Data Processing Addendum

Last Updated:
July 17, 2026

This Data Processing Addendum ("DPA") applies where Reer, Inc. ("Reer," "we," or "us") processes personal data on behalf of a customer on a paid plan ("Customer," "you") in connection with the Reer Services. This DPA is incorporated into and forms part of Reer's Terms of Service. For Team plans, the Team Admin accepts this DPA on behalf of the whole team, and it covers all seats under that team account.

This DPA is intended to meet the requirements for processor contracts under the GDPR, UK GDPR, and similar data protection laws, where applicable to your use of the Services.

1. Definitions

"Customer Personal Data" means personal data that you submit to or process through the Services, such as personal data contained in project files, workspace content, comments, or account information about your own team members, clients, or project stakeholders.

"Data Protection Law" means applicable data protection and privacy laws governing the processing of Customer Personal Data, including the GDPR, UK GDPR, and Swiss Federal Act on Data Protection, where applicable.

The terms "controller," "processor," "personal data," "processing," and "data subject" have the meanings given under applicable Data Protection Law.

2. Roles of the Parties

For Customer Personal Data, you are the controller and Reer is the processor. Reer acts as an independent controller for account, billing, and security data that we collect directly to operate our business, as described in our Privacy Policy.

You're responsible for determining the purposes and lawful basis for processing Customer Personal Data, for providing any required notices to the individuals concerned, and for ensuring you have the right to submit their personal data to the Services.

3. Scope of Processing

You instruct Reer to process Customer Personal Data to:

Reer will process Customer Personal Data only on these instructions, on your other documented instructions, or as required by law.

4. No Training on Customer Personal Data

Reer does not use Customer Personal Data, including project files or design content, to train or fine-tune AI models. This applies across all paid plans. Any use of aggregated or anonymized data to improve our own Services is limited to data that no longer identifies you or the individuals whose data appears in your content.

5. Confidentiality

Reer ensures that personnel authorized to process Customer Personal Data are subject to confidentiality obligations, and that access is limited to what's needed to provide, secure, and support the Services.

6. Security Measures

Reer implements technical and organizational measures designed to protect Customer Personal Data, including encryption in transit and at rest and access controls limiting internal access, consistent with the practices described in our Privacy Policy.

7. Subprocessors

You authorize Reer to engage subprocessors to provide the Services, including hosting and infrastructure providers, AI model providers used for inference, payment processors, and email delivery providers. Reer enters into written agreements with subprocessors that impose data protection obligations consistent with this DPA. Where Reer engages a new subprocessor that will process Customer Personal Data, we'll provide reasonable notice, and you may raise objections on reasonable data protection grounds within 30 days.

Reer's AI model providers are subject to their own data processing terms, which include commitments not to use Customer Personal Data to train or fine-tune their models and to limit retention of prompts, files, and outputs to what's needed to provide the inference service or as required by law. Reer passes these protections through to Customer Personal Data processed via the Services.

8. International Transfers

Where Reer transfers Customer Personal Data from the EEA, UK, or Switzerland to a country not recognized as providing an adequate level of protection, Reer relies on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, where applicable.

9. Data Subject Requests

Reer will provide reasonable assistance to help you respond to requests from individuals seeking to exercise their rights under Data Protection Law regarding Customer Personal Data. If Reer receives such a request directly, we may direct the individual to you, unless we're required by law to respond directly.

10. Security Incident Notification

Reer will notify you without undue delay after becoming aware of a security incident affecting Customer Personal Data, including information reasonably available to us to help you meet your own notification obligations.

11. Return and Deletion

Upon termination of your paid plan or upon your documented request, Reer will delete or return Customer Personal Data in accordance with the Services' functionality and applicable law, except where we're required to retain it for legal, security, or backup purposes, in which case it remains protected under this DPA until deleted.

12. Audits

Reer will provide information reasonably necessary to demonstrate compliance with this DPA, such as security summaries or relevant documentation. Any audit request should be reasonable in scope, subject to confidentiality, and limited to once per year unless required by law or following a confirmed security incident.

13. Your Obligations

You're responsible for ensuring that Customer Personal Data you submit to the Services is accurate and lawfully obtained, for providing required notices and consents to the individuals concerned, and for not submitting special category data, children's data, or other high-risk personal data unless we've agreed to that in writing.

14. Precedence

If this DPA conflicts with the Terms of Service or Privacy Policy regarding the processing of Customer Personal Data, this DPA controls.

15. Contact Us

Questions about this DPA? Reach us at hello@reer.co.