Data Processing Agreement (DPA)
*Annex 1 to the Fotillo Cloud Photographer Account Terms. This document is an English translation of the Polish original, provided for information purposes only. Solely the Polish version is binding.*
§1 General provisions
1. This data processing agreement (the "DPA") is concluded between the Photographer (also referred to as: the Controller) and the Provider (also referred to as: the Processor).
2. Capitalised terms have the meaning given to them in the Fotillo Cloud Photographer Account Terms (the "Terms").
3. The DPA is concluded upon acceptance of the Terms together with this Annex, by electronic means. The electronic form satisfies the requirement of Art. 28(9) GDPR. The Provider records the fact, time and version of the accepted documents.
§2 Roles of the parties
1. The controller of the personal data of persons visible in the Content, including their images, is the Photographer. It is the Photographer who decides on the purposes and means of processing that data.
2. The Provider processes that data solely on behalf of and for the Controller, as a processor within the meaning of Art. 4(8) and Art. 28 GDPR.
3. The DPA does not cover personal data processed by the Provider for its own purposes, in particular the Photographer's data relating to account, settlement and complaint handling, as well as registers of document acceptance and technical logs maintained in order to demonstrate compliance with the law, ensure security and establish, pursue or defend claims. In this respect the Provider acts as a separate controller, and the rules of processing are set out in the Privacy Policy.
§3 Subject matter, nature, purpose and duration of processing
1. The subject matter of the processing is personal data contained in Content transferred to the Service and the technical data associated with it.
2. The processing consists of automated operations in the IT systems of the Service and comprises: receiving, recording, organising, storing, making available under an individual Link, displaying, downloading and deleting.
3. The purpose of the processing is to provide the Service to the Controller in accordance with the Terms.
4. The processing takes place for as long as the Controller uses the Service, taking into account the periods set out in §7 of the Terms and the Gallery expiry dates set by the Controller.
§4 Type of data and categories of data subjects
1. The processing covers: the image recorded in photographs and other materials, technical data associated with the Content (date of transfer, Gallery identifier, Link, IP address of the device from which the Content was transferred) and other personal data, if the Controller places it in the Content or in Gallery names.
2. Categories of data subjects: persons photographed by the Controller and Recipients to whom the Controller makes Galleries available.
3. The Controller should not place in the Service data of special categories within the meaning of Art. 9 GDPR without prior agreement with the Processor on additional security measures.
§5 Obligations of the Processor
1. The Processor processes the data solely on the documented instruction of the Controller. The Terms, this DPA and the configuration of the Account and Galleries made by the Controller, including the Passwords and expiry dates set by them, are deemed to constitute a documented instruction. An exception applies where processing is required by Union law or the law of a Member State; in such a case the Processor informs the Controller before processing begins, unless the law prohibits this.
2. The Processor immediately informs the Controller if, in its opinion, an instruction given to it infringes the GDPR or other data protection provisions.
3. The Processor ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4. The Processor implements the technical and organisational measures required under Art. 32 GDPR, appropriate to the risk, in particular: encryption of data transmission (TLS), encryption of Content stored with the sub-processor providing storage space (AES-256), whereby the encryption key remains solely at the Processor's disposal and the sub-processor has no access to Content in plain form; making Content available exclusively through the Processor's servers, without transferring data of persons viewing the Content to the sub-processor; access control to systems, individual, hard-to-guess Links and the option to protect a Gallery with a Password set by the Controller, periodic backups of the application server stored for no longer than 7 days, and logging of deletion operations. The Processor makes an up-to-date description of the measures available to the Controller on request.
5. Taking into account the nature of the processing, the Processor assists the Controller in fulfilling the obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR. Supporting functions include in particular the ability to delete an individual item of Content, to delete an entire Gallery, to change or set a Password, and to set a Gallery expiry date.
6. The Processor assists the Controller in complying with the obligations set out in Art. 32–36 GDPR. It notifies the Controller of an identified personal data breach concerning the entrusted data without undue delay, no later than within 48 hours of becoming aware of the breach, providing the information necessary to notify the breach to the supervisory authority.
7. After the provision of the Service has ended, the Processor, at the Controller's decision, deletes or returns to it all entrusted data and deletes existing copies thereof, unless the law requires further storage. The Controller's decision may be expressed by means of the functions of the Service, in particular by deleting the Account (choice of deletion) or by downloading the Content before deletion (return of data). In the absence of a decision, the data is deleted in accordance with §7 of the Terms. At the Controller's request, the Processor confirms the deletion of the data.
8. The Processor makes available to the Controller the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allows for audits on the following conditions: an audit requires at least 14 days' notice, takes place on business days during the Processor's working hours, no more than once per calendar year (unless the audit follows an identified breach or a request of the supervisory authority), and its costs are borne by the Controller. The auditor may not be an entity competing with the Provider.
9. The Processor does not disclose entrusted data or grant access to it to third parties, unless this takes place on the Controller's instruction, in accordance with the DPA and the Terms, or on the basis of a legal obligation. It directs requests from authorities to the Controller wherever possible; if it is legally obliged to disclose, it informs the Controller and provides a copy of the request, unless the law prohibits this, and discloses the data only to the extent required.
10. If a data subject addresses a request concerning entrusted data directly to the Processor, the Processor immediately forwards the request to the Controller and directs that person to the Controller.
§6 Sub-processing
1. The Controller gives general consent to the Processor's use of the services of other processors (sub-processors).
2. The current list of sub-processors is published on the Service's website and, as at the date of conclusion of the DPA, comprises:
1) SEOHOST Sp. z o.o., with its registered office at ul. Obornicka 330, 60-689 Poznań, Poland, NIP: 9721323212, REGON: 520718284, KRS: 0000939910 – the hosting provider for the Service: application, database and cached copies of Content (data location: European Economic Area),
2) Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (HRB 6089, Amtsgericht Ansbach) – provider of storage space in which Content is stored exclusively in a form encrypted by the Processor (data location: Germany, European Economic Area).
3. The Processor informs the Controller of any intended changes concerning the addition or replacement of sub-processors at least 14 days before their implementation, by publishing an updated list and providing information by e-mail. The Controller may object within that period.
4. Due to the uniform nature of the Service, raising an objection makes further provision of the Service to the Controller impossible. In such a case the Controller may cease using the Service, and the DPA expires in accordance with §8.
5. The Processor imposes on sub-processors, by contract, the same data protection obligations as those set out in this DPA, and remains liable to the Controller for the sub-processors' performance of their obligations.
§7 Transfers of data outside the EEA
1. Personal data is stored on servers located within the European Economic Area.
2. Any transfer of data to a third country may take place only in compliance with the conditions set out in Chapter V GDPR, in particular on the basis of an adequacy decision or standard contractual clauses, and after this has been reflected in the list of sub-processors in the manner set out in §6(3).
§8 Liability, duration and final provisions
1. The parties are liable for the processing of personal data on the terms set out in Art. 82 GDPR. Towards Controllers who are businesses, the Processor's liability under this DPA is subject to the limitation set out in §10(3) of the Terms, to the extent permitted by mandatory law.
2. The DPA applies for as long as the Controller uses the Service. Termination of use of the Service causes the DPA to expire, which does not release the Processor from the obligations set out in §5(7).
3. Amendments to the DPA are made in the manner provided for amendments to the Terms (§11 of the Terms).
4. Solely the Polish-language version of the DPA is binding. In matters not regulated herein, the provisions of the Terms and the GDPR apply.
