Data Processing Addendum
Last updated 2026-09-30.
1. Scope and how this applies
This Data Processing Addendum ("DPA") is part of the Terms of Service between GUINEA PIG SOFTWARE DEVELOPMENT INC., a corporation incorporated in Ontario, Canada ("ogmake", "we", "us") and the customer who holds the ogmake account ("you"). It applies automatically when you use ogmake and the GDPR, the UK GDPR, or PIPEDA applies to personal data in your content. No signature is needed. If any conflict arises between this DPA and the Terms of Service on the handling of personal data, this DPA prevails.
2. Roles
- Customer content: you are the controller, we are the processor. This is the content you send us to render: titles, text, images and logos, HTML, and URLs. We process it only to provide the rendering service.
- Account and billing data: we are the controller. This is your sign-in email, plan, API key records, usage counts and subscription status. It is governed by our Privacy Policy, not by this DPA. Paddle is the Merchant of Record and handles payment details on its own terms.
3. Details of processing
- Subject matter and purpose: generating, caching and serving the images you request through the generator, editor, API and public URLs, and storing assets you upload (brand logo, template images).
- Duration: for as long as your account is active, plus the deletion periods in section 8.
- Data subjects: individuals whose personal data you include in content you send us (for example names in a title or a person's picture).
- Categories of personal data: whatever you choose to include in titles, text, images, HTML or URLs. You should not send special-category data.
4. Our obligations as processor
We will:
- process customer content only on your documented instructions, which are the Terms, this DPA and your use of the service, unless the law requires otherwise (in which case we tell you first, where the law allows);
- ensure the people who can access customer content are bound by confidentiality;
- apply the security measures in section 6;
- respect the sub-processor conditions in section 5;
- help you respond to requests from data subjects and meet your obligations under GDPR Articles 32 to 36, taking into account the nature of the processing;
- delete customer content as set out in section 8;
- make available the information needed to show compliance with Article 28 and allow audits as set out in section 9.
We will tell you if we believe an instruction of yours breaches data protection law. If a data subject contacts us directly about your content, we will forward the request to you rather than answer it.
5. Sub-processors
You give us general authorisation to use the sub-processors on our Sub-processors page. We will email account owners at least 30 days before adding or replacing one. You may object in writing to support@ogmake.com within that period; if we cannot reasonably accommodate the objection, you may cancel your plan and we will delete your data under section 8. We bind each sub-processor to data protection terms no less protective than this DPA and remain responsible for their performance.
6. Security measures
- Encryption in transit: traffic to ogmake and to our infrastructure providers uses HTTPS/TLS.
- API keys are stored only as a hash (with a server-side secret), never in plain text; signing secrets are stored in encrypted form.
- Access control: every stored object and database record is scoped to an account; API access requires a key or a signed session, and rate limits apply.
- Minimal logging: render parameters (titles, text and the like) are not logged, and IP addresses are used only as a rate-limit key and are not stored.
- Limited retention: see section 8. Nightly backups of core account data are kept for 35 days on a rolling basis.
We do not currently hold a third-party security certification (such as SOC 2 or ISO 27001) and do not claim one. Our hosting provider publishes its own certifications on its website.
7. Personal data breaches
We will notify you by email without undue delay after becoming aware of a personal data breach affecting customer content, with the information we have to help you meet your own notification duties.
8. Return and deletion
- Free-plan renders stored in our storage are deleted automatically after 30 days. The anonymous free generator does not store images; they are only cached at the edge for up to 7 days.
- Paid-plan renders, your brand logo and template image uploads are kept while your account is active. You can remove a logo yourself at any time.
- On your written request (email support@ogmake.com) or when your account ends, we delete customer content and account data, and we aim to do so within 30 days. Copies in nightly backups expire within 35 days after that.
- We may keep data that the law requires us to keep, for example accounting records, and will keep it protected and unused for any other purpose.
9. Audits and information
On reasonable written request we will provide the information needed to show that we meet this DPA, including our answers to a reasonable security questionnaire. Where that does not satisfy a supervisory authority's requirement or a mandatory legal right to audit, we will cooperate with an audit on reasonable notice, once a year, during business hours, at your cost and under confidentiality.
10. International transfers
ogmake is operated from Canada and runs on Cloudflare's global network, so customer content may be processed outside your country, including the United States. Where GDPR or UK GDPR restricts such a transfer, it relies on the transfer mechanism (such as Standard Contractual Clauses, or an adequacy decision) that the relevant sub-processor commits to in its own data processing terms, linked on the Sub-processors page. Canada has an EU adequacy decision for commercial organisations subject to PIPEDA. If Standard Contractual Clauses are needed between you and us, write to support@ogmake.com and we will sign the applicable module with you.
11. General
This DPA is governed by the same law as the Terms of Service (Ontario, Canada), except where a mandatory data protection law or the Standard Contractual Clauses require otherwise. Questions or requests: support@ogmake.com.