Legal
Data Processing Addendum
Effective date: September 18, 2026
This Data Processing Addendum (“DPA”) is part of the VisibleIO Terms of Service. It applies when VisibleIO processes personal data on your behalf as a processor (or service provider) so you can use the CMS, Viewer, Blender plugin, embeds, and related hosting. Print or save this page as a PDF. Privacy requests: privacy@visibleio.com.
01Parties and roles
VisibleIO Limited (“VisibleIO,” “we,” “us,” or “our”) is a limited company incorporated in Hong Kong Special Administrative Region. Business Registration Number: 80883395. Registered address: Room D, 16/F, DAN6, 2-6 Fui Yiu Kok Street, Tsuen Wan, Hong Kong. Official website: https://visibleio.com. Privacy contact: privacy@visibleio.com.
You (the account holder, or the organization you represent) are the controller (or “business”) for personal data you submit to the Services or that end users generate in your published Viewer experiences. VisibleIO is the processor (or “service provider”) for that customer data. VisibleIO remains the controller for its own account, billing, security, and website data, as described in the Privacy Policy.
If you use the Services as an individual for your own professional work, you are still the controller of project and Viewer data you put in the account.
02Subject matter, duration, and nature
Subject matter: hosting and operating the VisibleIO platform so you can create, store, render, configure, share, and embed 3D product experiences.
Duration: for the life of your account and any retention period in the Privacy Policy after deletion or termination.
Nature: storage, transmission, display, rendering, logging, support, backup, and security processing. VisibleIO does not sell customer personal data and does not use your Blender scenes or commercial project assets to train public generative AI models.
03Types of personal data and data subjects
Depending on how you use the Services, this may include:
- Account users: name, email, hashed credentials, locale, workspace role, and support messages.
- Billing contacts (when paid billing is enabled): legal name or company name, billing address, country, tax ID, invoices, and payment-provider identifiers. VisibleIO does not store full card numbers.
- Project content: files, scene metadata, materials, renders, thumbnails, and configuration logic you upload. This includes personal data only if you put it there.
- Viewer / embed end users: IP address (which may be truncated), device and browser data, and interaction events needed to deliver the Viewer and your analytics.
- Data subjects: your team members, your clients, and visitors to your public links or embeds.
04Instructions and your responsibilities
VisibleIO will process customer data only on your documented instructions, which are: (a) this DPA and the Terms; (b) your use of the product settings (for example visibility, embeds, and member access); and (c) written instructions you send to privacy@visibleio.com that we accept. We will tell you if we believe an instruction violates applicable data-protection law.
You are responsible for a lawful basis to process end-user data in your embeds, for your own privacy notice, and for not uploading special-category data unless you have a lawful basis and have told us in writing.
05Security
VisibleIO will implement appropriate technical and organizational measures for the nature of the Services, including access controls, encryption in transit, credential hashing, staff access limited to support and operations, and logging. No internet service is perfectly secure. Report suspected incidents to privacy@visibleio.com.
06Subprocessors
You authorize VisibleIO to use subprocessors needed to run the Services. Current categories include cloud hosting and CDN, object storage, email delivery, and payment processing (currently Stripe for card payments). We remain responsible for subprocessors we appoint.
We will impose written data-protection terms on subprocessors that are no less protective than this DPA. If we add a subprocessor that materially changes where customer data is processed, we will update this DPA or the Privacy Policy. You may object on reasonable data-protection grounds by writing to privacy@visibleio.com and, if we cannot accommodate the objection, you may stop using the affected Services and cancel as described in the Terms.
07International transfers and SCCs
VisibleIO is established in Hong Kong. Infrastructure and subprocessors may process data in other regions (including the United States and the EEA) to deliver the Services.
Where the EU GDPR or UK GDPR requires a transfer mechanism for customer data that VisibleIO processes as processor, the parties agree that the European Commission’s Standard Contractual Clauses (processor-to-processor or controller-to-processor modules as applicable), and the UK International Data Transfer Addendum where required, are incorporated by reference. You are the data exporter; VisibleIO Limited is the data importer. Clause-required details are those in this DPA and the Privacy Policy. A signed paper copy is available on request at privacy@visibleio.com.
08Assistance, incidents, and audits
Taking into account the nature of processing, VisibleIO will assist you with data-subject requests, DPIAs, and consultations with authorities by providing self-serve tools and reasonable support. We will notify you without undue delay after becoming aware of a personal-data breach affecting customer data we process as processor, and will provide information you need to meet your own notification duties.
You may audit VisibleIO’s compliance with this DPA once per 12 months (or after a breach) on 30 days’ written notice, during business hours, and subject to confidentiality. We may satisfy an audit with current security summaries, questionnaire responses, and relevant third-party reports where available. You pay your own costs unless the audit finds a material breach of this DPA.
09Return and deletion
You may export or delete project content through the Services while the account is active. After account closure or a written deletion request, VisibleIO will delete customer data from active systems within 30 days, except backups that expire on the normal backup cycle and data we must keep for law, billing, or dispute resolution. Residual copies are protected at the same level until they expire.
10Liability and order of documents
This DPA is subject to the liability limits, disclaimers, and governing-law clauses in the Terms, except that neither party excludes liability that cannot be limited under data-protection law. If this DPA conflicts with the Terms on data-protection obligations for processor activities, this DPA controls.
Enterprise customers with a signed order or MSA that includes a DPA use that signed document instead of this page for that engagement.
11Contact
Privacy and DPA notices: privacy@visibleio.com. Legal entity: VisibleIO Limited, BR 80883395, Room D, 16/F, DAN6, 2-6 Fui Yiu Kok Street, Tsuen Wan, Hong Kong.
Questions? Contact us at privacy@visibleio.com.
Official website: visibleio.com