Legal
Data processing agreement
The thirds.ai data processing terms, including processing details, security measures, deletion, and the current service-provider list.
Last updated 14 September 2026
thirds.ai is a service run by an individual sole trader in England. The operator uses thirds.ai as a trading name. In this DPA, “thirds.ai” means that operator and the service.
This Data Processing Agreement, or DPA, forms part of the thirds.ai Terms of service when a customer and thirds.ai agree to it. It covers customer content that thirds.ai processes on the customer's behalf. For that content, the customer is the controller and thirds.ai is the processor. A word used in this DPA has the meaning given to it by applicable data protection law.
thirds.ai remains a controller for the account, billing, security, and legal records that it needs to run its own service. The Privacy policy explains that separate processing.
Scope and term
thirds.ai processes personal data in customer content only to provide the service under the customer's written instructions, including the instructions in the Terms of service and the customer's use of the product. This DPA starts when the customer and thirds.ai agree to it. It ends when thirds.ai finishes processing that customer content, except where the law requires a limited record to remain.
If thirds.ai believes an instruction breaks data protection law, it will tell the customer unless the law stops that notice. The customer is responsible for its lawful instructions, notices, permissions, and data.
Processing details
| Detail | Description |
|---|---|
| Subject | Create, edit, render, store, and deliver branded PDFs, static images, and templates. |
| Duration | For the customer's use of the service and the fixed retention periods below. |
| People | The customer's staff, users, clients, recipients, and any person named in customer content. |
| Data | Personal data in prompts, chat text, HTML, template data, source images, brand assets, and rendered files. |
| Operations | Receive, check, store, use, render, transmit, back up where stated, delete, and return through product downloads. |
| Purpose | Provide and secure the customer-content parts of the service. |
Confidentiality and security
thirds.ai limits personal-data access to people and service providers who need it to provide or support the service. They must protect it and keep it confidential.
The service uses HTTPS and TLS for public traffic. It isolates browser rendering from the website and API, uses a fresh browser context for each render, controls remote asset requests, limits resources, keeps customer content out of logs and analytics, checks stored files against SHA-256 records, and uses short-lived signed download links. The Security page describes these measures and the backup boundary.
Sub-processors and other service providers
The customer gives general written permission for the providers below when they act as sub-processors for customer content. Some providers also process account, billing, security, or legal data for thirds.ai as a controller. Each provider gets only the data needed for its listed task.
| Provider | Role and task |
|---|---|
| Hetzner Online GmbH | Sub-processor and live host for the application, database, and file storage in Finland. |
| Cloudflare | Sub-processor for R2 backups; controller service provider for bot checks. |
| OpenRouter | Sub-processor for template-builder prompts, brand details, source images, and model responses. |
| OpenRouter-selected model host | Sub-processor for the same template-builder content. The selected host may train on that content. The route does not promise EU or UK data residency. |
| Resend | Controller service provider for sign-in and account email. |
| GitHub | Controller service provider for identity details when the customer chooses GitHub sign-in. |
| Controller service provider for identity details when the customer chooses Google sign-in. | |
| PostHog Cloud | Controller service provider in the European Union for allowlisted product events under a random analytics ID. It does not receive customer content. |
| Stripe | Controller service provider for checkout, subscription, payment, tax, invoice, and billing records. Stripe receives card details directly. |
thirds.ai will keep this list current and give advance written notice before it adds or replaces a sub-processor. A customer can raise a reasonable data-protection objection through Support before the change. The parties will try to resolve it in good faith. If they cannot, the customer can stop the affected use of the service.
International transfers
Some providers can process data outside the customer's country. Where the law requires a transfer safeguard, the parties use the EU Standard Contractual Clauses and the UK International Data Transfer Agreement or UK Addendum, as applicable. A customer can ask for current transfer information through Support.
Help with customer duties
thirds.ai will give reasonable help with a person's data request, a data protection impact assessment, prior consultation with a regulator, a security assessment, a breach notice, or a regulator question when the request relates to data processed for that customer. The customer remains responsible for its reply and legal duties.
Security incidents
thirds.ai will tell the affected customer without undue delay after it confirms a personal-data breach. The notice will include the known nature and impact of the breach, the steps taken, and the contact path for updates, as far as this information is available and lawful to share.
Return and deletion
The customer can download or ask for the return of its data while it remains available. At the end of the service, thirds.ai deletes or returns personal data as the customer directs, unless the law requires it to remain. thirds.ai deletes render input when a render ends, account outputs after 30 days, and anonymous playground outputs after one hour. It deletes account content through the account-closure process. Backup copies age out as the backup sync and retention process runs.
thirds.ai can keep limited records where the law requires them. Those records do not include customer document content unless a law specifically requires it.
Information and review
thirds.ai will provide information that is reasonably needed to show compliance with this DPA. The customer or its independent auditor can audit and inspect the relevant controls on reasonable written notice and reasonable terms. The parties will first use current security documents and other available proof. Any further review must protect other customers, service security, and confidential information, and must not disrupt the service.
Order of terms
If this DPA conflicts with the Terms of service about processing personal data, this DPA controls that point. The Terms of service control other points, including fees, liability, and governing law.
To request this DPA for your account, email support@thirds.ai.
Ready to make the next file?
Start from a gallery template, change the words to yours, and download the finished file.