Security Gdpr Shield Streamline Icon: https://streamlinehq.com

GDPR Data Processing Agreement (DPA)

Version July 2025. This agreement defines the conditions under which Fotostudio processes personal data on behalf of its users.

1. Purpose

This Data Processing Agreement (hereinafter "the Agreement") supplements the Fotostudio Terms and Conditions.

Its purpose is to define the conditions under which Fotosoft SA, acting as data processor, processes personal data on behalf of the User, acting as data controller, in compliance with the General Data Protection Regulation (EU 2016/679).

2. Definitions

  • Personal data: any information relating to an identified or identifiable natural person
  • Data controller: the User (photographer), who determines the purposes and means of processing
  • Data processor: Fotosoft SA, which processes data on behalf of the data controller
  • Processing: any operation applied to personal data (collection, storage, deletion, etc.)

3. Nature and Purpose of Processing

Fotosoft processes data to enable you to:

  • manage your clients, contracts, galleries, bookings, invoices and communications
  • host and share images, documents and messages with your clients
  • receive online payments through the integrations provided

⚠️ Fotosoft commits to processing data only for these purposes and never for its own account.

4. Types of Data Processed

Depending on the features used, Fotostudio may process:

  • Identification data: first name, last name, email, phone, address
  • Contractual data: quotes, invoices, contracts, forms, electronic signatures
  • Images and files: photos, client documents, PDFs, etc.
  • Navigation data: IP address, connection logs (technical logs)

No sensitive data within the meaning of GDPR (health, religion, orientation, etc.) is intentionally collected.

5. Fotosoft's Commitments (data processor)

Fotosoft commits to:

  • Process data only on documented instructions from you
  • Ensure confidentiality of data and its authorized personnel
  • Implement appropriate technical and organizational measures (encryption, backups, access control, etc.)
  • Guarantee the security, integrity and availability of processed data
  • Assist you in fulfilling your GDPR obligations (e.g., right of access, rectification or deletion)
  • Promptly notify any security incident or data breach
  • Delete or return all data at the end of the contract

6. User's Obligations (data controller)

You commit to:

  • Process only lawful, relevant and necessary data for your business
  • Inform your own clients about how their data is processed through Fotostudio
  • Comply with applicable data protection regulations
  • Determine the retention period for the data you manage

7. Authorized Sub-processors

To deliver its services, Fotosoft uses GDPR-compliant sub-processors, notably:

  • Heroku (Salesforce Inc., Europe) – application hosting
  • Amazon Web Services S3 (Europe) – secure file storage
  • Smtp2go – transactional email delivery
  • Stripe, Mollie and Paypal – online payments

Fotosoft ensures contractually that each of them complies with the same security and confidentiality requirements.

8. Assistance and Audit

  • Upon written request, Fotosoft can provide you with the information necessary to demonstrate GDPR compliance
  • You may, at your own expense, request a limited and reasonable security audit, subject to confidentiality and without disrupting the service

9. Transfers Outside the EU

Fotosoft does not transfer personal data outside the European Economic Area, except if:

  • the service provider is covered by an adequacy decision from the European Commission, or
  • appropriate safeguards (standard contractual clauses, etc.) are in place

10. Retention Period and Deletion

At the end of the contractual relationship:

  • Data is permanently deleted within 30 days
  • Automatic backups are erased at the end of their cycle
  • Upon written request, proof of deletion can be provided

11. Liability

  • Each party is responsible for damages caused by non-compliance with their respective obligations
  • Fotosoft cannot be held liable for a breach resulting from GDPR-contrary instructions given by you

12. Applicable Law

  • This Agreement is governed by Belgian law
  • Any dispute relating to its interpretation or execution shall be submitted to the courts of Liège, Belgium

Last updated: July 2025

For any questions regarding data protection, contact us at support@fotostudio.io

Business Management Teamwork Hands Clap Streamline Icon: https://streamlinehq.com

Ready to simplify your daily workflow?

Join over 3,000 photographers who save time every day.