Data Processing Addendum

Last updated: August 26, 2026

1. Parties and roles

This Data Processing Addendum ("DPA") is incorporated into the Terms of Service by reference. "Provider" is Watermarks Remover (contact: [email protected]). "Customer" is the business or individual using the Service (web app, REST API, or MCP server).

We are the controller for account data and for data collected by analytics and consent tools. For Customer Content that contains personal data, we act as a processor on the Customer's documented instructions.

2. Definitions

  • Customer Content — text and files the Customer submits for cleaning.
  • Account data — email address, usage timestamps, referral record, plan and billing details, and API key metadata.
  • Personal Data — information relating to an identified or identifiable natural person, as defined in the GDPR/UK GDPR, the CCPA/CPRA, or other applicable law.
  • Process — any operation on personal data, including collection, storage, use, disclosure, and deletion.
  • Subprocessor — a third party that processes personal data on our behalf.
  • Personal Data Breach — a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.

3. Processing we perform

We process only what is needed to deliver the Service:

  • Categories: Customer Content (in memory only); account data; usage and quota records; billing metadata; analytics events; consent choices.
  • Purpose: cleaning Customer Content; enforcing quotas; preventing abuse; billing; measuring aggregate usage; storing consent choices.
  • Duration: Customer Content is discarded immediately after delivery. Account data is kept while the account exists and as described in the Privacy Policy.

4. Customer instructions and obligations

The Customer instructs us to clean Customer Content and to delete it after delivery. The Customer must have a lawful basis for any personal data it submits, and must not submit special-category data or protected health information (the Terms of Service exclude regulated uses).

5. Our security measures

  • All traffic is TLS-encrypted.
  • Customer Content is processed in memory and deleted after download; it is never written to logs.
  • Signed, httpOnly session cookies; per-IP rate limits; disposable-email blocklist; fail-closed job processing.
  • Access to account data is limited to the people who operate the Service. The cleaning engine is open source (MIT), so the processing logic is auditable.

6. Subprocessors

Customer Content is never sent to a subprocessor. Each subprocessor processes only what is needed for its listed purpose, under a contract with appropriate safeguards. New subprocessors are announced by updating this page.

  • Google LLC — sign-in (Google OAuth2) and aggregate analytics (Google Analytics 4).
  • Stripe, Inc. — subscription and API-credit payments; card data is handled by Stripe, and we never see full card numbers.
  • CookieYes — consent banner and consent records.
  • Cloudflare, Inc. — proxy and CDN for the public site.

7. Data subject rights

We support Customers and data subjects with access, correction, deletion, restriction, objection, and portability requests for personal data we hold. Requests go to the contact address; we respond within the time limits applicable law sets. For visitors to the site, these rights are also described in the Privacy Policy.

8. Personal data breach

If a Personal Data Breach affects Customer Content, we notify the Customer without undue delay and no later than 72 hours where required, describing the breach, the affected categories, and the measures taken. The Customer remains responsible for notifying its own regulators and data subjects.

9. International transfers

Customer Content is processed on our own infrastructure and is not transferred across borders. Where subprocessors process personal data (Google, Stripe, CookieYes, Cloudflare), they do so under their own data-processing terms and, for EEA/UK personal data, under adequacy decisions or standard contractual clauses.

10. Retention and deletion

We retain Customer Content no longer than needed to deliver it. Account data is retained while the account is active and afterward only to comply with legal obligations. Deletion requests are honored as described in the Privacy Policy.

11. Audits

On a Customer's written request, not more than once per 12 months, we provide reasonable information and a summary of our security posture that demonstrates compliance with this DPA. The cleaning engine is open source, so the Customer can audit the processing logic directly.

12. Term and liability

This DPA applies while the Service is used and survives as long as we hold personal data covered by it. Our liability is subject to the Terms of Service; this DPA does not increase it.

13. Contact

Questions about this DPA: [email protected].