Legal

Data Processing Agreement

Data Processing Agreement for GALLERYDOCK Effective date: June 17, 2026

This English translation is provided for convenience. If it differs from the German original, the German version controls. View the legally controlling German original

Agreement text

Data Processing Agreement for GALLERYDOCK Effective date: June 17, 2026 between the customer of GALLERYDOCK hereinafter referred to as the “Customer” and GALLERYDOCK Edmond Rätzel Karmarschstraße 16 30159 Hannover Germany Email: info@gallerydock.com VAT identification number: DE 306 256 380 hereinafter referred to as the “Processor” 1. Subject and purpose of the contract 1.1 This Data Processing Agreement regulates the processing of personal data by the Processor on behalf of the Customer in accordance with Art. 28 GDPR. 1.2 The Processor provides the Customer with the web-based software GALLERYDOCK. GALLERYDOCK is used to create, manage, store, process, present and provide media galleries for photographers, filmmakers, studios, agencies and other businesses. 1.3 As part of its use of GALLERYDOCK, the Customer may process personal data of its customers, end customers, depicted individuals, employees, contacts or other data subjects through GALLERYDOCK. 1.4 To the extent the Processor processes personal data of the Customer, its end customers or other data subjects on the Customer's behalf, it does so exclusively in accordance with this Agreement, the main agreement, the Terms of Service, the service description and the Customer's documented instructions. 1.5 This Agreement does not apply to processing for which the Processor acts as an independent controller. This includes, in particular, the Processor's own contract administration, invoicing, payment enforcement, support communications, abuse prevention, statutory record-keeping obligations and security measures, unless those activities are performed on the Customer's behalf. 2. Duration of processing 2.1 This contract applies for the duration of the use of GALLERYDOCK by the customer. 2.2 The contract ends automatically with the termination of the main contract, provided that no legal retention obligations, legitimate interests, security reasons or processing measures conflict with this. 2.3 After the end of the contract, personal data will be deleted or returned in accordance with this contract, unless there are legal obligations or legitimate reasons for further storage. 3. Type and purpose of processing 3.1 The processing serves to provide the functions of GALLERYDOCK. 3.2 The processing includes in particular: a) Storage of images, videos and other files b) Storage of gallery information c) Management of gallery access d) Provision of shared galleries e) Upload, download and display media f) Creation of preview images, thumbnails, web variants and video posters, if technically required g) Processing of file and media metadata h) Processing of selection, favorites, comments or download information, if used by the customer i) technical access control j) Security, error and misuse checking k) Storage of status information about uploads, processing and galleries l) Support with support requests from the customer 3.3 The Processor does not use content processed on the Customer's behalf for its own advertising, AI training, resale or any other purpose outside the performance of the Agreement unless the Customer has separately and expressly consented. 4. Type of personal data 4.1 The following categories of personal data may be processed on the Customer's behalf: a) Pictures and videos of people b) Names and contact details of end customers c) Email addresses of end customers d) Customer numbers or internal designations of the customer, if used e) Gallery names f) File names g) Metadata of images, videos and files, if available h) Comments, favorites, selection marks and download information, if activated i) Access codes, password status and release information j) IP addresses and technical access data k) Device, browser and session information l) Upload status, processing status and error status m) technical protocol and security data 4.2 Special categories of personal data within the meaning of Art. 9 GDPR should generally not be specifically processed via GALLERYDOCK, but may be indirectly affected by image or video content, for example health data, religious characteristics, political views or other sensitive information, to the extent that these can be recognized in images or videos. 4.3 The customer is responsible for ensuring that there is a sufficient legal basis for the processing of special categories of personal data to the extent that such data is affected by its content. 5. Categories of data subjects 5.1 The following categories of data subjects may in particular be affected by the processing: a) Customers and end customers of the customer b) people depicted c) Customer, contact persons and employees of the customer d) Guests and visitors to shared galleries e) People who use comments, favorites, selection marks or downloads f) other persons whose data are processed through the customer's content 6. Responsibility and instructions 6.1 The customer is responsible within the meaning of the GDPR for the personal data that he processes or has processed via GALLERYDOCK. 6.2 The processor processes personal data exclusively on documented instructions from the customer, unless he is obliged to process it by the law of the European Union or a member state. 6.3 The customer's instructions result from this contract, the main contract, the general terms and conditions, the service description, the settings within GALLERYDOCK and the functions used by the customer. 6.4 Individual instructions can be given in text form or via the functions provided in GALLERYDOCK. 6.5 If the processor is of the opinion that an instruction violates data protection law, he will inform the customer of this. The processor is entitled to suspend the implementation of the relevant instruction until it has been confirmed or changed. 6.6 The customer remains responsible for the lawfulness of the processing, the legal basis, the information obligations towards data subjects, the necessary consents and the admissibility of the uploaded content. 7. Obligations of the processor 7.1 The processor processes personal data only within the scope of this contract and the documented instructions of the customer. 7.2 The processor ensures that persons authorized to process personal data have been obliged to maintain confidentiality or are subject to an appropriate legal obligation of confidentiality. 7.3 The processor takes appropriate technical and organizational measures to protect personal data. 7.4 The processor provides the customer with appropriate support in fulfilling his data protection obligations in accordance with the legal requirements. 7.5 The Processor will inform the Customer without undue delay if it becomes aware of a personal data breach affecting data processed on the Customer's behalf. 7.6 The processor keeps a register of processing activities to the extent required by law. 7.7 The Processor will participate in data protection impact assessments and prior consultations to the extent required by law and relevant to the processing by GALLERYDOCK. 8. Obligations of the customer 8.1 The customer is responsible for the lawful use of GALLERYDOCK. 8.2 The customer ensures that there is a sufficient legal basis for all personal data processed via GALLERYDOCK. 8.3 The customer properly informs end customers, depicted persons and other affected persons about the processing of their data. 8.4 The customer is responsible for the configuration of his galleries, in particular password protection, releases, download rights, visibility, expiry dates and link distribution. 8.5 The customer may not process any personal data via GALLERYDOCK whose processing is unlawful or violates the rights of third parties. 8.6 The customer is obliged to treat his access data confidentially and to prevent unauthorized access to his account. 8.7 The customer informs the processor immediately if he detects any indications of data protection violations, unauthorized access or misuse of his account. 9. Technical and organizational measures 9.1 The processor shall take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk. 9.2 The measures take particular account of the confidentiality, integrity, availability and resilience of the systems. 9.3 The measures include in particular: a) Restrictions on access to personal data b) role-based permissions c) Separation of customer and gallery data d) private storage of media content e) server-side access controls f) encrypted transmission g) Protection of access data and secrets h) Logging of security-relevant processes, if necessary i) Protection against unauthorized access j) Protection against accidental loss, alteration or disclosure k) secure software development l) regular testing and further development of appropriate protective measures 9.4 The technical and organizational measures are described in more detail in Appendix 2. 9.5 The processor may further develop technical and organizational measures provided that the level of protection is not significantly lower. 9.6 The processor checks, assesses and evaluates the effectiveness of the technical and organizational measures at least once a year and as necessary when there are significant changes to the platform, the infrastructure or the risk situation. Findings from such reviews can be used to further develop the measures appropriately. 10. Sub-processors 10.1 The customer grants the processor general authorization to use sub-processors. 10.2 The processor uses in particular the sub-processors and service providers listed in Appendix 3 for GALLERYDOCK V1. 10.3 The Processor obliges sub-processors by contract to comply with data protection requirements that essentially correspond to the level of protection in this contract. 10.4 The processor will inform the customer about significant changes to sub-processors, to the extent this is required by law. 10.5 The customer can object to the change or involvement of a sub-processor for important data protection reasons. The objection must be explained in text form and comprehensibly justified. 10.6 If the processor cannot adequately remedy the objection, the customer can terminate the affected service in accordance with the main contract. An objection without an objective data protection reason does not entitle you to terminate current payment obligations free of charge. 10.7 The use of service providers who do not process personal data on behalf of others or who act exclusively as their own controllers does not constitute subcontracted processing within the meaning of this contract. 11. Third Country Transfers 11.1 Personal data may be processed by service providers who are based outside the European Union or the European Economic Area or who process data there. 11.2 If personal data is transferred to a third country, this will only occur if the legal requirements are met. 11.3 Suitable guarantees may in particular be an adequacy decision by the European Commission, EU standard contractual clauses, the EU-US Data Privacy Framework or other mechanisms provided for by law. 11.4 The processor obliges the sub-processors used to comply with appropriate guarantees for third-country transfers, if necessary. 12. Support for data subject rights 12.1 The Processor supports the Customer, where reasonably possible, in responding to requests from data subjects. 12.2 This applies in particular to information, correction, deletion, restriction of processing, data portability and objection. 12.3 If a data subject contacts the processor directly and the request concerns data that is processed on behalf of the customer, the processor can forward the request to the customer if an assignment is possible. 12.4 The processor does not answer such inquiries independently in terms of content, provided that the customer is the responsible party and the processor is not legally obliged to answer on his own. 13. Data Breaches 13.1 The Processor will inform the Customer without undue delay if it becomes aware of a personal data breach affecting data processed on the Customer's behalf. 13.2 The notice shall contain, where possible, information on: a) Type of data breach b) affected data categories c) affected groups of people d) likely consequences e) measures taken or proposed f) Contact option for questions 13.3 The processor provides the customer with appropriate support in fulfilling its reporting and notification obligations in accordance with Articles 33 and 34 of the GDPR. 13.4 There is no obligation to report if a data breach obviously does not affect the customer's personal data or does not affect order processing. 14. Deletion and return of data 14.1 After termination of the main contract, the processor will delete or return personal data at the customer's discretion, to the extent that this is technically possible and legally permissible. 14.2 The customer can delete or export data himself during the contract term within the scope of the functions provided, provided such functions are available. 14.3 After the end of the contract, the processor can delete personal data after a reasonable period of time, provided that there are no legal retention obligations, billing purposes, security reasons or legitimate interests. 14.4 Backup copies and technical backups can be deleted with a delay if this is necessary for technical reasons. Access to such data will be limited to what is necessary. 14.5 GALLERYDOCK is not an archiving, long-term archiving or sole backup solution. The customer is responsible for keeping his own backup copies of his original files and business-critical data outside of GALLERYDOCK. 15. Control rights and evidence 15.1 Upon request, the processor will provide the customer with appropriate information that is necessary to demonstrate compliance with the obligations under Art. 28 GDPR. 15.2 Data protection documentation, security information, certifications, test reports, technical descriptions or written information can be provided as evidence, if available and appropriate. 15.3 On-site inspections are only permitted after prior agreement, during normal business hours, with reasonable advance notice and without affecting the Processor's business operations or the safety of other customers. 15.4 The customer bears the costs of an inspection unless the inspection was caused by a significant data protection violation for which the processor is responsible. 15.5 As part of inspections, the customer may not view other customers' data, business secrets, source code, security architecture, internal systems or confidential information of the processor, unless this is legally required. 15.6 Evidence, information and controls are only provided to an extent that does not endanger the security of the platform, business secrets, source code, access data, secrets, security concepts, internal systems and data of other customers. The processor can set appropriate confidentiality and security requirements for this. 15.7 Auditors appointed by the customer must not be competitors of the processor and must be obliged to maintain confidentiality. The processor can reject auditors if their use would jeopardize legitimate security, confidentiality or competition interests. 16. Confidentiality 16.1 The processor treats the customer's personal data and confidential information confidentially. 16.2 This obligation continues even after the termination of the contract. 16.3 The processor ensures that only those persons who need this access to carry out their tasks have access to personal data. 17. No use for personal purposes 17.1 The Processor does not process personal data entrusted to it under this Agreement for its own purposes. 17.2 Customer content, images, videos or end customer data will not be used for advertising, AI training, product promotion, resale or other independent purposes unless the customer has expressly consented to this separately. 17.3 The processor may process personal data to the extent this is necessary for security, troubleshooting, prevention of misuse, execution of the contract, legal defense or fulfillment of legal obligations. 18. Support and Remote Access 18.1 Support services are only provided to the extent that they are necessary for operation, error analysis, customer support or security. 18.2 Access to personal data for support or troubleshooting purposes will be limited to what is necessary. 18.3 The customer should not transmit any unnecessary personal data, sensitive data or original files when requesting support. 19. Changes to this Agreement 19.1 The Processor may change this Agreement if this is necessary due to legal changes, technical changes, new functions, new service providers or further development of GALLERYDOCK. 19.2 The processor informs the customer about significant changes in an appropriate form. 19.3 If the customer continues to use GALLERYDOCK after the change comes into force, the change is deemed to have been accepted provided the customer has been properly informed and there is no legal formal requirement to the contrary. 20. Order of precedence 20.1 If this Agreement conflicts with the Terms of Service, this Agreement controls with respect to processing carried out on the Customer's behalf. 20.2 The main contract, the Terms of Service and this contract apply in addition, unless they contradict each other. 21. Final provisions 21.1 German law applies. 21.2 Place of performance and place of jurisdiction are based on the provisions of the main contract, to the extent permitted by law. 21.3 Should individual provisions of this contract be or become ineffective, the effectiveness of the remaining provisions remains unaffected. Appendix 1: Description of processing 1. Subject of processing Providing the SaaS platform GALLERYDOCK for creating, managing, storing, processing, presenting and delivering media galleries. 2. Purpose of processing The purpose of the processing is the technical provision of the platform functions used by the customer, in particular uploading, storing, managing, processing, displaying and releasing media galleries. 3. Type of processing Raise Save Arrange Structuring Read out Provide Submit Ads Change Convert Compress Creating preview images and variants Delete Back up Log Check Restrict Restore, if technically possible 4. Categories of Personal Data Images and videos Files and media content names Email addresses IP addresses Gallery data Access and sharing data Comments Favorites Selection markers Download information technical metadata Device and browser data Upload and processing status Support information where required 5. Categories of data subjects Customers of the customer End customers of the customer people depicted Visitors to shared galleries Employees and contact persons of the customer other persons whose data is processed through the customer’s content 6. Duration of processing For the duration of the main contract and thereafter only if legal obligations, processing purposes, security reasons or legitimate interests require further processing. Appendix 2: Technical and organizational measures 1. Access control The processor uses cloud-based infrastructure. Physical access control to data centers is carried out by the respective infrastructure providers. 2. Access control Systems are accessed via protected user accounts. Administrative access is limited to authorized persons. Access data and secrets may not be saved publicly or stored in the source code. 3. Access control Access to customer data is restricted based on roles, permissions and technical necessity. Owner, gallery and media data are logically separated. Private storage paths and storage keys are not publicly issued. 4. Transfer control Personal data is only passed on via secure transmission channels and only to authorized recipients. Data transfers are encrypted as far as technically possible. 5. Input control Security-relevant processes can be logged if this is necessary for security, error analysis or traceability. 6. Order control Sub-processors will only be used in accordance with this Agreement and with appropriate contractual data protection obligations. 7. Availability control The processor takes appropriate measures to ensure the availability of the platform. However, GALLERYDOCK is not a backup or archiving solution for the customer's original files. 8. Separation control Data from different customers is logically separated. Galleries, media and access are checked on the server side using owner, gallery and authorization concepts. 9. Transport encryption The transmission of personal data takes place via encrypted connections, as long as this is technically planned and is customary in the market. 10. Storage of Media Media is stored in private cloud storage. Public access does not take place via private storage keys, but rather via the authorization and delivery mechanisms provided by GALLERYDOCK. 11. Software development GALLERYDOCK is being further developed using a structured development process. Secrets should not end up in GitHub or public repositories. Productive customer data should not be stored in development environments or source code. 12. Data protection through technology design GALLERYDOCK follows the principle of only processing necessary data, not passing on private storage keys to public editions and technically separating owner and public areas. 13. Protection of Secrets and Access Keys Access keys, tokens, and other secrets are not published in customer code and are not provided as public environment variables. Access to productive secrets is limited to authorized persons and technically necessary purposes. 14. Environmental separation and productive access Production environments and development or test environments are operated logically separately. Productive customer data should not be used in development or testing environments unless exceptionally necessary and appropriate for support, error analysis, security or recovery. 15. Review of security-relevant infrastructure Security-relevant changes to infrastructure, storage, authorizations, access keys and delivery routes are checked on an ad-hoc basis. In doing so, the processor takes particular account of the risk of unauthorized access, unintentional disclosure, modification, deletion or unauthorized distribution of media content. Appendix 3: Sub-processors and service providers for GALLERYDOCK V1 1. Vercel Purpose: Hosting, deployment, application execution, platform provision, technical logs, security and error analysis. Possible data: IP addresses, technical access data, server logs, request information, error data, session and security information. Role: Processor or sub-processor, if personal data is processed on behalf of the company. 2. Neon Purpose: PostgreSQL database for account data, gallery data, media metadata, upload status, roles, permissions, plan and platform data. Possible data: Account data, names, email addresses, gallery data, media metadata, upload and processing status, technical status data, end customer data as far as processed by gallery functions. Role: Processor or sub-processor, if personal data is processed on behalf of the company. 3. Cloudflare R2 Purpose: Storage of media and files, especially images, videos, original files, preview images, web variants, thumbnails and video posters. Possible data: Images, videos, files, media metadata, storage information, technical access information, security and log data. Role: Processor or sub-processor, if personal data is processed on behalf of the company. 4. Stripe Purpose: Payment processing, invoicing, subscription management, payment status, fraud prevention and legal proof of payment. Possible data: Name, company, email address, billing address, VAT number, tariff, payment status, invoice details, transaction details, payment method and technical payment information. Role: Depending on the processing, processor, sub-processor or independent controller, especially if Stripe fulfills its own legal, regulatory or compliance obligations. 5. GitHub Purpose: Source code management, technical development and version management. Possible data: Basically no productive customer content, end customer data, images, videos or gallery data. Personal data should not be stored in source code, commits, issues or logs. Processing can exceptionally occur during error analysis or technical documentation, if necessary. Role: Technical development service provider. No regular storage of productive customer data is planned. Appendix 4: Contact for data protection and reports Data protection requests: info@gallerydock.de