Data processing addendum
This addendum applies when Pecalium Pty Ltd (ABN 28 701 425 434), trading as Asterlyn Space (“we”, “us”, “our”), processes customer content on behalf of an Asterlyn Space customer (“you”). It forms part of our terms of service, and you accept it when you accept those terms. No separate signature is needed.
Last updated: 27 September 2026
1. Scope and order of precedence
This addendum covers customer content: the pictures, drawings, plans, project details and renders processed in your team, including anything about your own customers and their homes. It does not cover information we handle for our own purposes, such as your account, billing, support, security, website and marketing information. Our privacy policy covers that.
If this addendum and the terms conflict on the processing of customer content, this addendum applies.
2. Roles and your responsibilities
For customer content, you are the controller (or “business” under some US state laws). You decide what is uploaded and why. We are the processor (or “service provider”), processing it on your behalf.
You are responsible for having a lawful basis to upload customer content and for giving any notices and getting any consents the law requires. That includes permission from a home owner before you upload photos of their home, and from any identifiable person in a picture.
3. Processing instructions
We process customer content only to provide, secure, support, maintain and improve the Service, to comply with the law and to enforce the terms. Your use and settings in the Service are your instructions: uploading a drawing and starting a render instructs us to analyse the drawing and generate the render.
We do not sell customer content, use it for advertising, or use it to train AI models. If we believe an instruction breaks data protection law, we will tell you where the law allows.
4. Processing details
Subject matter and duration
Processing customer content to provide the Service, for as long as you have an account, plus the post-subscription and deletion periods in section 13.
Nature and purpose
- storing uploads, projects and renders;
- analysing drawings and photos, and generating and checking renders with AI;
- checking render quality, including testing our own quality checks; and
- support, troubleshooting, security, backup and monitoring.
Types of customer content
- photos of kitchens and rooms, which may show belongings, and sometimes people or addresses;
- drawings, plans and elevations, which may include a customer's name or site address;
- project names and notes;
- colours, materials, finishes, reference pictures, logos and product pictures; and
- renders and render feedback.
People the content may be about
- your customers and prospective customers, and the occupants of the homes you photograph;
- people who appear in uploaded pictures; and
- your team members, where their details appear in project content.
5. AI processing
To analyse drawings and generate renders, we send the relevant pictures and instructions to our AI subprocessor. That is OpenRouter, which routes to Google's Gemini models. We set every request to use Zero Data Retention routing and to refuse any provider that collects data. The content is only processed to produce the response and is not kept by the provider afterwards or used for training.
We do not train or fine-tune any AI model on customer content. We send only what is needed for the render, and never your account name, email address or billing details.
6. Restricted information
You must not upload the restricted information listed in section 10 of the terms, including pictures of children, health information, government identifiers and financial credentials. We may delete restricted information, or ask you to remove it, when we find it.
7. Confidentiality and access
Staff who can access customer content are bound by confidentiality. Access is limited to the staff and subprocessors who need it for the purposes in this addendum. When staff view the app as a customer to find a fault, that access is logged.
8. Security measures
We maintain reasonable technical and organisational measures to protect customer content against unauthorised access and accidental or unlawful loss, change or disclosure. The current measures are on our subprocessors and security page. They may change over time, but not in a way that materially reduces the overall protection of customer content.
9. Subprocessors
You authorise us to use the subprocessors listed on our subprocessors and security page. We bind them to data protection obligations suited to what they do, and we remain responsible for their processing of customer content as the law requires.
Before we add or replace a subprocessor that processes customer content, including an AI provider, we will update that page and tell account owners by email. You may object on reasonable data protection grounds within 30 days. If we cannot address the objection, you may cancel and get a pro rata refund of prepaid fees for the unused part of your billing period.
10. Help with requests and compliance
Taking into account the nature of the processing and the information we hold, we will give you reasonable help with requests from the people the content is about, with your security obligations, and with privacy impact assessments and regulator enquiries where the law requires. You remain responsible for responding to those requests. If someone contacts us directly about customer content, we will refer them to you where we can identify you.
11. Security incidents
If we confirm a security incident affecting customer content, we will tell you without undue delay, share what we know as far as the law allows, and cooperate reasonably with your investigation and any notifications you need to make, including under the Notifiable Data Breaches scheme.
12. International transfers
Customer content is stored in Sydney, Australia. It is processed in the United States for AI processing, and may be processed in New Zealand, the European Union and other countries where our subprocessors operate, as listed on the subprocessors page. Where the GDPR, UK GDPR or a similar law requires a transfer mechanism, we will rely on standard contractual clauses, the UK addendum, adequacy decisions or another lawful mechanism.
13. Return and deletion
While you have an account you can download your renders and delete projects and uploads at any time. When a subscription ends, we keep the team's customer content for 90 days, then delete it. A free account that has never paid is deleted, with its customer content, once nobody has signed in to it for 90 days. When you delete content or your account, it is deleted straight away.
Copies can remain in backups and logs for a limited period before they are overwritten, and in records we must keep by law. We keep those copies protected and do not process them for any other purpose.
14. Information and audit
We will give you reasonable information to show we comply with this addendum. Audits must be carried out in a way that protects other customers, our systems, security, confidentiality and availability. On-site audits, penetration tests, scans and load tests need our written permission first.
Contact
- Legal notices and privacy
- legal@pecalium.com
- Billing
- support@pecalium.com
- Product support
- support@asterlynspace.com
Pecalium Pty Ltd (ABN 28 701 425 434), Queensland, Australia.