Developer API Terms

Version 1.0 · Effective August 14, 2026

These terms cover the BudgetPixel developer API, API keys, and the MCP connector. You accept them once, in the developer console, before creating your first API key.

Annex A below is our Data Processing Addendum and is part of this document — accepting these terms accepts it too. Where your data is processed is covered in section 15, and section A6 explains how to obtain our sub-processor list.

1. Scope and relationship to our other terms

These Developer API Terms ("Developer Terms") govern your access to and use of the BudgetPixel developer API (the "API"), API keys, the BudgetPixel MCP connector, and any SDK, sample code, or documentation we provide for them (together, the "Developer Services"). They are entered into between Budget Pixel ("BudgetPixel", "we", "us") and the person or entity accepting them ("you" or "Customer").

The Developer Services are part of the Service governed by our general Terms of Service, and our Terms of Service and Privacy Policy continue to apply to you in full. These Developer Terms add obligations that only make sense for programmatic use. Where a provision of these Developer Terms conflicts with the Terms of Service, these Developer Terms control for your use of the Developer Services, and the Terms of Service control for everything else.

Annex A (Data Processing Addendum) is part of this document. By accepting these Developer Terms you accept Annex A; no separate signature is required. If your organisation requires a countersigned DPA, contact support@budgetpixel.com.

If you are accepting these Developer Terms on behalf of a company or other legal entity, you represent that you have authority to bind that entity, and "you" means that entity. You must be at least 18 years old.

2. Definitions

  • "Application" means any product, service, agent, workflow, or integration you build that calls the Developer Services.
  • "End User" means any person or system, other than you, who directly or indirectly causes a call to the Developer Services through your Application — including your customers, your employees, and any autonomous agent you operate.
  • "Input" means any prompt, image, video, audio, file, parameter, or other content you or your End Users submit to the Developer Services.
  • "Output" means any content the Developer Services return in response to an Input.
  • "Customer Content" means Inputs and Outputs together.
  • "Model Provider" means a third party whose model, infrastructure, or service we use to fulfil a request.
  • "Documentation" means the API documentation we publish at docs.budgetpixel.com, including the OpenAPI specification served at /v1/openapi.yaml.

3. Eligibility, keys, and account security

Access to the Developer Services requires an eligible subscription plan or an express grant from us. We may change which plans include API access. If your plan ceases to include API access, your keys stop working immediately.

An API key is a bearer credential: anyone who holds it can spend your credits and act as you. You are responsible for keeping keys confidential, and any activity performed with a valid key is deemed to be your act, whether or not you authorised it. Do not embed keys in client-side code, mobile applications, browser extensions, public repositories, or anything else an End User can read.

You must notify us at support@budgetpixel.com without undue delay if you know or suspect a key has been exposed, and revoke it in your developer console. We may revoke any key we reasonably believe to be compromised, without notice.

You may not share keys across legal entities, resell key access, or use a key to provide the Developer Services to a third party as a standalone service that competes with BudgetPixel.

4. Programmatic use: there is no human in the loop

This section is the core of these Developer Terms. Read it before you accept them.

When a person uses BudgetPixel through our website, our interface does a great deal of safety work on their behalf: it verifies age, applies a content safety level to their account, constrains what can be requested, shows warnings, and puts a human being in front of every generation. When you call the API or drive the MCP connector, none of that is present. Requests arrive already formed, at machine speed, from parties we cannot see and have no relationship with.

You therefore acknowledge and agree that:

  • You, not BudgetPixel, are the operator of your Application and the party in a position to know who your End Users are and what they are asking for.
  • Our interface-level safety measures — age verification, safety levels, per-request warnings, and human review — do not apply to your traffic, and you must not rely on them.
  • Any automated filtering we do apply on the API path is a backstop for our own protection. It is not a compliance service provided to you, it is not guaranteed to catch anything in particular, and its existence does not reduce your obligations under this section.

Accordingly, you must operate your own controls, appropriate to your Application and its audience, before Inputs reach us and before Outputs reach an End User. At minimum you must:

  • Screen Inputs and Outputs for the prohibited content described in section 5, using automated moderation, human review, or both. Our own moderation endpoints (POST /v1/moderations/nsfw and POST /v1/moderations/csam) are available to you for this purpose, and we recommend using them, but using them does not discharge your obligation.
  • Apply age assurance appropriate to your Application, and never make the Developer Services available to anyone under 18.
  • Maintain rate, spend, and concurrency limits within your own Application so that a runaway loop or a hostile End User cannot generate content at volume in your name.
  • Maintain a mechanism by which a person can report abusive content generated through your Application, and act on those reports.
  • Log enough information to identify which End User caused a given request, and provide it to us on request in connection with an abuse, safety, or legal investigation.

You are fully responsible for all Inputs submitted and all Outputs generated under your keys, including those originating from End Users and from autonomous agents you operate, to exactly the same extent as if you had created them yourself.

5. Acceptable use

The acceptable-use provisions of our Terms of Service apply to the Developer Services in full. In addition, you must not use, and must not permit any End User to use, the Developer Services to generate, request, store, or distribute:

  • Child sexual abuse material, or any sexualised depiction of a minor or of a person who appears to be a minor, whether or not any real person is depicted. We report suspected material to NCMEC as United States law requires, and we ban the responsible account permanently.
  • Intimate or sexual imagery of an identifiable real person created or altered without that person's consent.
  • Content that depicts an identifiable real person saying or doing something they did not say or do, where it is presented as authentic or is reasonably likely to deceive — including political, financial, and evidentiary deepfakes.
  • Content intended to harass, defame, threaten, sexualise, or impersonate a specific real person.
  • Content that infringes another party's copyright, trademark, publicity, or other rights, or that you lack the rights or consents to submit.
  • Biometric identification or surveillance of individuals without a lawful basis and their consent.
  • Material supporting fraud, scams, phishing, malware, spam, or circumvention of security controls.
  • Fully automated decisions producing legal or similarly significant effects on a person — employment, credit, housing, insurance, education, or access to public services — without meaningful human review.
  • Discrimination against individuals on the basis of a protected characteristic.
  • Content that misrepresents the Outputs as human-created where doing so would deceive a person to their detriment.

Adult content. Generation of sexually explicit content is disabled platform-wide, including on the Developer Services, in order to comply with the requirements of our payment processors and the card networks. You must not attempt to circumvent this restriction, and you must not market your Application as a means of obtaining such content from BudgetPixel. You acknowledge that this restriction may change, in either direction, on the requirement of a payment network and without notice to you.

You must comply with all laws applicable to your Application and to your End Users, including data protection, consumer protection, AI transparency, and export control laws in every jurisdiction you operate in.

6. Your End Users

Our agreement is with you. We have no contract with your End Users and no ability to reach them. If you make the Developer Services available to anyone else, whether directly or through an Application, you must put your own agreement in place with them, and that agreement must:

  • Impose restrictions on your End Users that are at least as protective as sections 4 and 5 of these Developer Terms;
  • Disclaim warranties and limit liability on behalf of BudgetPixel and our Model Providers at least as much as sections 12 and 13 do;
  • Require your End Users to hold all rights and consents necessary for the Inputs they submit;
  • Give you the right to suspend or terminate an End User immediately for a breach, and require you to exercise it when we ask you to; and
  • Name BudgetPixel as a third-party beneficiary entitled to enforce those provisions, or otherwise permit us to require their enforcement.

You must publish your own terms of service and privacy notice covering your Application, and you must disclose to your End Users that their Inputs are processed by third-party AI providers which may operate outside your End User's country, as described in section 15.

Where your Application presents Outputs to a person, you must clearly disclose that the content is AI-generated, in the manner required by the laws applicable to your End Users.

You are liable for the acts and omissions of your End Users under these Developer Terms as if they were your own. A breach by an End User is your breach.

7. Model Providers and pass-through terms

The Developer Services route requests to models operated by us and by Model Providers. Which Model Provider serves a given model changes over time, and the identity of our Model Providers is our confidential business information. We disclose the regions in which processing takes place in section 15, and we will identify the Model Providers relevant to your use of the Developer Services on written request, subject to a confidentiality agreement, as described in section A6 of Annex A.

Each Model Provider imposes its own licence terms and acceptable-use policy on the models it makes available. Some model licences carry restrictions that go beyond ours — for example, on commercial use, on redistribution of the model or its Outputs, on building competing models, or on the sectors in which Outputs may be used. You are responsible for identifying and complying with the terms applicable to each model you call, and for flowing down any restrictions that require it to your End Users. We are not a party to those terms and are not responsible for them.

We may add, change, deprecate, or remove a model at any time, including because a Model Provider has changed its terms, changed its behaviour, or ceased to offer it. Model behaviour may change without notice as a result of a Model Provider's own updates, and we do not warrant that a model will produce consistent Outputs over time.

Where a Model Provider requires it, we may pass identifying or contextual information about a request to that provider for abuse-prevention purposes, and we may be required to disclose your identity to a Model Provider investigating misuse.

8. Ownership of Inputs and Outputs

As between you and BudgetPixel, you retain all right, title, and interest in your Inputs. To the extent we hold any rights in the Outputs generated for you, we assign them to you on generation, subject to your payment of the applicable fees, to the licences of the relevant Model Provider, and to your compliance with these Developer Terms.

You grant us a worldwide, non-exclusive, royalty-free licence to host, store, transmit, reproduce, and modify Customer Content solely as needed to operate the Developer Services, fulfil your requests, provide support, enforce these Developer Terms, and comply with law. This licence ends when the content is deleted, except for copies retained in backups or as legally required.

Outputs are not unique. Other users may submit similar Inputs and receive similar or identical Outputs, and we make no representation that any Output is original, novel, or free from third-party rights.

Training. We do not use Customer Content submitted through the Developer Services to train our own models, and we contractually require our Model Providers not to train on it. We do not control our Model Providers and cannot warrant their compliance. We do use aggregated, de-identified operational metadata — request counts, model identifiers, latencies, error rates, credit consumption — to operate, secure, bill, and improve the Developer Services.

9. Your representations

You represent and warrant, on each call you make, that:

  • You hold all rights, licences, consents, and permissions necessary for us and our Model Providers to receive, process, transmit, and store each Input, and to generate Outputs from it, in every region listed in section 15;
  • Where an Input depicts, describes, or contains information about an identifiable person, you have that person's informed consent, or another lawful basis, for the processing you are asking us to perform, including its transfer outside their country;
  • Your Inputs and your use of the Outputs comply with all applicable law and infringe no third party's rights; and
  • You have satisfied the obligations in sections 4, 5, and 6 with respect to the request.

10. Fees, credits, and metering

Use of the Developer Services consumes credits from your account balance, at the rates published in the Documentation and returned by POST /v1/cost. Credits are non-refundable, and the credit and refund provisions of our Terms of Service apply.

We meter each request and record it against the key that made it. Our records are the authoritative measure of your usage, absent manifest error.

We may change pricing on 30 days' notice. Where an underlying Model Provider changes its pricing to us, we may change the credit cost of the affected model with less notice, or make it unavailable.

We apply rate limits, concurrency limits, and payload size limits, which we may change to protect the Service. Exceeding them results in throttling, not in a service credit.

11. Suspension and termination

We may suspend or revoke any API key, any MCP session, or your access to the Developer Services immediately and without prior notice where we reasonably believe that:

  • There has been a breach of section 4 or section 5, by you or by an End User;
  • A key has been compromised, or is being used in a way that threatens the security, integrity, or availability of the Service;
  • Continued provision would expose us or a Model Provider to legal, regulatory, or payment-network liability, or would breach a Model Provider's terms;
  • Your usage is generating cost or risk materially out of line with your account's history; or
  • We are required to do so by law, by a regulator, by a payment network, or by a Model Provider.

We will tell you what happened when we reasonably can, and restore access if the concern is resolved. We are not liable to you or to your End Users for any loss arising from a suspension made in good faith under this section, and you remain responsible for informing your End Users. Given how quickly a content-safety problem can escalate at API volume, you accept that we will act first and discuss afterwards.

Either party may terminate these Developer Terms at any time: you by revoking your keys and ceasing to call the Developer Services, and we on 30 days' notice, or immediately for a material breach. Sections 5, 8, 9, 12, 13, 14, and 15 survive termination.

12. Disclaimers

THE DEVELOPER SERVICES ARE PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS, WITHOUT WARRANTY OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.

OUTPUTS ARE GENERATED BY MACHINE LEARNING MODELS AND MAY BE INACCURATE, OFFENSIVE, INCOMPLETE, OR FABRICATED. THEY MAY DEPICT REAL PEOPLE, PLACES, OR EVENTS INCORRECTLY. YOU MUST NOT RELY ON AN OUTPUT AS A STATEMENT OF FACT, AND MUST NOT USE AN OUTPUT AS A SUBSTITUTE FOR PROFESSIONAL ADVICE OR FOR YOUR OWN INDEPENDENT JUDGEMENT, PARTICULARLY IN MEDICAL, LEGAL, FINANCIAL, EMPLOYMENT, OR SAFETY-CRITICAL CONTEXTS.

WE DO NOT WARRANT THAT THE DEVELOPER SERVICES WILL BE UNINTERRUPTED, TIMELY, SECURE, OR ERROR-FREE, THAT ANY MODEL WILL REMAIN AVAILABLE, OR THAT OUTPUTS WILL BE FREE OF THIRD-PARTY RIGHTS. NO SERVICE LEVEL AGREEMENT APPLIES TO THE DEVELOPER SERVICES UNLESS WE HAVE AGREED ONE WITH YOU IN A SIGNED WRITING.

13. Your indemnity

You will defend, indemnify, and hold harmless BudgetPixel, its affiliates, and their officers, employees, and agents from and against any claim, demand, proceeding, loss, liability, damage, fine, penalty, and reasonable legal cost arising out of or relating to:

  • Your Inputs, your Outputs, and your use or distribution of either;
  • Your Application and its operation;
  • Any act or omission of an End User, including any claim brought by an End User;
  • Your breach of these Developer Terms, of a Model Provider's terms, or of applicable law;
  • Any claim that an Input or Output infringes or misappropriates a third party's intellectual property, privacy, publicity, or other right; and
  • Any regulatory investigation or enforcement action arising from your use of the Developer Services.

We will notify you of any claim we seek indemnification for and may participate in its defence with counsel of our choosing at our own expense. You may not settle any claim in a way that imposes an obligation or admission on us without our prior written consent.

14. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY IS LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS OPPORTUNITY, EVEN IF ADVISED OF THE POSSIBILITY.

TO THE MAXIMUM EXTENT PERMITTED BY LAW, OUR TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE DEVELOPER SERVICES, WHETHER IN CONTRACT, TORT, OR OTHERWISE, WILL NOT EXCEED THE GREATER OF (A) ONE HUNDRED UNITED STATES DOLLARS (US$100) AND (B) THE AMOUNTS YOU PAID US FOR THE DEVELOPER SERVICES IN THE THREE MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.

The exclusions and limits in this section do not apply to your obligations under section 13, to either party's liability for fraud or wilful misconduct, or to any liability that cannot be excluded or limited by law.

These limits are an essential basis of the bargain and apply even if a limited remedy fails of its essential purpose. Any claim must be brought within one year of the date you became aware of the facts giving rise to it.

15. Data protection and where your data is processed

Read this section together with Annex A. It is the part of these Developer Terms most likely to matter to your own compliance obligations.

Roles. For personal data contained in Customer Content that you submit on behalf of your own users, you are the controller and we act as your processor, on the terms set out in Annex A. For the personal data of your own BudgetPixel account — your name, email address, billing details, and account activity — we are a controller, and our Privacy Policy applies.

Processing locations. BudgetPixel is operated from the United States and our primary storage is in the United States. Fulfilling a generation request, however, requires sending your Inputs to the Model Provider that serves the model you selected, and our Model Providers operate in a range of jurisdictions. Processing currently takes place in the United States, the European Union, the United Kingdom, and Singapore and other parts of the Asia-Pacific region.

The model you select determines where your Inputs are processed. By calling a model you instruct us to transfer the associated Inputs to that model's Model Provider in that provider's region, and you confirm you have a lawful basis to do so for every person whose personal data the Input contains. We will tell you, on request, which of the regions above applies to a specific model, so that you can decide whether to call it.

We do not currently offer region-restricted processing, and we may change which Model Provider serves a given model, including to a provider in a different one of the regions listed above. If your Application cannot lawfully send data outside a particular jurisdiction, contact us before building on the Developer Services.

Transfer safeguards. For transfers of personal data out of the EEA, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss addendum as applicable, together with the transfer mechanisms our Model Providers maintain. Details are in Annex A, section A7.

Prohibited categories. Unless we have agreed otherwise in writing, you must not submit special categories of personal data (Article 9 GDPR), personal data of children, government identification numbers, payment card data, or protected health information through the Developer Services.

16. Confidentiality and publicity

Each party will protect the other's non-public information disclosed in connection with the Developer Services with at least reasonable care, and will use it only for the purposes of these Developer Terms. This does not apply to information that is public, independently developed, lawfully received from a third party, or required to be disclosed by law.

Neither party may use the other's name or logo publicly without prior written consent, except that we may identify you as a user of the Developer Services in a customer list if you tell us you are happy for us to.

17. Changes to these Developer Terms

We may update these Developer Terms. Each version carries a version number, shown at the top of this page and recorded against your acceptance.

For material changes — including a change to acceptable use, to liability, or the addition of a new processing region or category of sub-processor — we will increment the version, give at least 30 days' notice by email and in the developer console, and require you to accept the new version before you create your next API key or continue using the MCP connector. Non-material changes, such as corrections and clarifications, do not change the version.

Your existing API keys continue to operate under the version you accepted until you accept a new one or we tell you otherwise.

18. General

Governing law and disputes. These Developer Terms are governed by the laws of the State of California, and the governing-law, informal-resolution, binding-arbitration, and class-action-waiver provisions of our Terms of Service apply to any dispute arising under them.

Assignment. You may not assign these Developer Terms without our written consent, except to a successor of your business. We may assign them to an affiliate or in connection with a merger, acquisition, or sale of assets.

Independent contractors. Nothing here creates a partnership, joint venture, agency, or employment relationship.

Entire agreement and severability. These Developer Terms, together with Annex A, our Terms of Service, and our Privacy Policy, are the entire agreement about the Developer Services. If any provision is held unenforceable, the rest remains in effect.

Contact. support@budgetpixel.com. For data protection matters, write to the same address with "Data Protection" in the subject line.

Annex A — Data Processing Addendum

Incorporated into and forming part of the Developer API Terms above.

A1. Roles, scope, and duration

This Data Processing Addendum ("DPA") forms part of the Developer Terms and applies where, in your use of the Developer Services, you submit personal data on behalf of your own users and are the controller of it. In that processing, you are the controller and BudgetPixel is your processor. Where we determine the purposes of processing — your own account, billing, security, and abuse prevention — we act as a controller and our Privacy Policy governs.

This DPA applies for as long as we process personal data on your behalf, and its obligations survive termination for as long as we retain any of that data.

Where terms are defined in Regulation (EU) 2016/679 (GDPR), the UK GDPR, or the Swiss Federal Act on Data Protection, they have the same meaning here.

A2. Details of processing (Annex I equivalent)

Subject matter and nature. Receiving Inputs, transmitting them to the selected Model Provider, generating Outputs, storing Customer Content, and returning it to you, together with the logging, metering, security, and abuse-prevention activity necessary to operate the Developer Services.

Purpose. To provide the Developer Services you have requested.

Duration. For the term of the Developer Terms, plus the retention windows described in our Privacy Policy and in section A11 below.

Categories of data subject. Your End Users; any individual depicted in, described by, or identifiable from an Input or Output you submit or generate.

Categories of personal data. Any personal data you choose to include in an Input — including images and video of individuals, voice recordings, names and other identifiers appearing in prompts, and the personal data contained in the Outputs generated from them — together with the technical metadata of your requests, such as API key identifier, timestamps, IP address, request parameters, and model identifiers.

Special categories. Not permitted. Section 15 of the Developer Terms prohibits submitting Article 9 data, children's personal data, government identifiers, payment card data, and health records without our prior written agreement. Biometric data may be inherent in facial imagery you submit; you are responsible for the lawful basis for it.

Frequency. Continuous, on your instruction, for as long as your Application makes calls.

A3. Processing on documented instructions

We will process personal data only on your documented instructions, which consist of the Developer Terms, this DPA, the Documentation, and the API calls you make — including your selection of a model, which is your instruction to transfer the associated Inputs to that model's provider in its region.

We will process personal data outside your instructions only where required by law, and where permitted will inform you first.

We will inform you if, in our opinion, an instruction infringes applicable data protection law. We may decline to act on an instruction that would.

A4. Confidentiality of personnel

We ensure that personnel authorised to process personal data are bound by an appropriate duty of confidentiality, are granted access on a least-privilege basis limited to what their role requires, and receive training appropriate to their access.

A5. Security measures (Annex II equivalent)

We implement technical and organisational measures appropriate to the risk, as required by Article 32 GDPR. These currently include:

  • Encryption of personal data in transit using TLS, and encryption at rest for stored Customer Content and database contents;
  • Storage of API keys as salted one-way hashes only, so that the credential cannot be reconstructed from our database;
  • Delivery of private media through signed, short-lived URLs rather than public object storage;
  • Role-based access control, least-privilege service identities, and multi-factor authentication for administrative access;
  • Network segregation of application, database, and worker components, with databases not exposed to the public internet;
  • Logging of access and administrative action, with retention sufficient for investigation;
  • Automated content-safety scanning designed to detect and block prohibited material;
  • Backup and restoration procedures, and a documented incident response process;
  • Vendor review of Model Providers before onboarding, including their security and data-handling posture.

We may update these measures over time, provided we do not materially reduce the level of protection.

A6. Sub-processors

You give us general written authorisation to engage sub-processors. We engage sub-processors in the following categories: AI model inference providers; cloud hosting, compute, and object storage; content delivery; payment processing; transactional email delivery; and bot and abuse prevention.

The identity of our sub-processors is our confidential business information and we do not publish it. We maintain a current list stating each sub-processor, the purpose it serves, and the region in which it processes, and we will provide that list to you on written request to support@budgetpixel.com, subject to a confidentiality agreement. Once you have requested it, we will keep you on the notification list described below.

We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

We will give at least 30 days' notice before a change to our sub-processors that introduces a new processing region or a new category of sub-processor, by email to developers with an active API key. We will notify developers who have requested the sub-processor list of any change to that list, on the same notice period. You may object on reasonable data-protection grounds within the notice period. If we cannot resolve your objection, you may terminate the Developer Terms and stop using the Developer Services, which is your sole remedy. Where a change is required urgently for security or continuity, we may make it immediately and notify you promptly afterwards.

A7. International transfers

Providing the Developer Services necessarily involves transferring personal data internationally, because our Model Providers operate in several jurisdictions. Section 15 states the regions in which processing takes place, and section A6 describes how to obtain the per-sub-processor detail.

For transfers of personal data from the EEA to a country without an adequacy decision, the parties incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914). Module Two (controller to processor) applies where you are a controller, and Module Three (processor to processor) applies where you are yourself a processor. Clause 7 (docking) applies; Clause 9 option 2 (general written authorisation) applies with the 30-day notice period in section A6; Clause 11 does not include the optional independent dispute resolution body; Clause 17 selects the law of Ireland; Clause 18(b) selects the courts of Ireland. Annex I and Annex II of the SCCs are populated by sections A2 and A5 above and by the sub-processor list provided under section A6.

For transfers from the United Kingdom, the SCCs apply as amended by the UK International Data Transfer Addendum (version B1.0), with the Addendum's Tables completed by reference to this DPA. For transfers from Switzerland, the SCCs apply with references to the GDPR read as references to the Swiss FADP, the Swiss Federal Data Protection and Information Commissioner as supervisory authority, and "member state" read so as not to deprive a data subject in Switzerland of the right to sue in their place of habitual residence.

Where a Model Provider maintains its own transfer mechanism, that mechanism applies to the onward transfer in addition to the above.

We will notify you if we become subject to a law that prevents us from meeting these obligations, and will assist you in assessing transfer risk on reasonable request.

A8. Data subject rights

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data subject rights.

If we receive a request directly from one of your End Users about data we process on your behalf, we will not respond to it substantively and will refer them to you, notifying you without undue delay unless prohibited by law.

You can delete Customer Content through the API and the developer console, which is normally the fastest route to fulfilling an erasure request.

A9. Personal data breach

We will notify you without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting personal data we process on your behalf.

The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned where known, the likely consequences, the measures taken or proposed, and a contact point. Where we cannot provide all of it at once, we will provide it in phases without undue delay.

We will cooperate with you and take reasonable steps to assist in your investigation, mitigation, and any notification you must make to a supervisory authority or to data subjects. Our notification is not an acknowledgement of fault or liability.

A10. Data protection impact assessments

We will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities relating to the Developer Services, taking into account the nature of the processing and the information available to us. Assistance beyond providing our published documentation may be chargeable.

A11. Deletion and return

On termination of the Developer Terms, or on your written request, we will delete the personal data we process on your behalf, unless applicable law requires us to retain it.

You may export Customer Content through the API before termination; exercise that option first, because deletion is not reversible.

Two exceptions apply. Backups age out on their ordinary rotation rather than being individually purged, and remain subject to this DPA until they do. Material identified as child sexual abuse material, and the associated account information, is preserved and reported as United States federal law requires, regardless of any deletion request.

A12. Audits

We will make available the information reasonably necessary to demonstrate compliance with this DPA, ordinarily by providing our security documentation and by responding to a reasonable security questionnaire no more than once in any twelve-month period.

Where that is genuinely insufficient for you to meet a legal obligation, you may conduct an audit, at your own cost, no more than once in any twelve-month period, on at least 30 days' written notice, during business hours, without disrupting our operations, through an independent auditor who is not our competitor and who is bound by confidentiality. A supervisory authority may audit where it has the power to do so, without these limits.

A13. Liability and precedence

Each party's liability under this DPA is subject to the exclusions and limits in section 14 of the Developer Terms, to the extent permitted by applicable law.

In the event of a conflict between this DPA and the rest of the Developer Terms in relation to the processing of personal data, this DPA prevails. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.