**Proposed standard form - September 11, 2026** This review version is not yet in effect or available for acceptance. It is published for discussion while the accompanying operational and provider information is finalized. It does not amend existing agreements, authorize new processing or replace an executed DPA. Contact [support@astria.ai](mailto:support@astria.ai) about the final version and its incorporation into your agreement. ## 1. Parties, scope and application This Data Processing Addendum (DPA), once finalized and incorporated into the applicable agreement, supplements the written or electronic agreement governing the customer's use of Astria's services (Agreement). The parties are Astria LTD, Israeli company number 516713989 (Astria), and the customer identified in the Agreement (Customer). Astria's correspondence address is 18 Raul Wallenberg St., Building D, 3rd-4th Floors, 6971915 Tel Aviv, Israel. The covered services and accounts are those identified in the Agreement. They may include the web platform, built-in agents and, where covered by the Agreement, API access and integrations. This DPA does not expand the services purchased or authorize access outside that scope. It is not limited to a particular industry or intended output. Personal Data means information relating to an identified or identifiable individual under applicable data protection law. Customer Personal Data means Personal Data that Astria processes on Customer's behalf in providing the covered services. Inputs include prompts, instructions, product references, image references and other submitted text, files, images, video or audio. Outputs are results generated by the service. Inputs and Outputs together are Customer Content. This DPA applies to Customer Content and associated metadata only to the extent they contain Customer Personal Data. Other confidentiality and content-use obligations remain governed by the Agreement. Data Protection Laws means laws actually applicable to the processing, including applicable Israeli privacy, data-security and overseas-transfer requirements and other mandatory privacy laws where they apply. The terms controller and processor describe the parties' functions; statutory roles follow the actual processing and applicable law. For Customer-directed processing, Customer acts as controller, or as a processor authorized by its controller, and Astria acts as processor or subprocessor respectively. ## 2. Instructions and permitted processing Customer instructs Astria to process Customer Personal Data to provide the services selected under the Agreement, including receipt, storage, organization, generation, editing, delivery, authorized sharing, support, troubleshooting, security and deletion. Instructions include the Agreement, this DPA, Customer's prompts, selected features and settings, and other lawful documented instructions agreed with Astria. Schedule 1 describes the processing. Customer is responsible for having the rights, permissions, notices and lawful authority needed for its submissions and instructions. Astria remains responsible for its own obligations. Astria will process Customer Personal Data only on documented instructions unless otherwise required by law, notify Customer of that legal requirement where permitted, and promptly inform Customer if it reasonably believes an instruction infringes applicable Data Protection Laws. Authorized personnel may access generations and metadata where reasonably necessary for permitted service, support, troubleshooting, quality-analysis or security duties, subject to confidentiality and access controls. A private workspace does not mean its contents are inaccessible to authorized Astria personnel or providers. ## 3. Quality improvement and separate processing purposes Astria and model providers may use Inputs and Outputs for model training and quality improvement only to the extent permitted by the Agreement, applicable disclosed provider terms and Data Protection Laws. This DPA does not create an additional content license, establish a no-training commitment, or treat Customer's commercial permission as a substitute for lawful authority to process Personal Data. Where Astria determines a separate purpose, such as its own model improvement, account administration, billing, fraud prevention or legal compliance, its role and duties must be assessed for that processing. Separate-purpose use must have the necessary lawful basis, notices, confidentiality safeguards and retention limits. Customer-directed service processing does not automatically authorize such use. The [Privacy Policy](/privacy) describes Astria's personal-information practices; a privacy notice does not independently enlarge a contractual license. Astria's permitted training use is limited to training and evaluating AI models for improved quality and performance, including necessary internal dataset preparation. It does not authorize publishing or selling private Customer Content, using it in marketing, or supplying or reusing it as assets, templates or references for another customer. General improvements to model capabilities may benefit other users; this does not authorize deliberately reproducing Customer's confidential content for them. These limits also apply to providers carrying out training on Astria's behalf. Independent provider uses must be disclosed and compatible with the Agreement's protections. Applicable deletion obligations also extend to separately retained source copies; deleting an account item does not itself establish that an already-trained model has unlearned it. ## 4. Confidentiality and security Astria will restrict access to specifically authorized personnel and providers who need it for permitted duties and are subject to contractual or applicable statutory confidentiality obligations. Personnel access to Customer Content requires privileged permissions. The Agreement's confidentiality obligations protect private Customer Content whether or not it contains Personal Data; permitted training is not permission for disclosure or reuse outside its stated purpose. Astria will maintain technical and organizational measures appropriate to the processing risks and applicable legal requirements, taking account of the nature, scope, context and purposes of processing. Schedule 2 describes the proposed security framework and relevant service characteristics. Astria may update its measures without materially reducing the protection agreed for Customer Personal Data. Customer remains responsible for its own credentials, authorized users, sharing decisions and selected configurations; those responsibilities do not excuse Astria's own obligations. ## 5. Subprocessors and model providers Customer provides general authorization for subprocessors engaged to provide the covered services, subject to the information, notice and safeguards in this section. Astria will make relevant recipient identities, functions, processing locations and material processing conditions available for the covered service before relying on that authorization. Astria will require its subprocessors to provide the contractual protections required by applicable law and remains responsible for their performance to the extent required by this DPA, the Agreement and applicable law. Astria will provide advance notice of intended material additions or replacements of subprocessors supporting an existing service and a reasonable opportunity to object on data-protection grounds. The parties will seek a compatible alternative for a justified objection. If none is reasonably available, the affected service may be ended under the Agreement, with its applicable refund and other remedies. Where urgent legal or security circumstances require a faster change, Astria will provide notice as soon as practicable; urgency does not authorize incompatible processing. Optional models and providers may change over time. Selecting a new optional model authorizes the disclosed processing necessary for that selection, subject to applicable law and agreed restrictions; adding a model to the catalogue alone does not authorize sending existing Customer Content to it. Material provider conditions must be disclosed before the relevant selection. Some model providers may retain Inputs and Outputs or use them for their own training under their applicable terms. Those independent purposes are distinct from processing solely on Customer's behalf. The parties must establish the actual role, lawful authority and required disclosures and protections for such processing. A provider's label or policy does not remove Astria's own obligations. No universal provider no-training or zero-retention promise is made. The current [account subprocessor list](/subprocessors) requires sign-in. Provider information for the final standard DPA will be made available without requiring an account before that DPA is offered for acceptance. Questions about a particular service or model can be sent to [support@astria.ai](mailto:support@astria.ai). ## 6. Assistance, oversight and security incidents Taking account of the nature of processing and information available to it, Astria will reasonably assist Customer with applicable individual rights requests, security obligations, impact assessments and regulatory consultations. Astria will forward relevant requests received directly and act on Customer's lawful instructions unless independently required to act by law. Astria will make available information reasonably necessary to demonstrate compliance and permit proportionate audits or inspections where required by applicable law. Reviews will ordinarily begin with relevant documentation and available reports, with reasonable notice, confidentiality and protection of other customers and systems. These arrangements do not restrict mandatory oversight. Any exceptional paid assistance must be agreed in advance and must not delay legally required action. Astria will notify Customer without undue delay after becoming aware of a security incident affecting Customer Personal Data and comply with any shorter applicable legal requirement. Notices will describe the known nature and scope, likely consequences, measures taken or proposed and a contact, with further information as it becomes available. Astria will investigate, contain and remediate within its responsibility and reasonably assist with required notifications. Notification is not an admission of liability. Unsuccessful attempts with no compromise of Customer Personal Data do not alone require notification, but credible indicators must be assessed. ## 7. Retention, return and deletion Astria retains Customer Personal Data for the covered service in accordance with the Agreement, applicable product settings and lawful documented instructions. Marking an item as deleted in the application is a documented deletion instruction for that item and the associated content within the scope of that action. Customer-requested storage and Customer-requested deletion are separate instructions; archiving is not deletion. A pause in purchases does not itself constitute a deletion request. Disclosed subscription-specific retention rules may apply where permitted by the Agreement. The service-specific retention and deletion arrangements must be supplied with the final DPA. Upon a valid deletion instruction or the end of processing, Astria will, at Customer's choice, return or delete Customer Personal Data and delete existing copies without undue delay, except to the extent lawful retention is required. Retained exceptions must be limited to the necessary data and period, protected from unauthorized use and deleted when the exception ends. The relevant deletion and backup-expiry periods must be documented for the covered service. Deletion must completely clear the affected Customer Content from active records and media, including prompt text, references and Outputs, and address derivatives, controlled caches and applicable downstream copies, not merely remove content from the interface. Minimal transaction records may be retained where necessary for accounting or legal obligations; an accounting record does not justify retaining prompt text, reference files or Outputs. Backups may remain until their documented expiry, with restricted access and measures to prevent deleted data from being returned to ordinary use after restoration. Astria will provide reasonable deletion-status information on request, including justified remaining categories and periods. Copies independently downloaded by recipients outside Astria's control cannot necessarily be recalled. If Astria creates source copies for separately permitted training, those copies must have a defined lawful purpose and retention rule and remain subject to applicable deletion rights and the Agreement. This conditional permission does not establish that a separate training dataset exists or that ordinary service use automatically creates one. It does not authorize collecting new copies from deleted account content or indefinite retention merely because training is possible. ## 8. International processing Astria uses United States-hosted primary application and database infrastructure. Processing locations for model providers, storage and content delivery are identified in the applicable provider information for the covered service. Customer Personal Data may therefore be processed outside Customer's country. Astria will comply with applicable transfer requirements, including required recipient undertakings and safeguards for onward transfers. Where applicable law requires additional transfer terms, such as EU standard contractual clauses or a UK transfer addendum, the applicable instrument, parties, roles and required annex information must be completed before the affected restricted transfer. This review form does not itself incorporate or complete those instruments and is not a representation that every international processing configuration is ready for use. ## 9. Relationship to the Agreement This DPA prevails over conflicting provisions of the Agreement concerning protection of Customer Personal Data, subject to mandatory transfer terms and other non-excludable law. It does not alter pricing, payment terms, minimum commitments or permitted product scope. Liability is governed by the applicable Agreement, subject to mandatory law; this DPA does not establish an additional or separate damages cap. Independent statutory rights of individuals and authorities remain unaffected. The Agreement's governing law, forum and notice provisions apply, subject to mandatory Data Protection Laws. Customer's authorized contractual or account contact will receive operational notices. This DPA continues for as long as Astria processes Customer Personal Data subject to it, including lawful retained copies. The version incorporated into the Agreement must be identified. A later webpage revision does not silently replace that agreed version. Changes follow the Agreement and applicable law, including the subprocessor process above. Merely reading this review page does not accept or activate a DPA. ## Schedule 1. Processing description | Item | Description | | --- | --- | | Subject matter | Processing Customer Personal Data through the services and accounts covered by the Agreement. | | Purpose | Execute Customer's prompts, instructions and references; generate, edit, store and deliver outputs; operate, support and secure the selected service. Separate-purpose training and administration are addressed in Section 3. | | Operations | Collection, receipt, storage, organization, inference, transformation, retrieval, transmission, authorized disclosure, return and deletion. | | Data categories | Personal Data in prompts, instructions, product references, image references, other submitted text/files/images/video/audio, generated outputs and associated service metadata. | | Individuals | Customer's authorized users and other individuals whose Personal Data is lawfully submitted, referenced or generated in the covered service. | | Frequency and duration | On submission or selected automated activity, and continuously where storage is instructed; for the service duration and applicable documented deletion/retention periods. | | Sensitive information | Any processing needing additional safeguards must be assessed and supported before use. A reference image is not automatically nonpersonal, and a face image is not automatically biometric identification. | | Systems and access | Covered accounts/workspaces, selected processing and storage infrastructure and authorized support/security systems. No general access to unrelated customer systems is granted. | ## Schedule 2. Security framework and service characteristics The following describes the framework proposed for the final DPA. Availability of this review version is not a certification that all operational details have been verified. | Area | Measures and relevant characteristics | | --- | --- | | Application access | Account authentication and workspace permissions control application access. Administrative functions use authentication and role-based authorization. | | Personnel | Access to Customer Content requires specific authorization and privileged permissions, with confidentiality obligations, appropriate authentication and timely removal when authorization ends. | | Media delivery | Some references and outputs are delivered through link-based URLs that do not require a separate application login. A person or provider holding such a URL may be able to retrieve the file. These URLs are not represented as signed or short-lived. Link-based delivery is distinct from publishing content in a public gallery. | | Transport and storage | The public website supports HTTPS; Cloudflare R2 provides encryption at rest for objects stored there. The applicable infrastructure, access controls and additional transport/storage protections must be documented for the covered service. | | Logging and maintenance | The application filters selected sensitive parameters and restricts selected provider payload logging to debug mode. Appropriate log access, retention, security updates and review processes apply to the covered service; these controls do not imply that every log is free of Personal Data. | | Deletion | Media removal uses asynchronous purge workflows with retries for selected transient storage errors. Completion includes the relevant records, derivatives, controlled caches and downstream copies under Section 7. | | Recovery | Database hosting includes Neon and Heroku. The proposed backup policy is weekly database backups retained for one year. Implementation, coverage and restore procedures must be confirmed before this DPA becomes effective. Provider-managed recovery is separate. This description does not promise a fixed recovery time or maximum data-loss interval. | | Incident management | Astria maintains a documented incident-response procedure covering escalation, containment, evidence preservation, impact assessment, customer communications, remediation and follow-up. Responsible personnel must maintain relevant records and provide the communications required under Section 6. | ## Contact For questions about this proposed DPA, contact [support@astria.ai](mailto:support@astria.ai). Use the agreed notice channels for any existing contract or executed DPA.