Skip to main content
Last updated: August 3, 2026 This Data Processing Addendum (“DPA”) applies only when it is expressly incorporated into an order form or other written agreement accepted by Refero Inc. (“Refero”, “we”, “us”, or “Processor”) and the customer that uses Refero for business, team, MCP, API, or other applicable services (“Customer” or “Controller”). Once incorporated, it forms part of that agreement when Refero processes Customer Personal Data on Customer’s behalf. This DPA is intended to satisfy applicable data protection laws, including GDPR Article 28, UK GDPR, Swiss data protection law, and applicable US state privacy laws, where they apply. If there is a conflict between this DPA and the Terms of Use or another agreement, this DPA controls only for the processing of Customer Personal Data.

1. Definitions

“Agreement” means the Terms of Use, order form, subscription agreement, MCP/API agreement, or other written agreement between Customer and Refero. “Customer Personal Data” means personal data that Customer submits to the Service and that Refero processes on Customer’s behalf as a processor or service provider. “Data Protection Laws” means applicable privacy and data protection laws, including GDPR, UK GDPR, Swiss data protection law, the California Consumer Privacy Act as amended, and similar US state privacy laws. “Security Incident” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Refero. It does not include unsuccessful attempts that do not compromise Customer Personal Data, such as blocked attacks, scans, pings, or failed login attempts. “Subprocessor” means a third party engaged by Refero to process Customer Personal Data on behalf of Customer. Capitalized terms not defined here have the meanings given in the Agreement or applicable Data Protection Laws.

2. Roles

For Customer Personal Data, Customer is the controller or business, and Refero is the processor or service provider. Customer determines the purposes and means of processing Customer Personal Data. Refero processes Customer Personal Data only on Customer’s documented instructions, including the Agreement, this DPA, Customer’s use of the Service, and Customer’s configuration of features. Refero may process account, billing, security, usage, analytics, support, and business operations data as an independent controller where permitted by law and described in the Privacy Policy (“Service Operations Data”). Customer Personal Data does not include Service Operations Data except where Refero processes that data solely on Customer’s behalf under the Agreement.

3. Scope of processing

Refero will process Customer Personal Data to:
  • provide, maintain, secure, and support the Service;
  • operate team, shared workspace, board, bookmark, research chat, upload, MCP, API, and related features;
  • process Customer instructions and user requests;
  • troubleshoot, prevent abuse, and protect the Service;
  • comply with law and enforce the Agreement;
  • perform other processing described in Annex A or authorized by Customer.
Refero will not sell Customer Personal Data. Refero will not retain, use, or disclose Customer Personal Data outside the business purposes described in the Agreement and this DPA, except as permitted or required by law.

4. Customer responsibilities

Customer is responsible for:
  • having a lawful basis to collect, use, and submit Customer Personal Data to the Service;
  • providing required notices and obtaining required consents from data subjects;
  • ensuring Customer’s instructions comply with Data Protection Laws;
  • configuring the Service appropriately for Customer’s intended use;
  • not submitting sensitive, regulated, or high-risk data unless the Agreement expressly allows it;
  • maintaining appropriate copies or exports of Customer Personal Data where Customer needs an independent backup or archive;
  • responding to data subject requests where Customer is the controller, with reasonable assistance from Refero as described below.

5. Refero processing obligations

Refero will:
  • process Customer Personal Data only on documented instructions from Customer, unless required by law;
  • ensure that persons authorized to process Customer Personal Data are subject to confidentiality obligations;
  • implement and maintain appropriate technical and organizational security measures;
  • assist Customer, taking into account the nature of processing and information available to Refero, with data subject requests and compliance obligations;
  • assist Customer, taking into account the nature of processing and information available to Refero, with security, breach notification, data protection impact assessment, and prior consultation obligations where required by Data Protection Laws;
  • notify Customer if Refero believes an instruction violates Data Protection Laws, unless prohibited by law;
  • delete or return Customer Personal Data after termination of the Service as described in the Agreement, this DPA, and applicable retention practices;
  • make available information reasonably necessary to demonstrate compliance with this DPA.

6. Subprocessors

Customer gives Refero general authorization to engage Subprocessors to provide the Service. Refero will require Subprocessors to protect Customer Personal Data under written obligations that are substantially similar to those in this DPA, to the extent applicable to the services they provide. Refero remains responsible for its Subprocessors’ performance of their data protection obligations to the extent required by Data Protection Laws. Current Subprocessor categories and examples may include:
  • cloud hosting, storage, CDN, and infrastructure providers, such as AWS or similar services;
  • database, logging, monitoring, and security providers, such as Bugsnag, New Relic, or similar services;
  • payment processors, including Stripe and Lemon Squeezy for legacy subscriptions;
  • authentication providers, including Google where users choose Google sign-in;
  • email delivery and customer communication providers, such as MailerLite or similar services;
  • analytics and product measurement providers, such as Google Analytics, Mixpanel, Microsoft Clarity, or similar services;
  • AI routing and model providers, including providers such as OpenRouter, OpenAI, Anthropic, Google, and similar services when Customer uses AI-assisted features. AI routing providers may route requests to downstream model providers;
  • support, operations, and professional service providers.
Refero may update Subprocessors periodically. Refero will make available information about Subprocessors relevant to Customer’s use of the Service, such as through a public legal page, support article, email notice, or upon request. Where required by Data Protection Laws, Refero will provide reasonable notice of an intended material new Subprocessor and allow Customer to object on reasonable data protection grounds. If an objection cannot be resolved, Customer may stop using the affected feature or terminate the affected Service as permitted by the Agreement. Customer acknowledges that some Subprocessors may be essential to the Service. If Customer objects to an essential Subprocessor and the parties cannot resolve the objection, Refero may be unable to continue providing the affected Service.

7. Security measures

Refero will maintain reasonable technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. The measures will take into account the nature of the processing, reasonably available technology, implementation costs, and the risks presented by the processing. Refero may update its security measures as the Service evolves, provided that it does not materially reduce the overall level of protection during the term of the Agreement. Refero may provide additional information about current measures on reasonable request, subject to confidentiality and without disclosing information that could compromise security or other customers.

8. Security incidents

Refero will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data, as required by applicable Data Protection Laws. Refero will provide information reasonably available to it to help Customer understand the incident and meet applicable notification obligations, and may provide that information in stages as it becomes available. Customer is responsible for determining whether it must notify regulators or data subjects. Refero will provide reasonable assistance where required by applicable Data Protection Laws.

9. Data subject requests

Taking into account the nature of the Service, Refero will provide reasonable assistance to Customer in responding to requests from data subjects to exercise rights under Data Protection Laws. If Refero receives a request directly from a data subject relating to Customer Personal Data, Refero may direct the person to Customer or respond if legally required or authorized by Customer.

10. Deletion and return

Upon termination or expiration of the Agreement, Refero will delete or return Customer Personal Data as required by Data Protection Laws and the Agreement, unless retention is required or permitted by law. Deletion may be subject to technical limitations, backup retention, fraud prevention, security, billing, legal, accounting, dispute resolution, and compliance requirements. Customer is responsible for exporting or preserving Customer Personal Data before termination where available and needed. Account deletion and data deletion requests may be sent to support@refero.design.

11. International transfers

Refero and its Subprocessors may process Customer Personal Data in the United States and other countries. Where Customer Personal Data is transferred from the EEA, UK, Switzerland, or another jurisdiction that requires a transfer mechanism, Refero will rely on appropriate safeguards where required, such as:
  • Standard Contractual Clauses;
  • UK Addendum or UK International Data Transfer Agreement, where applicable;
  • adequacy decisions;
  • Data Privacy Framework participation by relevant providers;
  • another lawful transfer mechanism.
If Standard Contractual Clauses are required, the parties will complete and enter into the applicable controller-to-processor clauses, including the required annex information and signatures, and any applicable UK addendum. This DPA does not replace any information or signature that the applicable transfer mechanism requires. For EEA transfers, the parties will use Module 2 of the Standard Contractual Clauses where Customer is the controller and Refero is the processor. For UK transfers, the parties will use the UK Addendum or other applicable UK transfer mechanism. For Swiss transfers, references to GDPR supervisory authorities and member states will be interpreted as required by Swiss data protection law.

12. Audits and information

Refero will make available information reasonably necessary to demonstrate compliance with this DPA. This may include security summaries, written responses, documentation, or third-party reports if available. Any audit must be:
  • limited to information relevant to Customer Personal Data;
  • conducted during normal business hours with reasonable prior notice;
  • subject to confidentiality obligations;
  • no more than once per calendar year unless required by Data Protection Laws or following a Security Incident affecting Customer Personal Data;
  • conducted in a way that does not disrupt the Service or compromise security or other customers’ data.
Onsite audits are not permitted unless required by Data Protection Laws and cannot reasonably be satisfied through documentation or remote review.

13. US state privacy laws

Where US state privacy laws apply and Refero acts as Customer’s service provider, processor, or contractor, Refero will:
  • process Customer Personal Data only for the business purposes described in the Agreement and this DPA;
  • not sell or share Customer Personal Data;
  • not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by law;
  • not combine Customer Personal Data with personal data from other sources except as permitted by law;
  • notify Customer if Refero determines it can no longer meet its obligations under applicable law.
Customer has the right to take reasonable and appropriate steps to help ensure Refero uses Customer Personal Data consistently with Customer’s obligations, subject to the audit and information process in this DPA.

14. AI processing

If Customer uses AI-assisted features, Customer instructs Refero to process relevant prompts, chats, uploads, files, tool results, metadata, and outputs through Refero systems and third-party AI routing, model, and infrastructure providers as needed to provide those features. Customer is responsible for ensuring it has the rights and lawful basis to submit such data to AI-assisted features. Customer should not submit sensitive, regulated, confidential, or high-risk personal data to AI-assisted features unless Customer has confirmed that such use is lawful and appropriate. Refero may use different AI providers, models, routing, prompts, and processing methods to provide AI-assisted features. Refero does not guarantee that a specific model or provider will be used for a specific request. Refero will not use Customer Personal Data submitted to AI-assisted features to train or fine-tune general-purpose AI models unless Customer expressly authorizes that use. Refero will not authorize third-party AI providers to use Customer Personal Data for model training where Refero controls the processing terms.

15. Liability

Each party’s liability under this DPA is subject to the exclusions and limitations of liability in the Agreement, unless Data Protection Laws require otherwise.

16. Contact

Questions, requests, objections, and notices under this DPA may be sent to support@refero.design.

Annex A: Details of processing

Subject matter

Refero’s processing of Customer Personal Data to provide the Service, including design reference search, saved materials, boards, folders, teams, research chat, MCP/API access, uploads, support, security, billing support, and related features.

Duration

For the term of the Agreement and thereafter as needed for deletion, backup retention, legal compliance, security, fraud prevention, dispute resolution, and other permitted purposes.

Nature and purpose

Hosting, storing, transmitting, displaying, organizing, searching, analyzing, generating, securing, supporting, and deleting Customer Personal Data as needed to provide the Service and comply with the Agreement.

Categories of data subjects

  • Customer users and team members;
  • invited users;
  • admins and billing contacts;
  • support contacts;
  • individuals whose information is included in Customer-submitted content, prompts, uploads, or communications.

Categories of Customer Personal Data

  • identifiers, such as name, email address, account ID, profile image, team role, and authentication identifiers;
  • account and workspace data, such as team membership, invitations, boards, folders, bookmarks, and settings;
  • content data, such as prompts, chat messages, images attached to Research or visual search, notes, saved references, and other user-submitted content;
  • usage and technical data, such as logs, API token metadata, request metadata, feature usage, IP address, device/browser data, and security events;
  • billing-related contact and subscription metadata, where applicable.

Sensitive data

The Service is not intended for processing sensitive personal data, special category data, protected health information, payment card numbers outside payment processor flows, government identifiers, children’s data, or other regulated high-risk data unless expressly agreed in writing.

Processing operations

Collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment, combination, restriction, erasure, and destruction, as needed to provide the Service.