We will notify you by email at least 30 days before engaging a new Sub-Processor or making a material change to an existing Sub-Processor's role. You may object to a new Sub-Processor within that 30-day period by contacting us. If we cannot reasonably accommodate your objection, you may terminate the affected Service without penalty.

We ensure that each Sub-Processor is bound by data protection obligations no less protective than those in this DPA.

7. Data Subject Rights

We will assist you in fulfilling your obligations to respond to Data Subject requests to exercise their rights under applicable Data Protection Laws (access, rectification, erasure, restriction, portability, and objection). Specifically:

8. Data Breach Notification

In the event of a Personal Data breach, we will:

9. International Data Transfers

The Service is operated from the United States. If you are located in the EEA, UK, or another jurisdiction with data transfer restrictions:

Transfer Mechanism: We rely on the European Commission's Standard Contractual Clauses (SCCs), specifically Module Two (Controller to Processor), as our legal mechanism for transferring Personal Data from the EEA/UK to the United States.

Supplementary Measures: In addition to the SCCs, we implement the following supplementary measures to protect transferred data:

If you require executed SCCs, contact us and we will provide them.

10. Data Protection Impact Assessments

We will provide reasonable assistance to you with data protection impact assessments (DPIAs) and prior consultations with supervisory authorities, to the extent required under applicable Data Protection Laws, taking into account the nature of the processing and the information available to us.

11. Audits and Inspections

Upon reasonable request and subject to appropriate confidentiality obligations, we will make available to you information necessary to demonstrate our compliance with this DPA. This may include:

If you require an on-site audit, we will accommodate reasonable audit requests with at least 30 days' advance notice, during normal business hours, and no more than once per year (unless a breach or specific compliance concern justifies an additional audit). Audits are conducted at your expense and must not disrupt our operations or compromise other customers' data.

12. Data Deletion and Return

Upon termination of the Service agreement or upon your written request:

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions set forth in the Terms of Service. Nothing in this DPA limits either party's liability for breaches of data protection obligations that cannot be limited under applicable Data Protection Laws.

14. Term and Termination

This DPA takes effect when you begin using the Service and remains in effect for as long as we process Personal Data on your behalf. Upon termination of the Service agreement, the provisions of this DPA that by their nature should survive (including Sections 8, 9, 12, and 13) will continue to apply.

15. Conflict

In the event of a conflict between this DPA and the Terms of Service, this DPA prevails to the extent of the conflict with respect to the processing of Personal Data. In the event of a conflict between this DPA and the Standard Contractual Clauses, the SCCs prevail.

16. Updates to This DPA

We may update this DPA to reflect changes in Data Protection Laws, our Sub-Processors, or our data processing practices. Material changes will be communicated by email at least 30 days before taking effect. If a change materially reduces the protections in this DPA, you may terminate the Service without penalty.

17. Contact

For DPA-related inquiries, data protection questions, or to request a signed copy:
CNG Studios LLC
Data Protection Contact: Gonzalo Figueroa
Email: Contact Form (subject: "DPA Request")
Website: cngstudios.biz