safepic

safepic Terms of Use

Effective date: 6 July 2026

This English version is provided for users who use safepic in English. The Polish version dated 6 July 2026 is the canonical source text. If there is a discrepancy, the Polish version prevails to the extent permitted by mandatory law and without limiting mandatory consumer rights.

1. General provisions

  1. The service operates under the name safepic and is available in particular at safepic.app and drive.safepic.app.
  2. The service provider is Supplier Patryk Sęk-Heljasiński, sole proprietor Patryk Sęk-Heljasiński, address: Czerwonka-Parcel 4, 96-500 Czerwonka-Parcel, Poland, Polish tax ID (NIP): 8371868079, REGON: 385776653.
  3. The Service Provider can be contacted at contact@safepic.app and by telephone at +48 508 444 076.
  4. These Terms govern the use of safepic by Users and Recipients and constitute terms for electronically supplied services.
  5. The Service may be offered in countries supported by Stripe Managed Payments, except countries excluded by the Service Provider, Stripe/Link, or applicable law.
  6. In relation to a Consumer, these Terms do not limit mandatory rights available in the country of the Consumer's habitual residence.

2. Definitions

For the purposes of these Terms:

  1. User means a person who has a safepic Account.
  2. Consumer means a natural person using the Service for purposes not directly related to that person's business or professional activity.
  3. Entrepreneur with consumer rights means a natural person entering into an agreement related to business activity where the agreement is not professional in nature for that person, to the extent consumer protection laws grant that person consumer protection.
  4. Business User means a User other than a Consumer or Entrepreneur with consumer rights who uses the Service in connection with business or professional activity.
  5. Content Provider means a User who is a photographer, graphic designer, photography studio, or graphic studio and supplies owned or properly licensed Content for protected streaming access by designated Recipients.
  6. Account means an individual User account in the Service.
  7. Album means a set of Photos together with related data, derivative materials, and features.
  8. Photo means an image file uploaded by a User, including a photograph, graphic, illustration, or visual design saved in a supported format.
  9. Derivative Materials means a video, thumbnail, cover image, or other technical material created from Photos to provide the Service.
  10. Content means Photos, Derivative Materials, Album names, comments, and other information supplied through the Service.
  11. Share Link means a link enabling access to an Album, optionally protected by a password and expiry date.
  12. Recipient means an adult person using a Share Link without needing an Account.
  13. Protected Playback / DRM means encryption and stream access control mechanisms such as Google Widevine and Microsoft PlayReady and, after launch in a compatible Apple web environment, Apple FairPlay Streaming, applied depending on device and software compatibility.
  14. Technology Provider means an entity such as Mux to which the Service Provider entrusts, to the necessary extent, storage or processing of Content, transcoding, encryption, distribution, or technical operation of DRM licenses.
  15. Digital Service / Service means the safepic features described in these Terms.
  16. Paid Plan means any paid Service variant whose features, limits, price, term, and renewal rules are presented before purchase.
  17. Subscription means a Paid Plan billed periodically and automatically renewed until cancelled.
  18. Link/Stripe means the entity operating Stripe Managed Payments and acting as merchant of record for purchases of Paid Plans.
  19. Prohibited Content means Content that violates the law or the rules in section 7.
  20. Terms means these safepic Terms of Use together with the attachments.
  21. Content Upload means a Content Provider-initiated transfer to the Service of specific files identified in the record of a given upload.

3. Contract formation and acceptance of the Terms

  1. Authentication by Google OAuth or one-time code may create a technical Account record before a contract is concluded.
  2. Before access to Account features is granted, the User receives the current Terms in a manner that allows the User to obtain, save, and reproduce them free of charge, including as immutable HTML and PDF documents identified by version number.
  3. The contract is concluded and the Account is activated when the authenticated User selects a checkbox that is unchecked by default and chooses the button used to submit the acceptance statement. Acceptance also covers the statements in section 7 and the framework license terms in section 8.
  4. The Service Provider records the Account identifier, version and hash of the accepted document, acceptance date, and language to the extent necessary to prove contract formation and license grant.
  5. Each later Content Upload is a separate act by which the Content Provider makes the statements in section 7 and grants a license to the specific uploaded Content under section 8. Acceptance of the Terms alone does not grant a license to files that have never been uploaded to the Service.
  6. The Service Provider records, against the upload record, the acceptance identifier, license grant date, and metadata allowing identification of the files covered by the license.
  7. After successful upload finalization, the acceptance identifier and license grant date are copied to the Album record.
  8. Purchase of a Paid Plan takes place through Stripe Managed Payments. The moment of conclusion of the paid contract, transaction parties, and purchase confirmation correspond to the information presented in the payment process and to the Link/Stripe terms.
  9. Provisions addressed to a Recipient are made available before the Recipient uses interactive features such as comments or likes.
  10. Merely receiving a Share Link does not mean that the Recipient makes any statement beyond the rules necessary for lawful access to Content.

4. Scope of the Service and plans

  1. The Service is intended for Content Providers - photographers, graphic designers, photography studios, and graphic studios - and enables them to provide protected streaming access to Content, for which they hold the required rights or licenses, to designated adult Recipients.
  2. The Service Provider provides Recipients with a streaming service for Albums. For this purpose it enables creating Albums, storing Photos, technically transforming them into Derivative Materials, including video materials, and protected streaming access through Share Links.
  3. Video material is encoded, encrypted, and delivered as an HLS stream protected by Protected Playback mechanisms (DRM). The Service Provider defines access rules, verifies the Link and password, issues time-limited playback authorizations, and supports Users and Recipients.
  4. Safepic uses Content as the direct licensee of the Content Provider under section 8. The license does not transfer ownership of Content and does not allow safepic to use Content beyond the scope necessary to provide the Service.
  5. Mux acts as a Technology Provider, including as distribution partner and DRM license server operator. This does not make Mux a party to the contract between the Service Provider and the User or Recipient.
  6. A Share Link may be protected by a password and expiry date.
  7. The Service allows Recipients to add likes and comments.
  8. Account, Album management, and purchase of Paid Plans are available in the web application.
  9. Free access includes the Account, settings, and demo features or other features indicated in the Service.
  10. The scope of features requiring a Paid Plan follows the current offer presented before purchase.
  11. Expiry of a Paid Plan may limit the features indicated in its offer. It does not automatically delete existing Content; the Content remains available to the extent indicated to the User until deletion or termination of the contract.

5. Technical requirements and specific risks

  1. Use of the Service requires an internet connection, up-to-date software, and a device meeting requirements presented in the Service.
  2. Playback of protected Albums requires a compatible device, operating system, web browser, and availability of required Protected Playback components.
  3. After the relevant feature is launched in a compatible Apple web browser environment, Apple FairPlay Streaming may be used.
  4. The Service may refuse playback if the technical environment does not meet requirements or threatens Content protection.
  5. Accepted Photo formats are JPG, JPEG, PNG, WEBP, and AVIF.
  6. Protection against screenshots, recording, and downloading is a risk-reducing measure and does not guarantee complete protection. It may be bypassed by methods outside the Service Provider's control, for example by photographing the screen with another device.
  7. Any use of the Apple FairPlay Streaming technology or name does not mean that Apple sponsors, approves, or certifies safepic or the effectiveness of Content protection. The Apple FairPlay Streaming name and technology are used only to describe the playback protection mechanism and in accordance with Apple rules and guidelines. Apple and FairPlay are trademarks of Apple Inc., registered in the United States and other countries. HLS (HTTP Live Streaming) is technology of Apple Inc.
  8. Specific risks connected with the Service include takeover of access credentials, malware, sharing a Link or password with an unauthorized person, and loss of Content.
  9. The User should protect the Account and keep their own copies of important files.

6. Registration and Account

  1. Login is performed through Google OAuth or a one-time code sent by email.
  2. One Account is intended for one person.
  3. The User is responsible for protecting Account access and promptly reporting any suspected Account takeover.
  4. The Service is intended only for persons aged 18 or older. This applies to both Account owners and Recipients.
  5. The User must hold the rights, consents, and legal bases necessary to process and make available data of all persons depicted in Photos.

7. Permitted use and Prohibited Content

  1. The Content Provider may upload only Content for which the Content Provider has rights, licenses, consents, and legal bases necessary to use the Service and grant the licenses and permissions in section 8.
  2. At the moment of each Content Upload, the Content Provider represents, in relation to exactly those files, that the Content Provider owns the relevant rights or has obtained a license covering at least digital fixation and reproduction, technical modifications, creation and use of Derivative Materials, encryption, protected streaming, public or non-public making available to designated Recipients, and granting the necessary sublicenses to Technology Providers.
  3. The Content Provider also represents that it has permissions or consents required to make technical changes, exercise derivative rights within the scope in section 8, and present Content without author attribution if such use is needed for operation of the selected Service feature.
  4. For photographs, graphics, illustrations, and visual designs, the representation also covers rights to all elements used, in particular fonts, stock materials, trademarks, likenesses, and other components or designations to the extent necessary to use the Service.
  5. The representations are assigned to an upload record containing metadata of the specific files. Upon a justified request connected with an infringement allegation or rights verification, the Content Provider provides information or documents confirming possession of rights.
  6. It is prohibited to upload or make available Content:
  7. It is prohibited to circumvent security, access restrictions, and Service limits, to obtain or use DRM keys, tokens, or licenses without authorization, to disrupt the Service, or to perform unauthorized vulnerability testing.
  8. Measures applied in the event of violation should be proportionate and may include access restriction, Content removal, Account suspension, or contract termination.
  9. The Service Provider may act without prior warning in the event of obvious unlawfulness, security threat, CSAM, an obligation resulting from a public authority decision, or the need to prevent serious harm.
  10. Lack of a fee refund does not occur automatically and does not limit statutory Consumer rights or Link/Stripe refund rights.

8. Rights to Content and license

  1. The Content Provider retains rights to uploaded Photos and other own Content. The license does not limit the Content Provider's right to use the works or license them to others.
  2. At the moment of each Content Upload, the Content Provider grants directly to the Service Provider - Supplier Patryk Sęk-Heljasiński - a license separate for each specific item of Content, non-exclusive, royalty-free, worldwide, and limited to the purpose of providing, securing, and terminating the Service. The Content Provider is not entitled to separate remuneration for this license.
  3. The license covers the following fields of exploitation and uses, only to the extent necessary for the Service:
  4. To the extent technical transformations or Derivative Materials constitute adaptations of a work, the Content Provider authorizes the Service Provider to exercise and to authorize Technology Providers to exercise derivative copyrights solely to create and use such materials in the Service. This permission does not cover independent artistic adaptations or use outside the Service.
  5. The Content Provider authorizes the Service Provider to grant Mux, its legal successors, subcontractors, and other replacing Technology Providers limited sublicenses in the fields and scope specified in paragraphs 2-4, solely to store, process, transcode, package, encrypt, distribute Content, and technically operate the DRM server and licenses.
  6. The sublicense does not authorize a Technology Provider to use Content for its own advertising purposes, model training, or any other independent purposes unrelated to providing the Service.
  7. The license does not transfer ownership of Content or moral rights to the Service Provider and does not authorize the Service Provider to use Content for safepic advertising, model training, or other purposes unrelated to the Service without a separate legal basis and, if required, the Content Provider's consent.
  8. The license expires after Content is deleted and the technical deletion cycle is completed, no later than 30 days from the start of the relevant deletion period, except to the extent required by law or needed to defend claims. Backups are deleted in the same ordinary cycle and, until deletion, are not used for other purposes.
  9. A Recipient grants an analogous limited license to comments and other Content that the Recipient supplies through the Service.
  10. Rights to safepic software, interface, and brand belong to the Service Provider or its licensors.

9. Moderation and reporting illegal Content

  1. Contact point for Recipients and Users concerning infringement reports: contact@safepic.app.
  2. Contact point for Member State authorities, the European Commission, and the European Board for Digital Services: dsa-authorities@safepic.app.
  3. Supported communication languages are Polish and English.
  4. A report should include a justification of unlawfulness, exact location of the Content, contact details of the reporting person, and a statement of good-faith action.
  5. A report of intellectual property infringement should additionally identify the protected work or designation, the basis of the reporter's entitlement, and the scope of alleged infringement. The Service Provider may ask the User to provide proof of rights referred to in section 7.
  6. Providing first name, last name, and email address is not required when reporting information concerning sexual offences against minors covered by applicable provisions.
  7. The Service Provider confirms receipt of a report and informs the reporting person of the decision taken, if it has the person's electronic contact details.
  8. A User whose Content has been restricted receives a statement of reasons and information about available options to challenge the decision, unless law or safety prohibits providing such information.
  9. Moderation is performed manually. If automated tools are introduced, the moderation policy description will be updated before their use.
  10. The Service Provider applies obligations under the Digital Services Act (DSA) appropriate to the nature of the Service and the Service Provider's status.

10. Rules for Recipients

  1. A Recipient may use an Album only within the scope intended by the User.
  2. Without consent of the rights holder, it is prohibited to copy, record, download, distribute Content, circumvent technical safeguards, or obtain or use keys, tokens, and playback licenses outside the Service.
  3. The Recipient is responsible for confidentiality of the received Link and password and should not use in the Service a password used in other services.
  4. The User may not knowingly provide a Link to a person under 18.
  5. Recipient comments are subject to sections 7-9.

11. Limits and fair use

  1. The Service is subject to limits on storage, monthly upload transfer, downloads, Photo size, and invitations sent.
  2. Current limits are presented in the Service or on the Plan page before purchase.
  3. After a limit is exceeded, the relevant feature may be temporarily restricted.
  4. Material changes to limits for an active Subscription require the rules in section 18 and may not violate statutory Consumer rights.

12. Stripe Managed Payments, prices, and Paid Plans

  1. Paid Plans are purchased through Stripe Managed Payments.
  2. Link/Stripe acts as merchant of record for transactions and, within the supported scope, is responsible for payment collection, indirect taxes, transaction documents, transaction support, payment disputes, and part of refund decisions.
  3. The Service Provider is responsible for delivery and product support of safepic.
  4. Price, currency, taxes, billing period, and accepted payment methods are presented before the order is placed in the Link/Stripe process.
  5. The Service Provider does not store full payment card data.
  6. If the selected Paid Plan is a Subscription, it renews automatically until cancelled.
  7. Cancellation of a Subscription preserves access until the end of the paid period unless laws or a Link/Stripe decision provide otherwise.
  8. A voluntary pro-rata refund for an unused part of a started period is not guaranteed. This does not limit withdrawal rights, rights for non-conformity of the Service, or rights granted by Link/Stripe.
  9. The User is informed in advance of a change to the price of a renewable Subscription. The new price applies from the next period and the User may cancel the Plan earlier.

13. Consumer withdrawal right

  1. A Consumer may withdraw from a distance contract within 14 days of its conclusion without giving a reason, subject to statutory exceptions.
  2. Starting provision of the Service before that period expires requires the Consumer's express request.
  3. If the Consumer subsequently withdraws from the contract, the Consumer may be required to pay an amount proportionate to the performance provided until withdrawal.
  4. In relation to a paid service, the withdrawal right expires after full performance only if requirements concerning prior consent, information, and acknowledgement of that information have been met.
  5. Merely starting a monthly Subscription does not automatically cause loss of the withdrawal right.
  6. The withdrawal statement may be submitted according to Link/Stripe instructions or sent to contact@safepic.app.
  7. The Service Provider and Link/Stripe cooperate on correct settlement of withdrawal according to the applicable division of responsibilities.
  8. Business Users do not have a withdrawal right, except for protection granted to Entrepreneurs with consumer rights.

Attachment No. 1 - withdrawal form template

Addressee: Supplier Patryk Sęk-Heljasiński, Czerwonka-Parcel 4, 96-500 Czerwonka-Parcel, Poland, contact@safepic.app

I/We hereby give notice that I/we withdraw from the contract concerning the Paid Plan.

Contract conclusion date: [...]

Full name: [...]

Account email address: [...]

Consumer address: [...]

Date: [...]

Signature - only if this form is submitted on paper: [...]

14. Conformity of the Digital Service with the contract

  1. The Service Provider supplies the Service without undue delay after conclusion of the relevant contract and is liable to a Consumer for conformity with the contract during the period of supply.
  2. The Service should correspond to the description, functionality, compatibility, availability, continuity, and security that a Consumer may reasonably expect considering the Terms, technical requirements, and public assurances.
  3. The Service Provider supplies updates, including security updates, necessary to preserve conformity of the Service.
  4. In the event of lack of conformity, the Consumer may request that the Service be brought into conformity and, in cases provided by law, price reduction or withdrawal from the contract.
  5. After withdrawal or termination of the contract, the Service Provider makes available, upon request, Content created or supplied by the Consumer where required by law, within a reasonable time and in a commonly used format.
  6. Provisions on availability, backups, and liability do not limit Consumer rights under mandatory law.

15. Liability and availability

  1. The Service Provider may perform technical works and does not guarantee availability free from every interruption, but this does not limit statutory liability toward Consumers.
  2. The User should keep their own copies of important Photos. The Service is not a dedicated archiving or backup system.
  3. The Service Provider does not guarantee full effectiveness of anti-copying safeguards.
  4. Toward Business Users, to the extent permitted by law, liability for lost profits and indirect damages is excluded.
  5. B2B liability limitations do not apply to damage for which liability cannot be excluded or to intentional breach of duties by the Service Provider.
  6. The User's obligation to cover justified third-party claims applies to culpable breach of law or the Terms and does not limit Consumer rights.

16. Contract termination, deletion, and 30-day retention

  1. The User may terminate the contract and request Account deletion by contacting support at contact@safepic.app.
  2. The Service Provider may verify the identity of the person making the request.
  3. The User may delete individual Albums using the feature available in the web interface.
  4. Data is normally stored for the duration of the active Account or Album. The deletion period starts, respectively, after an effective Account deletion request or after Album deletion.
  5. The Account, Albums, Photos, Derivative Materials, Share Links, invited persons' addresses, comments, and likes are deleted or anonymized no later than 30 days from the start of the relevant deletion period.
  6. The period includes deletion from active systems and the ordinary backup cycle, to the extent under the Service Provider's control.
  7. Only data required by law, necessary for settlements, or necessary to defend claims may be stored longer. Evidence of acceptance of the Terms and license grants is stored for 6 years from contract termination or Account deletion solely to establish, pursue, or defend claims.
  8. Stripe/Link may store transaction data as an independent controller under its own documents.
  9. The Service Provider may terminate the contract due to a material or repeated breach of the Terms, while respecting proportionality, statement-of-reasons requirements, and Consumer rights.

17. Complaints and out-of-court dispute resolution

  1. Complaints, including those concerning conformity of the Digital Service, may be sent to contact@safepic.app.
  2. A complaint should identify the Account, problem, circumstances, and the User's request.
  3. A response to a Consumer complaint will be provided within 14 days, unless mandatory law provides a more favorable deadline.
  4. Complaints concerning only payment, transaction document, or payment dispute may be handled by Link/Stripe under its terms.
  5. A Consumer may use competent ADR bodies, consumer ombudsmen, and consumer protection authorities.
  6. The Service Provider does not undertake to participate in voluntary proceedings before any specific out-of-court dispute resolution body unless such obligation results from mandatory law. A Consumer may use ADR bodies and authorities competent under applicable provisions.

18. Changes to the Service, limits, and price

  1. The Service Provider may change the Service where justified by a change in law, security, technology, providers, abuse prevention, or feature development.
  2. A change may not cause additional costs in the ongoing billing period.
  3. A change that materially and negatively affects a Consumer's access to or use of the Service must be notified sufficiently in advance on a durable medium, stating the nature of the change, date, and available remedies.
  4. A Consumer may terminate the contract without notice in cases and within deadlines specified by law, in particular where a materially adverse change does not allow maintaining the Service unchanged without additional cost.
  5. Discontinuation of the entire Service requires appropriate advance notice and settlement of the unused period in accordance with law and Link/Stripe rules.

19. Changes to the Terms

  1. The Terms may be changed for legal or security reasons, changes to the Service, providers, payments, or the need to remove ambiguities.
  2. Changes material to an ongoing contract require prior notice by email or on another durable medium and indication of the effective date.
  3. If a change materially worsens the User's situation, the User may terminate the contract before it takes effect, subject to special Consumer rights.
  4. A change to the license scope in section 8 or rights representations in section 7 requires express renewed acceptance of the new Terms version before further use of Account features.
  5. Technical, linguistic, or editorial changes that do not change User rights and obligations or the license scope do not require renewed acceptance, unless law provides otherwise.

20. Personal data

  1. Rules for personal data processing are set out in the safepic Privacy Policy.
  2. In B2B relationships, where the User determines the purposes and means of processing personal data in Albums, the Service Provider acts as processor.
  3. Data processing terms are set out in Attachment No. 2, which forms an integral part of the Terms.
  4. Attachment No. 2 applies automatically to a Business User who uses the Service to process personal data as a controller and is accepted electronically together with the Terms.
  5. Attachment No. 2 does not apply to a User using the Service solely privately.

21. Governing law and final provisions

  1. Polish law governs, without depriving a Consumer of protection granted by mandatory provisions of the country of the Consumer's habitual residence.
  2. Disputes with Business Users are resolved by the court competent for the Service Provider's registered address, except where mandatory provisions provide otherwise.
  3. For Consumers, jurisdiction follows applicable provisions.
  4. Notices are sent to the Account email address or provided in the web interface. If law requires a durable medium, the notice must allow saving and reproduction.
  5. The Service Provider may assign the contract in connection with reorganization or transfer of the enterprise, without limiting User rights and after required notice.
  6. Invalidity of one provision does not affect the remaining provisions.

Attachment No. 2 - data processing terms for B2B customers

1. Scope and term of the Attachment

  1. This Attachment constitutes a data processing agreement within the meaning of Article 28 GDPR and is an integral part of the Terms.
  2. This Attachment binds the Business User who uses the Service to process personal data as controller and the Service Provider.
  3. Electronic acceptance of the Terms also means acceptance of this Attachment.
  4. This Attachment does not apply to processing where the Service Provider acts as an independent controller or to a User using the Service solely privately.

2. Roles of the parties

  1. The Business User is the controller of personal data entrusted in Albums and determines the purposes and means of processing.
  2. The Service Provider is the processor of that data under documented instructions of the Business User.
  3. The Service Provider remains an independent controller of Account, billing, security, abuse prevention, analytics, and own legal-obligation data, as described in the Privacy Policy.

3. Subject matter and duration of processing

  1. The subject matter of processing is hosting, organization, technical transformation, protection, and making available data contained in Albums and performing other Service features selected by the Business User.
  2. Processing lasts for the period during which the Business User uses the Service and until completion of data deletion in accordance with the Business User's instruction, the Terms, and law.
  3. After Album deletion or an effective Account deletion request, entrusted data is deleted or anonymized no later than within 30 days, subject to any further storage obligation resulting from law.

4. Nature and purpose of processing

  1. Processing may include collection, fixation, organization, storage, retrieval, consultation, technical transformation, disclosure, restriction, erasure, and anonymization of data.
  2. The purpose of processing is:

5. Types of personal data

  1. Entrusted data may include:
  2. Data may reveal special categories of personal data. The Business User may entrust such data only if it has an appropriate legal basis and has implemented safeguards required by Article 9 GDPR.

6. Categories of data subjects

  1. Entrusted data may relate to:

7. Documented instructions

  1. The Business User's instructions are actions performed by the Business User using Service features, Account and Album settings, and additional lawful instructions agreed with the Service Provider in documentary form.
  2. An instruction concerning data transfer outside the EEA must comply with section 12 of this Attachment.
  3. If, in the Service Provider's opinion, an instruction infringes GDPR or other data protection laws, the Service Provider promptly informs the Business User and may suspend performance until the instruction is changed or lawfulness is confirmed.
  4. The Service Provider may process data without an instruction if required by Union or Member State law. The Service Provider informs the Business User of that obligation before processing starts unless law prohibits providing that information.

8. Service Provider obligations

  1. The Service Provider:

9. Business User obligations

  1. The Business User:

10. Sub-processors

  1. The Business User grants general authorization for the Service Provider to use Cloudflare, PlanetScale, Mux, PostHog, and other technical providers indicated in the current Privacy Policy as further processors, to the extent they process entrusted data.
  2. The Service Provider imposes on a sub-processor, by contract, data protection obligations no less strict than those in this Attachment.
  3. The Service Provider remains responsible for performance of sub-processor obligations to the extent required by GDPR.
  4. The Service Provider informs the Business User by email at least 14 days in advance of planned addition or replacement of a sub-processor.
  5. The period in paragraph 4 does not apply where an urgent change is necessary for security or legal reasons; then information is provided without undue delay.
  6. The Business User may object on justified data protection grounds within 7 days of receiving the information.
  7. The parties will make a reasonable attempt to resolve the objection. If this is not possible, the Business User may stop using the feature requiring the sub-processor or terminate the contract before processing by that sub-processor starts.

11. Information and audits

  1. In the first instance, the Service Provider may demonstrate compliance using current certificates, independent-auditor reports, descriptions of security measures, and responses to a justified Business User questionnaire.
  2. If this information is insufficient, the Business User may conduct an audit no more often than once every 12 months, after at least 30 days' notice, during business hours and without access to other customers' data.
  3. Frequency and notice limits do not apply where an audit is required by an authority, there has been a breach concerning the Business User's data, or there is a justified suspicion of material non-compliance.
  4. The Business User bears justified audit costs unless the audit shows a material breach of this Attachment by the Service Provider.

12. International transfers and location

  1. The Service Provider may transfer data outside the EEA only on documented instructions of the Business User or where a valid transfer mechanism is ensured, such as an adequacy decision, EU-US Data Privacy Framework, or standard contractual clauses together with required supplementary measures.
  2. The production PlanetScale PostgreSQL database operates in AWS region eu-central-1 in Frankfurt. No replicas are created outside that region without prior document update, transfer assessment, and application of appropriate safeguards.
  3. Other sub-processors may use infrastructure or support outside the EEA according to mechanisms described in the Privacy Policy and agreements concluded with them.

13. End of processing

  1. Before completion of deletion, the Business User may download data using available features or request return in an available, commonly used format, if return is technically possible and does not infringe rights of others.
  2. After the end of supply, the Service Provider deletes or anonymizes entrusted data within 30 days, including in controlled backups, unless law requires further storage.
  3. After deletion is completed, the Service Provider confirms deletion upon a justified request of the Business User.

14. Priority and liability

  1. In the event of conflict, this Attachment prevails over the Terms only with respect to processing of entrusted data.
  2. In payment, contract termination, and liability matters, the Terms apply unless this Attachment or mandatory law provides otherwise.
  3. This Attachment remains in force for the period during which the Service Provider processes entrusted data, including after termination of the main contract to the extent obligations by their nature survive.

Attachment No. 3 - acceptance statement text

For version 2026-07-06, the User makes the following statement by selecting a checkbox that is unchecked by default and choosing the “Accept and continue” button:

I accept the Terms of Use version 2026-07-06, including section 7 (rights statements) and section 8, under which, upon uploading Content, I grant the Service Provider a non-exclusive, royalty-free license necessary to provide and secure the Service. I confirm that I am authorized to grant it.