Data Processing Agreement (DPA)
Annex 1 to the Fotillo Cloud Terms of Service
*This is an English translation provided for information purposes only; solely the Polish version of this DPA is binding.*
§1 General provisions
1. This data processing agreement (the "DPA") is concluded between the Operator (also referred to as: the Controller) and the Provider (also referred to as: the Processor).
2. Capitalised terms have the meaning given to them in the Fotillo Cloud Terms of Service (the "Terms").
3. The DPA is concluded upon acceptance of the Terms together with this Annex, by electronic means, in accordance with §4 of the Terms. The electronic form satisfies the requirement of Article 28(9) GDPR. The Provider records the fact, time and version of the accepted documents.
4. The subject matter of the DPA is to determine the conditions under which the Processor processes personal data on behalf of the Controller in connection with the provision of the Service.
§2 Roles of the parties
1. The controller of the personal data of End Users, including their images recorded in Content, is the Operator. It is the Operator who decides on the purposes and means of processing that data, in particular on the use of the Device and the online function in its activity.
2. The Provider processes the personal data of End Users solely on behalf of and for the Operator, as a processor within the meaning of Article 4(8) and Article 28 GDPR.
3. The DPA does not cover personal data processed by the Provider for its own purposes, in particular the Operator's data relating to account, licence, settlement and complaint handling, as well as registers of document acceptance and technical logs maintained in order to demonstrate compliance with the law, ensure security and establish, pursue or defend claims. In this respect the Provider acts as a separate controller, and the rules of processing are set out in the Privacy Policy.
4. If a Device with an activated online function is transferred to another party, the DPA with the acquirer is concluded upon acceptance of the Terms together with the DPA in accordance with §4(9) of the Terms; at the same moment the DPA with the transferor expires in respect of that Device. Until acceptance by the acquirer, the transferor remains the Controller in respect of that Device.
5. The DPA does not cover Content transferred from a Device directly to an Account (Album) on the basis of a Pairing Code, in accordance with §3(6) of the Terms. The Provider stores such Content at the request and on behalf of the Account holder, on the terms set out in the Terms of the Account and the Album Fotillo Cloud service.
6. If the Operator is a natural person using the Software and the Service exclusively for personal or household purposes within the meaning of Article 2(2)(c) GDPR, they do not act as a controller and the provisions of the DPA do not apply in that respect; the rules for storing, sharing and deleting Content are set out in the Terms. The DPA applies to the extent that the Operator processes the personal data of End Users for purposes other than exclusively personal or household, in particular by servicing events for other persons, irrespective of whether they conduct a registered business activity.
§3 Subject matter, nature, purpose and duration of processing
1. The subject matter of the processing is personal data contained in Content transferred to the Service and the technical data associated with it.
2. The processing consists of automated operations in the IT systems of the Service and comprises: receiving, recording, organising, storing, making available under an individual Link, displaying, transferring for printing and deleting.
3. The purpose of the processing is to provide the Service to the Controller in accordance with the Terms.
4. The processing takes place for as long as the Controller uses the Service, taking into account the storage period for Content set out in §10 of the Terms.
§4 Type of data and categories of data subjects
1. The processing covers the following types of personal data:
1) the image recorded in photographs and, once such functions are launched, also in videos,
2) technical data associated with the Content, in particular the date of transfer, the Device identifier, the Link and the IP address of the device from which the Content was transferred,
3) e-mail addresses, if they are provided within the Service.
2. Categories of data subjects: End Users, in particular persons photographed using the Device and persons transferring Content via the Upload function.
§5 Obligations of the Processor
1. The Processor processes personal data solely on the documented instruction of the Controller. The Terms, this DPA and the configuration of the Software and the Service made by the Controller are deemed to constitute a documented instruction. An exception applies where the obligation to process is imposed on the Processor by Union law or the law of a Member State; in such a case the Processor informs the Controller of that obligation before processing begins, unless the law prohibits the provision of such information.
2. The Processor immediately informs the Controller if, in its opinion, an instruction given to it infringes the GDPR or other data protection provisions.
3. The Processor ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4. The Processor implements the technical and organisational measures required under Article 32 GDPR, appropriate to the risk, in particular: encryption of data transmission (TLS), access control to systems, individual, hard-to-guess Links, periodic backups stored for no longer than 7 days, automatic and permanent deletion of Content after the storage period, and logging of deletion operations. The Processor makes an up-to-date description of the measures available to the Controller on request.
5. Taking into account the nature of the processing, the Processor assists the Controller, by appropriate technical and organisational measures, in fulfilling the obligation to respond to requests from data subjects exercising their rights set out in Chapter III GDPR. Supporting functions include in particular the "Delete photo" button on the Sharing Page and the presentation on that page of the Controller's details provided by it in accordance with §5(2)(7) and §9a of the Terms; the Controller is responsible for the accuracy and currency of those details.
6. The Processor assists the Controller in complying with the obligations set out in Articles 32–36 GDPR, taking into account the nature of the processing and the information available to it. The Processor notifies the Controller of an identified personal data breach concerning the entrusted data without undue delay, no later than within 48 hours of becoming aware of the breach, providing the information necessary to notify the breach to the supervisory authority.
7. After the provision of the Service to the Controller has ended, the Processor, at the Controller's decision, deletes or returns to it all entrusted personal data and deletes existing copies thereof, unless Union law or the law of a Member State requires further storage. The Controller's decision may also be expressed by means of the functions of the Service, in particular by using the option to delete all data in the Service panel (choice of deletion) or by downloading the Content before deletion (return of data). In the absence of a decision by the Controller, the data is deleted in accordance with §10 of the Terms. At the Controller's request, the Processor confirms the deletion of the data.
8. The Processor makes available to the Controller the information necessary to demonstrate compliance with the obligations set out in Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by it, on the following conditions: an audit requires at least 14 days' notice, takes place on business days during the Processor's working hours, no more than once per calendar year (unless the audit follows an identified breach or a request of the supervisory authority), and its costs are borne by the Controller. The auditor may not be an entity competing with the Provider.
9. The Processor does not disclose entrusted data or grant access to it to third parties, unless this takes place on the Controller's instruction, in accordance with the DPA and the Terms, or on the basis of a legal obligation. The Processor directs requests for disclosure of entrusted data originating from authorities to the Controller wherever possible; if it is legally obliged to disclose, it informs the Controller and provides it with a copy of the request, unless the law prohibits this, and discloses the data only to the extent required by law. The Processor rejects requests from other third parties or directs them to the Controller. The Processor grants no one unlimited access to the entrusted data.
10. If a data subject addresses a request concerning entrusted data directly to the Processor, the Processor immediately forwards the request to the Controller and directs that person to the Controller. This does not apply to the self-service functions and reports provided for in the Terms, in particular the "Delete photo" button and abuse reports, which the Processor handles in accordance with the Terms.
§6 Sub-processing
1. The Controller gives general consent to the Processor's use of the services of other processors (sub-processors).
2. The current list of sub-processors is published on the Service's website and, as at the date of conclusion of the DPA, comprises: SEOHOST Sp. z o.o., with its registered office at ul. Obornicka 330, 60-689 Poznań, Poland, NIP: 9721323212, REGON: 520718284, KRS: 0000939910 – the hosting provider for the Service (data location: European Economic Area).
3. The Processor informs the Controller of any intended changes concerning the addition or replacement of sub-processors at least 14 days before their implementation, in particular by publishing an updated list and providing information by e-mail or by a message in the Software. The Controller may object within that period.
4. Due to the uniform nature of the Service, raising an objection makes further provision of the Service to the Controller impossible. In such a case the Controller may cease using the online function, and the DPA expires in accordance with §9.
5. The Processor imposes on sub-processors, by contract, the same data protection obligations as those set out in this DPA, and remains liable to the Controller for the sub-processors' performance of their obligations.
6. The planned development of the Service may require entrusting processing to further sub-processors, in particular providers of automated image analysis tools (content moderation) and providers of storage space (storage of originals and videos). These entities will be added to the list of sub-processors before the relevant functions are launched, in the manner set out in paragraph 3.
§7 Transfers of data outside the EEA
1. Personal data is stored on servers located within the European Economic Area.
2. Any transfer of data to a third country may take place only in compliance with the conditions set out in Chapter V GDPR, in particular on the basis of an adequacy decision or standard contractual clauses, and after this has been reflected in the list of sub-processors in the manner set out in §6(3).
§8 Liability
1. The parties are liable for the processing of personal data on the terms set out in Article 82 GDPR.
2. Towards Controllers who are businesses, the Processor's liability under this DPA is subject to the limitation set out in §12(3) of the Terms, to the extent permitted by mandatory law.
§9 Duration and termination
1. The DPA applies for as long as the Controller uses the Service.
2. Termination of use of the Service, on whatever basis, including termination of the provision of the Service on grounds of inactivity in accordance with §13a(3) of the Terms, causes the DPA to expire. Expiry of the DPA does not release the Processor from the obligations set out in §5(7).
§10 Final provisions
1. The DPA is governed by Polish law and the GDPR.
2. Amendments to the DPA are made in the manner provided for amendments to the Terms (§14 of the Terms).
3. Solely the Polish-language version of the DPA is binding. Versions in other languages are for information purposes only.
4. In matters not regulated herein, the provisions of the Terms and the GDPR apply.