Data Processing Agreement
Data Processing Agreement of Dreamdrive, operated by Synthetic White AB. Version 1.0, effective 3 October 2026.
1. Parties and how this agreement applies
This Data Processing Agreement ("DPA") is between Synthetic White AB, company registration number 559519-7665, [STREET ADDRESS], Stockholm, Sweden ("Dreamdrive", the "Processor") and the customer who uses the Dreamdrive service for business purposes (the "Customer", the "Controller").
This DPA applies automatically and forms part of the Terms of Service whenever the Customer uses the Service for business purposes. It governs the processing of personal data that the Customer puts into the Service and for which the Customer is the controller ("Customer Personal Data"). The Customer may request a signed copy by emailing info@dreamdrive.ai; the signed copy has the same content.
This DPA does not cover personal data that Dreamdrive processes as a controller (the Customer's own account data, billing data, usage events and server logs), which is described in the Privacy Policy.
2. Definitions
"GDPR" means Regulation (EU) 2016/679. "Data Protection Law" means the GDPR, the Swedish Data Protection Act (2018:218) and any other data protection law that applies to the processing. "Personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR. "Subprocessor" means a processor engaged by Dreamdrive to process Customer Personal Data. "SCCs" means the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914. "Service" has the meaning given in the Terms of Service.
3. Roles
The Customer is the controller of Customer Personal Data and Dreamdrive is its processor. Where the Customer is itself a processor for a third party, the Customer warrants that its instructions to Dreamdrive are consistent with the instructions of that third party, and Dreamdrive is a subprocessor.
4. Scope and instructions
- Dreamdrive processes Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to third countries, unless required to do so by EU or Member State law. In that case Dreamdrive will tell the Customer before processing, unless the law prohibits it on important grounds of public interest.
- The Customer's instructions are: this DPA, the Terms of Service, the Customer's use of the Service and its settings (for example creating a capture, a project, a share link or an export), and any further written instructions agreed between the parties. Annex I describes the processing.
- Dreamdrive will tell the Customer immediately if, in its opinion, an instruction infringes Data Protection Law. Dreamdrive is not obliged to carry out a legal review on the Customer's behalf.
- Dreamdrive will not use Customer Personal Data for its own purposes, will not sell it, and will not use it to train machine-learning models.
5. The Customer's responsibilities
The Customer is responsible for the lawfulness of the Customer Personal Data it records (for example having a basis to record a client's or approver's name), for providing any information required to data subjects, for its own compliance with the terms of the AI platforms it connects, and for the content it chooses to make public through share links.
6. Confidentiality
Dreamdrive ensures that people authorised to process Customer Personal Data have committed themselves to confidentiality or are under a statutory duty of confidentiality, and that access is limited to what each person needs to perform their role.
7. Security
Dreamdrive implements the technical and organisational measures in Annex II, taking into account the state of the art, costs, the nature, scope, context and purposes of processing and the risk to data subjects. Dreamdrive may update the measures from time to time provided the overall level of protection is not reduced.
8. Subprocessors
- The Customer gives Dreamdrive general written authorisation to engage the subprocessors listed in Annex III and at Subprocessors.
- Dreamdrive will give the Customer at least 30 days' notice before adding or replacing a subprocessor, by updating the Subprocessors page and emailing customers who have asked to be notified at info@dreamdrive.ai. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Service and receive a pro-rata refund of prepaid fees for the remaining period.
- Dreamdrive imposes on each subprocessor, by written contract, data protection obligations that provide at least the same level of protection as this DPA, and remains fully liable to the Customer for the subprocessor's performance.
9. Assisting with data subject requests
Taking into account the nature of the processing, Dreamdrive will assist the Customer with appropriate technical and organisational measures in fulfilling its obligation to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). The Service lets the Customer view, edit, export and delete its records directly. If Dreamdrive receives a request directly from a data subject about Customer Personal Data, it will not respond on the merits but will pass the request to the Customer without undue delay, to the extent it can identify the Customer.
10. Personal data breaches
Dreamdrive will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point, so far as this information is available; information may be provided in phases. Dreamdrive will cooperate with the Customer and take reasonable steps to mitigate the effects of the breach.
11. Impact assessments and prior consultation
Dreamdrive will provide reasonable assistance to the Customer with data protection impact assessments and prior consultation of a supervisory authority, taking into account the nature of the processing and the information available to Dreamdrive.
12. Deletion and return
At the end of the provision of the Service, Dreamdrive will delete all Customer Personal Data within 30 days of account deletion and remove it from backups within 90 days, unless EU or Member State law requires storage. Before deletion the Customer can export its data from the Service (images, CSV, JSON) or ask Dreamdrive for a copy. Share links stop working on account deletion.
13. Audits and information
- Dreamdrive will make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, including this DPA, the Security Overview, the Subprocessors list and relevant documentation from its subprocessors (such as Cloudflare's compliance reports).
- If the information is not sufficient, the Customer, or an independent auditor bound by confidentiality and mandated by the Customer, may audit Dreamdrive's compliance once in any 12-month period, or additionally where a supervisory authority requires it or after a personal data breach, on at least 30 days' written notice, during normal business hours, in a way that does not unreasonably disrupt Dreamdrive's business or compromise the security of other customers. The Customer bears its own costs and reimburses Dreamdrive's reasonable costs for time spent beyond one working day per audit.
- Audits of subprocessors are satisfied by the subprocessor's third-party audit reports and certifications.
14. International transfers
- Dreamdrive stores Customer Personal Data in the European Union. Dreamdrive will not transfer Customer Personal Data outside the EU or EEA, or permit a subprocessor to do so, except to a country covered by an adequacy decision, under the SCCs, or under another transfer mechanism recognised by Chapter V GDPR. Annex III states the mechanism for each subprocessor.
- Where the Customer is established in a third country and the Customer's disclosure to Dreamdrive is treated as a restricted transfer under the law that applies to the Customer, the SCCs (Module Two or Module Three as applicable) are incorporated into this DPA by reference, with the Customer as data exporter and Dreamdrive as data importer; the optional docking clause does not apply; option 2 of clause 9 (general authorisation, 30 days' notice) applies; the optional wording in clause 11 does not apply; clause 17 option 1 and clause 18 select the law and courts of Sweden; and Annexes I to III of this DPA populate Annexes I to III of the SCCs. The UK International Data Transfer Addendum applies in the same way where UK law so requires.
15. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, to the extent permitted by Data Protection Law. Nothing in this DPA limits either party's liability to data subjects or supervisory authorities under Articles 82 to 84 GDPR.
16. Term, precedence and changes
- This DPA applies for as long as Dreamdrive processes Customer Personal Data.
- In case of conflict, this DPA prevails over the Terms of Service on matters of personal data processing, and the SCCs prevail over this DPA where they apply.
- Dreamdrive may update this DPA to reflect changes in law or in the Service, with notice to the Customer as for changes to the Terms of Service, provided the level of protection is not reduced. Changes required by law may take effect immediately.
- This DPA is governed by the law of Sweden.
Annex I. Description of the processing
A. Parties
Data exporter / controller: the Customer, identified by the account details held in the Service. Data importer / processor: Synthetic White AB, [STREET ADDRESS], Stockholm, Sweden, info@dreamdrive.ai.
B. Subject matter
Provision of the Dreamdrive service: a Chrome extension and web service that records the Customer's own generative-AI work (prompts, settings, result references, thumbnails) and organises it into projects, approval trails and usage sheets.
C. Nature and purpose
Collection via the Customer's browser on platforms the Customer connects or from files the Customer imports; storage; organisation; retrieval and search; display to the Customer; export (images, CSV, JSON); display to third parties at share links the Customer creates; deletion. The purpose is to give the Customer a record of its AI work and to produce client-facing usage documentation.
D. Categories of data subjects
- The Customer's staff and contractors who use the Service.
- The Customer's clients and their staff, where named in projects, approvals or notes.
- Any other person mentioned in a prompt, note, file name or metadata that the Customer records.
E. Categories of personal data
- Names (client names, approver names), email addresses where the Customer records them.
- Prompt text, negative prompts, notes and ratings, which may incidentally contain personal data.
- Result image URLs and thumbnails, which may incidentally depict people.
- Timestamps, platform and model names, page URLs and titles, embedded file metadata.
Special categories of data are not intended to be processed. The Customer undertakes not to record such data deliberately.
F. Frequency and duration
Continuous, for the duration of the Customer's use of the Service, with deletion as set out in section 12.
G. Competent supervisory authority
The Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), or the authority of the Member State where the Customer is established.
Annex II. Technical and organisational measures
- Encryption in transit: all connections between the extension, browser, API and website use TLS; plain HTTP is not served.
- Encryption at rest: data in Cloudflare D1, R2 and KV is encrypted at rest by Cloudflare; third-party API keys held by the Service are additionally encrypted with AES-GCM using a key derived from a secret that is not stored with the data.
- Data location: database with EU jurisdiction setting; thumbnail bucket in the EU region.
- Access control: administrative access is limited to the owner's Google account; staff access to customer records is limited to what is needed for operation and support; no shared passwords; secrets kept in the platform's secret store, never in source code.
- Authentication: Google sign-in via OpenID Connect or short-lived six-digit email codes; session tokens are random and revocable; sign-in codes expire within minutes.
- Tenant isolation: every database query is scoped to the authenticated user's account; share tokens are random 32-byte values and are checked for revocation on every request.
- Read-only client: the extension never writes to third-party platforms and reads only on sites the user has granted permission for, reducing the data collected to the user's own work.
- Minimisation: card data never reaches the Service (Stripe hosts the checkout); website analytics use a daily-rotating hash with no cookies; logs are kept for a short period.
- Integrity of payment events: Stripe webhook signatures are verified before any billing change is applied.
- Web security: security headers (content security policy, frame protection, strict transport security, referrer policy); input validation on the API; same error format with no sensitive detail leaked.
- Availability and recovery: hosted on Cloudflare's distributed network; database backups and point-in-time recovery as provided by the platform; configuration in version control.
- Change management: changes deployed from version control; type-checked builds; remote configuration for the extension carries data (such as page selectors), not executable code.
- Subprocessor management: written data processing terms with each subprocessor; 30 days' notice of changes.
- Incident response: incidents are logged, assessed and notified as described in section 10.
- Deletion: account deletion within 30 days of request, backups within 90 days; export available beforehand.
Annex III. Subprocessors
| Subprocessor | Purpose | Location of processing | Transfer safeguard |
|---|---|---|---|
| Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA (and Cloudflare EMEA affiliates) | Hosting of API and website (Workers, Pages), database (D1), object storage for thumbnails (R2), key-value storage (KV), DNS and network security | Data stored in the EU; global edge network terminates connections; limited remote access from the USA for support and operations | Cloudflare Data Processing Addendum including EU SCCs; EU-US Data Privacy Framework certification |
| Resend, Inc., USA | Transactional email (sign-in codes, receipts, service notices) | USA and EU | Data Processing Agreement including EU SCCs |
Possible future subprocessors, not currently used and only ever with prior notice: a model provider (OpenAI, Google, DeepSeek, Groq or OpenRouter) for the opt-in prompt assistant, which would receive prompt text the user chooses to send. Stripe (payments) and Google (sign-in) act as independent controllers and are listed for transparency at Subprocessors.