Legal
Data Processing Addendum
Last updated: September 23, 2026
The terms on which NOLGIA processes personal data on behalf of business customers. Each section starts with a short summary where it helps; the full text is what counts.
1. About this Addendum
In short: When NOLGIA processes personal data for a business customer, this Addendum sets the rules. It is part of your agreement with us.
2. Definitions
- Data Protection Laws: the laws on personal data that apply to the processing, including the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act.
- Customer Personal Data: personal data in the content you and your users submit to the Service or create with it (Inputs and Outputs), and in your organization's workspace, that we process on your behalf.
- Subprocessor: a third party we engage that processes Customer Personal Data.
- Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- Controller, processor, data subject, processing and supervisory authority have the meanings given in the GDPR. Under US state laws, "processor" includes "service provider".
3. Roles and instructions
In short: You decide what happens to your data. We process it only to provide the Service and on your instructions.
4. Confidentiality
5. Security
In short: We protect your data with the technical and organizational measures in Annex 2.
6. Subprocessors
In short: You authorize us to use subprocessors. We tell you before adding one and you can object.
7. Helping you meet your obligations
8. Personal data breaches
In short: If a breach affects your data, we tell you without undue delay and help you respond.
9. Deletion or return at the end
In short: When the Service ends, you can export your content first, and then we delete it.
10. Information and audits
11. International transfers
In short: We store data in the United States. For transfers out of the EU, UK or Switzerland, the Standard Contractual Clauses apply.
- EU: the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914 are incorporated into this Addendum, using Module Two (controller to processor) and, where you are a processor, Module Three (processor to processor). Clause 7 does not apply; under Clause 9, Option 2 applies with the notice period in the Subprocessors section of this Addendum; the optional wording in Clause 11 does not apply; under Clause 13, the supervisory authority is the one competent for you; under Clauses 17 and 18, the law and courts of Ireland apply. Annexes 1 to 3 of this Addendum complete the Annexes of the Clauses.
- UK: the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner applies, with the details above completing its tables, and either party may end it as its Part 2 allows.
- Switzerland: the Standard Contractual Clauses apply with the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority, and references to the GDPR read as references to the Swiss Federal Act on Data Protection.
12. Liability and general terms
13. Annex 1: Details of the processing
| Item | Details |
|---|---|
| Parties | Data exporter: you, the customer, contactable through your account. Data importer and processor: Nolgia Inc., 8549 Wilshire Blvd, Suite 1180, Beverly Hills, CA 90211, United States, contact@nolgia.ai. |
| Subject matter and duration | Providing the Service under the Agreement, for its term and until deletion as described in this Addendum. |
| Nature and purpose | Hosting and storing content; generating images, video, audio and other Outputs, including sending Inputs to the model providers you choose; running NOLGIA Agent for your users; sharing content at your direction; support; and security. |
| Data subjects | Your authorized users; people whose images, voices or other personal data appear in content submitted to or created with the Service; and people mentioned in agent chats. |
| Personal data | Users' names, email addresses, roles and activity within your organization's workspace; any personal data in prompts, uploads, reference photos, voice clips, chats and Outputs. |
| Special categories | You decide what content is submitted. The face identity check processes face templates only for reference photos a user has agreed to have checked, as described in our Privacy Policy. Do not submit other special category data unless it is necessary. |
| Frequency | Continuous, while the Service is in use. |
14. Annex 2: Security measures
- Encryption of data in transit and at rest.
- Content kept in private storage and shown to users only through short-lived access links.
- Separation of each customer's data within the Service, with access checked on every request.
- Access to production systems limited to authorized staff who need it, with access to customer chats recorded.
- Passwords and access tokens stored only in hashed form, and credentials for customer-connected storage encrypted.
- Databases reachable only on a private network.
- Regular backups with limited retention, and the ability to restore service.
- Software and dependencies kept up to date, with changes reviewed and tested before release.
- An incident response process for investigating and containing security events and notifying customers.
- Due diligence on Subprocessors and written data protection terms with them.
- For the face identity check: processing only with consent, on our own systems, with face templates never stored.
15. Annex 3: Subprocessors
16. Contact
Change history
- September 23, 2026: First published.

