Parties and scope
This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the Terms of Service concluded between VIONTA MANAGEMENT CONSULTING FZCO (“PhotoMea”) and the customer (“Customer”). No separate signature is required: by accepting the Terms of Service and using the platform, the Customer accepts this DPA.
The DPA applies where PhotoMea processes personal data on the Customer’s behalf in the course of providing the service — in particular event content uploaded by or for the Customer, and the access and usage records associated with it (“Customer Data”).
The DPA does not apply to processing for which PhotoMea determines the purposes and means in its own right, in particular account administration, billing, platform security, and face matching. That processing is described in the Privacy Policy and the Biometric Data Policy.
Where the Customer is itself acting as a processor for a further controller, PhotoMea acts as a sub-processor and this DPA is read accordingly.
Applicable data protection law
“Applicable Data Protection Law” means personal data protection legislation that applies to the Customer Data and to the parties’ relevant activities, including the EU General Data Protection Regulation and UK General Data Protection Regulation where applicable.
Each party complies with Applicable Data Protection Law for its own activities. PhotoMea’s assistance obligations are those set out in this DPA, taking account of the nature of processing and information available to it. Mandatory requirements prevail.
The Customer remains responsible for its controller obligations, including notices, legal bases, registrations, and representatives where required.
Roles of the parties
Whether a party is a controller or a processor depends on the processing activity. The table below sets out that allocation.
For the creation of an event, the choice of which content is uploaded, who may access it, and how long it remains available, the Customer determines the purposes and is the controller; PhotoMea acts as processor on the Customer’s instructions.
For face matching, face grouping, and demographic estimation, PhotoMea determines the purposes and means, obtains explicit consent directly from the participant, and applies the retention and deletion periods. PhotoMea is the controller for that processing and it falls outside the scope of this DPA.
The parties intend the allocation described here; their actual roles and statutory responsibilities are determined by applicable law. Neither may bind the other without authority.
| Processing activity | Controller | PhotoMea’s role |
|---|---|---|
| Creating an event and configuring access | Customer | Processor |
| Uploading, storing, and sharing event content | Customer | Processor |
| Registration selfie, face vector generation, and matching | PhotoMea | Controller |
| Age and gender estimation, anonymous event statistics | PhotoMea | Controller |
| Account creation, sign-in, and authentication | PhotoMea | Controller |
| Package purchase, invoicing, and accounting records | PhotoMea | Controller |
| Platform security, abuse prevention, and audit logs | PhotoMea | Controller |
Instructions and Customer undertakings
PhotoMea processes Customer Data only on the Customer’s documented instructions, which comprise this DPA, the Terms of Service, and the configuration choices the Customer makes on the platform, unless permitted by Applicable Data Protection Law. Where Article 28 GDPR applies, processing outside those instructions is permitted only where required by applicable Union or Member State law, or UK law for UK GDPR processing.
Where PhotoMea is required by law to process Customer Data otherwise than on the Customer’s instructions, it will inform the Customer of that requirement before processing, unless the law prohibits it from doing so.
If PhotoMea considers that an instruction infringes the Applicable Data Protection Law, it will inform the Customer without delay and may suspend performance of that instruction until it is resolved.
The Customer warrants that it has a valid legal basis for the personal data it uploads or causes to be uploaded, that it has informed the individuals concerned as required, and that it has obtained any permissions needed. PhotoMea provides an Event Notice Template to assist with this.
The Customer must not upload special category data beyond what the service is designed to process, and must not upload unlawfully obtained content or content that infringes third-party rights.
PhotoMea’s obligations
PhotoMea will process Customer Data only for the purposes of providing the service, will implement the technical and organizational measures set out in Annex 2, and will ensure that personnel authorized to process Customer Data are bound by an obligation of confidentiality.
PhotoMea provides reasonable assistance with individual-rights requests, data protection impact assessments, and competent-authority consultations, taking into account the nature of processing and information available to PhotoMea.
Where PhotoMea receives a request directly from an individual concerning Customer Data, it will not respond to it on its own account, other than to acknowledge receipt and to direct the individual appropriately, and will inform the Customer without undue delay.
Where PhotoMea receives a legally binding request from an authority in relation to Customer Data, it will inform the Customer unless prohibited by law, will assess the legal basis and scope of the request, and will disclose only what is strictly necessary.
Sub-processors
The Customer gives PhotoMea general written authorization to engage sub-processors. The sub-processors authorized as at the date of this DPA are listed in Annex 3.
PhotoMea imposes on each sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, and remains fully liable to the Customer for the performance of that sub-processor’s obligations.
PhotoMea will give prior notice of intended additions or replacements, allowing a reasonable opportunity to object on data protection grounds before the change takes effect. The parties will seek a reasonable resolution of any objection.
If no reasonable resolution is available, the Customer may terminate the affected service before the change takes effect. Refunds required by applicable law or agreed purchase terms remain available.
Security and personal data breach
PhotoMea implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. Those measures are set out in Annex 2 to this agreement.
PhotoMea will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data.
The notification will describe the nature of the breach, the categories and approximate number of records affected, the likely consequences, the measures taken or proposed to address it, and a contact point for further information. Where all of that information is not available at the time, it will be provided in phases as the investigation progresses.
PhotoMea will cooperate with the Customer and take reasonable steps to assist in the Customer’s own notification obligations towards supervisory authorities and individuals.
International transfers
Application hosting, photo storage, and face analysis are carried out in the European Union. Certain providers involved in payments, messaging, content delivery, and app distribution also process data in the United States or on a global edge network. The destinations are set out in Annex 3.
Transfers must comply with Applicable Data Protection Law and the Customer’s documented instructions, including any required transfer safeguards. The Customer may request information about safeguards relevant to its Customer Data, subject to protection of other customers’ data, security information, and commercial confidentiality.
Return and deletion
On termination of the Terms of Service, PhotoMea will, at the Customer’s election, delete or return the Customer Data it processes on the Customer’s behalf, and will provide confirmation on request.
The Customer may export its content before termination. Where the Customer makes no election, PhotoMea will delete Customer Data after termination without undue delay.
Copies are also deleted unless retention is required by applicable law. For processing governed by Article 28 GDPR, any retention exception must be required by Union or Member State law, or UK law for UK GDPR processing. Pending deletion through the backup cycle, backup data is isolated from further use and protected until erased.
The automatic deletion period applies irrespective of termination: event Content is deleted two years after the event date unless deleted earlier.
Information and audit
PhotoMea will make available information reasonably necessary to demonstrate compliance with this DPA on written request to privacy@photomea.com, subject to appropriate confidentiality and security safeguards.
Where that information is not sufficient, the Customer may request a limited audit by an independent auditor no more than once a year and on at least thirty days’ notice. It must occur during normal business hours, under confidentiality, without disrupting the service, and generally at the Customer’s cost.
Audits must protect other customers’ data, confidential information, and system security. Routine frequency and notice limits do not restrict audits or inspections required by law, a competent authority, or a substantiated data-protection incident. PhotoMea will allow and contribute to those audits as required by Applicable Data Protection Law.
Where an audit reveals a non-conformity, PhotoMea will remedy it within a reasonable period and will inform the Customer of the steps taken.
Annex 1 — Subject matter and nature of the processing
Subject matter and purpose: creating events; uploading, storing, converting, displaying, sharing, and downloading photos and videos; access management; search; support; and security services performed on the Customer’s behalf. Account administration, billing, platform security, face matching, and demographic estimation, for which PhotoMea is controller, are outside this DPA; their data and retention periods are described in the Privacy Policy.
Data subjects: the Customer, the Customer’s staff and representatives, event hosts, photographers, participants, guests, and other people appearing in event photos or videos.
Duration of processing: processing continues for as long as the Terms of Service are in force and Customer Data is retained by PhotoMea. The periods below concern processing on the Customer’s behalf.
| Data category | Content | Retention period |
|---|---|---|
| Event and content data | Event name, date, settings, photos and videos, previews | 2 years from the event date |
| User and event roles | Event owner, host, photographer, and participant permissions | For the duration of the event |
| Event activity records | Event access, upload and download activity recorded on the Customer’s behalf | 12 months from the date of the record |
Annex 2 — Technical and organizational measures
PhotoMea applies the measures below to Customer Data where relevant to the processing. Measures may evolve provided the level of protection is not reduced.
| Area | Measure applied |
|---|---|
| Encryption in transit | All client and server communication is encrypted using current TLS versions; unencrypted connections are refused |
| Encryption at rest | Photos, database records, and backups are stored encrypted at the cloud provider level |
| Access authorization | Role-based access control, least privilege, and multi-factor authentication on administrator accounts |
| Isolation of face data | Face vectors are held in separate data spaces per event; cross-event search is not possible |
| Logging and monitoring | Authentication, administrator access, and content deletion are written to an audit log and retained for twelve months |
| Network security | Attack protection, rate limiting, and abuse detection at the content delivery network level |
| Backups | Regular automated backups, verified by restore testing |
| Data minimization | Only data necessary for the service is collected; GPS and precise location data are not collected |
| Automatic deletion | Mandatory platform-level automatic deletion periods for face data and event content |
| Personnel | Confidentiality undertakings, role-based authorization, and immediate removal of access on departure |
| Supplier management | Written agreements with sub-processors, security assessment, and publication of a current list |
| Change management | Code review, version control, dependency updates, and separated test environments |
Annex 3 — Sub-processors
The table below identifies Customer Data sub-processors. The separate service-provider list also includes providers used for PhotoMea’s controller activities and providers acting as independent controllers; listing them does not make them Customer Data sub-processors.
| Provider | Service | Data processed | Processing region |
|---|---|---|---|
| Google Cloud Platform (Google Cloud EMEA Limited) | Application hosting, database, and photo storage | Account data, event data, photos and videos | European Union |
| Cloudflare | Content delivery network, domain management, and attack protection | IP address, request headers, security logs | Global edge network |
Service providers and processing locations
This informational list covers providers used across the service. Their role depends on the activity; only providers processing Customer Data on the Customer’s behalf are governed by the sub-processor provisions of this DPA.
| Provider | Service | Data processed | Processing region |
|---|---|---|---|
| Google Cloud Platform (Google Cloud EMEA Limited) | Application hosting, database, and photo storage | Account data, event data, photos and videos | European Union |
| Google Firebase (Google Cloud EMEA Limited) | Authentication, push notifications, and app infrastructure | User ID, email address, phone number, notification tokens | European Union and United States |
| Amazon Web Services (AWS) | Face analysis, face vector generation, and matching | Event photos, registration selfies, face vectors | European Union |
| Stripe | Collection and processing of card payments | Name, email address, billing details, payment transaction data | United States and European Union |
| Twilio | Delivery of SMS verification codes and notifications | Phone number, message content, and delivery records | United States and European Union |
| Cloudflare | Content delivery network, domain management, and attack protection | IP address, request headers, security logs | Global edge network |
| Vercel | Hosting and analytics for the marketing website | Visit data derived from IP address, page view records | United States and European Union |
| Apple App Store and Google Play | Mobile app distribution and in-app purchases | Store account details, purchase transaction records | United States and European Union |
Term, precedence, and contact
This DPA takes effect when the Customer accepts the Terms of Service and remains in force for as long as PhotoMea processes Customer Data on the Customer’s behalf.
In the event of conflict, this DPA prevails over the Terms of Service on matters of processing Customer Data.
Liability under this DPA is subject to the limitations in the Terms of Service. The cap in those Terms is one aggregate cap for the Terms and this DPA together, except for liability that cannot lawfully be limited.
If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions continue in force and the parties will replace the affected provision with a valid one having equivalent effect.
For questions about this DPA, or to request a countersigned copy, write to privacy@photomea.com.