in.photo

Data processing agreement

Review draft for business customers using in.photo to store and share event photos on their instructions under Article 28 GDPR.

Draft — not yet effective

This document is a proposal for review, not an effective data processing agreement. Every TODO must be resolved, the annexes completed and the final version agreed before business processing under this agreement begins.

Version: 0.1-draft · Draft prepared: September 20, 2026

Effective date: TODO — to be set for the approved version. This draft has no effective date.

German is the primary version at in.photo/de/avv. This English version is a translation. The proposed agreement gives the German version precedence if the two versions differ.

To keep a copy, use your browser’s Print command and choose Save as PDF or a printer. The print layout includes the version, draft status and both annexes. A copy supports your documentation; it does not replace your own Article 30 records of processing.

https://in.photo/en/dpa

1. Parties and contact

The processor is Adam Cooper, trading as Adam Cooper Softwareentwicklung, a non-registered sole proprietor, c/o GAM, Pappelallee 64, 10437 Berlin, Germany (“in.photo”). The controller is the business customer identified in the service contract (“customer”). The person concluding that contract must be authorised to represent the customer.

TODO — record the customer’s legal name, address, authorised representative and privacy/instruction contact with the agreed version and date. Notices and instructions to in.photo go to mail@in.photo; in.photo must verify the sender’s authority. A launch-notification signup alone does not conclude this agreement.

mail@in.photo

2. Scope, roles and duration

This agreement supplements the service contract for customers acting in a business or professional capacity within § 14 BGB, only insofar as the customer determines the purposes and essential means of processing event data and in.photo processes those data on the customer’s behalf. It lasts for the commissioned processing, including the return or deletion of data at its end. If the customer itself acts as a processor, a suitable subprocessing arrangement must first be agreed.

The customer is responsible for a lawful basis, required information and permissions, and the lawfulness of its instructions. in.photo remains responsible for its own GDPR obligations and for processing it carries out as controller, such as its own account administration and business correspondence, as described in the privacy policy. Consumer status does not automatically create a household exemption: that exemption concerns purely personal or household activities without a professional or commercial connection and does not exempt the platform’s own processing.

3. Subject matter, nature and purpose

The subject matter is operating private event-photo collections for the customer. On documented instructions, in.photo receives and stores uploads, associates photos with a collection, creates display versions, makes photos available through enabled invitations and event walls, and exports or deletes them. Supporting operations include authorised support, security logging and backups insofar as required for this commissioned service. The purpose is collecting and delivering event photos to the audience chosen by the customer.

The customer determines which collections and participants are included, whether sharing or the wall is enabled, and the agreed retention period. Disabling sharing blocks guest access; re-enabling it restores the same invitation link and QR code. Disabling sharing is not a deletion instruction. TODO — confirm the commissioned features, data flows and retention instructions for the business offering; the general terms’ storage promises must match the implemented deletion and notice procedures.

4. Data and people concerned

Data include photos of identifiable people and embedded image metadata; uploader identifiers and upload times; collection names, event information and invitation/access identifiers; and technical request, device or connection information insofar as processed for the commissioned service. Data subjects include event guests, people depicted in photos, the customer’s clients, uploaders and the customer’s staff or contacts involved in an event.

Photos can include children or reveal special categories of data, depending on their content and context. A photograph is not automatically biometric data used for unique identification. No facial identification, advertising or AI training with customer photos is authorised by this agreement. TODO — confirm the actual metadata and log fields, any intended sensitive-data use and appropriate additional safeguards before accepting such instructions.

5. Documented instructions

in.photo processes customer data only on documented instructions, including for transfers to a third country or an international organisation, unless EU or Member State law requires the processing. In that case, in.photo informs the customer of the legal requirement before processing unless that law prohibits notice on important grounds of public interest. The agreed contract and authorised collection settings form the initial instructions; subsequent instructions must be recorded electronically or in writing.

in.photo immediately informs the customer if an instruction appears to infringe the GDPR or other EU or Member State data-protection law and suspends the affected instruction while it is clarified. in.photo may not use the data for its own unrelated purposes. TODO — establish a verifiable instruction register and customer contact procedure; do not put personal photos or invitation secrets in ordinary support logs.

6. Confidentiality and authorised persons

in.photo ensures that persons authorised to process the data are bound by confidentiality commitments or an appropriate statutory duty of confidentiality. Access is limited to what their assigned tasks require. Confidentiality continues after access or the service relationship ends.

TODO — verify the confidentiality commitments, training, access approvals and prompt removal of access for every person with customer-data access, including support and administrators. Do not infer that a sole proprietorship has additional staff, a data protection officer or certifications.

7. Security and processing locations

in.photo implements and maintains measures appropriate to the risks under Article 32 GDPR, considering the nature, scope, context and purposes of processing and the risks to individuals. Annex 1 must describe the agreed measures concretely. Changes may improve those measures but must not reduce the agreed level of protection; material changes are documented and communicated to the customer.

Proposed location restriction: commissioned customer data, backups and related logs are processed only in verified EU locations, including any remote administration. TODO — verify that restriction and every provider’s actual locations before agreement. Any proposed processing outside it requires prior documented agreement, appropriate instructions and compliance with Chapter V GDPR. An EU server address alone does not establish that all processing stays in the EU.

8. Subprocessors

The customer grants general written authorisation for the subprocessors in the completed and agreed Annex 2 and for subsequent changes made under the following procedure. Proposed additions or replacements must be notified to the customer’s designated contact at least 30 calendar days before access begins, with the provider, tasks, data, locations and safeguards stated. The customer may object on reasonable data-protection grounds within that period. This 30-day period is a proposed contractual term, not a statutory fixed period.

in.photo will seek an alternative or safeguards that resolve a justified objection. The proposed subprocessor must not receive the affected data while that objection remains unresolved; if no solution is possible, the customer may terminate the affected service before the change and request return or deletion. in.photo imposes substantively the same data-protection duties by written contract and remains fully liable to the customer for the subprocessor’s performance of those duties. TODO — approve the notice period, notification channel, initial list and objection procedure. Candidate entries in this draft are not authorisations.

9. Assistance with rights and compliance

Taking account of the nature of processing, in.photo assists the customer through appropriate technical and organisational measures, insofar as possible, with requests under Chapter III GDPR, including access, correction, erasure, restriction, portability and objection. It promptly forwards requests concerning commissioned data, provides the information needed to respond within applicable deadlines and does not decide them independently unless instructed or legally required.

Taking account of the nature of processing and information available to it, in.photo also assists with security, breach assessment and notification, data-protection impact assessments and prior consultation under Articles 32–36 GDPR. TODO — confirm how staff locate and export/delete originals, derivatives, metadata and copies; test the request workflow and support response targets. The controller’s statutory deadline must not be delayed by an internal approval or fee dispute.

10. Personal data breaches

in.photo notifies the customer without undue delay after becoming aware of a personal data breach affecting commissioned data. The notice describes the nature of the breach, where possible the categories and approximate numbers of people and records concerned, a contact, likely consequences and measures taken or proposed to address it and mitigate harm. Missing information is supplied in stages without further undue delay.

in.photo takes reasonable immediate containment and recovery measures, preserves relevant evidence and assists the customer’s notifications to the authority and affected people. The customer decides its own required notifications; in.photo’s independent legal duties remain unaffected. TODO — verify the monitored incident contact, escalation procedure and notification drill. The controller’s possible 72-hour authority deadline is not a 72-hour grace period for the processor.

11. Return and deletion

At the end of the commissioned services, in.photo, at the customer’s choice, returns the personal data in a usable format or deletes them, and deletes existing copies unless EU or Member State law requires retention. Return does not remove the duty to delete remaining copies. The choice and instructions are documented; the customer must have a practical opportunity to obtain its data before deletion.

TODO — agree and implement the export format, completion deadline and maximum backup-expiry period before this agreement takes effect. Until backup copies are erased within that agreed period, they remain protected, isolated from ordinary use and subject to this agreement; any necessary restoration reapplies outstanding deletion instructions. in.photo confirms completion on request. Legally required retention is identified to the customer, restricted to that purpose and ended when the requirement expires.

12. Information and audit rights

in.photo makes available all information necessary to demonstrate compliance with Article 28 GDPR and allows and contributes to audits, including inspections, by the customer or an auditor mandated by it. Reports and other evidence can support an audit but do not eliminate inspection rights when needed. Appropriate confidentiality arrangements protect other customers’ data without preventing meaningful verification.

Ordinary audits are coordinated with reasonable notice and proportionate scope. Urgent incidents, suspected non-compliance and supervisory-authority requirements permit shorter notice as necessary. No fixed annual limit, discretionary veto or blanket fee may make the statutory right ineffective. TODO — establish the evidence pack, responsible contact and practical inspection arrangements; do not claim an independent certification that has not been obtained.

13. Incorporation, priority and versions

Once completed, approved and effectively incorporated at contract conclusion, this agreement and its annexes form part of the business customer’s service contract. For commissioned data processing, they prevail over conflicting service terms. Statutory duties and liability remain unaffected. Amendments and instructions must be documented, including electronically; a newly published version does not automatically amend an existing contract.

The German version is intended to prevail over its English translation. TODO — obtain legal review of incorporation and language priority, retain the exact agreed version and annexes, and record the customer, representative, agreement date and version. There is no separate DPA checkbox planned: the final agreement must be presented and incorporated through effective terms acceptance. The current launch-notification form does not perform that step.

Annex 1 — Technical and organisational measures

Proposed measures for verification. None of the following is a statement that a control has been implemented or independently audited. Replace every TODO with the confirmed scope, configuration, responsible person and evidence before agreement.

1. Encryption in transit

TODO — verify HTTPS/TLS for browser traffic, uploads, downloads and service/provider connections; record protocol settings, certificate renewal and any internal network exceptions. Prohibit unprotected transfer of customer photos.

2. Encryption at rest

TODO — verify encryption of application databases, photo objects, volumes and backups separately, including algorithms, key ownership, storage, access and rotation. Private buckets and a hosting contract do not by themselves demonstrate encryption at rest; do not promise it until verified.

3. Access control

TODO — document individual administrator accounts, strong authentication/MFA, least privilege, credential handling, access review and revocation. Verify host/guest authorisation on every photo operation and support access only for an authorised purpose. Printed invitation links remain sensitive access capabilities.

4. Separation and confidentiality

TODO — verify separation of customers and collections, private object storage, separation of test and production data and confidential support procedures. Check that originals and display versions cannot be retrieved outside the authorised collection; use synthetic test data.

5. Hosting and physical protection

TODO — verify Hetzner Online GmbH’s role, contracted EU sites, administrative access locations and contractual physical-security measures. Confirm the locations of photo storage, databases, processing, logs and each backup; complete the provider agreement and Annex 2.

6. Availability and recovery

TODO — define and verify backup scope and schedule, encryption, separate access, EU destinations, retention, deletion and restoration tests. Record achievable recovery-time and data-loss targets. A persistent disk is not a backup, and a proposed backup policy is not evidence of a successful restoration.

7. Logging and monitoring

TODO — verify bounded security logs, access restrictions, retention and alert handling. Exclude photos, invitation secrets and unnecessary identifiers from logs. Record actual log fields and locations and test redaction, expiry and incident alerts.

8. Maintenance, deletion and regular review

TODO — document patching, vulnerability handling, change review, incident response, rights handling and deletion of originals, derivatives and backups. Regularly test and evaluate the effectiveness of these measures under Article 32(1)(d), record findings and remedy failures.

Annex 2 — Subprocessor register

TODO — complete and approve the actual list before the agreement takes effect. These are candidate roles to investigate, not an approved or complete register. Include any onward subprocessors and remote support access relevant to the commissioned processing.

Unverified candidates — no authorisation granted by this draft
Name / statusService / dataProcessing locations
Hetzner Online GmbH — proposed; TODO verify contractTODO — specify application/database hosting and customer data accessible under the commissioned service.TODO — identify contracted EU sites and all administrative access locations; verify rather than assume EU-only processing.
TODO — photo/object-storage providerTODO — identify the legal entity, original/display-photo storage, metadata and onward providers; consolidate with hosting if appropriate.TODO — actual storage, replication and support locations.
TODO — backup provider or confirmed hosting scopeTODO — identify the legal entity, backed-up data and restoration responsibilities; do not invent a separate provider.TODO — backup, replica and support locations; verify EU processing.
MailPace / OhMySMTP Ltd — TODO assess whether in scopeTODO — include only if used on the customer’s behalf; confirm legal entity, message contents and delivery metadata. in.photo’s own account correspondence requires a separate role assessment.TODO — verify all sending, storage, backup and support locations. Resolve any UK or other non-EU processing against section 7 before authorisation.

For each entry, retain the provider’s address, agreement, security evidence, onward-provider list and any transfer assessment. Remove unused candidates and add every actual subprocessor. TODO — date and version the approved register and establish the advance-notice process in section 8.

Review required before going live

This draft needs review by a lawyer before going live as an effective agreement. TODO — the operator must verify every infrastructure statement, complete both annexes and customer details, approve operational deadlines, and implement effective contract acceptance with version evidence. Until then, this document must remain clearly marked as a non-binding review draft.

Back to the terms of use

ImprintPrivacy policyTerms of use