Effective date: 1st July 2026
This Data Processing Addendum (the “DPA”) forms part of the Terms of Service between Customer and AbstractGroup. It applies whenever an AbstractGroup operating subsidiary processes Personal Data on Customer’s behalf in the course of providing a Service. References to the “Agreement” in this DPA have the meaning given in the Applicable Terminology section of the Terms of Service. The cap-bridging scope of the Agreement, including the multi-claim non-stacking and per-entity isolation rules, is set out in the Liability section of the Terms of Service.
For each Service used by Customer, the operating subsidiary for that Service (as identified on the Service’s website, imprint, or in the relevant order documentation) is the Processor under this DPA. Where Customer uses multiple Services operated by different subsidiaries, this DPA applies separately as between Customer and each operating subsidiary, and each operating subsidiary’s obligations and liability under this DPA are several and not joint.
If there is any conflict between this DPA and the Agreement, this DPA controls for matters covered by it.
The terminology used in this DPA follows the definitions in our Terms of Service. In addition:
“Customer Personal Data” means Personal Data that AbstractGroup processes on Customer’s behalf in the course of providing the Services, including Personal Data contained in Customer Content and Personal Data otherwise transmitted by Customer through the Services for processing under Customer’s instructions. Where the same Personal Data is also processed by AbstractGroup as a controller for its own purposes (such as authentication of an organization’s User by the Identity Service), the controller-side processing is governed by the Privacy Policy and is not Customer Personal Data for purposes of this DPA.
“Data Protection Law” means the GDPR, and other data protection and privacy laws applicable to the processing of Customer Personal Data.
“Controller”, “Processor”, “Processing”, “Personal Data”, and “Data Subject” have the meanings given to them in Data Protection Law.
“Restricted Transfer” means a transfer of Customer Personal Data from the EEA to a country that is not subject to an adequacy decision.
“SCCs” means the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021.
“Sub-Processor” means a third party engaged by AbstractGroup to process Customer Personal Data.
References in this DPA to “AbstractGroup” performing or being subject to obligations, actions, rights, or liability in respect of a particular Service mean the operating subsidiary that is the Processor for that Service. Where Customer uses multiple Services, references to “AbstractGroup” apply separately and severally to each operating subsidiary in respect of its own Service. Collective references to “AbstractGroup” apply only where context clearly requires the collective meaning, including without limitation references to AbstractGroup’s group-wide subprocessor list, AbstractGroup’s industry-standard frameworks, AbstractGroup’s group-wide technical and organizational measures (Annex II), and AbstractGroup’s intra-group cooperation arrangements.
Customer is the Controller of Customer Personal Data, or where Customer is itself processing on behalf of a third party, the Processor for that third party. AbstractGroup is the Processor (or, where Customer is a Processor, the Sub-Processor) for Customer Personal Data.
Where Customer is a Processor on behalf of a third-party Controller, Customer warrants that its instructions to AbstractGroup are consistent with the instructions Customer has received from that Controller, and that Customer has the authority to enter into this DPA. Customer further warrants that Customer Personal Data has been and continues to be collected, transferred to AbstractGroup, and otherwise made available for processing under this DPA in compliance with Data Protection Law, including all required notices to Data Subjects, all required lawful bases, and all required consents. Customer’s failure to comply with this warranty does not relieve Customer of any obligation under the Agreement, is a breach of these Terms within the meaning of the Indemnification section of the Terms of Service, and entitles AbstractGroup to suspend or terminate processing of the affected Customer Personal Data without liability.
This DPA takes effect when Customer accepts the Agreement, and continues for as long as AbstractGroup processes Customer Personal Data, or until earlier termination of the Agreement followed by deletion of Customer Personal Data in accordance with this DPA.
AbstractGroup will process Customer Personal Data only:
The Agreement, this DPA, the documentation we publish for the Services, and Customer’s use of the Services together constitute Customer’s documented instructions to AbstractGroup.
If AbstractGroup considers that an instruction infringes Data Protection Law, AbstractGroup will inform Customer without undue delay (unless prohibited by law) and may suspend processing of the affected Customer Personal Data until Customer issues an instruction that AbstractGroup considers compliant.
AbstractGroup will ensure that anyone authorized to process Customer Personal Data is subject to a duty of confidentiality, whether by contract or by statutory obligation, and that the duty of confidentiality survives termination of the relevant authorization.
AbstractGroup will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data, taking into account the state of the art, the costs of implementation, the nature of the processing, and the risks to Data Subjects. The current measures are set out in Annex II.
AbstractGroup may update the technical and organizational measures from time to time, provided that the updated measures continue to comply with Art. 32 GDPR.
Customer provides general written authorization, for purposes of Art. 28(2) GDPR, for AbstractGroup to engage Sub-Processors to process Customer Personal Data. The current list of Sub-Processors, including the function each performs and the country of processing, is available at abstract3d.com/subprocessors. Customer is responsible for monitoring the subprocessor page for changes.
Before adding or replacing a Sub-Processor, AbstractGroup will provide notice at least fourteen (14) days before the change takes effect, through the subprocessor page or by email to Customer’s notified contact, in AbstractGroup’s discretion. Where the change is required to (a) maintain or restore the security or operation of the Services, (b) comply with a legal obligation, court order, or regulatory directive, or (c) replace a Sub-Processor that has ceased to be available, the change may take effect immediately, and AbstractGroup will provide notice as soon as reasonably practicable.
Except where a change may take effect immediately as set out above, AbstractGroup will not allow the new Sub-Processor to process Customer Personal Data before the end of the notice period. If Customer objects to a new Sub-Processor on reasonable data protection grounds within fourteen (14) days of notice, Customer’s sole remedy is to terminate the affected Subscription and receive a pro-rata refund of pre-paid fees for the unused portion of the term. Failure to object within this period constitutes acceptance of the new Sub-Processor.
AbstractGroup will impose on each Sub-Processor data protection obligations that are no less protective than those in this DPA. Each AbstractGroup operating subsidiary remains liable to Customer for the performance of its own Sub-Processors. No AbstractGroup entity is liable for the acts or omissions of Sub-Processors engaged by another AbstractGroup entity.
The Services are not designed for the processing of certain categories of Personal Data. Customer warrants that Customer Personal Data does not include, and that Customer will not upload or process through the Services:
If Customer requires processing of any of these categories, the parties must agree in writing on additional terms, including any necessary additional safeguards and pricing.
Upload or processing of Restricted Categories of Personal Data without prior written agreement is a breach of these Terms within the meaning of the Indemnification section of the Terms of Service, entitles AbstractGroup to suspend or terminate processing of the affected Customer Personal Data without liability, and obligates Customer to indemnify AbstractGroup for any regulatory action, fine, or third-party claim arising from such breach.
Customer will not use the Services to develop, train, deploy, or operate a “high-risk AI system” as defined in the EU AI Act (Regulation (EU) 2024/1689) without prior written agreement from AbstractGroup. Customer is solely responsible for the classification of its use of the Services under the EU AI Act, and for compliance with all obligations under the EU AI Act applicable to its use of the Services. AbstractGroup makes no representation as to the suitability of the Services for any particular use case under the EU AI Act.
Use of the Services for a high-risk AI system without prior written agreement is a breach of these Terms within the meaning of the Indemnification section of the Terms of Service and entitles AbstractGroup to suspend or terminate Customer’s access to the Services without liability.
AbstractGroup is not the appropriate point of contact for Data Subjects of Customer; Data Subjects should direct rights requests to Customer as Controller. Where a Data Subject contacts AbstractGroup directly with a request to exercise their rights under Data Protection Law, AbstractGroup may, where lawful, inform the Data Subject that the request should be directed to Customer, and AbstractGroup will notify Customer of the request without undue delay.
AbstractGroup will provide reasonable assistance to Customer, taking into account the nature of the processing and the information available to AbstractGroup, in responding to Data Subject requests through the self-service functionality of the Services. Where assistance beyond self-service is required, AbstractGroup may charge fees at AbstractGroup’s then-current standard rates as published or otherwise made available to Customer.
If AbstractGroup becomes aware of a Personal Data Breach affecting Customer Personal Data, AbstractGroup will notify Customer without undue delay. For purposes of this section, AbstractGroup “becomes aware” of a Personal Data Breach when AbstractGroup has reasonable certainty that a security incident has occurred resulting in a breach of security as defined in Art. 4(12) GDPR. Initial alerts, suspected anomalies, or under-investigation events that have not been confirmed as Personal Data Breaches do not, by themselves, trigger the notification obligation. The notification will include, to the extent known and to the extent required for Customer to meet its own notification obligations, a description of the breach, the categories and approximate number of Data Subjects and records concerned, the contact point at AbstractGroup for further information, the likely consequences, and the measures taken or proposed to address the breach.
Customer is responsible for assessing whether the breach triggers notification obligations to supervisory authorities or Data Subjects, and for providing those notifications. AbstractGroup’s notification of a Personal Data Breach to Customer under this section is not an admission of fault or liability by AbstractGroup, and the contents of the notification reflect the information available at the time of notification, which may be incomplete or subject to revision as the investigation progresses.
AbstractGroup may engage independent third-party auditors from time to time to assess its Services against industry-standard frameworks. On Customer’s reasonable request, and subject to confidentiality obligations no less protective than those in the Agreement, AbstractGroup may make summary audit reports available to Customer. Customer acknowledges that such reports are the primary mechanism for verifying AbstractGroup’s compliance with this DPA.
Where Data Protection Law gives Customer a right to audit AbstractGroup directly that is not satisfied by the foregoing, the parties will agree on the scope, timing, duration, and frequency of the audit in advance, no more than once in any twelve (12) month period (except where required by a supervisory authority or in connection with a substantiated Personal Data Breach affecting Customer Personal Data). Any such audit will be carried out:
The auditor’s findings are Confidential Information of AbstractGroup. Customer will provide AbstractGroup with a copy of all audit findings before disclosing them to any third party. Where Customer is required to disclose findings to a supervisory authority, Customer will, to the extent legally permitted, notify AbstractGroup of such disclosure without undue delay. Customer will not use the findings for any purpose other than verifying AbstractGroup’s compliance with this DPA.
Customer authorizes AbstractGroup and its Sub-Processors to transfer Customer Personal Data internationally as needed to provide the Services, including to the United States and other countries where Sub-Processors are located.
For Restricted Transfers, the parties agree as follows:
If a transfer mechanism becomes invalid, AbstractGroup may put in place an alternative mechanism that complies with Data Protection Law, and Customer authorizes such adoption. AbstractGroup will provide notice of the alternative mechanism through the subprocessor page or by email.
If AbstractGroup receives a legally binding request from a public authority for access to Customer Personal Data:
Where multiple legally binding requests bear on the same Customer or processing, AbstractGroup may aggregate the documentation.
On termination of the Agreement, Customer has thirty (30) days to retrieve Customer Content using the export functionality of the Services. AbstractGroup will thereafter delete Customer Personal Data from production systems within ninety (90) days, and from backup systems within one hundred eighty (180) days, except where law requires longer retention, where retention is necessary for security, fraud prevention, defense of claims, or compliance with legal process, or where deletion is not technically feasible without disproportionate effort. AbstractGroup may update these timelines from time to time on at least thirty (30) days’ notice through the subprocessor page or by email to Customer.
If Customer requests deletion of Customer Personal Data during the term of the Agreement, Customer can use the Services’ built-in deletion functionality. The same exceptions and deletion timelines apply.
Each party’s total aggregate liability arising out of or relating to this DPA is subject to, and counts toward, the per-entity aggregate liability cap and the carve-outs set out in the Liability section of the Terms of Service. The cap applies separately to each AbstractGroup operating subsidiary in respect of its own Service. Multiple claims under the Terms of Service, this DPA, the Privacy Policy, or the use of the Services do not increase the cap that applies to any AbstractGroup entity.
Neither party is liable to the other under this DPA for indirect, consequential, incidental, special, or exemplary damages, including loss of profits, loss of business, or loss of data, even if advised of the possibility of such damages. This exclusion does not apply to liability that cannot be limited or excluded under applicable mandatory law.
The carve-outs set out in the Liability section of the Terms of Service apply equally to claims under this DPA. Without limiting those carve-outs, nothing in this DPA limits:
Where AbstractGroup pays compensation to a Data Subject in respect of a matter for which Customer is also liable under Data Protection Law, AbstractGroup is entitled to claim back from Customer the share of compensation corresponding to Customer’s share of responsibility, in accordance with Art. 82(5) GDPR. The same applies in reverse.
Data Exporter (Controller): Customer, as identified by the account registration information.
Data Importer (Processor): The operating subsidiary for the Service used by Customer, as identified on the Service’s website, imprint, or in the relevant order documentation. Each operating subsidiary is a subsidiary of Abstract Group GmbH & Co. KG, Silberburgstraße 102, 70176 Stuttgart, Germany. Privacy contact: privacy@abstract3d.com.
Module One Controller-to-Controller Transfers (Intra-group): Where Customer Personal Data is transferred between AbstractGroup entities acting as separate controllers, the entities and their roles are described in the Recipients of Your Personal Data section of the Privacy Policy and in the intra-group cooperation agreement referenced therein. The Privacy contact for any such recipient is privacy@abstract3d.com.
SCC Module: Module Two (Controller to Processor), or Module Three (Processor to Processor) where Customer is itself a Processor.
Categories of Data Subjects: Customer’s employees, contractors, customers, end users, partners, suppliers, and other individuals whose Personal Data Customer chooses to upload to or process through the Services.
Categories of Customer Personal Data: Customer Personal Data as defined in this DPA, comprising Personal Data Customer chooses to include in Customer Content, and Personal Data otherwise transmitted by Customer through the Services for processing under Customer’s instructions, in each case except for the Restricted Categories listed in this DPA. May include names, identifiers, contact information, content metadata, communications, and (incidentally) likenesses of identifiable persons in 3D scans, materials, or media uploaded by Customer.
Special Categories of Personal Data: Excluded by this DPA, except where incidentally present (such as visible health-related features in a non-biometric scan).
Frequency of the Transfer: Continuous.
Nature of the Processing: Hosting, storage, processing, transformation, transmission, and deletion of Customer Content as part of providing the Services.
Purpose: Provision of the Services to Customer in accordance with the Agreement.
Duration: For the term of the Agreement, plus the deletion timeline in this DPA.
Sub-Processor Processing: Sub-Processors process Customer Personal Data for the same purpose and duration. The current list is at abstract3d.com/subprocessors.
Where the EU GDPR applies, the supervisory authority is the supervisory authority of the EU Member State in which Customer (or its EU representative) is established. Where Customer has no EU establishment or representative, the Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg applies, as the authority for AbstractGroup’s main establishment.
We encrypt Customer Personal Data in transit and at rest using industry-standard cryptographic mechanisms.
Access to production systems requires unique user accounts with multi-factor authentication. We apply role-based access control on a least-privilege basis. Access is logged and reviewed; access is removed promptly upon role change or termination.
User authentication is supported via password, with optional second-factor authentication (such as time-based one-time passwords and passkeys), and via OAuth single sign-on. Some authentication methods may be available only for certain plans. AbstractGroup may make additional authentication methods available from time to time. Account credentials are not stored in plaintext.
Production environments are segmented from corporate networks. Inbound traffic is filtered at the edge. Production access for AbstractGroup personnel requires VPN and multi-factor authentication.
Customer Personal Data is logically separated by Customer and Workspace. Application-level controls are designed to prevent cross-Customer access.
We perform regular backups of Customer Content. Backups are encrypted using the same standards as production data and are retained on the schedule described in this DPA.
We log application and infrastructure events relevant to security and operations. Logs are protected against unauthorized access and used for incident investigation, audit, and operational review.
We perform vulnerability scans of our production environment.
AbstractGroup personnel with access to Customer Personal Data are subject to confidentiality obligations, whether by contract or by statutory obligation, that survive termination of the relevant authorization. We provide regular security and data-protection training to personnel with access to Customer Personal Data.
We perform a risk-based review of each Sub-Processor before engagement, and we maintain contractual data-protection obligations with each Sub-Processor that are no less protective than this DPA.
Customer Personal Data is hosted in data centers operated by our Sub-Processors, as identified on the subprocessor page. Physical security is maintained by the data center operator, with measures typically including 24/7 monitoring, access controls, environmental controls, and resilience against natural events.
The Services include self-service functionality for export, deletion, and access to Customer Content. Where additional assistance is required, our privacy team responds to requests within applicable legal time limits.
We maintain an incident response plan covering detection, containment, eradication, recovery, and post-incident review. We notify affected Customers of Personal Data Breaches without undue delay as set out in this DPA.
Abstract Group GmbH & Co. KG, Silberburgstraße 102, 70176 Stuttgart, Germany, on behalf of its operating subsidiaries. Privacy contact: privacy@abstract3d.com.
Whether you're building games, designing cars, or creating immersive experiences — we'd love to show you what a complete platform can do.