Data Processing Agreement (DPA)

This Data Processing Agreement (hereinafter: the "Agreement" or the "DPA") is concluded in accordance with Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter: the "GDPR") between:


§ 1. Parties to the Agreement

Entrusting Party (Controller):

The Photographer holding an Account in the Picvelo service, identified by the data provided on registration and in the Account settings (name or first name and surname, email address, billing details)

hereinafter referred to as the "Entrusting Party" or the "Controller"

and

Processor:

Name: Jakub Ciepielowski Contact: [email protected]

hereinafter referred to as the "Processor" or "Picvelo"

The Entrusting Party and the Processor are jointly referred to as the "Parties".

[!info] This Agreement constitutes Annex 1 to the Picvelo Terms of Service and is concluded at the moment the Photographer (the Entrusting Party) accepts those Terms. The date of conclusion of the Agreement is the date of registration of the Account or the date of acceptance of the current version of the Terms.


§ 2. Subject matter, duration, nature and purpose of the processing

2.1 Subject matter

The subject matter of this Agreement is the entrustment by the Controller to the Processor of the processing of the personal data of the Controller's End clients in connection with the provision of the Picvelo platform services, namely the storage of photo galleries and making them available to End clients for selection.

2.2 Duration

The Agreement applies for the duration of the Picvelo Subscription concluded by the Controller and, as regards the obligation to delete or return the data, until their permanent deletion or return is confirmed, but no longer than 90 days after the end of the Subscription.

2.3 Nature of the processing

The processing is automated (the Picvelo IT systems) and is carried out on the instructions of the Controller. The Processor does not take independent decisions concerning the purpose of the processing.

2.4 Purpose of the processing

  • Storing photo galleries and displaying them to End clients
  • Enabling End clients to select photos and leave notes
  • Sending email notifications to End clients (if the Controller activates this feature)
  • Technical handling of the browsing session and securing access to the gallery

§ 3. Categories of personal data

The Processor processes the following categories of personal data on behalf of the Controller:

3.1 Data provided by the Controller

  • First name and surname or nickname of the End client (if the Controller entered them)
  • Email address of the End client (if the Controller provided it)
  • The End client's gallery login credentials: username and password. The password is stored as a bcrypt hash (to verify the login) and additionally as a reversibly encrypted copy which the Controller can read in the panel in order to pass it on to the End client

3.2 Data generated automatically while the gallery is used

  • IP address and other technical data (HTTP headers, session identifier)
  • Information about the photos selected (list of IDs of the selected photographs)
  • Notes left by the End client on the photos
  • Timestamp of activity and of the completion of the selection

3.3 Special categories of data

The entrusted data does not include special categories of data referred to in Article 9 GDPR (health, biometric, genetic data and the like), unless the Controller knowingly and deliberately entrusts such data to the Processor. In that case the Controller assumes responsibility for ensuring an appropriate legal basis.

[!warning] Photos uploaded by the Controller may contain images of individuals (personal data within the meaning of the GDPR). The Controller is responsible for obtaining all necessary consents or for demonstrating another legal basis for processing those images.


§ 4. Categories of data subjects

  • The Controller's End clients, natural persons to whom the Controller has made a gallery link available (for example wedding couples, photo session clients, business clients)
  • Persons captured in the photos, natural persons whose image appears in the photographs stored in the gallery

§ 5. Obligations of the Processor

The Processor undertakes to:

5.1 Process only on instructions

Process personal data solely on the documented instructions of the Controller. The configuration of galleries, access rights and End client settings by the Controller in the Picvelo panel constitutes a documented instruction within the meaning of Article 28(3)(a) GDPR.

If applicable Union law or Polish law requires the Processor to process data for another purpose, the Processor will inform the Controller of this before processing, unless that law prohibits such information on important grounds of public interest.

5.2 Ensure confidentiality

Ensure that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5.3 Apply security measures

Implement and maintain technical and organisational measures (TOMs) in accordance with Article 32 GDPR, described in detail in Annex 2 to this Agreement.

5.4 Assist the Controller

Assist the Controller, as far as possible, in fulfilling the obligation to respond to requests from data subjects (Articles 15 to 22 GDPR), taking into account the nature of the processing and the information available.

5.5 Assist with Articles 32 to 36 GDPR

Assist the Controller in fulfilling the obligations set out in Articles 32 to 36 GDPR (security, notification of breaches, impact assessment, prior consultation), taking into account the nature of the processing and the information available to the Processor.

5.6 Delete or return the data

After the end of the provision of services, at the Controller's choice, delete or return all personal data and delete existing copies, unless Union law or Polish law requires the storage of that data.

5.7 Make information available

Make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this paragraph and allow for and actively support audits and inspections in accordance with § 11.


§ 6. Sub-processing (further entrustment)

6.1 General authorisation and list of subprocessors

The Controller gives the Processor general authorisation to use the subprocessors indicated in Annex 1 to this Agreement.

The current list of subprocessors is publicly available at /subprocessors and forms an integral part of Annex 1.

6.2 Notification of changes

The Processor informs the Controller of any intended changes concerning the addition or replacement of subprocessors at least 30 days before the change is made. The Controller has the right to object to such changes within 14 days of receiving the notification.

If the Controller raises a justified objection and the Parties do not reach agreement, the Controller may terminate the Agreement (and the Subscription) without additional charges.

6.3 Responsibility for subprocessors

The Processor imposes on every subprocessor the same data protection obligations as those set out in this Agreement. The Processor remains fully liable to the Controller for the performance of the subprocessor's obligations.


§ 7. Location of processing and transfers outside the EEA

7.1 Primary location

The database and the application run on OVH SAS servers located in France (the European Economic Area). Photo files (originals, previews, thumbnails) may be stored in the Cloudflare R2 object storage service and on the hosting server.

7.2 Transfers outside the EEA

Some subprocessors process data outside the EEA (mainly in the USA). Every such transfer takes place on the basis of appropriate legal mechanisms:

Subprocessor Transfer mechanism
Cloudflare Inc. (USA) Standard Contractual Clauses (SCCs), EC Decision 2021/914
Google LLC, GA4, Ads (USA) SCCs + EU-US Data Privacy Framework (DPF)
Stripe Inc. (USA) SCCs + DPF
Sentry / Functional Software (USA) SCCs + DPF
Google, Meta, Apple, OAuth (USA) SCCs + DPF

The Processor undertakes to inform the Controller of any changes concerning transfer mechanisms.


§ 8. Technical and organisational measures (TOMs)

A detailed description of the security measures applied by Picvelo is contained in Annex 2 to this Agreement.

Summary of the key measures:

  • Encryption in transit: TLS 1.2+ (HTTPS) for all connections, HSTS
  • Encryption at rest: sensitive data (email addresses, 2FA secrets, gallery access passwords) encrypted at database level
  • Password authentication: bcrypt hashes
  • Access control: separation of roles at application level (owner, photographer, team member, client), the principle of least privilege; optional 2FA for photographer accounts
  • Application protection: CSP, CSRF protection, SQL prepared statements, HTTP security headers
  • Audit: access and change logs stored for 90 days
  • Backups: automatic database backups with 30-day retention
  • Monitoring: automated detection of anomalies and errors (Sentry)
  • Procedures: monitoring and alerts enabling a rapid response to incidents; a database copy before every deployment and automatic rollback of a failed deployment

§ 9. Assistance with the exercise of data subjects' rights

Where an End client or another data subject approaches the Processor directly with a request concerning the exercise of rights under the GDPR (access, rectification, erasure, restriction and the like), the Processor will:

  1. Inform the Controller of such a request within 5 business days of receiving it
  2. Refrain from responding to the request independently, unless the Controller authorises the Processor to act
  3. Provide the Controller with the technical assistance (for example data export, confirmation of the scope of processing) necessary to respond to the request in good time

§ 10. Personal data breaches (Breach Notification)

10.1 Notification obligation

If a personal data breach within the meaning of Article 4(12) GDPR is detected, the Processor will notify the Controller without undue delay, no later than within 72 hours of becoming aware of the breach.

10.2 Content of the notification

The notification will contain, as far as the information is available:

  • A description of the nature of the breach (categories of data, approximate number of persons and records)
  • Contact details for obtaining further information
  • A description of the likely consequences of the breach
  • A description of the measures taken or planned by the Processor to address the breach

If all the information is not available at the same time, it may be provided in stages.

10.3 Documentation

The Processor documents all personal data breaches, including their effects and the remedial action taken, and makes this documentation available to the Controller on request.


§ 11. Audit

11.1 Right to audit

The Controller has the right to carry out audits or inspections (independently or through an authorised third party) in order to verify the Processor's compliance with this Agreement and with the GDPR. An audit takes place after prior written notice to the Processor at least 14 days in advance.

11.2 Alternative: reports and certificates

The Processor may replace or supplement a full audit by providing current reports from audits carried out by accredited external bodies, or certificates (for example ISO 27001), if it holds any.

11.3 Costs

The costs of the audit on the Controller's side are borne by the Controller. If the audit reveals a material breach of this Agreement by the Processor, the costs of the audit are borne by the Processor.


§ 12. Return and deletion of data

12.1 After the end of the Agreement

After the end of the provision of services (termination of the Subscription), at the Controller's request the Processor:

  • Deletes all personal data entrusted by the Controller within 90 days of the end of the Subscription, or
  • Provides the Controller with a data export in JSON format (obtained independently from the panel in the Data export section, or on written request submitted before the 90-day deadline expires)

12.2 Backups

The data may be kept by the Processor for an additional period resulting from the backup rotation cycle (max. 30 days after the 90-day deadline expires). After that time it is permanently deleted.

12.3 Confirmation of deletion

At the Controller's request, the Processor provides written confirmation of the permanent deletion of the data.


§ 13. Final provisions

13.1 Precedence

In matters not regulated by this Agreement, the provisions of the Picvelo Terms of Service apply. In the event of a conflict between the Agreement and those Terms, this Agreement prevails as regards the protection of personal data.

13.2 Amendments

Any amendments to this Agreement require written form (email constitutes written form for the purposes of this Agreement) and take effect once accepted by both Parties. Picvelo may update the DPA by notifying the Controller at least 30 days in advance.

13.3 Governing law

The Agreement is governed by Polish law. In matters not regulated here, the provisions of the GDPR, of the Polish Civil Code and the relevant provisions of Polish law apply.

13.4 Dispute resolution

The Parties will endeavour to resolve disputes arising from this Agreement amicably within 30 days. Failing agreement, the competent court is the court for the registered office of the Processor (Jakub Ciepielowski).


Annex 1: List of subprocessors

The list below constitutes the disclosure, required under Article 28(2) GDPR, of the subprocessors authorised by Jakub Ciepielowski to process personal data entrusted by Controllers.

Subprocessor Role Registered office Categories of data Transfer mechanism
OVH SAS Server hosting, data storage France (EEA) All entrusted data No transfer, EEA
Stripe Payments Europe Ltd. Processing of subscription payments Ireland (EEA) + USA Name, email, billing details of the Photographer SCCs + DPF
Cloudflare Inc. CDN, DDoS protection, proxy; storage of photo files (Cloudflare R2) USA IP addresses, HTTP headers, gallery photo files SCCs
Google LLC (Google Analytics 4) Analytics of service users' behaviour USA Anonymised IP, session events (Photographers) SCCs + DPF
Google LLC (Google Ads) Attribution of advertising conversions USA IP, Google Click ID (Photographers) SCCs + DPF
Microsoft Corporation (Microsoft Clarity) Usage analysis and session recording (excluding End Client galleries) USA IP, interface events, session flow (Photographers) SCCs + DPF
Sentry / Functional Software Inc. Monitoring of application errors and exceptions USA Stack traces, partial request logs (anonymised) SCCs + DPF
SMTP provider (configurable) Sending emails to End clients Depending on configuration Email address of the End client, content of the notification Depending on configuration, EEA or SCCs
Apple Inc. / Google LLC / Meta Platforms (OAuth) Social login for Photographers USA Email and basic profile of the Photographer (OAuth) SCCs + DPF

[!info] The SMTP provider may be configured individually by each Photographer (own SMTP server or an external provider). In that case the Photographer, as the Controller, is responsible for verifying that the chosen provider complies with the GDPR.

The current version of this list is always available at: /subprocessors


Annex 2: Technical and Organisational Measures (TOMs)

In accordance with Article 32 GDPR, Jakub Ciepielowski has implemented the following technical and organisational measures:

A. Encryption and protection of data in transit

  • HTTPS/TLS 1.2+ for all connections to the service (mandatory, HTTP is redirected)
  • HSTS (HTTP Strict Transport Security)
  • SSL certificates managed by Cloudflare and renewed automatically

B. Encryption and protection of data at rest

  • Passwords of photographers stored as bcrypt hashes; passwords of End clients as a bcrypt hash plus a reversibly encrypted copy available to the Controller (see § 3.1)
  • 2FA keys (TOTP secrets) stored in encrypted form
  • Contact data (email addresses of photographers and clients) encrypted in the database

C. Access control

  • Separation of roles at application level (owner, photographer, team member with limited rights, end client)
  • The principle of least privilege, every role in the system has access only to the resources it needs
  • Server access solely through SSH keys, restricted to the owner of the service
  • Session management, secure PHP sessions with session ID rotation after login

D. Application protection

  • Prepared statements (PDO), protection against SQL Injection
  • CSRF tokens, in every form and state-changing request
  • Content Security Policy (CSP), protection against XSS
  • HTTP security headers, X-Frame-Options, X-Content-Type-Options, Referrer-Policy

E. Audit and monitoring

  • Access logs stored for 90 days (Nginx and application logs)
  • Audit logs of significant operations (activity log) stored for 90 days
  • Error monitoring (Sentry), automatic notification of anomalies
  • Alerts about critical application errors in real time

F. Backups and business continuity

  • Automatic backups of the database with 30-day retention; an additional database copy before every deployment
  • Photo files stored in high-durability object storage (Cloudflare R2)
  • Restoration, a procedure for restoring from a backup; a failed deployment is rolled back automatically (smoke test and rollback)
  • Availability monitoring, automatic alerts when the service is unavailable

G. Organisation and procedures

  • Access to the infrastructure and to production data restricted to the owner of the service; every person granted access to the data is bound by a confidentiality commitment
  • Incident response, error monitoring and alerts in real time
  • Vulnerability control, automated static code analysis and audit of dependency vulnerabilities on every code change (CI)

This document was prepared on the basis of the legal situation as at 2026-05-26. Last updated: 2026-05-26.

Last updated: 2026-09-11

Are you a photographer's client? Looking for your session photos? Enter the client zone and log in with the details from your photographer.
Enter the client zone