Data Processing Addendum

Last updated: 12 August 2026

This Data Processing Addendum ("Addendum") forms part of Viewroom's Terms of Service. It applies where the User entrusts Viewroom with personal data relating to other persons, including through the contact book or CSV/XLSX import.

It sets out the parties' commitments under Article 28 of the General Data Protection Regulation ("GDPR"). Legal roles always depend on the facts of each processing activity.


1. Roles of the parties

Where the User determines why contact data is collected and used, the User acts as controller. Viewroom then acts as processor and processes that data solely to provide the requested features and secure them.

Viewroom remains controller for processing activities for which it determines its own purposes, including account management, billing, service security and the strictly aggregate operational measurements described in the Privacy Policy.


2. Description of the entrusted processing

Item Description
Subject matter Provision of the contact book and AI-assisted CSV/XLSX import
Duration Duration of the feature's use and the retention periods stated in the Privacy Policy
Nature of operations Receipt, temporary storage, file reading, structure detection, mapping suggestions, preview, duplicate detection, creation of confirmed rows only, hosting, viewing, editing, export and deletion
Purposes Carrying out the User's instructions and providing contact-management features
Data subjects Contacts, prospects, customers, collectors, partners, suppliers or other persons added by the User
Types of data Name, relationship type, email, phone, company, address, city, country, free-text notes, sheet names and cells selected by the User

The Service is not designed to import special categories of data under Article 9 GDPR, criminal-conviction or offence data, passwords, banking data, or other secrets unrelated to professional contact management. The User undertakes not to import them.


3. User instructions

These Terms, the actions taken by the User in the interface and the User's written requests constitute documented instructions.

Viewroom informs the User if an instruction appears to infringe the GDPR or another applicable rule. If a legal obligation requires processing outside the instructions, Viewroom informs the User before processing unless the law prohibits that notice.


4. Viewroom obligations

Viewroom undertakes to:

  • process data only on the User's documented instructions;
  • restrict access to persons who need it and are bound by confidentiality;
  • apply technical and organisational measures appropriate to the risk;
  • reasonably assist the User with requests for access, rectification, erasure, restriction, portability and objection;
  • assist the User with security, breach handling, impact assessments and authority consultations relating to the entrusted processing;
  • notify the User without undue delay after becoming aware of a breach affecting data processed on the User's behalf;
  • at the end of the service, delete or return the data in accordance with the User's choice and the available export features, subject to legal obligations and documented backup periods;
  • make available the information reasonably necessary to demonstrate compliance with this Addendum and allow a proportionate audit, subject to the security and confidentiality of other customers.

5. No reuse

Viewroom does not reuse any contact value, cell, note, filename, prompt or model output for advertising, direct marketing, profiling, dataset creation, benchmarking, model improvement or AI training.

Such content is processed solely to perform the requested import. Reliability, duration and cost measurements use only technical metadata and counters without contact content.

Any future reuse for Viewroom's own purpose would require a separate decision, a valid legal basis and, where Viewroom acts as processor, the User's specific written authorization.


6. Sub-processors and transfers

The User gives general authorization for Viewroom to engage the sub-processors listed in the Privacy Policy to the extent required to provide the Service.

Viewroom informs active Users of any material change to that list at least 30 days before it takes effect. During that period, the User may submit a reasoned data-protection objection. The parties will then seek a reasonable solution; if none is available, the User may stop using the affected feature or terminate the Service.

Viewroom imposes appropriate data-protection obligations on each sub-processor. Where processing involves a transfer outside the European Economic Area, Viewroom documents the applicable mechanism and any required supplementary safeguards.


7. User responsibilities

The User undertakes to:

  • have a legal basis and the authority required to collect, use and entrust the data to Viewroom;
  • provide the required information to data subjects where that obligation falls on the User;
  • import only data that is adequate, relevant and necessary for the User's purpose;
  • keep the data accurate and handle data-subject requests;
  • not use the Service for any unlawful, discriminatory purpose or any purpose incompatible with the information provided to data subjects.

8. Data disposal and requests

Source files and temporary import artifacts are deleted after confirmation or cancellation and expire no later than 24 hours after upload finalization. Contacts are retained only after the User confirms them. Other retention periods and backup handling are described in the Privacy Policy.

Requests and incidents relating to entrusted data may be sent to contact@viewroom.art. The User must not attach a source file, an unredacted screenshot or raw contact data to a support request.