Skip to content
Stylaform

Legal

Data Processing Agreement

The processor terms that apply where Stylaform processes personal data on behalf of a business customer.

Version
1.0
Effective
18 August 2026
Last updated
18 August 2026

This Data Processing Agreement (the "DPA") forms part of the Terms of Service between the Customer and Turtle Works B.V., trading as Stylaform.

This DPA applies only to Customer Personal Data that Stylaform processes as processor on behalf of the Customer. It does not apply to personal data for which Stylaform is itself the controller, such as account administration, billing, security and fraud prevention; that processing is described in the Privacy Policy.

1. Subject matter, nature, purpose and duration

Subject matter: the provision of the Stylaform service as described in the Terms, including brand management, asset storage, website analysis and sweeping, Brand Drift monitoring, AI Features and exports.

Nature and purpose: collection, storage, structuring, rendering, analysis, generation, retrieval, transmission, backup, erasure and other operations necessary to provide the Service on the Customer's instructions.

Duration: for as long as the Customer uses the Service, plus the retention periods set out in clause 10.

2. Types of personal data and categories of data subjects

Types of personal data: names, email addresses, roles and workspace membership; identifiers and metadata contained in uploaded assets; personal data incidentally present in brand content, notes, AI Input, AI Output and in publicly accessible pages of a Submitted Site; usage and audit records relating to a User's actions in the Workspace.

Categories of data subjects: the Customer's personnel and contractors who use the Workspace, individuals whose personal data the Customer places in Customer Content, and individuals whose personal data appears on a Submitted Site the Customer has authority to submit.

The Customer must not place special categories of personal data or criminal-offence data in the Service. Stylaform is not designed for such data.

3. Processing on documented instructions

Stylaform processes Customer Personal Data only on the Customer's documented instructions. The Terms, this DPA and the Customer's use of the functionality of the Service, including which sites it submits and which AI Features it runs, constitute those instructions.

Stylaform may process Customer Personal Data where required by Union or Member State law, in which case it informs the Customer beforehand unless that law prohibits it. Stylaform informs the Customer if, in its opinion, an instruction infringes data protection law.

4. Confidentiality

Stylaform ensures that persons authorised to process Customer Personal Data are bound by confidentiality obligations and receive access only to the extent necessary for their role.

5. Security of processing

Stylaform implements appropriate technical and organisational measures under Article 32 GDPR, taking into account the state of the art, costs, and the nature, scope, context and purposes of processing. These include:

  • tenant isolation enforced at database level, so records are reachable only within the Workspace they belong to;
  • server-side authorisation on every request, with role and brand scoping;
  • encryption of data in transit, and encryption at rest as provided by our hosting and storage providers;
  • private object storage for uploaded assets, served through short-lived signed links;
  • authentication protections including brute-force limits and rate limiting on sensitive endpoints;
  • audit logging of sensitive actions such as role changes, version locks, domain claims and deletions;
  • least-privilege access for personnel, and separation of production from development environments;
  • encrypted backups with a defined rotation.

Stylaform does not currently hold an ISO 27001 or SOC 2 certification and has not completed an independent penetration test. Measures may change over time provided the level of protection is not reduced.

6. Subprocessors

The Customer gives general authorisation for Stylaform to engage Subprocessors. The current Subprocessors are listed on the Subprocessor List page, which forms part of this DPA.

Stylaform imposes data protection obligations on each Subprocessor that are no less protective than this DPA, and remains fully liable to the Customer for their performance.

Stylaform announces the addition or replacement of a Subprocessor at least 30 days in advance by updating the Subprocessor List and, where the change is material, by email. The Customer may object on reasonable data protection grounds within that period by writing to stylaform@turtleworks.nl. If the parties cannot find a workable solution, the Customer may terminate the affected part of the Service without penalty, with a pro rata refund of prepaid fees for the unused period.

7. International transfers

Where Customer Personal Data is transferred outside the European Economic Area, Stylaform relies on an adequacy decision where one applies, including the EU-US Data Privacy Framework for certified providers, and otherwise on the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Three where Stylaform acts as processor engaging a sub-processor, and Module Two where the Customer is the controller.

The Standard Contractual Clauses are hereby incorporated into this DPA by reference. For their purposes: the Customer is the data exporter, Stylaform is the data importer, the Annexes are filled in by the description of processing in clauses 1 and 2, the security measures in clause 5, and the Subprocessor List; the optional docking clause applies; the governing law is Dutch law and the courts are those of the Netherlands. Where the Clauses conflict with this DPA, the Clauses prevail.

8. Assistance to the Customer

Taking into account the nature of the processing, Stylaform assists the Customer with appropriate technical and organisational measures in fulfilling requests from data subjects exercising their rights. The Service itself provides much of this: the Customer can access, correct, export and delete content within its Workspace.

If Stylaform receives a request from a data subject relating to Customer Personal Data, it does not respond on the merits and refers the individual to the Customer, informing the Customer without undue delay.

Stylaform assists the Customer with its obligations under Articles 32 to 36 GDPR, including security of processing, breach notification, data protection impact assessments and prior consultation, to the extent the required information is available to Stylaform.

9. Personal data breaches

Stylaform notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event within 48 hours, providing the information available at the time: the nature of the breach, the categories and approximate volume of data and data subjects concerned, the likely consequences, the measures taken or proposed, and a contact point. Further information is supplied in phases as the investigation progresses.

Notification is not an acknowledgement of fault. The Customer is responsible for notifying its supervisory authority and data subjects where required.

10. Return and deletion of data

The Customer can export its brand information at any time during the term using the export functionality available on its plan.

On deletion of a Workspace or on termination of the Terms, Customer Personal Data is placed in a soft-deleted state for 30 days in a soft-deleted state and then erased from live systems. Encrypted backups containing residual copies are overwritten within 30 days on a rolling basis. Data that Stylaform must keep by law, such as invoices, is retained for the statutory period and remains protected by this DPA until erased.

11. Audit information

Stylaform makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, including this DPA, the Subprocessor List, the description of security measures and answers to reasonable written questions.

Where that information is not sufficient, the Customer may request an audit no more than once per year, on 30 days' written notice, during business hours, subject to confidentiality, limited to the systems used to process its Customer Personal Data, and without disrupting the Service or accessing other customers' data. The Customer bears the costs, unless the audit reveals a material breach by Stylaform.

12. AI processing boundaries

Where the Customer uses AI Features, Customer Personal Data contained in AI Input is transmitted to the AI provider listed on the Subprocessor List, which acts as Subprocessor and processes it only to return the response.

Stylaform does not use Customer Personal Data to train general-purpose AI models and contracts with its AI providers on a no-training basis for content submitted through the Service. AI request logs are retained for 90 days for support, abuse prevention, billing and troubleshooting.

AI Features are advisory and do not carry out automated decision-making with legal or similarly significant effects on data subjects.

13. Customer responsibilities

The Customer warrants that it has a lawful basis for the personal data it places in the Service, that it has provided any required information to data subjects, that it manages roles and access within its Workspace, that it does not upload special categories of data, and that it has the right or legitimate authority to submit each Submitted Site for analysis and monitoring.

14. Liability, term and general

Liability under this DPA is subject to the limitations and exclusions in the Terms, except where mandatory law provides otherwise, in particular Article 82 GDPR.

This DPA takes effect when the Customer accepts the Terms and continues for as long as Stylaform processes Customer Personal Data. In case of conflict, this DPA prevails over the Terms for the processing of Customer Personal Data.

Contact for all matters under this DPA: stylaform@turtleworks.nl.

Version history

  • v1.0 - 18 August 2026 - First published version.