Trust Center · Legal

Data Processing Addendum

The standard terms under which Infinite Library SAS processes your company's content as your processor. Read it here, print it as a PDF, and accept it online — the acceptance record carries the version and a fingerprint of this exact text.

Version 1.0Effective 2026-09-10Fingerprint 062c7186a1a975aaMarkdown

Accept online for your company Trust Center Sub-processor register Print / save as PDF

1. Parties and scope

This Data Processing Addendum (“DPA”) forms part of the agreement (the Terms of Service at https://www.infinitelibrary.ai/terms, together with any order or plan, the “Agreement”) between the customer that accepts it (“Customer”) and Infinite Library SAS, a French société par actions simplifiée with its registered office in Montrouge, just south of Paris, France (“Infinite Library”, “we”), for the Bindery studio and the Infinite Library website (the “Services”).

It applies wherever Infinite Library processes Personal Data on Customer's behalf as a processor. It is accepted online by a person authorised to bind Customer; the acceptance record (version, fingerprint, signatory, date) is emailed to the signatory and kept in Customer's account.

2. Definitions

Terms such as “Personal Data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in the EU General Data Protection Regulation 2016/679 (“GDPR”). In addition:

3. Roles

Customer is the controller of Customer Content (or a processor acting for its own controllers, in which case it warrants it has the authority to instruct Infinite Library). Infinite Library is Customer's processor for Customer Content.

For the account, billing and usage data of the individuals who sign in to the Services, Infinite Library acts as an independent controller as described in its Privacy Policy (https://www.infinitelibrary.ai/privacy). This DPA does not apply to that data.

4. Details of processing

The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of data subjects are described in Annex I.

5. Infinite Library's obligations as processor

Infinite Library shall:

6. No AI training on Customer Content

Infinite Library does not train, fine-tune or otherwise improve any machine-learning model with Customer Content, and does not permit any third party to do so on its behalf.

Customer Content is transmitted to AI Sub-processors solely to perform the function Customer's user invokes (writing, editing, translating, illustrating, narrating, transcribing) and is retained by them only for the abuse-monitoring periods stated in Annex III. Infinite Library engages each AI Sub-processor on terms under which Customer Content is not used to train the Sub-processor's models, or maintains that Sub-processor's account-level training opt-out; the live status of each is recorded, vendor by vendor, in Annex III.

Product analytics processed by Infinite Library are pseudonymous event counts and never contain the text of Customer Content.

7. Sub-processors

Customer gives general authorisation to the Sub-processors listed in Annex III, which is the live register published at the Trust Center and incorporated here by reference.

Infinite Library will notify the email address on the acceptance record at least 30 days before a new Sub-processor receives Customer Content. Customer may object in writing within that period on reasonable data-protection grounds; if the parties cannot resolve the objection in good faith, Customer may terminate the affected Service and receive a pro-rata refund of prepaid fees for the unused term.

Infinite Library imposes on each Sub-processor data-protection obligations no less protective than those in this DPA.

8. Personal data breach

Infinite Library will notify Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Content, describing the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact. Information may be provided in phases as it becomes available.

9. Audits and information

The Trust Center (Annex IV) is Infinite Library's standing evidence: the sub-processor register, retention schedule, security controls and compliance status are published there and written from the running system. On request Infinite Library will provide its security questionnaire answers and its SOC 2 control map, and will answer Customer's own questionnaire by email at hello@infinitelibrary.ai.

Where the above does not reasonably satisfy an audit obligation under applicable law, Customer (or an independent auditor bound by confidentiality) may audit Infinite Library's compliance with this DPA once in any twelve-month period, on at least thirty days' written notice, during business hours, in a manner that does not disrupt the Services, remotely and document-based first, and at Customer's cost. A supervisory authority's audit rights are unaffected.

10. Return and deletion

Customer's users may export Customer Content at any time from the account dialog (a complete archive of every book, its history and account records). On deletion of an account, Infinite Library locks it immediately and erases Customer Content after a 14-day safety window, save where Union or Member State law requires retention (in which case the data is isolated and retained only for that purpose). Sub-processors delete on their own published schedules (Annex III).

11. International transfers

Infinite Library processes Customer Content in the United States (Annex I). To the extent a transfer of Personal Data from the European Economic Area, the United Kingdom or Switzerland is subject to Chapter V GDPR (or its UK or Swiss equivalents), the parties enter into the SCCs, which are incorporated by reference with Customer as data exporter and Infinite Library as data importer; the optional docking clause applies; Clause 7 is included; the governing law and forum under Clauses 17 and 18 are those of France; Annexes I and II of this DPA serve as the SCC Annexes; and the UK Addendum applies to UK transfers. Where a Sub-processor is certified under the EU-US Data Privacy Framework, Infinite Library may also rely on that certification for the onward transfer.

12. Liability, precedence and term

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where applicable data-protection law does not permit them to be limited. In the event of conflict, the SCCs prevail over this DPA, and this DPA prevails over the Agreement, in each case for the matters they govern.

This DPA takes effect on acceptance and lasts for as long as Infinite Library processes Customer Content, surviving termination of the Agreement until the last Customer Content is deleted. It is governed by the laws of France.

Annex I — Description of the processing

Annex II — Technical and organisational measures

The measures Infinite Library maintains, grouped as on the Trust Center:

Annex III — Sub-processors

The live register, incorporated by reference. Each entry states the vendor, its purpose, the Personal Data it receives, its location, and — for AI vendors — whether Customer Content may be used to train its models and how long it is retained.

Annex IV — Trust Center

The Trust Center and its machine-readable twins are part of this DPA's evidence: /trust (this addendum's context, retention schedule, security controls, compliance status), /trust/subprocessors.json (the register), /trust/questionnaire (standing questionnaire answers), /.well-known/security.txt (security contact).

Accept online for your companyAsk a question

Acceptance happens in the studio's account dialog (Privacy & data): sign in, enter the company's legal name and the signatory, and confirm. Your copy — with the fingerprint above — is emailed at once.