Skip to content

Data Processing Agreement

DIKA DESIGN LTD, a company registered in England and Wales under company number 16251779, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Contact: hello@dika.design.

Effective 20 August 2026. We will tell you before a material change takes effect.

This agreement applies where you use Dika Studio to process personal data for which you are the controller: for example, customer records you import, contacts in a marketing list, or personal data inside content you upload. It forms part of the Terms of Service and takes effect automatically when you use the product for that purpose. If your organisation needs it signed, write to hello@dika.design.

1. Roles

For your account data and for how we run the service, we are the controller and the Privacy Policy applies. For personal data you bring into the product about your own customers or contacts, you are the controller and we are the processor.

2. Scope

  • Subject matter: providing Dika Studio.
  • Duration: for as long as your account exists, plus any deletion period stated below.
  • Nature and purpose: storage, editing, generation, automation, publishing and delivery, as instructed by you through your use of the features.
  • Types of data: whatever you choose to put in. Typically names, email addresses, telephone numbers, addresses, images and free text.
  • Data subjects: your customers, contacts, staff and anyone depicted in content you upload.

3. Our obligations

  • We process this data only on your documented instructions, which include your use of the product's features, unless the law requires otherwise, in which case we tell you before we act unless the law forbids it.
  • Everyone with access is bound by confidentiality.
  • We keep appropriate technical and organisational security measures, described in section 5.
  • We help you respond to data subject requests and to your own obligations on security, breach notification and impact assessments, so far as the product allows.
  • On termination we delete the data as described in section 7.
  • We make available the information you need to show compliance with this agreement.

4. Sub-processors

You authorise us to use sub-processors. The current list is published and kept up to date at Subprocessors, and the groups are set out in the Privacy Policy. We impose data protection obligations on each of them no less protective than these, and we remain responsible to you for what they do. We will give notice before adding a new one, and you may object on reasonable data protection grounds.

5. Security

  • Traffic is encrypted in transit. Support content, stored provider keys and encrypted storage folders are encrypted at rest.
  • Access to production systems is restricted, authenticated and audited; staff accounts require a second factor.
  • Administrative actions are recorded in an audit log that the customer can read.
  • Backups are taken, verified by restore drills, and encrypted where a key is configured.
  • Team workspaces support per-member permissions, per-member storage and AI ceilings, and suspension without data loss.

6. Personal data breach

If we become aware of a breach affecting your data, we notify you without undue delay and in any case within 72 hours, with what we know: what happened, which categories and roughly how many records, the likely consequences and what we are doing about it. We update you as we learn more.

7. Deletion and return

You can export your data at any time from the product. When your account is deleted, your data is removed after the 30-day recoverable period, except for billing records we are legally required to keep. On request we will confirm deletion in writing.

8. International transfers

Our infrastructure is in the European Union. Where a sub-processor, in particular an AI provider, processes data outside the UK and the EU, we rely on the UK International Data Transfer Addendum, the European Commission's standard contractual clauses, or an adequacy decision, as applicable.

9. Audit

On reasonable written notice, and no more than once a year unless a regulator requires otherwise, we will answer a reasonable audit questionnaire and provide the documentation we hold. On-site audits are by agreement.