Legal
This Data Processing Agreement (“DPA”) forms part of the agreement between VisualiseO Limited, a company registered in England and Wales (company number 17171606, registered office 27 Beverley Close, Normanton, WF6 1BU) (“Processor”, “we”, “us”) and the retailer or business customer that subscribes to the Visualiseo service (“Controller”, “you”). It records how we process personal data on your behalf under Article 28 of the UK GDPR.
By using the Visualiseo service you accept this DPA. You may also request a countersigned copy for your records by emailing legal@visualiseo.co.uk. This DPA operates in addition to our Terms and Privacy Policy. Capitalised terms not defined here have the meanings given in the Terms or the UK GDPR.
Last updated: 21 July 2026
For personal data that end users submit through the Visualiseo widget embedded on your website for the purpose of generating a render, and for personal data that end users submit through the chat and quote assistant embedded on your website — including the conversation transcript, any contact details they give and their answers to the quote questions you configure — you are the Controller and we are the Processor. This DPA applies to all such processing.
Where an end user opts in at the widget Save popup to publish their before/after images to the public gallery (on visualiseo.co.uk and on your own gallery), that processing is joint-controller under Article 26 UK GDPR, not processor. That processing is governed by the Joint Controller Agreement incorporated into our Terms, not by this DPA. A plain-English summary is at /legal/joint-controller-summary.
For data we process as our own controller (our server logs, aggregate usage statistics, security telemetry, and your account information), our Privacy Policy applies, not this DPA.
| Subject matter | Generating AI-composited product visualisations from photos submitted by the Controller's end users, and operating the Controller's embedded chat and quote assistant, including capturing, storing and making available to the Controller enquiries from its end users. |
| Duration | For as long as the Controller's subscription is active, plus any retention period required by law or set out in our Privacy Policy. |
| Nature and purpose | Receiving an end-user photo, sending it to our AI sub-processor to generate a composited render, returning the render, and (if the end user opts in) storing the before/after images for display in the Controller's gallery. Separately: receiving and storing messages exchanged between the Controller's end users, the AI assistant and the Controller's own staff; generating assistant replies via an AI sub-processor; recording the end user's answers to the quote questions the Controller configures and any contact details they provide; and notifying the Controller when an enquiry needs a human reply. |
| Types of personal data | Images of spaces uploaded by end users; server-log metadata (IP address, user-agent, timestamps) incidental to delivering the Service. The Service runs an automated person-detection pre-check and rejects images that appear to contain people before any further processing. For the chat and quote assistant: name, email address and telephone number where the end user provides them, free-text message content, quote answers, the product or render the conversation relates to, and a random visitor identifier stored in the end user's browser. |
| Categories of data subjects | End users of the widget, and end users of the chat and quote assistant, on the Controller's website. |
| Special-category data | We do not knowingly process special-category data. The Service is not designed for biometric identification. Photographs of people are rejected before processing. Controllers must not configure or permit processing of special-category data without first contacting us, including by adding quote questions that invite health, disability, religious, ethnic or similar information. |
We will:
The security measures we apply are described in Annex 1 below. You accept those measures as appropriate to the risk of the processing.
You give us general authorisation to engage sub-processors to deliver the Service. The current list of sub-processors is in Annex 2 and is also published at /sub-processors. We will:
Some of our sub-processors are based outside the UK and EEA. Where this is the case we rely on safeguards recognised by UK data protection law:
We have completed a Transfer Risk Assessment for each international sub-processor. By agreeing to this DPA you also authorise these transfers. You may request copies of the relevant transfer mechanisms and TRAs by emailing legal@visualiseo.co.uk.
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as this is possible, in responding to requests from data subjects to exercise their rights under the UK GDPR. If a data subject contacts us directly about their rights, we will inform them to contact you and forward the request where appropriate.
End users of the chat and quote assistant frequently give us no identifier other than the random visitor key held in their browser, which we cannot use to locate them from a request made by email. Where an end user asks us directly to access or delete a conversation, we will forward the request to you and assist you in locating the thread; responding to it remains your obligation as Controller.
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting your data. The notification will contain the information we have at the time to the extent required under Article 33(3) UK GDPR and will be updated as further information becomes available.
We will make available all information reasonably necessary to demonstrate compliance with this DPA. Because we are a multi-tenant SaaS provider, on-site audits are not generally available. Instead you may, at your cost and no more than once a year (or more often if required by law or following a breach), submit a written audit questionnaire covering matters relevant to this DPA, which we will answer within 30 days.
On termination of the Service, we will, at your choice, delete or return all personal data we process on your behalf, unless we are required by law to retain it. Deletion from backups may take up to 90 days.
Retention during the term. In addition to deletion on termination, we apply the following default periods to data we process on your behalf, enforced automatically by a scheduled deletion job:
These are defaults, not a decision we make for you. Deciding how long you need an enquiry is yours as Controller under Article 5(1)(e) UK GDPR: you may instruct us in writing to apply a shorter period across your account, or to delete any individual conversation or enquiry at any time, by emailing privacy@visualiseo.co.uk. We will not extend these periods on request without agreeing a documented instruction and a justification for the longer period.
Contact details captured through the quote assistant are collected for the purpose of responding to that enquiry only. No marketing consent is captured on your behalf. You must not use them for direct marketing unless you have your own lawful basis and, where required, consent or a valid soft opt-in under regulation 22 PECR.
The liability of each party under this DPA is subject to the limitations and exclusions in the Terms. Nothing in this DPA limits either party's statutory liability under UK data protection law.
If there is a conflict between this DPA and the Terms on the subject of data protection, this DPA prevails. This DPA starts when you accept the Terms and ends when your account is terminated and all data has been returned or deleted in accordance with Clause 11.
We may update this DPA from time to time. Changes that materially affect your rights or our obligations will be notified to you by email at least 30 days before they take effect. Changes that narrowly reflect an updated sub-processor list, address or similar operational detail may be made by updating the Annexes and the “Last updated” date.
We apply the following technical and organisational measures:
We review these measures periodically and may update them to take account of the state of the art and the risks of processing, provided the level of protection is not reduced.
We use the following sub-processors to provide the Service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Google (Gemini API) | AI image generation (primary) and generating the retailer chat and quote assistant's replies | United States |
| Google Cloud Vertex AI | AI image generation (alternate model chain, Gemini Enterprise) | United States / European Union |
| OpenAI | AI image generation (alternate model chain) | United States |
| Google Cloud Storage | Product and gallery image storage | European Union |
| Neon | PostgreSQL database hosting | European Union |
| Vercel, Inc. | Web application hosting and edge network | United States / global edge |
| Stripe, Inc. | Payment processing | United States / Ireland |
| Resend | Transactional email delivery | United States |
| Pusher | Real-time delivery of chat messages — our own support chat and conversations between a visitor and a retailer | United States |
Any changes to this list will be reflected on this page with a new “Last updated” date and, for material additions, notified to account holders by email.