Data processing addendum

Version 1.0Effective 30 August 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between CobaltAI OÜ, registry code 17561613, Männimäe/1, Pudisoo küla, Kuusalu vald, Harju maakond 74626, Estonia ("Processor", "we") and the customer ("Controller", "you").

It applies where, in your use of the Service, we process personal data for which you determine the purposes and means. It reflects Article 28 of Regulation (EU) 2016/679 ("GDPR"). In case of conflict with the Terms of Service, this DPA prevails for the processing it covers.


1. Subject Matter and Details of Processing

Subject matter: provision of the cobalt12 listing generation service. Duration: the term of your account, plus the retention periods in the Privacy Policy. Nature and purpose: hosting, storage, transmission, and automated generation of product listing content; transmission of content to a marketplace at your instruction; support.

Categories of data subjects: your personnel and authorised users; individuals depicted in images you upload; individuals identifiable in product or marketplace data you submit.

Categories of personal data: identification and contact data of your users; content data you upload that contains personal data; marketplace account identifiers and business data. Special category data must not be submitted.


2. Roles

2.1 You are the Controller and we are the Processor for the processing covered by this DPA.

2.2 For our own account administration, billing, security, and service improvement, we act as an independent Controller as described in our Privacy Policy.


3. Our Obligations

We will:

3.1 process personal data only on your documented instructions, including as to international transfers, unless required by EU or Member State law, in which case we will inform you unless that law prohibits it on important grounds of public interest. Your use of the Service constitutes your instructions;

3.2 promptly inform you if, in our opinion, an instruction infringes the GDPR or other data protection law;

3.3 ensure that persons authorised to process the data are bound by confidentiality;

3.4 implement the technical and organisational measures set out in Annex A;

3.5 respect the conditions in Sections 4 and 5 for engaging sub-processors;

3.6 assist you, insofar as possible and taking into account the nature of the processing, in responding to requests from data subjects exercising their rights;

3.7 assist you in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of processing and the information available to us;

3.8 at your choice, delete or return all personal data at the end of the provision of services, and delete existing copies unless retention is required by law. Deletion follows the retention schedule in the Privacy Policy, including limited persistence in encrypted backups;

3.9 make available all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits under Section 7.


4. Sub-processors

4.1 You give general written authorisation for us to engage sub-processors. Current sub-processors — including cloud hosting, storage and database services, AI model providers, payment processing, email delivery, and support mailbox hosting — are listed at cobalt12.com/subprocessors.

4.2 We will give at least 30 days' notice before adding or replacing a sub-processor, by updating that page and, where you have subscribed to notifications, by email. You may object on reasonable data protection grounds within that period; if we cannot accommodate the objection, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees.

4.3 We impose on each sub-processor data protection obligations no less protective than those in this DPA and remain fully liable to you for their performance.


5. International Transfers

5.1 We may transfer personal data outside the EEA only where an adequacy decision applies, or under the European Commission's Standard Contractual Clauses (Decision 2021/914), or another lawful transfer mechanism.

5.2 Where the Standard Contractual Clauses apply, Module Two (controller to processor) is incorporated by reference: you are the data exporter, we are the data importer; the optional docking clause applies; the governing law and forum are Estonia; Annexes I, II, and III are populated by the details in this DPA, Annex A, and the sub-processor list.

5.3 We carry out transfer risk assessments and apply supplementary measures including encryption in transit and at rest.


6. Personal Data Breach

6.1 We will notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting personal data processed on your behalf.

6.2 The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, measures taken or proposed, and a contact point. Information may be provided in phases as it becomes available.

6.3 We will cooperate with you and take reasonable steps to mitigate and remediate.


7. Audit

7.1 We will make available information necessary to demonstrate compliance with this DPA, including current third-party certifications or reports where we hold them.

7.2 Where that information is insufficient, you may conduct an audit no more than once per twelve months (or following a personal data breach affecting your data), on at least 30 days' written notice, during business hours, without unreasonable disruption, subject to confidentiality, and at your cost.


8. Data Subject Requests

If we receive a request from a data subject relating to personal data processed on your behalf, we will not respond directly except to confirm that the request should be directed to you, and we will forward it to you without undue delay and assist you as set out in Section 3.6.


9. Liability

Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where those limitations are not permitted by applicable data protection law.


10. Term

This DPA takes effect when you accept the Terms of Service and continues until all processing on your behalf has ceased and data has been deleted or returned.


Annex A — Technical and Organisational Measures

Access control — role-based access on the principle of least privilege; unique accounts; multi-factor authentication for administrative access; prompt revocation on role change or departure.

Encryption — TLS 1.2 or higher in transit; encryption at rest for stored content and backups; secrets and API tokens stored in a managed secrets service.

Segregation — logical separation of customer data; separated production, staging, and development environments; no production personal data in non-production environments.

Resilience — managed cloud infrastructure with redundancy; regular automated encrypted backups; documented restoration procedures and periodic restore testing.

Monitoring and logging — access and application logging; error and anomaly monitoring; log retention as stated in the Privacy Policy.

Secure development — code review; dependency vulnerability scanning and timely patching; change management.

Vendor management — due diligence before engaging sub-processors; written data protection terms with each.

Personnel — confidentiality undertakings; data protection and security awareness.

Incident response — documented procedure for detection, escalation, containment, notification, and post-incident review.

Deletion — documented retention schedule; deletion from active systems within 30 days of a deletion request; backup expiry within 90 days.


Signature (on request). To receive a countersigned copy, email [email protected] with your company name, registered address, and signatory details.