VERSION 2026-09-27-beta-3 · 27 SEPTEMBER 2026
Studio data processing terms
1. Parties and scope
The studio identified at registration is the controller, or a processor authorized by its own controller. Olga Aleksandrovna Sukhova, Denmark. Email: chumastudiobyelena@gmail.com. The operator acts as processor or subprocessor for personal data in studio content. These terms form part of the service agreement and take priority for that processing. They do not replace the studio's own duties to establish a lawful basis, inform individuals or obtain its client's authorization.
2. Processing description
Subject: hosting and organizing the studio's project file archive. Duration: the service period plus the agreed return and deletion period. Operations: receiving, storing, generating previews, indexing descriptions, retrieving, transmitting to authorized users, correcting and deleting. Optional AI processes text and filenames at the studio's request. The CHUMA room labeling pilot also processes reduced image previews when requested. Data types: project documents, drawings, tables, 3D files, textures, images, embedded metadata, names, professional credits, project descriptions, location and filenames. Individuals: studio users, designers, visualization artists, photographers, clients and people incidentally depicted. Sensitive data and children's personal data must not be intentionally submitted.
3. Instructions and confidentiality
The agreement, user actions and documented support requests are the studio's instructions. The operator processes content only on those instructions, including transfers, unless applicable law requires otherwise; where permitted, the studio will be informed of that requirement beforehand. The operator will inform the studio if an instruction appears to infringe data protection law and may pause that instruction while it is resolved. Anyone authorized to process content must be bound by confidentiality and receive only the access necessary for their role.
4. Technical support
Authorized administrators may access a workspace where necessary to investigate a reported problem, correct project metadata, restore a project from Trash, or address a security incident. This is part of providing support; a separate access permission button is not required. Administrators must record a specific reason and limit access to the affected data. The support interface permits previews and metadata corrections but blocks original and ZIP downloads, uploads, AI requests and permanent deletion. Support actions are logged. Access for curiosity, marketing, portfolio use, sale or model training is prohibited. Viewing a preview necessarily transmits that preview to the administrator's browser. Infrastructure administrators retain technical access beyond these interface controls and are subject to the same purpose and confidentiality restrictions.
5. Security and assistance
Measures include HTTPS, private object storage, separation of workspaces through server authorization, hashed access keys, limited sessions, rate limits, origin checks, and logging of support actions. The operator will assess risks, maintain and test appropriate measures, and give the studio information reasonably required to assess them. The beta is not designed for sensitive or regulated data.
The operator will assist with requests from individuals, security obligations, impact assessments and prior consultation where applicable, taking account of the nature of processing and information available. It will notify the studio of a personal data breach without undue delay after becoming aware, provide available facts, effects and remedial measures, and supplement the notice as information becomes available. It will not wait for a complete investigation before the first notice. Each party remains responsible for its own notifications under law.
6. Subprocessors and transfers
The studio gives general authorization to Cloudflare, Inc. for hosting, database and storage, and, only when AI is requested, OpenRouter, Inc. and the configured Google model endpoint for text inference. Their infrastructure may involve the United States and other countries; EU only processing is not configured. No new direct subprocessor or materially different AI provider will be enabled for studio data without advance notice, normally at least 30 days, and an opportunity to object on reasonable data protection grounds. If no acceptable alternative is available, the studio may stop the affected function or close its account without a penalty.
The operator must bind subprocessors to equivalent data protection obligations and remains responsible for their obligations to the studio. International transfers require a valid Chapter V mechanism and any supplementary measures necessary in the circumstances. A provider's published standard contract alone does not prove that the operator has completed all account specific checks. Current supplier documentation is linked below.
7. Accountability and audit
The operator will make available information necessary to demonstrate compliance with these terms and allow and contribute to proportionate audits, including inspections, by the studio or its mandated auditor. Arrangements must protect other customers' information and service security; they must not prevent legally required audits or regulator access. Contact the operator to arrange a review.
8. Return and deletion
At the end of the service, the studio may choose return or deletion of content. Original files and metadata are available in common formats as described in the terms. Remaining live copies are normally removed within 30 days after the agreed retrieval period. The operator will confirm completion and the handling of restricted backup copies. Any legally required retention is limited to its specific purpose, with access restricted. Deleted content must not silently reappear following recovery from a backup.
Supplier documentation
Cloudflare DPA · Cloudflare subprocessors · OpenRouter DPA · OpenRouter privacy controls