Last updated: 24 September 2026
This Data Processing Addendum ("DPA") is made between Fortis Ventures Ltd ("we", "us" or "Verbier") and the customer that has accepted our Terms of Service at /terms (the "Terms") and uses the API for business purposes ("Customer"). It forms part of the Terms. It applies automatically when Customer accepts the Terms, and no signature is needed.
1. Definitions and interpretation
1.1 In this DPA:
- "API", "Customer Content", "Output" and "Service" have the meanings given in the Terms.
- "Customer Personal Data" means personal data contained in Customer Content (including images, image URLs, background images and background image URLs sent to the API) or in Output, which we process on Customer's behalf in providing the API.
- "Data Protection Law" means the UK GDPR and the Data Protection Act 2018. Where the EU GDPR applies to the processing of Customer Personal Data, it also means the EU GDPR and the laws of EU member states that supplement it.
- "UK GDPR" means the General Data Protection Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland under section 3 of the European Union (Withdrawal) Act 2018, as amended.
- "EU GDPR" means the General Data Protection Regulation (EU) 2016/679.
- "EU SCCs" means the standard contractual clauses for the transfer of personal data to third countries annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- "UK Addendum" means the International Data Transfer Addendum to the EU SCCs, version B1.0, issued by the Information Commissioner under section 119A(1) of the Data Protection Act 2018, as revised under its Section 18.
- "IDTA" means the International Data Transfer Agreement issued by the Information Commissioner under section 119A(1) of the Data Protection Act 2018.
- "Transfer Clauses" means the EU SCCs and the UK Addendum, to the extent incorporated under clause 8.
- "Restricted Transfer" means a transfer of Customer Personal Data that would be prohibited by Data Protection Law without an adequacy decision or regulations, or an appropriate safeguard.
- "Sub-processor" means a third party we engage to process Customer Personal Data.
- "Supervisory Authority" means the Information Commissioner's Office ("ICO") and, where the EU GDPR applies, the competent supervisory authority under it.
1.2 "Controller", "processor", "data subject", "personal data", "personal data breach", "processing" and "special categories of personal data" have the meanings given in Data Protection Law.
1.3 The Annexes form part of this DPA. "Including" means "including without limitation".
2. Scope and roles
2.1 This DPA applies to our processing of Customer Personal Data in providing the API. Annex 1 describes that processing.
2.2 Customer is the controller of Customer Personal Data, and we are its processor. If Customer is itself acting as a processor for a third-party controller, we are Customer's sub-processor, and Customer warrants that its instructions and the authorisations it gives in this DPA (including for Sub-processors) are authorised by that controller.
2.3 This DPA does not cover personal data we process as a controller, for example account, sign-in, billing, usage and log data about Customer and its users, or data from the homepage demo. Our Privacy Policy at /privacy covers that processing.
2.4 Customer is responsible for:
(a) having a lawful basis, and where relevant a condition under Article 9 or 10 of the UK GDPR, for the processing it instructs;
(b) giving data subjects any information Data Protection Law requires;
(c) having the right to send us the Customer Content, and to have us fetch images from the URLs it gives us;
(d) assessing whether its use of the API and of Output is lawful, including any use it makes of Output to identify people; and
(e) complying with our Acceptable Use Policy at /acceptable-use.
3. Processing on documented instructions
3.1 We will process Customer Personal Data only on Customer's documented instructions, including with regard to Restricted Transfers. The exception is where UK law (or, where the EU GDPR applies, EU or member state law) to which we are subject requires otherwise. In that case, we will inform Customer of that legal requirement before processing, unless that law prohibits this on important grounds of public interest.
3.2 Customer's documented instructions are:
(a) each API request, including the Customer Content in it and the options Customer selects (the API request is the instruction to process that Customer Content and return the Output);
(b) the Terms and this DPA; and
(c) any other written instructions that the parties agree.
3.3 We will immediately inform Customer if, in our opinion, an instruction infringes Data Protection Law.
3.4 We will not:
(a) process Customer Personal Data for our own purposes;
(b) use Customer Content or Output to train or improve any model;
(c) sell Customer Personal Data; or
(d) combine it with other data.
4. Confidentiality
4.1 We will ensure that everyone we authorise to process Customer Personal Data is bound by an appropriate duty of confidentiality, whether contractual or statutory.
5. Security
5.1 We will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data, as required by Article 32 of the UK GDPR, including the measures in Annex 2.
5.2 We may update those measures, provided that the update does not materially reduce the overall level of protection.
6. Sub-processors
6.1 General authorisation. Customer gives us general written authorisation to engage Sub-processors. The Sub-processors engaged at the date of this DPA are listed in Annex 3, and Customer approves them.
6.2 Sub-processor terms. Before a Sub-processor processes Customer Personal Data, we will put in place a written contract with it that imposes data protection obligations which, in substance, are no less protective of Customer Personal Data than those in this DPA, so far as they are relevant to the service the Sub-processor provides. In particular, the contract will give sufficient guarantees of appropriate technical and organisational measures.
6.3 Our liability. We remain liable to Customer for the performance of each Sub-processor's obligations, subject to clause 14.
6.4 Notice of changes. We will tell Customer about any intended addition or replacement of a Sub-processor at least 30 days before it starts processing Customer Personal Data. We will do this by email to the address on Customer's account and by updating the list at /dpa. If a change is urgently needed to protect the security or continuity of the Service, we may give shorter notice, and we will explain why.
6.5 Objection. Customer may object to a new Sub-processor on reasonable data protection grounds by emailing hello@verbier.dev within the notice period. The parties will then discuss the objection in good faith. If it is not resolved within 30 days, Customer may terminate the Terms and close its account. We will refund any fees Customer has paid for the unused part of the billing period in which it terminates. This refund is an exception to the general rule in the Terms that fees for part-periods are not refunded.
7. Assistance
7.1 Data subject requests. Taking into account the nature of the processing, we will assist Customer by appropriate technical and organisational measures, so far as possible, to respond to requests from data subjects to exercise their rights. Because we do not keep Customer Content or Output after processing (clause 12), we will usually hold no Customer Personal Data to which a request could relate. If we receive a request directly that we can identify as relating to Customer, we will not respond ourselves, except to direct the data subject to Customer, and we will tell Customer promptly.
7.2 Other obligations. Taking into account the nature of the processing and the information available to us, we will give Customer reasonable assistance to meet its obligations under Articles 32 to 36 of the UK GDPR, namely:
(a) security;
(b) notifying personal data breaches;
(c) data protection impact assessments; and
(d) prior consultation with a Supervisory Authority.
We will also provide reasonable information to help Customer assess the Restricted Transfers made under this DPA.
7.3 Costs. Our assistance consists mainly of the documentation in this DPA and its Annexes. We may charge reasonable costs for assistance that goes beyond that documentation, unless the assistance is needed because we have breached this DPA.
7.4 Records and Supervisory Authorities. We will keep the records required by Article 30(2) of the UK GDPR, and we will cooperate with Supervisory Authorities as Data Protection Law requires.
7.5 Requests from public authorities. If a public authority asks us to disclose Customer Personal Data, we will tell Customer before disclosing it, unless the law prohibits this. We will disclose only what the law requires.
8. International transfers
8.1 Where processing happens. We are established in the United Kingdom. Our Sub-processors process Customer Personal Data in the United States and, while it is in transit, in other countries where Vercel operates its network (Annex 3).
8.2 Our transfers to Sub-processors. We will make a Restricted Transfer of Customer Personal Data to a Sub-processor only where a valid transfer mechanism under Data Protection Law applies. The mechanism for each current Sub-processor is listed in Annex 3.
8.3 Transfers between Customer and us.
(a) Where Customer is in the UK, sending Customer Personal Data to us is not a Restricted Transfer.
(b) Where Customer is in the European Economic Area, transfers to us are covered by the European Commission's adequacy decision for the United Kingdom under the EU GDPR.
(c) To the extent that any transfer of Customer Personal Data from Customer to us is nevertheless a Restricted Transfer, including if that adequacy decision ceases to apply, the Transfer Clauses in clauses 8.4 and 8.5 are incorporated into this DPA by reference. Customer is the data exporter and we are the data importer.
8.4 EU SCCs. Where the EU GDPR applies to the transfer:
(a) Module 2 (controller to processor) applies where Customer is a controller, and Module 3 (processor to processor) applies where Customer is a processor;
(b) the optional docking clause in Clause 7 does not apply;
(c) in Clause 9, Option 2 (general written authorisation) applies, and the time period for notice of changes is that in clause 6.4 of this DPA;
(d) the optional wording in Clause 11 does not apply;
(e) in Clause 13, the competent supervisory authority is the one determined under Clause 13(a) of the EU SCCs, according to Customer's circumstances;
(f) in Clause 17, Option 1 applies, and the governing law is Irish law;
(g) in Clause 18(b), the courts are the courts of Ireland; and
(h) Annexes I, II and III of the EU SCCs are completed with Annexes 1, 2 and 3 of this DPA respectively.
8.5 UK Addendum. Where the UK GDPR applies to the transfer, the EU SCCs are incorporated as amended by the UK Addendum, and:
(a) in Table 1, the parties are Customer (exporter) and us (importer), with the details in Annex 1;
(b) in Table 2, the selected modules and clauses are as set out in clause 8.4;
(c) in Table 3, the Appendix Information is in Annexes 1 to 3 of this DPA; and
(d) in Table 4, neither party may end the UK Addendum under its Section 19.
8.6 Changes to mechanisms. If a transfer mechanism relied on under this clause 8 or in Annex 3 ceases to be valid, the parties will cooperate in good faith to put in place a valid alternative, such as the IDTA. Customer agrees that we may rely on the alternative mechanisms in our Sub-processors' terms.
9. Personal data breaches
9.1 We will notify Customer of a personal data breach affecting Customer Personal Data without undue delay, and in any event within 48 hours of becoming aware of it. We will notify by email to the address on Customer's account.
9.2 The notice will include, as far as the information is then available:
(a) the nature of the breach, including the categories and approximate number of data subjects and records concerned;
(b) its likely consequences;
(c) the measures we have taken or propose to take to address it and mitigate its effects; and
(d) a contact point for more information.
Where we cannot provide all this information at once, we will provide it in phases without undue further delay.
9.3 We will take reasonable steps to contain and investigate the breach, and we will cooperate with Customer. Customer is responsible for any notification to Supervisory Authorities or data subjects that is required of it as controller. A notice under this clause is not an admission of fault or liability.
10. Audits and information
10.1 We will make available to Customer all information necessary to demonstrate our compliance with Article 28 of the UK GDPR and this DPA. We will do this primarily through documentation, including this DPA and its Annexes, written answers to Customer's reasonable security and privacy questions, and the list and terms of our Sub-processors.
10.2 Where that information is not reasonably sufficient to demonstrate compliance, or where a Supervisory Authority requires it, we will allow for and contribute to audits, including inspections, by Customer or an independent auditor it appoints, subject to the following conditions:
(a) Customer gives at least 30 days' written notice;
(b) there is no more than one audit in any 12-month period, unless a personal data breach affecting Customer Personal Data has occurred or a Supervisory Authority requires it;
(c) the audit takes place during business hours, with reasonable duration and scope, and without disrupting our business or other customers;
(d) the auditor is bound by confidentiality and is not our competitor; and
(e) Customer bears its own costs and our reasonable costs of the audit.
10.3 Our Sub-processors' audit reports, such as SOC 2 reports, are confidential to them. Where their terms allow, we will share them, or summaries of them, on request.
11. Duration
11.1 This DPA applies for as long as we process Customer Personal Data under the Terms.
12. Deletion and return
12.1 We process Customer Personal Data only for the duration of each API request. We return the Output in the response to that request, and we do not keep the Customer Content or the Output afterwards. Nothing remains for us to delete or return when the Terms end. The Output delivered in each API response is the return of the data. Our Sub-processor Modal's platform deletes the data passed through it within 7 days at most (Annex 2, paragraph 2).
12.2 On request, we will confirm in writing that we hold no Customer Personal Data.
13. Customer obligations
13.1 Customer will comply with Data Protection Law in its use of the API.
13.2 Customer is responsible for keeping its API keys secret and for all use made with them, as the Terms provide.
14. Liability
14.1 Each party's liability arising out of or in connection with this DPA (including under the Transfer Clauses, to the extent the Transfer Clauses permit) is subject to the limitations and exclusions of liability in clause 16 of the Terms. It counts towards the same aggregate cap.
14.2 Nothing in this DPA limits:
(a) any liability that cannot be limited or excluded by law; or
(b) the rights of data subjects under the Transfer Clauses or Data Protection Law.
15. Order of precedence
15.1 If there is a conflict:
(a) the Transfer Clauses prevail over this DPA; and
(b) this DPA prevails over the Terms, in relation to the processing of Customer Personal Data.
Clause 14 applies despite this clause.
16. Changes
16.1 We may update this DPA to reflect changes in Data Protection Law, in guidance from Supervisory Authorities, or in the Service. We will publish the updated version at /dpa. If a change materially reduces Customer's protection, we will give at least 30 days' notice by email, unless the law requires the change sooner. Changes to Sub-processors follow clause 6.
17. Governing law and jurisdiction
17.1 This DPA and any dispute arising from it are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction. The exception is where the Transfer Clauses provide otherwise.
18. Contact
18.1 Notices and questions about this DPA: hello@verbier.dev. Fortis Ventures Ltd, C/O Aardvark Accounting, 1 Cedar Office Park, Cobham Road, Wimborne, BH21 7SB, United Kingdom.
Annex 1: Details of processing
Parties
- Controller (data exporter): Customer, as identified in its account. Contact: the email address on the account. Role: controller, or processor on behalf of a third-party controller (clause 2.2).
- Processor (data importer): Fortis Ventures Ltd, company number 14849535, C/O Aardvark Accounting, 1 Cedar Office Park, Cobham Road, Wimborne, BH21 7SB, United Kingdom. Contact: hello@verbier.dev. Role: processor, or sub-processor.
Subject matter. Providing the API: removing the background from images and the optional processing Customer selects, namely:
- adding shadows;
- cleaning up specks;
- 2x upscaling;
- trimming;
- placing the subject on a colour or on a background image; and
- colour matching, where a machine-learning model adjusts the subject's colours to the background.
Duration.
- Each API request is processed only for as long as the request lasts, which is about 2 minutes at most. Modal's platform then keeps the data for up to 7 days (Annex 2, paragraph 2).
- This DPA lasts for the term of the Terms.
Nature of the processing. The processing is automated. It consists of:
(a) receiving images sent as base64 data, or fetching them from URLs Customer provides;
(b) fetching background images from URLs Customer provides;
(c) transmitting the data through Vercel's network to GPU servers run by Modal;
(d) processing the images in memory with machine-learning models;
(e) returning the Output in the API response; and
(f) erasing the data.
Requests may contain one image (POST /v1/cutout) or up to 32 images (POST /v1/batch). Images may be up to 20 MB and 64 megapixels.
Purpose. Solely to produce and return the Output that Customer requests. There is no other purpose, and Customer Personal Data is not used for model training.
Types of personal data.
- Images of people, which may include their faces, and any other personal data visible in images, such as a person's appearance or text shown in the image.
- Metadata embedded in image files (for example, EXIF data, which can include location, date and device information).
- Personal data contained in the image URLs or background image URLs that Customer provides.
Special categories of personal data. None intended.
- We do not process images to uniquely identify anyone, so the processing does not involve biometric data within the meaning of Article 9 of the UK GDPR.
- We do not analyse images to infer information about the people in them, such as racial or ethnic origin, religious beliefs or health.
- Customer must assess its own use of the Customer Content and the Output. That includes whether any use it makes of them involves special category data, or data about children, and whether it has a lawful basis and condition for that use.
Categories of data subjects. Individuals who appear in, or can be identified from, the images and URLs Customer sends. For example: Customer's own customers, employees, models or contractors, and members of the public.
Frequency. Continuous, as and when Customer sends API requests.
Retention. None after the request is completed, except as described in Annex 2, paragraph 2.
Transfers to Sub-processors. As set out in Annex 3, for the duration of each request.
Competent supervisory authority. The ICO. For transfers under the EU SCCs, the authority determined under clause 8.4(e).
Annex 2: Technical and organisational measures
1. Encryption in transit. All traffic to and from the API (https://api.verbier.dev) is encrypted with TLS. Modal states that all user data is encrypted in transit and at rest, and that its public APIs use TLS 1.3.
2. No storage of Customer Content or Output.
- Customer Content is processed in memory. We do not write Customer Content or Output to any database, file store or log of our own.
- Output is returned in the API response and not kept.
- Caching of API responses on Vercel's network is switched off.
- Modal's platform stores the inputs and outputs of processing calls, encrypted at rest, and deletes them within a maximum of 7 days. Neither we nor Modal use them for any other purpose.
3. Logging limits.
- For each API request we log only: the account identifier, the route called, the number of images, the processing time and a label for the processing mode.
- We do not log image content, image URLs or Output.
- Request logs contain no Customer Personal Data.
4. Access control.
- API requests are authenticated with secret API keys. Customer creates and revokes keys in its dashboard, and keys are checked on every request.
- Our own credentials for our providers are kept in our hosting provider's secrets store, not in source code.
- Access to production systems and to our providers' administration consoles is limited to authorised personnel who need it. Those accounts are protected by strong authentication.
5. Account security.
- Passwords must be at least 15 characters.
- Email addresses are verified with a code.
- Sessions use short-lived signed tokens, managed by Clerk.
6. No training. Customer Content and Output are not used to train or improve any model.
7. Input and resource limits.
- Images are limited to 20 MB and 64 megapixels.
- Requests must complete within about 2 minutes.
- Usage is limited by plan.
8. Sub-processor selection. We engage Sub-processors that give sufficient guarantees under written data processing terms. Vercel and Modal have each completed SOC 2 Type 2 audits.
9. Personnel. Everyone authorised to process Customer Personal Data is bound by confidentiality (clause 4).
10. Incident response. Personal data breaches are handled and notified in line with clause 9.
11. Review. We review these measures at least once a year and whenever we make a significant change to the Service.
Annex 3: Sub-processors
Part A: Sub-processors of Customer Personal Data
| Sub-processor | Service | Customer Personal Data | Location | UK transfer mechanism | EU transfer mechanism (where the EU GDPR applies) |
|---|---|---|---|---|---|
| Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA | Network and hosting: requests to api.verbier.dev are routed through Vercel's network to Modal | Customer Content and Output, in transit only | United States, and other countries where Vercel operates its network | UK Extension to the EU-US Data Privacy Framework (Vercel's certification, including the UK Extension, was active on the Data Privacy Framework List on 24 September 2026). Vercel's DPA also incorporates the UK Addendum | EU-US Data Privacy Framework. Vercel's DPA also incorporates the EU SCCs |
| Modal Labs, Inc. (a Delaware corporation), United States | Runs the API and the machine-learning models on GPU servers | Customer Content and Output, processed in memory and held by Modal's platform as described in Annex 2, paragraph 2 | United States | UK Addendum to the EU SCCs, incorporated in Modal's DPA | EU SCCs (Modules 1 to 3 as applicable), incorporated in Modal's DPA |
Part B: Providers that are not Sub-processors under this DPA
The following providers never receive Customer Content or Output. They process only personal data for which we are the controller, as described in our Privacy Policy at /privacy.
- Clerk, Inc. (United States): accounts, sign-in, sessions, API keys and billing records. When the API checks an API key, it sends Clerk the key and account identifiers, but no Customer Content.
- Stripe (Stripe Payments Europe, Limited; Stripe Payments UK, Ltd.; Stripe, LLC): card payments.
- OpenAI OpCo, LLC (United States): moderation of photos uploaded to the homepage demo only. Images sent through the API are not sent to OpenAI.
- jsDelivr (Volentio JSD Limited) and Scalar (API Documentation Inc.): serve files for the documentation page at /docs.
If any of these providers begins to process Customer Personal Data, we will treat that as a new Sub-processor under clause 6.