1. Definitions
“Agreement” means the Terms of Use, order form, subscription agreement, MCP/API agreement, or other written agreement between Customer and Refero. “Customer Personal Data” means personal data that Customer submits to the Service and that Refero processes on Customer’s behalf as a processor or service provider. “Data Protection Laws” means applicable privacy and data protection laws, including GDPR, UK GDPR, Swiss data protection law, the California Consumer Privacy Act as amended, and similar US state privacy laws. “Security Incident” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Refero. It does not include unsuccessful attempts that do not compromise Customer Personal Data, such as blocked attacks, scans, pings, or failed login attempts. “Subprocessor” means a third party engaged by Refero to process Customer Personal Data on behalf of Customer. Capitalized terms not defined here have the meanings given in the Agreement or applicable Data Protection Laws.2. Roles
For Customer Personal Data, Customer is the controller or business, and Refero is the processor or service provider. Customer determines the purposes and means of processing Customer Personal Data. Refero processes Customer Personal Data only on Customer’s documented instructions, including the Agreement, this DPA, Customer’s use of the Service, and Customer’s configuration of features. Refero may process account, billing, security, usage, analytics, support, and business operations data as an independent controller where permitted by law and described in the Privacy Policy (“Service Operations Data”). Customer Personal Data does not include Service Operations Data except where Refero processes that data solely on Customer’s behalf under the Agreement.3. Scope of processing
Refero will process Customer Personal Data to:- provide, maintain, secure, and support the Service;
- operate team, shared workspace, board, bookmark, research chat, upload, MCP, API, and related features;
- process Customer instructions and user requests;
- troubleshoot, prevent abuse, and protect the Service;
- comply with law and enforce the Agreement;
- perform other processing described in Annex A or authorized by Customer.
4. Customer responsibilities
Customer is responsible for:- having a lawful basis to collect, use, and submit Customer Personal Data to the Service;
- providing required notices and obtaining required consents from data subjects;
- ensuring Customer’s instructions comply with Data Protection Laws;
- configuring the Service appropriately for Customer’s intended use;
- not submitting sensitive, regulated, or high-risk data unless the Agreement expressly allows it;
- maintaining appropriate copies or exports of Customer Personal Data where Customer needs an independent backup or archive;
- responding to data subject requests where Customer is the controller, with reasonable assistance from Refero as described below.
5. Refero processing obligations
Refero will:- process Customer Personal Data only on documented instructions from Customer, unless required by law;
- ensure that persons authorized to process Customer Personal Data are subject to confidentiality obligations;
- implement and maintain appropriate technical and organizational security measures;
- assist Customer, taking into account the nature of processing and information available to Refero, with data subject requests and compliance obligations;
- assist Customer, taking into account the nature of processing and information available to Refero, with security, breach notification, data protection impact assessment, and prior consultation obligations where required by Data Protection Laws;
- notify Customer if Refero believes an instruction violates Data Protection Laws, unless prohibited by law;
- delete or return Customer Personal Data after termination of the Service as described in the Agreement, this DPA, and applicable retention practices;
- make available information reasonably necessary to demonstrate compliance with this DPA.
6. Subprocessors
Customer gives Refero general authorization to engage Subprocessors to provide the Service. Refero will require Subprocessors to protect Customer Personal Data under written obligations that are substantially similar to those in this DPA, to the extent applicable to the services they provide. Refero remains responsible for its Subprocessors’ performance of their data protection obligations to the extent required by Data Protection Laws. Current Subprocessor categories and examples may include:- cloud hosting, storage, CDN, and infrastructure providers, such as AWS or similar services;
- database, logging, monitoring, and security providers, such as Bugsnag, New Relic, or similar services;
- payment processors, including Stripe and Lemon Squeezy for legacy subscriptions;
- authentication providers, including Google where users choose Google sign-in;
- email delivery and customer communication providers, such as MailerLite or similar services;
- analytics and product measurement providers, such as Google Analytics, Mixpanel, Microsoft Clarity, or similar services;
- AI routing and model providers, including providers such as OpenRouter, OpenAI, Anthropic, Google, and similar services when Customer uses AI-assisted features. AI routing providers may route requests to downstream model providers;
- support, operations, and professional service providers.
7. Security measures
Refero will maintain reasonable technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. The measures will take into account the nature of the processing, reasonably available technology, implementation costs, and the risks presented by the processing. Refero may update its security measures as the Service evolves, provided that it does not materially reduce the overall level of protection during the term of the Agreement. Refero may provide additional information about current measures on reasonable request, subject to confidentiality and without disclosing information that could compromise security or other customers.8. Security incidents
Refero will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data, as required by applicable Data Protection Laws. Refero will provide information reasonably available to it to help Customer understand the incident and meet applicable notification obligations, and may provide that information in stages as it becomes available. Customer is responsible for determining whether it must notify regulators or data subjects. Refero will provide reasonable assistance where required by applicable Data Protection Laws.9. Data subject requests
Taking into account the nature of the Service, Refero will provide reasonable assistance to Customer in responding to requests from data subjects to exercise rights under Data Protection Laws. If Refero receives a request directly from a data subject relating to Customer Personal Data, Refero may direct the person to Customer or respond if legally required or authorized by Customer.10. Deletion and return
Upon termination or expiration of the Agreement, Refero will delete or return Customer Personal Data as required by Data Protection Laws and the Agreement, unless retention is required or permitted by law. Deletion may be subject to technical limitations, backup retention, fraud prevention, security, billing, legal, accounting, dispute resolution, and compliance requirements. Customer is responsible for exporting or preserving Customer Personal Data before termination where available and needed. Account deletion and data deletion requests may be sent to support@refero.design.11. International transfers
Refero and its Subprocessors may process Customer Personal Data in the United States and other countries. Where Customer Personal Data is transferred from the EEA, UK, Switzerland, or another jurisdiction that requires a transfer mechanism, Refero will rely on appropriate safeguards where required, such as:- Standard Contractual Clauses;
- UK Addendum or UK International Data Transfer Agreement, where applicable;
- adequacy decisions;
- Data Privacy Framework participation by relevant providers;
- another lawful transfer mechanism.
12. Audits and information
Refero will make available information reasonably necessary to demonstrate compliance with this DPA. This may include security summaries, written responses, documentation, or third-party reports if available. Any audit must be:- limited to information relevant to Customer Personal Data;
- conducted during normal business hours with reasonable prior notice;
- subject to confidentiality obligations;
- no more than once per calendar year unless required by Data Protection Laws or following a Security Incident affecting Customer Personal Data;
- conducted in a way that does not disrupt the Service or compromise security or other customers’ data.
13. US state privacy laws
Where US state privacy laws apply and Refero acts as Customer’s service provider, processor, or contractor, Refero will:- process Customer Personal Data only for the business purposes described in the Agreement and this DPA;
- not sell or share Customer Personal Data;
- not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by law;
- not combine Customer Personal Data with personal data from other sources except as permitted by law;
- notify Customer if Refero determines it can no longer meet its obligations under applicable law.
14. AI processing
If Customer uses AI-assisted features, Customer instructs Refero to process relevant prompts, chats, uploads, files, tool results, metadata, and outputs through Refero systems and third-party AI routing, model, and infrastructure providers as needed to provide those features. Customer is responsible for ensuring it has the rights and lawful basis to submit such data to AI-assisted features. Customer should not submit sensitive, regulated, confidential, or high-risk personal data to AI-assisted features unless Customer has confirmed that such use is lawful and appropriate. Refero may use different AI providers, models, routing, prompts, and processing methods to provide AI-assisted features. Refero does not guarantee that a specific model or provider will be used for a specific request. Refero will not use Customer Personal Data submitted to AI-assisted features to train or fine-tune general-purpose AI models unless Customer expressly authorizes that use. Refero will not authorize third-party AI providers to use Customer Personal Data for model training where Refero controls the processing terms.15. Liability
Each party’s liability under this DPA is subject to the exclusions and limitations of liability in the Agreement, unless Data Protection Laws require otherwise.16. Contact
Questions, requests, objections, and notices under this DPA may be sent to support@refero.design.Annex A: Details of processing
Subject matter
Refero’s processing of Customer Personal Data to provide the Service, including design reference search, saved materials, boards, folders, teams, research chat, MCP/API access, uploads, support, security, billing support, and related features.Duration
For the term of the Agreement and thereafter as needed for deletion, backup retention, legal compliance, security, fraud prevention, dispute resolution, and other permitted purposes.Nature and purpose
Hosting, storing, transmitting, displaying, organizing, searching, analyzing, generating, securing, supporting, and deleting Customer Personal Data as needed to provide the Service and comply with the Agreement.Categories of data subjects
- Customer users and team members;
- invited users;
- admins and billing contacts;
- support contacts;
- individuals whose information is included in Customer-submitted content, prompts, uploads, or communications.
Categories of Customer Personal Data
- identifiers, such as name, email address, account ID, profile image, team role, and authentication identifiers;
- account and workspace data, such as team membership, invitations, boards, folders, bookmarks, and settings;
- content data, such as prompts, chat messages, images attached to Research or visual search, notes, saved references, and other user-submitted content;
- usage and technical data, such as logs, API token metadata, request metadata, feature usage, IP address, device/browser data, and security events;
- billing-related contact and subscription metadata, where applicable.