How Rastock AI processes personal data on your behalf, including sub-processors and data transfer terms.
Data Processing Agreement (DPA)
Data protection and privacy framework for enterprise and professional customers
Rastock AI is committed to responsible data processing, privacy-by-design principles, and transparency in how personal data is handled across our platform, services, and browser extensions.
This page provides an overview of our Data Processing Agreement (DPA) framework and explains how Rastock AI processes personal data when acting as a data processor on behalf of customers.
Our DPA framework defines:
The scope and purpose of data processing
Roles and responsibilities of customers and Rastock AI
Security and confidentiality obligations
Procedures for handling data subject requests
Formal, executed Data Processing Agreements are provided during enterprise onboarding or upon request in a commercial or contractual context.
and determines the purpose and means of processing personal data.
and processes data only on documented instructions from the customer.
Rastock AI does not determine independent purposes for personal data processing.
Rastock AI processes uploaded image files to generate AI-powered metadata for stock photography and creative platforms.
Image files, generated titles, descriptions, keywords, and tags
Metadata generation and workflow automation
Data is retained only as necessary to provide the service or as configured by the customer.
Account & Service Management
Personal data may be processed to operate and support customer accounts.
Contact information, account identifiers, subscription or token-related data
Service delivery, customer support, billing coordination, and compliance
For the duration of the customer relationship and as required by applicable laws.
Rastock AI applies appropriate technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, or loss.
Encrypted data transmission (HTTPS/TLS)
Access controls and internal authorization policies
Limited data access based on operational necessity
While no system can guarantee absolute security, Rastock AI follows industry best practices appropriate to the nature and scope of data processed.
Rastock AI engages sub-processors to support infrastructure, hosting, analytics and payment processing. Those currently in use include Stripe (payments), Google Analytics 4 and Microsoft Clarity (website analytics, United States) and Yandex Metrica (website analytics, Russian Federation). Website analytics tools are only loaded for visitors who accept analytics cookies.
Sub-processors are bound by confidentiality and data protection obligations
Personal data is shared only to the extent necessary to deliver the service
Sub-processor engagement follows a risk-based assessment approach
Details may be provided during enterprise discussions or contractual review.
Data Subject Rights Support
Where required by applicable law, Rastock AI assists customers in responding to data subject requests, including access, correction, deletion, and portability. Requests are handled in cooperation with the customer, who remains responsible as the Data Controller.
Personal data may be processed or stored in jurisdictions outside the customer’s country. Where applicable, Rastock AI applies appropriate safeguards to support lawful cross-border data transfers in accordance with relevant data protection regulations.
Compliance Position (Early-Stage Disclosure)
Rastock AI aligns its data processing practices with recognized privacy and security principles, including GDPR and U.S. privacy requirements.
Formal certifications (such as SOC 2 or ISO 27001) are not currently in place. These frameworks are part of our long-term compliance and security roadmap. This disclosure is provided to ensure transparency and avoid overstating current compliance status.
Audit & Contractual Requests
Enterprise customers may request additional information regarding data processing practices during procurement, legal review, or contract negotiations. Any audits or contractual adjustments are subject to reasonable limitations and mutual agreement.
For questions related to data processing, privacy, or enterprise compliance, please contact: