Data Processing Addendum
Last Updated: July 30, 2026
This Data Processing Addendum ("DPA") amends and supplements the Metasteps Terms of Service ("Agreement") entered into between you, the user, together with any company or other business entity you are representing, if any (collectively, "User"), and Metasteps P.C., and is hereby incorporated by reference into the Agreement. All capitalized terms not otherwise defined in this DPA will have the meanings given to them in the Agreement. If there is any inconsistency or conflict between this DPA and the rest of the Agreement as it relates to data protection, this DPA will govern.
1. Definitions
"User Personal Data" means (i) the content (images, videos, 3D, text) that User uploads to or creates in the Services or Products, (ii) any labels, tags, comments, descriptions or categorizations that User adds to the content in the Services or Products, (iii) account registration data (name, email address, username, and hashed password) collected for the purpose of account creation and authentication; or (iv) billing and order information (name, email, address, payment details) processed for payments, excluding payment card details processed directly by third-party payment providers. Metasteps' Processing of the content described in sub-paragraphs (i) and (ii) is limited to hosting, storage, organisation, rendering, display, and deletion of that content as necessary to provide the Services. Metasteps does not access, analyse, index, extract, enrich, or profile personal data that may be incidentally contained within such content, except where necessary to respond to a support request initiated by User, to investigate a suspected violation of the Agreement, to maintain the security of the Services, or to comply with a legal obligation.
"Data Subject" means any individual to whom User Personal Data relates.
"Personal Data" means any information that relates to an identified or identifiable Data Subject, including but not limited to a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of the Data Subject.
"Process" or "Processing" means any operation or set of operations which is performed on Personal Data, whether or not by automated means, such as the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of User Personal Data.
“Subprocessor” means any third party (including Metasteps affiliates) engaged by Metasteps as a processor to process User Personal Data on behalf of Metasteps in connection with the Agreement.
“Security Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, User Personal Data transmitted, stored, or otherwise processed by Metasteps.
“Data Protection Legislation” means: (a) Regulation (EU) 2016/679 (EU GDPR); (b) to the extent applicable, the UK GDPR as defined in section 3(10) of the UK Data Protection Act 2018; and (c) any national implementing legislation, successor legislation, or binding guidance issued by a competent supervisory authority thereunder.
The terms ’controller’, ‘data subject’, ‘personal data’, ‘personal data breach’, ‘processor’, and ‘supervisory authority’ as used in this DPA will have the meanings ascribed to them in the GDPR, regardless of whether the GDPR applies.
2. Processing of Data
2.1 Purpose of Processing. The purpose of data Processing under this Agreement is the provision of the Services or Products pursuant to the Agreement.
2.2 Processor and Controller Responsibilities. The parties acknowledge and agree that: (a) Metasteps is a processor (or equivalent) of User Personal Data under the Data Protection Legislation, (b) User is a controller (or equivalent) of User Personal Data under the Data Protection Legislation, and (c) each party will comply with the obligations applicable to it under the Data Protection Legislation with respect to the Processing of User Personal Data.
2.3 User Instructions. User instructs Metasteps to Process User Personal Data. (a) in accordance with the Agreement, and (b) to comply with other reasonable written instructions provided by User where such instructions are consistent with the terms of the Agreement. Metasteps is prohibited from retaining, using, or disclosing the User Personal Data for any purpose other than for the specific purpose of performing such services for User, except as otherwise permitted by applicable law. User will ensure that its instructions for the Processing of User Personal Data comply with the Data Protection Legislation. User shall have sole responsibility for the accuracy, quality, and legality of User Personal Data and the means by which User obtained the User Personal Data.
2.4 Metasteps’ Compliance with User Instructions. Metasteps shall only retain, use, disclose and otherwise Process User Personal Data in accordance with User’s written instructions set forth above. Metasteps may process User Personal Data other than on the written instructions of User if it is required under applicable law to which Metasteps is subject. In this situation, Metasteps shall inform the User of such a requirement before Metasteps Processes the User Personal Data unless prohibited by applicable law. If User concludes that User’s instructions conflict with any Data Protection Legislation, Metasteps will inform User without unreasonable delay.
3. Security and Privacy Impact Assessments
3.1 Metasteps Personnel. Metasteps shall ensure that its personnel engaged in the Processing of User Personal Data are informed of the confidential nature of the User Personal Data, and are subject to obligations of confidentiality, and such obligations survive the termination of such individuals engagement with Metasteps.
3.2 Security. Metasteps will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing User Personal Data, taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of processing.
3.3 Data Protection Impact Assessments. Metasteps will take reasonable measures to cooperate and assist User in conducting a data protection impact assessment and related consultations with any supervisory authority, if User is required to do so under Data Protection Legislation.
4. Data Subject Rights
4.1 Notification and Assistance Obligations. User must respond to Data Subjects’ requests to exercise their rights under Data Protection Legislation (such as access, rectification, erasure, restriction, portability, or objection) within the timeframes required by applicable Data Protection Legislation — generally one (1) calendar month from receipt of the request under the EU GDPR, extendable to three (3) months for complex or multiple requests with prior notice to the Data Subject. User must honor such requests to the extent legally required. Metasteps shall, to the extent legally permitted, promptly either notify User if it receives such a request from a Data Subject, or direct such individual to contact User directly. Metasteps may communicate with the Data Subject, such as to facilitate this process, to explain why Metasteps has not immediately honored the individual’s request, to address potential violations of the Terms of Service, and to address requests unrelated to the ones covered by this paragraph.
4.2 Metasteps shall provide User with commercially reasonable cooperation and assistance in relation to handling of a Data Subject request, to the extent Metasteps is legally permitted and able to do so, where User does not have the ability to honor such requests through its use or receipt of the Services or Products. As part of this, Metasteps may take reasonable steps to restrict access to such User Personal Data to the extent legally permitted and notify User when the individual requests removal of User Personal Data but Metasteps concludes that User has not responded within 7 days.
5. Subcontractors
5.1 General Authorization. User provides a general authorization for the use of subprocessors to Process User Personal Data in connection with fulfilling Metasteps’s obligations under the Agreement and/ or this DPA. Metasteps’s third -party subprocessors are listed at Annex I below. Certain third parties process personal data as independent controllers rather than as subprocessors. These are listed in Annex II and are not subject to this Section 5.
5.2 New Subprocessors. When Metasteps engages any new Subprocessor to process User Personal Data, Metasteps will update the Subprocessor List to give User the opportunity to object to such Subprocessor by terminating the services in accordance with the Agreement.
5.3 Metasteps Obligations. Metasteps will contractually impose data protection obligations on its subprocessors that are at least equivalent to those data protection obligations imposed on Metasteps under this DPA.
6. International Data Transfers
6.1 Metasteps operates globally, which means personal data collected in the European Economic Area ("EEA") or Switzerland may be stored and processed outside of the country or region where it was initially collected. We protect your personal data in accordance with this DPA wherever it is processed and take appropriate contractual or other steps to protect it under applicable laws. These steps include implementing the European Commission's standard contractual clauses and relying on the European Commission's adequacy decisions about certain countries, as applicable, for data transfers from the EEA to the United States and other countries.
7. Security Breach
7.1 Notification Obligations. In the event of a confirmed Security Breach, Metasteps will notify User of the Security Breach without undue delay and in any event within forty-eight (48) hours of becoming aware of it. The obligations in this Section 7 do not apply to unsuccessful attempts or activities that do not compromise the security of User Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, and other network attacks on firewalls or networked systems. It is User’s responsibility to notify the relevant governmental authorities and affected Data Subjects. User authorizes Metasteps to notify governmental authorities or affected individuals of a Security Breach only to the extent required by applicable law or where Metasteps reasonably believes such notification is necessary to comply with legal obligations or to prevent imminent harm.
7.2 Manner of Notification. Notification (s) of Security Breaches, if any, will be delivered via email. It is User’s sole responsibility to ensure it maintains accurate contact information on Metasteps ’s support systems at all times.
8. Term and Termination
8.1 Term of DPA. This DPA will remain in effect until, and automatically expire upon, deletion of all User Personal Data as described in this DPA.
8.2 Deletion of User Data. Metasteps shall delete or return User Personal Data to User after the end of the provision of Services or Products under the Agreement and shall delete all existing copies thereof, except to the extent that Metasteps is required under applicable law to keep a copy of the User Personal Data.
9. Compliance Information
9.1 Information Available. To the extent applicable law requires User to impose the following provision on Metasteps, it applies: Metasteps will make available all information reasonably necessary to demonstrate compliance with the obligations set forth in this Addendum and will contribute to reasonable audits as necessary upon at least thirty (30) days' prior written notice, subject to agreement on scope, timing, and confidentiality obligations, and provided that audits are conducted no more than once per calendar year unless required by a supervisory authority.
10. Limitation of Liability
10.1 Because this DPA is part of the Agreement, Metasteps ’s liability for breach of its obligations in this DPA is subject to the limitation of liability provisions in the Agreement.
ANNEX I - Subprocessors
THIRD PARTY SERVICE/ VENDOR: DIGITALOCEAN
PURPOSE: Data Hosting, Content Delivery
ENTITY COUNTRY: Germany
WEBSITE: www.digitalocean.com
THIRD PARTY SERVICE/ VENDOR: TWILIO INC. (SENDGRID)
PURPOSE: Transactional and marketing email delivery, email open and click tracking analytics
ENTITY COUNTRY: United States
WEBSITE: www.twilio.com
TRANSFER MECHANISM: EU Standard Contractual Clauses (2021), Module 2 (Controller to Processor); EU-US Data Privacy Framework
THIRD PARTY SERVICE/ VENDOR: BREVO SAS (FORMERLY SENDINBLUE)
PURPOSE: Marketing email delivery, email open and click tracking analytics
ENTITY COUNTRY: France
WEBSITE: www.brevo.com
THIRD PARTY SERVICE/ VENDOR: OPENAI, LLC.
PURPOSE: AI-powered Pythia Editor — natural-language 3D space template recommendation; processes text prompts submitted by users (no user identifiers transmitted)
ENTITY COUNTRY: United States
WEBSITE: www.openai.com
TRANSFER MECHANISM: EU Standard Contractual Clauses (2021), Module 2 (Controller to Processor); UK Addendum for UK data
THIRD PARTY SERVICE/ VENDOR: INTERCOM R&D Unlimited Company
PURPOSE: In-app user support (including customer messaging for support)
ENTITY COUNTRY: United States (EU operations via Irish entity)
WEBSITE: www.intercom.com
TRANSFER MECHANISM: EU Standard Contractual Clauses (2021), Module 2 (Controller to Processor); EU-US Data Privacy Framework
ANNEX II – Independent Third-Party Controllers
The following third parties process personal data as independent controllers, in accordance with their own privacy policies and terms:
THIRD PARTY SERVICE/ VENDOR: STRIPE, INC.
PURPOSE: Payment processing, order fulfillment, tax/VAT calculation & remittance
ENTITY COUNTRY: United States
WEBSITE: www.stripe.com
ANNEX III – Processing Activities Description
Subject matter of processing
Metasteps provides a cloud-based platform for creating, hosting, and sharing 3D virtual spaces, exhibitions, and digital content (“Services”). User Personal Data is processed in order to provide and operate these Services.
Duration of processing
For the duration of the Agreement and, to the extent required by applicable law, for any legally mandated retention period thereafter.
Nature of processing
In respect of account registration and billing data: collection, storage, organisation, use, disclosure, and deletion as necessary to provide the Services. In respect of User Content: hosting, storage, organisation, rendering, display, and deletion, together with disclosure to the recipients configured by User through the publication settings of the relevant virtual space.
Purpose(s) of processing
(a) Account creation and authentication; (b) delivery and operation of the Services; (c) billing and payment processing; (d) customer support; (e) security and fraud prevention; (f) compliance with legal obligations; (g) AI-powered Pythia Editor (natural-language 3D space template recommendation) as described in Section 12 of the Terms of Service; (h) potential future use of anonymised or aggregated data to develop, train, or improve Metasteps’ own AI systems, subject to valid legal basis and prior notification to users as described in the Privacy Notice, (h) Moodle Integration (Academic Plan only): retrieval and synchronisation of course content from the User's Moodle instance via API token, for display and organisation within Metasteps 3D spaces. This processing is limited to course metadata and resources configured by the teacher or administrator; student data is not accessed through this integration.
Types of personal data processed
(a) Account data: name, email address, username, password (hashed); (b) User Content: images, videos, 3D assets, text, labels, descriptions uploaded or created by User. Such content may incidentally contain personal data relating to third parties (for example, images or recordings of identifiable individuals). Metasteps processes this content only as described under "Nature of processing" below and does not extract or independently process personal data contained within it. User, as controller, is responsible for establishing a lawful basis for any personal data included in User Content; (c) Billing data: name, billing address, last four digits of payment card (full payment card data is processed by Stripe as an independent controller); (d) Usage/log data: IP address, browser type, session identifiers, access logs; (e) AI input data: free-form text and content submitted by User via AI Features, which may incidentally contain personal data, (f) Moodle integration data: course names, descriptions, and course resources retrieved from the User's Moodle instance via API. This data may incidentally contain personal data where included in course materials by the teacher. The User (as data controller of their Moodle content) is responsible for ensuring that imported materials are appropriate to share via the integration.
Categories of data subjects
(a) Users (account holders and their authorised users); (b) Visitors and end-users of published virtual spaces; (c) Any third parties whose personal data is incidentally included in User Content or AI inputs.
Special category data
Metasteps does not intentionally process special category personal data (Art. 9 GDPR). Users are prohibited from submitting special category data via the AI Features or otherwise unless separately agreed in writing.