Legal

Data Processing Addendum

Last updated: July 18, 2026

This Data Processing Addendum ("DPA") supplements our Terms of Service and applies when ES Impact Ventures LLC, doing business as ColorMatch Assist ("Processor", "we"), processes personal data on behalf of a business customer ("Controller", "Customer") in connection with the Service.

1. Roles

Customer is the Controller of personal data it or its end users submit to the Service. ES Impact Ventures LLC is the Processor and processes that personal data only on documented instructions from the Customer, which include these Terms and this DPA.

2. Scope and purpose

Subject matter: providing the Service. Duration: the term of the subscription. Nature and purpose: hosting, authenticating users, storing photos and verdicts, processing images to generate color-match verdicts, and billing. Categories of data: account identifiers (email, auth ID), user-submitted photos, verdict metadata, support communications, and operational logs. Data subjects: Customer's end users and personnel.

3. Confidentiality

We ensure that personnel authorized to process personal data are bound by confidentiality obligations.

4. Security

We maintain appropriate technical and organizational measures designed to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, damage, or disclosure. These include encryption in transit, access controls, database row-level security, secrets management, and least-privilege administrative access.

5. Subprocessors

Customer authorizes us to engage the following subprocessors to provide the Service:

  • Lovable Cloud — application hosting, database, authentication, file storage.
  • Stripe — subscription billing and payment processing.
  • Google — Sign-in with Google (OAuth).
  • Lovable AI Gateway / Google Gemini — AI verdict generation.

Each subprocessor is bound to data-protection obligations no less protective than those in this DPA. We will provide reasonable prior notice of any new subprocessor and give Customer an opportunity to object on reasonable data-protection grounds.

6. Data-subject requests

Taking into account the nature of the processing, we will provide reasonable assistance so Customer can respond to data-subject requests (access, correction, deletion, objection, portability). Where a data subject contacts us directly about Customer's data, we will refer them to Customer.

7. Personal data breach

We will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer's data, and provide the information reasonably needed for Customer to comply with its own notification obligations.

8. International transfers

Personal data is processed in the United States. Where required by law, transfers will be made using appropriate safeguards, such as Standard Contractual Clauses or an equivalent lawful transfer mechanism.

9. Audit

On reasonable prior written notice, we will make available information necessary to demonstrate compliance with this DPA, and will support audits (including inspections) conducted by Customer or an auditor mandated by Customer, subject to reasonable confidentiality and security constraints.

10. Return or deletion

On termination of the Service, Customer may export or delete personal data through in-app controls. Within a reasonable period after termination we will delete or anonymize remaining Customer personal data, except where retention is required by law.

11. Acceptance

Customer accepts this DPA by using the Service on behalf of an organization. Business customers who require a countersigned copy may request one through /support.

12. Precedence

In the event of a conflict between this DPA and the Terms of Service, this DPA governs with respect to the processing of personal data.

Contact

Contact us through our Support page. Legal entity: ES Impact Ventures LLC, State of Texas, United States.