CM Studio+
For Manufacturers & Formulators
Formulator Ingredient Search Engine™ Marketplace Regulatory Compliance Compare Tools Free Migration Pricing
For Suppliers
The Company
About Us Platform Changelog Blog
Login Sign Up
Login Sign Up

Data Processing Agreement (DPA)

This Data Processing Agreement forms part of the CM Studio+ Terms of Service. Last Updated: August 27, 2026 · Effective Date: September 26, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between CM Studio, LLC (“Processor”) and the business entity utilizing the Services (“Controller”). It applies when the Processor processes Personal Data on behalf of the Controller in connection with the CM Studio+ platform (“Services”).

1. Definitions

  • “Personal Data” means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller.
  • “Applicable Data Protection Law” means the data protection and privacy laws applicable to the processing under this DPA, including the General Data Protection Regulation (EU) 2016/679 and UK GDPR where applicable.
  • “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
  • “Subprocessor” means a third party engaged by the Processor to process Personal Data on behalf of the Controller.

2. Roles, Scope, and Instructions

The customer is the Controller and CM Studio, LLC is the Processor for Personal Data submitted to the Services by or for the Controller. The Controller instructs the Processor to process Personal Data as necessary to provide, secure, support, and maintain the Services and as otherwise documented in the Controller’s use of the Services, the Terms of Service, and this DPA.

The Processor will process Personal Data only on the Controller’s documented instructions, including instructions regarding international transfers, unless applicable law requires otherwise. Where legally permitted, the Processor will inform the Controller before processing required by law. The Processor will promptly inform the Controller if, in its opinion, an instruction infringes Applicable Data Protection Law.

3. Controller Obligations

The Controller is responsible for the lawfulness, accuracy, and quality of Personal Data and its processing instructions. The Controller will provide all notices, obtain all consents and authorizations, and establish all legal bases necessary for the Processor to process Personal Data under this DPA.

4. Confidentiality and Personnel

The Processor will ensure that personnel authorized to process Personal Data are bound by confidentiality obligations and receive access only as necessary to perform their responsibilities.

5. Security Measures

Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, the Processor will maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The measures currently maintained are described in Annex 2.

6. Personal Data Breaches

The Processor will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA. The Processor will provide available information reasonably required for the Controller to meet applicable breach-notification obligations and will take reasonable steps to contain, investigate, and mitigate the breach. Notification does not constitute an admission of fault or liability.

7. Data Subject Requests and Compliance Assistance

Taking into account the nature of the processing, the Processor will provide reasonable assistance through appropriate technical and organizational measures to help the Controller respond to requests from data subjects. If the Processor receives a request directly concerning Personal Data processed on the Controller’s behalf, it will direct the requester to the Controller unless legally prohibited.

Taking into account the nature of processing and information available to it, the Processor will provide reasonable assistance with the Controller’s obligations concerning security, breach notifications, data protection impact assessments, and consultations with supervisory authorities under Applicable Data Protection Law.

8. Subprocessing

The Controller provides general written authorization for the Processor to use the providers listed below. Each provider acts as a Subprocessor under this DPA only to the extent it processes Controller Personal Data on the Processor’s behalf; a provider may have a different legal role for other activities as described in its terms and our Privacy Policy. The Processor will require each Subprocessor to protect Personal Data under written obligations providing a level of protection substantially equivalent to this DPA, to the extent applicable to the services performed. The Processor remains responsible for each Subprocessor’s performance of those obligations as required by Applicable Data Protection Law.

  • Google Cloud: Application hosting, database services, file storage, caching, real-time application services, task processing, and operational logging.
  • OpenAI: AI inference and conversation processing when users invoke AI-powered features.
  • Stripe: Payment, subscription, marketplace payment, and payout processing.
  • Mailgun: Transactional email delivery.
  • Omnisend: Contact synchronization and email or marketing communications.
  • Google Maps Platform: Address autocomplete and place-details services.
  • Google Analytics: Website and product analytics, subject to applicable consent choices.
  • LinkedIn: Advertising and retargeting, subject to applicable consent choices.
  • CookieYes: Cookie-consent management.

The Processor will provide reasonable advance notice of any new or replacement Subprocessor by updating this DPA and, where appropriate, by email or in-product notice. The Controller may object on reasonable data-protection grounds by contacting support@cmstudioplus.com before the change takes effect. The parties will work in good faith to address the objection; if no reasonable alternative is available, the Controller may discontinue the affected Service.

9. International Transfers

The Controller authorizes the Processor and its Subprocessors to process Personal Data in the United States and other countries in which they operate. Where Applicable Data Protection Law restricts an international transfer, the parties will use a legally recognized transfer mechanism, such as applicable Standard Contractual Clauses, together with supplementary measures where required.

10. Return and Deletion

Upon termination of the Services or the Controller’s written request, the Processor will, at the Controller’s choice and subject to applicable law, delete or return Personal Data processed on the Controller’s behalf. Personal Data may remain for a limited period where reasonably necessary to provide export or account-recovery options, comply with legal obligations, resolve disputes, prevent fraud, maintain security, or complete normal backup lifecycles. Data retained for those purposes will remain protected under this DPA and will not be processed for other purposes. Aggregated or de-identified data that no longer constitutes Personal Data may be retained.

11. Information and Audits

The Processor will make available information reasonably necessary to demonstrate compliance with this DPA. Upon reasonable written notice, the Processor will permit and contribute to audits or inspections by the Controller or an independent auditor appointed by the Controller, provided that the audit is limited to relevant systems and records, protects other customers’ information and the Processor’s confidential information, does not unreasonably disrupt operations, and uses existing independent audit reports or certifications where sufficient. These restrictions do not apply where prohibited by Applicable Data Protection Law or a supervisory authority.

12. Order of Precedence and Contact

If this DPA conflicts with the Terms of Service regarding the processing of Personal Data on the Controller’s behalf, this DPA controls. Questions and notices under this DPA may be sent to support@cmstudioplus.com.

Annex 1: Details of Processing

Subject MatterThe provision of a cosmetic formulation, production tracking, AI assistance, and client management SaaS platform.
Nature and PurposeHosting, storing, and analyzing data to facilitate the Controller’s cosmetic production, client relationship management, AI formulation queries, and regulatory compliance.
Categories of Data SubjectsThe Controller’s employees, contractors, and the Controller’s clients/customers whose details are entered into the platform’s CRM or production logs.
Types of Personal DataNames, contact details (email, phone, address), project briefs, AI formulation prompts and chat history, and any other personal data the Controller chooses to input into the platform’s modules.
Sensitive DataThe Services are not intended for special-category or highly sensitive Personal Data unless expressly agreed in writing. The Controller must not submit such data unless it has a lawful basis and has implemented appropriate safeguards.
FrequencyContinuous or as initiated by authorized users during the term of the Services.
DurationFor the term of the Services and thereafter only for the limited purposes and periods described in Section 10.

Annex 2: Technical and Organizational Measures

  • Encryption: Encryption in transit using industry-standard transport security and encryption at rest for primary application data and uploaded files on Google Cloud.
  • Access Control: Authentication, role-based access controls, organization-level data separation, and restricted privileged access.
  • Account Security: Secure session and cookie settings and additional authentication safeguards for sensitive access.
  • Application Security: Input validation, access checks, dependency management, and security-focused testing appropriate to the Services.
  • Availability and Recovery: Managed Google Cloud infrastructure designed to support service availability and recovery.
  • Monitoring: Application and infrastructure logging used to detect, investigate, and respond to operational and security events.
  • Vendor Management: Use of service providers under contractual data-protection and confidentiality obligations.
  • Data Handling: Retention, deletion, and de-identification procedures appropriate to the purpose and lifecycle of the data.
CM Studio+

We are a small team of passion-driven engineers and scientists trying to build better formulator software.

Platform

  • Formulator
  • Ingredient Search
  • Marketplace
  • Compare Tools
  • Platform Changelog

Company

  • About
  • Blog
  • Shop
  • For Suppliers
  • For Consultants

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
© 2026 CM Studio LLC