LEGAL

Data Processing Addendum

Last updated: August 10, 2026

LEGAL

Data Processing Addendum

Last updated: August 10, 2026


1. Purpose, Scope, And Acceptance

This Data Processing Addendum ("Addendum") forms part of, and is incorporated into, the Desenta Terms of Service or any other agreement governing your use of the Services (the "Agreement"). This Addendum applies only to the extent that Desenta processes Personal Data on your behalf as a Processor or Service Provider in connection with the provision of the Services and in accordance with the functionality of the Services.
This Addendum does not apply to Personal Data that Desenta processes as an independent Controller, including account administration, product operations, security, support, legal compliance, cookies, and other purposes described in the Desenta Privacy Policy or Cookie Policy.
If this Addendum conflicts with the Agreement on a matter covered by this Addendum, this Addendum controls for that matter.
This Addendum becomes binding when you electronically accept a checkbox or other acceptance control that refers to the Data Processing Addendum. Electronic acceptance is intended to satisfy the written agreement requirement under Article 28(9) of the GDPR.


2. Definitions

In this Addendum, "you" means the designer, studio, account holder, or other organisation using the Services under the Agreement. "Desenta" means DESENTA SIA, registration number 40203699982, registered address Jaunā Mežaparka iela 46 - 4, Rīga, LV-1014, Latvia, unless another Desenta contracting entity is identified in the Agreement.

  • Applicable Data Protection Law means privacy and data protection law applicable to the processing under this Addendum, including the EU General Data Protection Regulation 2016/679 ("GDPR") where applicable.
  • Personal Data means information relating to an identified or identifiable individual that Desenta processes on your behalf under this Addendum.
  • Personal Data Breach means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data processed under this Addendum.
  • Restricted Transfer means a transfer of Personal Data to a country or recipient that is not recognised as providing adequate protection under Applicable Data Protection Law.
  • Services means the Desenta website, web application, account features, project creation and management tools, project-presentation and publishing tools, preview functionality, shared project pages and links, support features, and related Desenta services covered by the Agreement.
  • Subprocessor means an external provider Desenta uses to help deliver the Services where that provider may process Personal Data on your behalf. Examples may include hosting, database, file storage, email delivery, authentication, monitoring, or AI providers. A provider is included only if it processes relevant Personal Data for Desenta.

The terms Controller, Processor, Data Subject, and process have the meanings given to them under Applicable Data Protection Law. The terms Business and Service Provider have the meanings given to them under applicable United States state privacy laws.


3. Roles, Instructions, And Responsibilities

You act as the Controller or Business for Personal Data that you upload, enter, share, or otherwise make available through the Services. Desenta acts as your Processor or Service Provider only to the extent that it processes that Personal Data on your behalf to provide the Services.

If you process Personal Data on behalf of your own client or another Controller, you act as a Processor and Desenta acts as your Subprocessor for that Personal Data. You confirm that you have authority to appoint Desenta and provide the instructions set out in this Addendum.

Your instructions are the choices and actions you make in Desenta, such as uploading project materials, choosing account and sharing settings, inviting people, creating or revoking shared links, using product features, and requesting support.

You are responsible for using the Services lawfully, having a valid legal basis for the Personal Data you provide, giving required notices and obtaining required consents, reviewing project materials before sharing them, managing shared links and invitations, and not uploading special-category, highly sensitive, or regulated data unless necessary, lawful, and appropriate for the Services.


4. Desenta's Obligations

When Desenta processes Personal Data on your behalf, Desenta will:

- process Personal Data only on your documented instructions or as required by law;
- inform you if, in Desenta's opinion, an instruction infringes Applicable Data Protection Law;
- ensure that authorised personnel handling Personal Data are bound by confidentiality duties;
- maintain reasonable technical and organisational measures designed to protect Personal Data;
- not sell Personal Data, share it for targeted advertising, use it to build advertising profiles, or use it for Desenta's own unrelated purposes except where permitted by law;
- notify you without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this Addendum and provide available information to help you investigate and respond;
- provide assistance with Data Subject requests, data protection impact assessments, regulator consultations, and deletion or return of Personal Data where required by law and technically available through the Services;
- make available information needed to demonstrate compliance with this Addendum and allow audits required by Applicable Data Protection Law, subject to confidentiality, security, proportionality, and non-disruption limits.

If Desenta receives a Data Subject request, government request, or third-party legal demand relating to Personal Data processed on your behalf, Desenta will notify you where legally permitted and will respond only as required by law or on your documented instructions.


5. Subprocessors

Desenta may use Subprocessors where reasonably necessary to provide the Services. Desenta will require Subprocessors that process Personal Data on Desenta's behalf to protect Personal Data under appropriate written data-protection obligations, and Desenta remains responsible for their performance to the extent required by Applicable Data Protection Law. Appendix 3 lists the current Subprocessors and explains the change-notice process.


6. International Transfers

Desenta's core hosting, database, file storage, and email delivery are currently processed in the European Union. Optional features or integrations, such as Pinterest, product URL autofill through Firecrawl, or image background removal through remove.bg, may involve Personal Data being stored in or accessed from outside the European Economic Area. Where required, Desenta will use an appropriate transfer safeguard, such as an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism. Appendix 4 provides the transfer details.


7. Liability And Governing Law

If there is a claim under this Addendum, the liability limits in the main Desenta Terms of Service or other applicable agreement also apply to that claim. This does not limit any liability that the law does not allow Desenta or the account holder to limit.

Latvian law governs this Addendum, and disputes about this Addendum must be handled by the courts in Rīga, Latvia, unless applicable data-protection law requires a different rule.


8. Changes

Desenta may update this Addendum where needed to reflect changes to the Services, law, or data processing practices. Desenta will not, without notice, reduce the level of protection in this Addendum while this Addendum applies to your account. Desenta will post the updated version and update the date above. Where required by law or where an updated version requires renewed acceptance, Desenta will provide additional notice.


Appendix 1 - Details Of Processing

Subject matter. Processing Personal Data that you provide, upload, submit, generate, or make available through Desenta in connection with your design projects and use of the Services.

Duration of processing. Desenta processes Personal Data for as long as it provides the Services to the relevant account holder. Published or archived project links remain accessible for up to 24 months after publication only while the account remains active and the relevant project or shared link has not been revoked, deleted, or disabled. Account deletion disables login access and all shared and preview links, removes account and project content from active product access, and starts the account-deletion process. Individual project deletion removes that project from account UI, active product access, and shared or preview access. Copies already present in routine backups are deleted or overwritten within 90 days after account closure, account deletion, or project deletion. Users cannot access or restore account or project data from these backups.

Frequency of processing. Desenta processes Personal Data whenever needed to provide the relevant Services during your use of Desenta.

Categories of Data Subjects.

  • your authorised account users and collaborators;
  • your clients and prospective clients;
  • recipients of project links and invitations;
  • suppliers, contractors, architects, consultants, and other project participants; and
  • other individuals whose Personal Data you choose to include in project content.

Types of Personal Data.

  • first and last names, account email addresses, business or studio names, business email addresses, business contact numbers, business website addresses, business Instagram account names, business addresses, business logos, and sign-up or onboarding details submitted through the Services;
  • project names, addresses, locations, property and room details, project notes, client briefs, preferences, and project materials submitted through the Services;
  • project content and files that may contain Personal Data, such as design briefs, concepts, references, moodboards, colour palettes, 3D renders and other visualisations, floor plans, drawings and source files, FF&E and Finishes schedules, product links, pricing information, vendor and supplier details, project status records, versions, and version history for project sections;
  • product information extracted from supplier URLs you submit in Finishes and FF&E schedules, such as product name, SKU, brand or vendor, material, finish, colour, dimensions, price, product image URL, and other publicly available supplier-page information;
  • Pinterest boards, Pins, account information, and related Pinterest data that you authorise Pinterest to share with Desenta and choose to import or use in Desenta project work;
  • project sharing information, such as recipient email addresses, share permissions and tokens, share link settings, and schedule item status updates submitted through shared project pages;
  • technical, authentication, and security information, such as IP address, browser type, user agent, session data, authentication tokens, password hashes, and server logs used to operate and secure the Services;
  • other Personal Data that you or your invited users choose to include in project materials, support requests, file names, or other information submitted through the Services.

Sensitive data. Desenta is not designed for special-category or highly sensitive Personal Data. You should not upload such data unless it is necessary, lawful, and appropriate for the Services.
Anonymised data. Desenta does not currently create or use irreversibly anonymised or aggregated datasets derived from customer Personal Data for purposes beyond operating the Services. Authorised administrators may view high-level aggregate statistics, such as total users or projects. Account deletion replaces certain identifying fields but does not produce anonymised data for secondary use. Desenta will not treat information as anonymised unless it is no longer reasonably possible to identify an individual from it.


Appendix 2 - Technical And Organisational Measures

Desenta maintains reasonable technical and organisational measures designed to protect Personal Data, including:

- Hosting and location. Core application hosting, database, file storage, backups, and logs are hosted in the European Union, currently Finland through Hetzner Cloud, unless an optional feature or integration listed in the Subprocessor list involves another location.
- Secure transmission and access. The Services use HTTPS with TLS 1.2+; production endpoints negotiate TLS 1.3. Access to account and project data is limited to authenticated account owners, authorised Desenta personnel, and recipients with valid shared-link permissions or invite tokens.
- Authentication. Passwords are stored as bcrypt hashes. Authentication uses Laravel Sanctum token-based authentication and an HTTP-only authentication cookie on the frontend.
- Backups and recovery. Desenta maintains daily production backups retained for no longer than 90 days. Backup access is restricted. If a restore rolls back a completed account or project deletion, Desenta reapplies the deletion manually.
- Logging and incident response. Desenta uses application, server, and administrative logs for security, troubleshooting, and investigation, and maintains a process for assessing and responding to potential Personal Data Breaches.
- Deletion, export, and retention. Desenta supports project export/download where available and applies the retention, deletion, and backup periods described in the Agreement, Privacy Policy, and this Addendum.
- Vendor controls. Desenta maintains a public Subprocessor list and requires written data-protection obligations from Subprocessors where required by Applicable Data Protection Law.

Desenta may update these measures as the Services evolve, provided that an update does not materially reduce the overall level of protection for Personal Data.


Appendix 3 - Subprocessors

How this list is used

This Appendix lists the external providers that may process customer Personal Data for Desenta. Desenta may update this list and, where required by Applicable Data Protection Law or this Addendum, provide advance notice of material Subprocessor changes.

Subprocessor register

  • Hosting and infrastructure: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Hosting and infrastructure services for the Desenta application, database, and uploaded files. Processing location: Hetzner Cloud hel1-dc2 / eu-central, Helsinki, Finland / European Union.
  • Database: Hetzner Online GmbH, Germany. Database hosting for account, project, and service data on the Desenta host. Processing location: Hetzner Cloud hel1-dc2 / eu-central, Helsinki, Finland / European Union.
  • File storage: Hetzner Online GmbH, Germany. Storage for uploaded project files and images on the Desenta host. Processing location: Hetzner Cloud hel1-dc2 / eu-central, Helsinki, Finland / European Union.
  • Email delivery: Sendinblue SAS (d/b/a Brevo), Paris, France (RCS Paris 498 019 298). Outbound transactional and service email delivery via Brevo SMTP, European Union. Brevo is used for email delivery and is not the final support-ticket mailbox.
  • Support mailbox: Microsoft 365 / Exchange Online for support@desenta.com. Support messages are delivered through Brevo SMTP and stored in Desenta's Microsoft 365 mailbox. The application does not store support messages as support tickets. Support messages are accessible only to authorised Desenta personnel who need access to respond, troubleshoot, secure, or maintain the Services, and are retained for as long as needed for those purposes unless earlier deletion is requested or longer retention is needed for security, legal, or operational reasons.
  • Product-data extraction: SideGuide Technologies, Inc. d/b/a Firecrawl, Delaware, United States. Product URL autofill / supplier webpage extraction where a user chooses to use that feature in Finishes or FF&E schedules. Processing location: United States. Provider terms and transfer safeguards have been confirmed for use of this feature.
  • Image background removal: Canva Austria GmbH (remove.bg), Vienna, Austria. Optional image background-removal processing where a user chooses to use remove.bg-powered image tools. Processing may occur in Europe and other countries where remove.bg or its service providers operate. Desenta uses remove.bg under its applicable provider terms.
  • Pinterest integration: Pinterest, Inc. and, where applicable, Pinterest Europe Ltd. Optional Pinterest connection where a user chooses to connect Pinterest through OAuth. Desenta may process Pinterest boards, Pins, account information, OAuth tokens, cached images, and related connection data authorised by the user for use in Desenta project work. Processing may involve the United States or other non-EEA locations. Desenta will rely on Pinterest's applicable published terms and transfer safeguards where available and will ensure that an appropriate transfer safeguard is in place where required by Applicable Data Protection Law.
  • Authentication: no external authentication subprocessor has been confirmed; Desenta uses first-party application authentication.
  • Monitoring: no external monitoring subprocessor has been confirmed.
  • Analytics: not currently used for the Desenta web application or shared project links. If introduced later and the provider processes customer Personal Data, the provider must be added to this list before use.
  • Payment processing: not currently used. If introduced later and the provider processes customer Personal Data, the provider must be added to this list before use.


Appendix 4 - International Transfer Schedule


What this schedule means

Desenta's primary application hosting, database, and file storage are located in the European Union, currently Finland through Hetzner Cloud. Email delivery is processed through Brevo in the European Union. Where a user connects Pinterest or uses product URL autofill through Firecrawl, Personal Data may be processed in the United States. Where this creates a Restricted Transfer under privacy law, Desenta will ensure that an appropriate transfer safeguard is in place, such as the European Commission Standard Contractual Clauses or another lawful transfer mechanism required by Applicable Data Protection Law.


Safeguards Desenta may use

Where Desenta transfers Personal Data to a country outside the European Economic Area, Desenta ensures that an appropriate safeguard is in place under Applicable Data Protection Law. Depending on the provider, country, and data involved, Desenta may rely on one or more of the following safeguards:
  • an adequacy decision, where the European Commission has recognised the destination country as providing an adequate level of data protection;
  • the European Commission's Standard Contractual Clauses, where those clauses are required for the transfer;
  • another lawful transfer mechanism allowed by applicable data-protection law, such as binding corporate rules or, where applicable, certification under an approved framework.


Where Standard Contractual Clauses are required

This section applies where Desenta transfers or makes Personal Data available to a Subprocessor or other recipient in a manner that constitutes a Restricted Transfer requiring the Standard Contractual Clauses under the GDPR. Where required, the Standard Contractual Clauses form part of the relevant data-processing arrangement.

Where Desenta relies on the European Commission's Standard Contractual Clauses for a Restricted Transfer, the module applicable to the roles of the parties to that Restricted Transfer will apply. Where Desenta acts as a Processor transferring Personal Data to a Subprocessor, Module Three applies.

Where applicable, Clause 7 (the docking clause) applies. The governing law and competent courts for the Standard Contractual Clauses will be determined in accordance with Clauses 17 and 18 of those clauses.

Activities relevant to the transfer. Processing Personal Data as needed to provide, secure, support, and operate the Services in accordance with the Terms of Service, any applicable account or plan terms, and this Addendum.

Where Standard Contractual Clauses are used for a Restricted Transfer by Desenta, the parties, binding mechanism, and transfer details are determined by the applicable arrangement between Desenta and the relevant recipient.

Competent supervisory authority. For Restricted Transfers that use the Standard Contractual Clauses, the relevant regulator is determined under Clause 13 of those clauses. If the Standard Contractual Clauses conflict with this Addendum or the Agreement, the Standard Contractual Clauses control for the transfer issue only.


Contact

For questions about this Addendum, contact admin@desenta.com.




1. Purpose, Scope, And Acceptance

This Data Processing Addendum ("Addendum") forms part of, and is incorporated into, the Desenta Terms of Service or any other agreement governing your use of the Services (the "Agreement"). This Addendum applies only to the extent that Desenta processes Personal Data on your behalf as a Processor or Service Provider in connection with the provision of the Services and in accordance with the functionality of the Services.
This Addendum does not apply to Personal Data that Desenta processes as an independent Controller, including account administration, product operations, security, support, legal compliance, cookies, and other purposes described in the Desenta Privacy Policy or Cookie Policy.
If this Addendum conflicts with the Agreement on a matter covered by this Addendum, this Addendum controls for that matter.
This Addendum becomes binding when you electronically accept a checkbox or other acceptance control that refers to the Data Processing Addendum. Electronic acceptance is intended to satisfy the written agreement requirement under Article 28(9) of the GDPR.


2. Definitions

In this Addendum, "you" means the designer, studio, account holder, or other organisation using the Services under the Agreement. "Desenta" means DESENTA SIA, registration number 40203699982, registered address Jaunā Mežaparka iela 46 - 4, Rīga, LV-1014, Latvia, unless another Desenta contracting entity is identified in the Agreement.

  • Applicable Data Protection Law means privacy and data protection law applicable to the processing under this Addendum, including the EU General Data Protection Regulation 2016/679 ("GDPR") where applicable.
  • Personal Data means information relating to an identified or identifiable individual that Desenta processes on your behalf under this Addendum.
  • Personal Data Breach means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data processed under this Addendum.
  • Restricted Transfer means a transfer of Personal Data to a country or recipient that is not recognised as providing adequate protection under Applicable Data Protection Law.
  • Services means the Desenta website, web application, account features, project creation and management tools, project-presentation and publishing tools, preview functionality, shared project pages and links, support features, and related Desenta services covered by the Agreement.
  • Subprocessor means an external provider Desenta uses to help deliver the Services where that provider may process Personal Data on your behalf. Examples may include hosting, database, file storage, email delivery, authentication, monitoring, or AI providers. A provider is included only if it processes relevant Personal Data for Desenta.

The terms Controller, Processor, Data Subject, and process have the meanings given to them under Applicable Data Protection Law. The terms Business and Service Provider have the meanings given to them under applicable United States state privacy laws.


3. Roles, Instructions, And Responsibilities

You act as the Controller or Business for Personal Data that you upload, enter, share, or otherwise make available through the Services. Desenta acts as your Processor or Service Provider only to the extent that it processes that Personal Data on your behalf to provide the Services.

If you process Personal Data on behalf of your own client or another Controller, you act as a Processor and Desenta acts as your Subprocessor for that Personal Data. You confirm that you have authority to appoint Desenta and provide the instructions set out in this Addendum.

Your instructions are the choices and actions you make in Desenta, such as uploading project materials, choosing account and sharing settings, inviting people, creating or revoking shared links, using product features, and requesting support.

You are responsible for using the Services lawfully, having a valid legal basis for the Personal Data you provide, giving required notices and obtaining required consents, reviewing project materials before sharing them, managing shared links and invitations, and not uploading special-category, highly sensitive, or regulated data unless necessary, lawful, and appropriate for the Services.


4. Desenta's Obligations

When Desenta processes Personal Data on your behalf, Desenta will:

- process Personal Data only on your documented instructions or as required by law;
- inform you if, in Desenta's opinion, an instruction infringes Applicable Data Protection Law;
- ensure that authorised personnel handling Personal Data are bound by confidentiality duties;
- maintain reasonable technical and organisational measures designed to protect Personal Data;
- not sell Personal Data, share it for targeted advertising, use it to build advertising profiles, or use it for Desenta's own unrelated purposes except where permitted by law;
- notify you without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this Addendum and provide available information to help you investigate and respond;
- provide assistance with Data Subject requests, data protection impact assessments, regulator consultations, and deletion or return of Personal Data where required by law and technically available through the Services;
- make available information needed to demonstrate compliance with this Addendum and allow audits required by Applicable Data Protection Law, subject to confidentiality, security, proportionality, and non-disruption limits.

If Desenta receives a Data Subject request, government request, or third-party legal demand relating to Personal Data processed on your behalf, Desenta will notify you where legally permitted and will respond only as required by law or on your documented instructions.


5. Subprocessors

Desenta may use Subprocessors where reasonably necessary to provide the Services. Desenta will require Subprocessors that process Personal Data on Desenta's behalf to protect Personal Data under appropriate written data-protection obligations, and Desenta remains responsible for their performance to the extent required by Applicable Data Protection Law. Appendix 3 lists the current Subprocessors and explains the change-notice process.


6. International Transfers

Desenta's core hosting, database, file storage, and email delivery are currently processed in the European Union. Optional features or integrations, such as Pinterest, product URL autofill through Firecrawl, or image background removal through remove.bg, may involve Personal Data being stored in or accessed from outside the European Economic Area. Where required, Desenta will use an appropriate transfer safeguard, such as an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism. Appendix 4 provides the transfer details.


7. Liability And Governing Law

If there is a claim under this Addendum, the liability limits in the main Desenta Terms of Service or other applicable agreement also apply to that claim. This does not limit any liability that the law does not allow Desenta or the account holder to limit.

Latvian law governs this Addendum, and disputes about this Addendum must be handled by the courts in Rīga, Latvia, unless applicable data-protection law requires a different rule.


8. Changes

Desenta may update this Addendum where needed to reflect changes to the Services, law, or data processing practices. Desenta will not, without notice, reduce the level of protection in this Addendum while this Addendum applies to your account. Desenta will post the updated version and update the date above. Where required by law or where an updated version requires renewed acceptance, Desenta will provide additional notice.


Appendix 1 - Details Of Processing

Subject matter. Processing Personal Data that you provide, upload, submit, generate, or make available through Desenta in connection with your design projects and use of the Services.

Duration of processing. Desenta processes Personal Data for as long as it provides the Services to the relevant account holder. Published or archived project links remain accessible for up to 24 months after publication only while the account remains active and the relevant project or shared link has not been revoked, deleted, or disabled. Account deletion disables login access and all shared and preview links, removes account and project content from active product access, and starts the account-deletion process. Individual project deletion removes that project from account UI, active product access, and shared or preview access. Copies already present in routine backups are deleted or overwritten within 90 days after account closure, account deletion, or project deletion. Users cannot access or restore account or project data from these backups.

Frequency of processing. Desenta processes Personal Data whenever needed to provide the relevant Services during your use of Desenta.

Categories of Data Subjects.

  • your authorised account users and collaborators;
  • your clients and prospective clients;
  • recipients of project links and invitations;
  • suppliers, contractors, architects, consultants, and other project participants; and
  • other individuals whose Personal Data you choose to include in project content.

Types of Personal Data.

  • first and last names, account email addresses, business or studio names, business email addresses, business contact numbers, business website addresses, business Instagram account names, business addresses, business logos, and sign-up or onboarding details submitted through the Services;
  • project names, addresses, locations, property and room details, project notes, client briefs, preferences, and project materials submitted through the Services;
  • project content and files that may contain Personal Data, such as design briefs, concepts, references, moodboards, colour palettes, 3D renders and other visualisations, floor plans, drawings and source files, FF&E and Finishes schedules, product links, pricing information, vendor and supplier details, project status records, versions, and version history for project sections;
  • product information extracted from supplier URLs you submit in Finishes and FF&E schedules, such as product name, SKU, brand or vendor, material, finish, colour, dimensions, price, product image URL, and other publicly available supplier-page information;
  • Pinterest boards, Pins, account information, and related Pinterest data that you authorise Pinterest to share with Desenta and choose to import or use in Desenta project work;
  • project sharing information, such as recipient email addresses, share permissions and tokens, share link settings, and schedule item status updates submitted through shared project pages;
  • technical, authentication, and security information, such as IP address, browser type, user agent, session data, authentication tokens, password hashes, and server logs used to operate and secure the Services;
  • other Personal Data that you or your invited users choose to include in project materials, support requests, file names, or other information submitted through the Services.

Sensitive data. Desenta is not designed for special-category or highly sensitive Personal Data. You should not upload such data unless it is necessary, lawful, and appropriate for the Services.
Anonymised data. Desenta does not currently create or use irreversibly anonymised or aggregated datasets derived from customer Personal Data for purposes beyond operating the Services. Authorised administrators may view high-level aggregate statistics, such as total users or projects. Account deletion replaces certain identifying fields but does not produce anonymised data for secondary use. Desenta will not treat information as anonymised unless it is no longer reasonably possible to identify an individual from it.


Appendix 2 - Technical And Organisational Measures

Desenta maintains reasonable technical and organisational measures designed to protect Personal Data, including:

- Hosting and location. Core application hosting, database, file storage, backups, and logs are hosted in the European Union, currently Finland through Hetzner Cloud, unless an optional feature or integration listed in the Subprocessor list involves another location.
- Secure transmission and access. The Services use HTTPS with TLS 1.2+; production endpoints negotiate TLS 1.3. Access to account and project data is limited to authenticated account owners, authorised Desenta personnel, and recipients with valid shared-link permissions or invite tokens.
- Authentication. Passwords are stored as bcrypt hashes. Authentication uses Laravel Sanctum token-based authentication and an HTTP-only authentication cookie on the frontend.
- Backups and recovery. Desenta maintains daily production backups retained for no longer than 90 days. Backup access is restricted. If a restore rolls back a completed account or project deletion, Desenta reapplies the deletion manually.
- Logging and incident response. Desenta uses application, server, and administrative logs for security, troubleshooting, and investigation, and maintains a process for assessing and responding to potential Personal Data Breaches.
- Deletion, export, and retention. Desenta supports project export/download where available and applies the retention, deletion, and backup periods described in the Agreement, Privacy Policy, and this Addendum.
- Vendor controls. Desenta maintains a public Subprocessor list and requires written data-protection obligations from Subprocessors where required by Applicable Data Protection Law.

Desenta may update these measures as the Services evolve, provided that an update does not materially reduce the overall level of protection for Personal Data.


Appendix 3 - Subprocessors

How this list is used

This Appendix lists the external providers that may process customer Personal Data for Desenta. Desenta may update this list and, where required by Applicable Data Protection Law or this Addendum, provide advance notice of material Subprocessor changes.

Subprocessor register

  • Hosting and infrastructure: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Hosting and infrastructure services for the Desenta application, database, and uploaded files. Processing location: Hetzner Cloud hel1-dc2 / eu-central, Helsinki, Finland / European Union.
  • Database: Hetzner Online GmbH, Germany. Database hosting for account, project, and service data on the Desenta host. Processing location: Hetzner Cloud hel1-dc2 / eu-central, Helsinki, Finland / European Union.
  • File storage: Hetzner Online GmbH, Germany. Storage for uploaded project files and images on the Desenta host. Processing location: Hetzner Cloud hel1-dc2 / eu-central, Helsinki, Finland / European Union.
  • Email delivery: Sendinblue SAS (d/b/a Brevo), Paris, France (RCS Paris 498 019 298). Outbound transactional and service email delivery via Brevo SMTP, European Union. Brevo is used for email delivery and is not the final support-ticket mailbox.
  • Support mailbox: Microsoft 365 / Exchange Online for support@desenta.com. Support messages are delivered through Brevo SMTP and stored in Desenta's Microsoft 365 mailbox. The application does not store support messages as support tickets. Support messages are accessible only to authorised Desenta personnel who need access to respond, troubleshoot, secure, or maintain the Services, and are retained for as long as needed for those purposes unless earlier deletion is requested or longer retention is needed for security, legal, or operational reasons.
  • Product-data extraction: SideGuide Technologies, Inc. d/b/a Firecrawl, Delaware, United States. Product URL autofill / supplier webpage extraction where a user chooses to use that feature in Finishes or FF&E schedules. Processing location: United States. Provider terms and transfer safeguards have been confirmed for use of this feature.
  • Image background removal: Canva Austria GmbH (remove.bg), Vienna, Austria. Optional image background-removal processing where a user chooses to use remove.bg-powered image tools. Processing may occur in Europe and other countries where remove.bg or its service providers operate. Desenta uses remove.bg under its applicable provider terms.
  • Pinterest integration: Pinterest, Inc. and, where applicable, Pinterest Europe Ltd. Optional Pinterest connection where a user chooses to connect Pinterest through OAuth. Desenta may process Pinterest boards, Pins, account information, OAuth tokens, cached images, and related connection data authorised by the user for use in Desenta project work. Processing may involve the United States or other non-EEA locations. Desenta will rely on Pinterest's applicable published terms and transfer safeguards where available and will ensure that an appropriate transfer safeguard is in place where required by Applicable Data Protection Law.
  • Authentication: no external authentication subprocessor has been confirmed; Desenta uses first-party application authentication.
  • Monitoring: no external monitoring subprocessor has been confirmed.
  • Analytics: not currently used for the Desenta web application or shared project links. If introduced later and the provider processes customer Personal Data, the provider must be added to this list before use.
  • Payment processing: not currently used. If introduced later and the provider processes customer Personal Data, the provider must be added to this list before use.


Appendix 4 - International Transfer Schedule


What this schedule means

Desenta's primary application hosting, database, and file storage are located in the European Union, currently Finland through Hetzner Cloud. Email delivery is processed through Brevo in the European Union. Where a user connects Pinterest or uses product URL autofill through Firecrawl, Personal Data may be processed in the United States. Where this creates a Restricted Transfer under privacy law, Desenta will ensure that an appropriate transfer safeguard is in place, such as the European Commission Standard Contractual Clauses or another lawful transfer mechanism required by Applicable Data Protection Law.


Safeguards Desenta may use

Where Desenta transfers Personal Data to a country outside the European Economic Area, Desenta ensures that an appropriate safeguard is in place under Applicable Data Protection Law. Depending on the provider, country, and data involved, Desenta may rely on one or more of the following safeguards:
  • an adequacy decision, where the European Commission has recognised the destination country as providing an adequate level of data protection;
  • the European Commission's Standard Contractual Clauses, where those clauses are required for the transfer;
  • another lawful transfer mechanism allowed by applicable data-protection law, such as binding corporate rules or, where applicable, certification under an approved framework.


Where Standard Contractual Clauses are required

This section applies where Desenta transfers or makes Personal Data available to a Subprocessor or other recipient in a manner that constitutes a Restricted Transfer requiring the Standard Contractual Clauses under the GDPR. Where required, the Standard Contractual Clauses form part of the relevant data-processing arrangement.

Where Desenta relies on the European Commission's Standard Contractual Clauses for a Restricted Transfer, the module applicable to the roles of the parties to that Restricted Transfer will apply. Where Desenta acts as a Processor transferring Personal Data to a Subprocessor, Module Three applies.

Where applicable, Clause 7 (the docking clause) applies. The governing law and competent courts for the Standard Contractual Clauses will be determined in accordance with Clauses 17 and 18 of those clauses.

Activities relevant to the transfer. Processing Personal Data as needed to provide, secure, support, and operate the Services in accordance with the Terms of Service, any applicable account or plan terms, and this Addendum.

Where Standard Contractual Clauses are used for a Restricted Transfer by Desenta, the parties, binding mechanism, and transfer details are determined by the applicable arrangement between Desenta and the relevant recipient.

Competent supervisory authority. For Restricted Transfers that use the Standard Contractual Clauses, the relevant regulator is determined under Clause 13 of those clauses. If the Standard Contractual Clauses conflict with this Addendum or the Agreement, the Standard Contractual Clauses control for the transfer issue only.


Contact

For questions about this Addendum, contact admin@desenta.com.