Data Processing Agreement (DPA)

Disclaimer: This English translation is for informational purposes only. The German version is legally binding.

Which version applies to you? The version for the country where your business is established. It is fixed at registration.

German law applies to all versions, place of jurisdiction Duisburg.

pursuant to Art. 28 GDPR · As of: September 2026 · Version 1.2

Note: This DPA is concluded electronically upon registration on the Pixalo platform (checkbox, timestamp, IP address, version).

Preamble

This Data Processing Agreement regulates the rights and obligations of the parties in connection with the processing of personal data by the Contractor on behalf of the Client pursuant to Art. 28 GDPR.

This Agreement applies to all activities in which the Contractor, its employees or engaged sub-processors process personal data on behalf of the Client. Terms used in this Agreement are to be understood as defined in Art. 4 GDPR. This DPA forms part of the main contract (Terms of Use); in the event of conflicts relating to the processing of personal data, the provisions of this DPA prevail.

§ 1 Parties to the Agreement

1.1 Client

The Client is the Tenant (photographer / company) registered on Pixalo who uses the platform to process personal data.

The data protection role of the Client is determined in accordance with Section 1.3.

1.2 Contractor (Processor)

Cloudox

– Pixalo Division –

Oststraße 181

47057 Duisburg

Germany

The contracting party is Erol Demirkoparan, trading under the business name “Cloudox”, business division “Pixalo” (sole proprietorship).

Email: [email protected]

The Contractor is the Processor within the meaning of Art. 4 No. 8 GDPR.

1.3 Roles of the Parties

Where the Client decides on the purposes and means of the processing (e.g. when collecting data via consent forms, QR cards or orders in the online shop), the Client is the Controller within the meaning of Art. 4 No. 7 GDPR and the Contractor acts as its Processor.

Where the Client itself acts as a processor for a third party (e.g. on the basis of a data processing agreement with a school or kindergarten), the Contractor is engaged as a further processor within the meaning of Art. 28(4) GDPR.

In this case the Client warrants that it holds the required authorization of its controller for the engagement of the Contractor and of the sub-processors listed in Annex 2 (including any third-country elements) and that it is entitled to pass on its controller's instructions to the Contractor.

§ 2 Subject Matter and Duration of the Agreement

2.1 Subject Matter

The subject matter of this Agreement is the processing of personal data by the Contractor within the scope of providing the SaaS platform Pixalo.

Pixalo is a technical platform for operating digital photographer shops. Pixalo is neither a marketplace nor a payment service provider and does not act as a contractual partner between the Client and their end customers.

The processing of the Client's contract, account, billing, payment, security and communication data for the Contractor's own purposes (e.g. registration and account management, subscription billing, the Contractor's own accounting, fraud and abuse prevention, contract communication) is carried out under the Contractor's own data protection responsibility and is not subject to this DPA. Details are set out in the Pixalo privacy policy.

2.2 Duration

This Agreement applies for the duration of the usage relationship. It ends automatically with the termination of the main contract (Terms of Use).

Statutory retention obligations remain unaffected by termination of the contract. The obligations regarding deletion, confidentiality and record-keeping continue to apply after the end of the contract.

§ 3 Type, Purpose, and Scope of Processing

3.1 Type of Processing

The processing comprises:

  • Collection, storage, organisation
  • Adaptation and alteration (e.g. downscaling of image files, creation of preview images and watermark versions)
  • Provision, transmission, logging
  • Restriction, deletion, archiving
  • Transmission to recipients and service providers integrated by the Client

3.2 Purpose of Processing

  • Operation of the platform and photographer online shops
  • Provision of preview images and downloads
  • Order processing
  • Ensuring security, stability, and abuse prevention

3.3 Categories of Data Subjects

  • Photographed persons and persons to be photographed (including minors)
  • End customers of the Client (e.g. parents, legal guardians, purchasers in the online shop)
  • Contact persons of the institutions (e.g. teachers, educators)
  • Persons making appointments or bookings
  • Employees and agents of the Client

3.4 Categories of Personal Data

  • Names and contact details
  • Assignment data (e.g., classes, groups, access codes)
  • Order and transaction data
  • Image data (uploaded original files, watermarked preview images, thumbnails, purchased image files)
  • Technical metadata (e.g., access times, IP addresses)

A detailed description is available in Annex 3.

§ 4 Obligations of the Client

Where the Client is the Controller, the Client is obligated to:

  • ensure the lawfulness of the data processing
  • guarantee valid legal bases for the processing
  • properly inform data subjects
  • obtain necessary consents (especially for minors)
  • issue only lawful instructions to the Contractor
  • ensure the correctness of the transmitted data

The Contractor is not subject to any general obligation to review the legal bases, consents or content chosen by the Client. The duty to give notice of an instruction the Contractor considers unlawful pursuant to § 6 remains unaffected.

Where the Client itself acts as a processor for a third party (Section 1.3), these obligations rest primarily with that third party as controller. In this case the Client is obligated to pass on only documented instructions of its controller and to ensure that the engagement of the Contractor has been authorized by its controller.

§ 5 Obligations of the Contractor

The Contractor commits to:

  • process personal data only on documented instructions from the Client
  • implement appropriate technical and organizational measures pursuant to Art. 32 GDPR
  • maintain the confidentiality of the processing
  • employ only persons bound by confidentiality obligations
  • assist the Client in fulfilling data subject rights requests
  • assist the Client in conducting data protection impact assessments
  • notify the Client of data breaches without undue delay
  • erase or return data upon termination of the contract

The Contractor takes reasonable measures to ensure system availability within the contractually agreed scope.

If the Contractor is required to process personal data by Union or Member State law, it informs the Client of that legal requirement before processing, unless that law prohibits such information.

§ 6 Right of Instruction

The Contractor processes personal data exclusively on instructions from the Client. The Terms of Use and this DPA constitute the basic documented instructions.

Instructions are to be issued in text form to [email protected]. In urgent cases instructions may be issued verbally; the Client confirms them in text form without undue delay. The Contractor documents instructions received and their implementation.

If the Contractor is of the opinion that an instruction infringes applicable law, it informs the Client without undue delay. It is entitled to suspend the implementation of the instruction until it is confirmed or amended by the Client.

§ 7 Confidentiality

The Contractor ensures that all persons entrusted with processing are bound by confidentiality or are subject to an appropriate statutory duty of confidentiality.

This obligation continues to exist after termination of the contract.

§ 8 Technical and Organizational Measures

The Contractor implements appropriate technical and organizational measures pursuant to Art. 32 GDPR to guarantee a level of security appropriate to the risk.

The measures are documented in Annex 1 (TOMs) and constitute a binding part of this contract.

The Contractor is entitled to further develop the measures, provided that the level of protection is not reduced. The Contractor informs the Client of material changes to the TOMs in an appropriate form (e.g. by email or in the dashboard).

§ 9 Sub-processors

9.1 General Authorization

The Client grants the Contractor general authorization to employ sub-processors.

Sub-processors employed at the time of contract conclusion are listed in Annex 2.

9.2 Modifications

The Contractor shall inform the Client of any intended changes regarding the addition or replacement of sub-processors.

The Client may object in text form within 14 days of receipt of the information for important data-protection-related reasons. If no objection is raised within this period, consent is deemed granted. In the event of an objection the parties first seek a reasonable solution; § 16 remains unaffected.

The information can be sent via email or the customer area.

9.3 Contractual Binding

The Contractor ensures that sub-processors are contractually subject to at least the same data protection obligations as agreed in this Agreement. Personal data is only passed on once the Contractor has satisfied itself that these obligations are complied with.

9.4 Liability for Sub-processors

Where a sub-processor fails to fulfil its data protection obligations, the Contractor is liable to the Client for the performance of that sub-processor's obligations in accordance with Art. 28(4) GDPR.

§ 10 Third Country Transfer

A transfer of personal data to third countries only occurs if the special requirements of Art. 44-49 GDPR are met.

This can be ensured in particular by:

  • Adequacy decision of the EU Commission (Art. 45 GDPR)
  • Standard contractual clauses (Art. 46 Abs. 2 lit. c GDPR)
  • Additional technical and organizational protection measures

The original storage of the data (hosting, database, object storage, backups, email dispatch) takes place in the AWS Frankfurt region (eu-central-1). When content is delivered via the content delivery network (Amazon CloudFront) and via the Cloudflare network (DNS, reverse proxy, TLS termination, DDoS protection), encrypted content and connection data may be cached or processed at worldwide locations depending on the user's location; this is based on the certifications of AWS and Cloudflare under the EU-US Data Privacy Framework and the EU Standard Contractual Clauses of the respective data processing agreements. Services with third-country elements integrated by the Client itself (e.g. its own analytics services) are the Client's responsibility.

§ 11 Support in Data Subject Rights

The Contractor supports the Client to a reasonable extent in fulfilling requests of data subjects pursuant to Art. 15–22 GDPR and – taking into account the nature of the processing and the information available to it – with the obligations under Art. 30 and Art. 32 to 36 GDPR.

Requests addressed directly to the Contractor are forwarded to the Client without undue delay. A substantive response to data subjects or third parties is only given with the Client's prior approval, unless a statutory obligation to respond directly exists.

The Contractor may request reasonable compensation for support services exceeding the contractually agreed scope.

§ 12 Notification of Data Breaches

The Contractor notifies the Client of personal data breaches without undue delay after becoming aware of them. Substantiated suspected cases are also reported; where not all information is available yet, it may be provided in stages.

The notification contains at least:

  • Description of the nature of the breach
  • Categories and approximate number of data subjects and datasets affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach
  • Time of detection and estimated period of the incident
  • Contact person for further information

The obligation to notify the supervisory authority under Art. 33 GDPR remains with the Client. The Contractor supports the Client to the required extent with its obligations under Art. 33 and 34 GDPR.

The Contractor also notifies without undue delay significant disruptions in the performance of the engagement, infringements of data protection provisions or of this Agreement by the Contractor or its employees, and inspections or measures by supervisory authorities insofar as they relate to the commissioned processing.

§ 13 Audit Rights

The Client has the right to verify compliance with this contract.

The Contractor provides the Client upon request with all necessary information to demonstrate compliance. This can occur in particular by:

  • Self-assessments and documentation
  • Certifications and audit reports
  • Answering questionnaires

On-site inspections take place upon prior notice in text form (at least 14 days), during normal business hours, without avoidable disruption of business operations and no more than once in any twelve months. In the event of a specific data protection incident or at the request of a supervisory authority, the restrictions on notice and frequency do not apply. Inspections are limited to the Client's data and the systems relevant thereto; data of other clients and the Contractor's business secrets remain protected. The provision of customary evidence is free of charge; for support beyond this the Contractor may request reasonable remuneration.

§ 14 Erasure and Return

Upon termination of the contract, the Contractor proceeds as follows, at the Client's choice:

  • the Contractor deletes all personal data, unless a retention obligation exists
  • the Contractor returns data on request in a common, machine-readable format
  • the Contractor procures deletion or return also at engaged sub-processors
  • the Contractor hands over documents that are subject to a statutory retention obligation of the Client (Sec. 147 AO, Sec. 257 HGB — accounting records and invoices generally eight years, certain books and financial statements ten years), at the Client's choice, for the Client's own retention, or stores them on the basis of a continuing documented instruction for the duration of the statutory period, blocked and exclusively for archiving purposes

If the Client does not exercise its choice within 30 days of termination, the data is deleted. Erasure – including erasure at sub-processors – is confirmed in writing upon request.

Personal data contained in database backups is blocked for operational use and automatically overwritten by the rolling backup retention (currently seven days); media files are subject to the storage and deletion mechanisms described in Annex 1. Restores from backups are performed exclusively for fault handling or security incident response; deletion instructions issued beforehand are re-applied after a restore. Documentation serving as evidence of proper processing is retained beyond the end of the contract in accordance with the applicable periods.

§ 15 Liability

The liability of the parties is governed by statutory provisions, in particular Art. 82 GDPR.

The Contractor is not liable for damages resulting from incorrect instructions, unlawful content, or missing consents of the Client. This applies only to the extent that the damage is attributable exclusively to the Client's sphere of responsibility and the Contractor has not contributed to causing the damage. Mandatory statutory liability provisions, in particular Art. 82 GDPR, remain unaffected.

§ 16 Extraordinary Termination

The Client may terminate the main contract and this DPA without notice in the event of a serious breach by the Contractor of data protection law or this Agreement, in particular substantial non-implementation of the agreed technical and organizational measures or an unlawful refusal of inspection rights. In the case of minor breaches the Client first sets a reasonable period for remedy.

The Contractor is entitled to extraordinary termination if the Client objects to the engagement of a sub-processor pursuant to § 9, no reasonable solution can be found and the service cannot be provided without the sub-processor concerned, or if the Client insists on a manifestly unlawful instruction.

§ 17 Final Provisions

  • This DPA is concluded electronically upon registration.
  • Upon acceptance it is legally binding (Art. 28(9) GDPR).
  • Amendments require text form.
  • Material changes to this DPA are provided to the Client as a new version for acceptance; acceptance is logged with time, version and account. Changes to sub-processors are governed by § 9, changes to the TOMs by § 8.
  • Both parties treat business secrets and security information of the other party confidentially, also after the end of the contract; disclosures for the purpose of exculpation under Art. 82(3) GDPR or to competent authorities remain permissible.
  • A right of retention with respect to the personal data processed under this engagement and the associated data carriers is excluded.
  • German law applies.
  • Place of jurisdiction is – where permissible – the registered seat of the Contractor.
  • Should individual provisions be invalid, the remainder of the Agreement remains effective.

Annex 1 – Technical and Organizational Measures (TOMs)

This annex describes the measures pursuant to Art. 32 GDPR.

1. Entry Control

Measures to prevent unauthorized entry to data processing systems.

  • Use of certified data centers with physical entry control
  • No proprietary physical servers outside of data centers

2. Access Control

Measures to prevent unauthorized system usage.

  • Strong authentication (password guidelines)
  • Protection against automated login attempts through rate limiting and temporary access restrictions
  • Encrypted transmission (TLS)
  • Multi-factor authentication for administrative access to the infrastructure
  • Personal administrator accounts

3. Usage Control

Measures to restrict to authorized usage.

  • Role-based access control systems (RBAC)
  • Principle of least privilege
  • Regular audit of authorization rights

4. Separation Control

Measures to process data of different clients separately.

  • Strict logical multi-tenant isolation
  • Tenant-ID-based access control on database level
  • No view of third-party tenant data
  • Separation of development, test and production environments

5. Transmission Control

Measures to secure transmission and storage.

  • Encrypted data transmission (TLS 1.2+)
  • Signed download links with expiry date
  • Encryption of data at rest (server-side encryption of database and object storage)
  • Personal data files are generally not sent as unencrypted email attachments; retrieval takes place via access-protected, time-limited links. Transmission to email systems is transport-encrypted (TLS) where supported by the receiving side.

6. Input Control

Traceability of data input and modifications.

  • Logging of security-relevant actions
  • Archiving of ordering processes with immutable price and order snapshots and consecutive invoice numbering
  • Version control and review processes for source code
  • Central management of credentials and secrets (no hard-coded credentials)
  • Verification of payment provider webhook signatures
  • Connection of payment provider accounts via account identifiers; the Client's access credentials are not stored

7. Availability Control

Protection against loss and destruction.

  • Daily automated database backups (rolling 7-day retention)
  • Highly redundant storage of media files in the object storage
  • Redundant infrastructure
  • Monitoring and alerting
  • DDoS protection and rate limiting

8. Recoverability

  • Defined recovery procedures
  • Automated snapshot creation and status monitoring by the hosting provider

Annex 2 – Sub-processors

The Contractor employs the following categories of sub-processors:

ServiceProviderRegion / Transfer basis
Cloud hosting (operation of the platform on Amazon EC2, including infrastructure monitoring)Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 LuxembourgEU – Frankfurt region (eu-central-1)
Object storage for media files (Amazon S3)Amazon Web Services EMEA SARL, LuxembourgEU – Frankfurt region (eu-central-1)
Database and daily backups (Amazon RDS)Amazon Web Services EMEA SARL, LuxembourgEU – Frankfurt region (eu-central-1)
Content delivery (Amazon CloudFront)Amazon Web Services EMEA SARL, LuxembourgWorldwide edge locations; EU-US Data Privacy Framework and EU Standard Contractual Clauses (AWS data processing addendum)
Email dispatch (Amazon SES): delivery of transactional and notification emails (e.g. gallery access codes, order and reminder emails)Amazon Web Services EMEA SARL, LuxembourgEU – Frankfurt region (eu-central-1)
AI-powered text recognition for class lists (Amazon Bedrock, Anthropic models)Amazon Web Services EMEA SARL, LuxembourgEU – connected via the Frankfurt region (eu-central-1); inference exclusively in AWS EU regions (EU inference profile). Inputs and outputs are not used to train the models
DNS, reverse proxy/CDN, TLS termination and DDoS protection for all Pixalo domains (including shop and gallery traffic)Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USAGlobal network; processed data comprises IP addresses, request metadata and security logs; EU-US Data Privacy Framework and EU Standard Contractual Clauses (Cloudflare DPA)

Amazon Web Services and Cloudflare are certified under the EU-US Data Privacy Framework; in addition, the EU Standard Contractual Clauses of the respective data processing agreements (AWS GDPR DPA, Cloudflare DPA) apply. The Contractor gives notice of intended changes to this list in accordance with § 9.

Services integrated by the Client itself (e.g. the Client's own payment provider accounts such as Stripe or PayPal, the Client's own Google Analytics tracking in the online shop, the Client's own domain and DNS providers) are not sub-processors of the Contractor; in this respect the Client itself is responsible.


Annex 3 – Description of Processing Activities

Subject Matter of Processing

Technical provision of a SaaS platform to operate digital photographer shops including storage, provision, and delivery of photos as well as processing of orders.

Duration of Processing

  • Active data: duration of the usage relationship
  • Download links: validity as configured by the Client (7 to 90 days from the order, default 7 days); the setting constitutes a documented instruction. After expiry, access is blocked and generated ZIP archives are deleted automatically.
  • Database backups: rolling, currently seven days; media files are subject to the storage and deletion mechanisms described in Annex 1
  • Invoice and accounting record data relevant under tax and commercial law: in accordance with the statutory retention period (generally eight or ten years); other components of orders (e.g. image files, galleries, access codes) are subject to the shorter periods of the usage relationship
  • Security logs: maximum 90 days

Purpose of Processing

  • Provision of platform functionality
  • Storage and delivery of photos (including generation of preview images and watermark versions)
  • Matching of photos to persons via access codes and QR codes
  • Order processing and archiving (including invoicing on behalf of the Client)
  • Management of appointments and bookings, where used by the Client
  • Dispatch of emails on behalf of the Client (e.g. gallery access codes, order and reminder emails including unsubscribe management)
  • Handling of support and contact requests
  • Ensuring security, stability, and availability
  • Transmission of the order and transaction data required for payment initiation and payment status queries to the payment service providers integrated by the Client on its own responsibility
  • AI-powered text recognition on class lists provided by the Client to create student records (processing within the EU, no use for model training)

Type of Personal Data

  • Master and contact data (names, email addresses, billing and delivery addresses, phone numbers where provided)
  • Assignment data (classes, groups, access codes, QR codes, appointment and booking data)
  • Order and transaction data (products, quantities, prices, payment status and transaction IDs of the payment providers as well as, where applicable, payment method, card brand, last four digits of the payment instrument and payer email address — full card or bank account data is not processed by the Contractor)
  • Image data (uploaded original files, watermarked preview images, thumbnails, purchased image files) together with technical image metadata
  • Consent and legal-basis records (e.g. documented consents, unsubscribe status)
  • Contract, dispatch and communication records (e.g. contract acceptances, dispatch logs)
  • Technical data (IP addresses, access times, user agent, security and error logs)

Categories of Data Subjects

  • Photographed persons and persons to be photographed (including minors)
  • End customers of the Client (e.g. parents, legal guardians, purchasers in the online shop)
  • Contact persons of the institutions (e.g. teachers, educators)
  • Persons making appointments or bookings
  • Employees and agents of the Client

Where the Client itself acts as a processor (Section 1.3), the above details apply accordingly to the sub-processing relationship; in that case the controller is the Client's client.

Cloudox – Pixalo Division
pursuant to Art. 28 GDPR · As of: September 2026 · Version 1.2