Versie 2 · 26 jul 2026
Tussen
de verwerker
Contrima GmbH, vertegenwoordigd door haar directeur de heer Mark Reinhardt, Enzianweg 29, 71384 Weinstadt
(hierna „CONTRIMA“ genoemd)
en
de verwerkingsverantwoordelijke
{photographer_name}
{photographer_address}
{photographer_email}
(hierna „jij“)
CONTRIMA levert aan jou diensten voor het ter beschikking stellen van een infrastructuur voor het doorsturen van foto’s naar de afgebeelde personen, alsmede voor het beheer van beeldlicentieovereenkomsten (hierna: „hoofdovereenkomst“). Onderdeel van de uitvoering van de hoofdovereenkomst is de verwerking van persoonsgegevens van de afgebeelde personen, die jij aan CONTRIMA verstrekt. Om te voldoen aan de vereisten van de AVG voor dergelijke situaties, sluit jij als verwerkingsverantwoordelijke in de zin van de wetgeving inzake gegevensbescherming de volgende overeenkomst inzake gegevensverwerking in opdracht met CONTRIMA.
1.1 De samenwerking tussen de partijen op grond van de hoofdovereenkomst houdt in dat CONTRIMA toegang krijgt tot de door u verstrekte persoonsgegevens (hierna „opdrachtgegevens“ genoemd) en deze uitsluitend in jouw opdracht en volgens jouw instructies in de zin van art. 4, nr. 8 en art. 28 AVG verwerkt.
1.2 De verwerking kan betrekking hebben op de volgende opdrachtgegevens:
| Betrokkenen (categorieën) | Soort gegevens |
|---|---|
| Afgebeelde personen |
|
| Ouderlijke voogden van de afgebeelde personen |
|
| Contactpersonen bij overheidsinstanties (bijv. belastingdiensten) |
|
1.3 De aard en omvang van de verwerking van de opdrachtgegevens zijn afgestemd op de doeleinden van de hoofdovereenkomst en blijven daartoe beperkt. De duur van de verwerking komt overeen met de looptijd van de hoofdovereenkomst.
1.4 Het is CONTRIMA verboden om opdrachtgegevens op een andere wijze te verwerken of verder te verwerken dan is vastgelegd in bijlage 1 en paragraaf 1.2. Dit geldt ook voor het gebruik van geanonimiseerde gegevens.
1.5 De verwerking van de opdrachtgegevens vindt uitsluitend plaats op het grondgebied van de Bondsrepubliek Duitsland, in een lidstaat van de Europese Unie of in een andere verdragsluitende staat van de Overeenkomst betreffende de Europese Economische Ruimte. Elke verplaatsing naar een derde land vereist de voorafgaande schriftelijke toestemming van de opdrachtgever en mag alleen plaatsvinden indien aan de bijzondere voorwaarden van de artikelen 44 tot en met 49 van de AVG is voldaan.
1.6 De bepalingen van deze overeenkomst zijn van toepassing op alle activiteiten die verband houden met de hoofdovereenkomst en waarbij CONTRIMA en haar werknemers of door CONTRIMA aangestelde personen in aanraking komen met persoonsgegevens die van jou afkomstig zijn of voor jou zijn verzameld.
2.1 CONTRIMA verwerkt de opdrachtgegevens uitsluitend in het kader van de opdracht en uitsluitend in jouw opdracht en volgens jouw instructies in de zin van artikel 28 AVG (verwerking in opdracht); dit geldt in het bijzonder met betrekking tot de doorgifte van persoonsgegevens naar een derde land. U hebt het exclusieve recht om instructies te geven over de aard, de omvang en de methode van de verwerkingsactiviteiten (hierna ook „instructierecht“ genoemd). Indien CONTRIMA op grond van het recht van de Europese Unie of van de lidstaten waaraan het onderworpen is, verplicht is tot verdere verwerkingen, zal CONTRIMA u vóór de verwerking op de hoogte stellen van deze wettelijke vereisten.
2.2 Instructies aan CONTRIMA worden door jou in principe schriftelijk gegeven (e-mailadres: info@contrima.com).
2.3 Indien CONTRIMA van mening is dat een van uw instructies in strijd is met de voorschriften inzake gegevensbescherming, dient CONTRIMA u hier onmiddellijk op te wijzen. CONTRIMA heeft het recht de uitvoering van de betreffende instructie op te schorten totdat deze door de opdrachtgever is bevestigd of gewijzigd.
3.1 CONTRIMA is verplicht de wettelijke bepalingen inzake gegevensbescherming na te leven en de van jou verkregen informatie niet aan derden door te geven of de toegang daartoe te beperken. Gegevens moeten, rekening houdend met de stand van de techniek, worden beveiligd tegen inzage door onbevoegden.
3.2 Voorts zal CONTRIMA alle personen die door CONTRIMA worden belast met de verwerking en de uitvoering van deze overeenkomst (hierna „medewerkers” genoemd) schriftelijk tot geheimhouding verplichten (vertrouwelijkheidsverplichting, art. 28, lid 3, onder b) AVG) en zal met de nodige zorgvuldigheid toezien op de naleving van deze verplichting. CONTRIMA zal dit op verzoek aan u aantonen.
3.3 CONTRIMA zal de interne organisatie zodanig inrichten dat deze voldoet aan de specifieke eisen op het gebied van gegevensbescherming. CONTRIMA verbindt zich ertoe alle passende technische en organisatorische maatregelen te nemen voor een passende bescherming van de opdrachtgegevens overeenkomstig art. 32 AVG, in het bijzonder de in bijlage 1 bij deze overeenkomst genoemde maatregelen, en deze te handhaven gedurende de gehele periode van verwerking van de opdrachtgegevens.
3.4 CONTRIMA behoudt zich het recht voor om de getroffen technische en organisatorische maatregelen te wijzigen, waarbij CONTRIMA ervoor zorgt dat het contractueel overeengekomen beschermingsniveau niet wordt onderschreden. CONTRIMA dient je onmiddellijk schriftelijk op de hoogte te stellen indien er reden is om aan te nemen dat de maatregelen overeenkomstig bijlage 1 niet langer toereikend zijn en zal met je overleggen over verdere technische en organisatorische maatregelen.
3.5 Op jouw verzoek zal CONTRIMA de naleving van de in bijlage 1 vastgelegde technische en organisatorische maatregelen aantonen aan de hand van geschikt bewijsmateriaal.
4.1 Bij storingen, vermoedens van inbreuken op de gegevensbescherming of schendingen van contractuele verplichtingen van CONTRIMA, bij vermoeden van veiligheidsrelevante incidenten of andere onregelmatigheden bij de verwerking van de opdrachtgegevens, bij CONTRIMA in het kader van de opdracht door in dienst zijnde personen of door derden, zal CONTRIMA u onmiddellijk, maar uiterlijk binnen 24 uur, schriftelijk of elektronisch op de hoogte stellen. Hetzelfde geldt voor controles van CONTRIMA door de toezichthoudende autoriteit voor gegevensbescherming. De meldingen overeenkomstig § 4, lid 1, zin 1 bevatten telkens ten minste de in artikel 33, lid 3, AVG genoemde gegevens.
4.2 CONTRIMA zal u in het geval van § 4.1, voor zover redelijk is, ondersteunen bij het nemen van de desbetreffende maatregelen op het gebied van voorlichting, herstel en informatieverstrekking. CONTRIMA zal met name onverwijld de nodige maatregelen nemen om de gegevens te beveiligen en mogelijke nadelige gevolgen voor de betrokkenen te beperken, en u hiervan op de hoogte stellen.
4.3 CONTRIMA verbindt zich ertoe om u op uw mondelinge of schriftelijke verzoek binnen een redelijke termijn alle inlichtingen en bewijsstukken ter beschikking te stellen die nodig zijn voor het uitvoeren van een controle overeenkomstig § 7.1 van deze overeenkomst. Voorts zal CONTRIMA u op uw verzoek een uitgebreid en actueel gegevensbeschermings- en beveiligingsconcept voor de verwerking in opdracht ter beschikking stellen, evenals informatie over personen met toegangsrechten.
5.1 CONTRIMA is verplicht om een register bij te houden van alle categorieën verwerkingsactiviteiten die in jouw opdracht worden uitgevoerd, overeenkomstig artikel 30, lid 2, van de AVG. Dit register moet op verzoek aan jou ter beschikking worden gesteld.
5.2 Indien de opdrachtgegevens bij CONTRIMA in gevaar komen door beslaglegging of inbeslagname, door een insolventie- of schikkingsprocedure of door andere gebeurtenissen of maatregelen van derden, dient CONTRIMA je hiervan onmiddellijk op de hoogte te stellen, tenzij dit bij gerechtelijk of ambtelijk bevel verboden is. CONTRIMA zal in dit verband alle bevoegde instanties onmiddellijk ervan op de hoogte stellen dat de beslissingsbevoegdheid over de gegevens uitsluitend bij de opdrachtgever als „verantwoordelijke“ in de zin van de AVG berust.
6.1 De contractueel overeengekomen diensten worden uitgevoerd met inschakeling van de in bijlage 2 genoemde onderaannemers. CONTRIMA is in het kader van haar contractuele verplichtingen bevoegd om onderaannemingsrelaties met onderaannemers aan te gaan („onderaannemingsrelatie”). Alvorens verdere onderaannemingsrelaties aan te gaan, stelt CONTRIMA je hiervan schriftelijk of elektronisch in kennis overeenkomstig artikel 28, lid 2, van de AVG, met een termijn van vier weken. Je kunt binnen twee weken na ontvangst van de bovengenoemde kennisgeving bezwaar maken tegen de wijziging.
6.2 Er is geen sprake van een onderaannemingsrelatie in de zin van deze bepalingen wanneer CONTRIMA derden opdracht geeft tot het verrichten van diensten die als louter bijkomende diensten moeten worden beschouwd. Hieronder vallen bijvoorbeeld post- of telecommunicatiediensten zonder concreet verband met diensten die CONTRIMA voor jou verricht, evenals overige maatregelen ter waarborging van de vertrouwelijkheid, beschikbaarheid, integriteit en robuustheid van de hardware en software van gegevensverwerkingssystemen.
7.1 Je hebt het recht om je regelmatig te vergewissen van de naleving van de bepalingen van deze overeenkomst, in het bijzonder van de implementatie en naleving van de technische en organisatorische maatregelen overeenkomstig § 3.3 van deze overeenkomst. Hiervoor kun je bijvoorbeeld inlichtingen inwinnen of certificeringen of interne controles laten voorleggen, of de technische en organisatorische maatregelen van CONTRIMA tijdens de gebruikelijke kantooruren zelf persoonlijk of door een deskundige derde laten controleren, mits deze geen concurrentieverhouding met CONTRIMA heeft.
7.2 Je voert controles alleen uit voor zover dat noodzakelijk is en houdt daarbij in redelijke mate rekening met de bedrijfsprocessen van CONTRIMA. De partijen komen tijdig overeen wanneer en op welke wijze de controle plaatsvindt.
7.3 Je documenteert het resultaat van de controle en deelt dit mee aan CONTRIMA. Bij fouten of onregelmatigheden die je met name bij de controle van opdrachtresultaten vaststelt, breng je CONTRIMA hiervan onmiddellijk op de hoogte.
8.1 CONTRIMA ondersteunt u waar mogelijk met passende technische en organisatorische maatregelen bij het nakomen van uw verplichtingen uit hoofde van de artikelen 12 tot en met 22 en de artikelen 32 tot en met 36 van de AVG. CONTRIMA zal je onmiddellijk, maar uiterlijk binnen 7 werkdagen, de gewenste informatie over de verwerkingsgegevens verstrekken, voor zover je niet zelf over de betreffende informatie beschikt.
8.2 Indien de betrokkene zijn rechten overeenkomstig de artikelen 16 tot en met 18 van de AVG doet gelden, is CONTRIMA verplicht om de verwerkingsgegevens op jouw instructie onmiddellijk, doch uiterlijk binnen een termijn van 7 werkdagen, te corrigeren, te wissen of de verwerking ervan te beperken. CONTRIMA zal je op verzoek schriftelijk bewijs leveren van de verwijdering, correctie of beperking van de gegevens.
8.3 Indien een betrokkene rechten, zoals het recht op inzage, rectificatie of verwijdering van zijn gegevens, rechtstreeks bij CONTRIMA doet gelden, zal CONTRIMA dit verzoek onmiddellijk aan u doorsturen en uw instructies afwachten. Zonder specifieke instructies zal CONTRIMA geen contact opnemen met de betrokkene.
9.1 De looptijd van deze overeenkomst komt overeen met de looptijd van de hoofdovereenkomst. In geval van twijfel geldt een opzegging van de hoofdovereenkomst ook als opzegging van deze overeenkomst en een opzegging van deze overeenkomst als opzegging van de hoofdovereenkomst.
9.2 U hebt te allen tijde het recht om deze overeenkomst buitengewoon op te zeggen om een zwaarwegende reden. Er is sprake van een zwaarwegende reden wanneer CONTRIMA zijn verplichtingen uit hoofde van deze overeenkomst niet nakomt, bepalingen van de AVG opzettelijk of door grove nalatigheid schendt, of een instructie niet kan of wil uitvoeren. Bij eenvoudige – dus noch opzettelijke noch grof nalatige – schendingen stel je CONTRIMA eerst een redelijke termijn, waarbinnen CONTRIMA de schending kan verhelpen. Na het vruchteloos verstrijken van deze termijn heb je vervolgens het recht op buitengewone opzegging.
10.1 CONTRIMA zal na beëindiging van de hoofdovereenkomst of op elk moment op verzoek alle aan CONTRIMA verstrekte gegevens aan jou teruggeven of, indien gewenst en voor zover er geen wettelijke bewaartermijn geldt, deze volledig en onherroepelijk verwijderen. Dit geldt ook voor kopieën van de opdrachtgegevens bij CONTRIMA, zoals back-ups, maar niet voor documentatie die dient als bewijs van de opdrachtconforme en correcte verwerking van de opdrachtgegevens. Dergelijke documentatie moet door CONTRIMA worden bewaard gedurende de wettelijke bewaartermijnen.
10.2 Je hebt het recht om op passende wijze te controleren of de gegevens bij CONTRIMA volledig en overeenkomstig de overeenkomst zijn teruggegeven of gewist.
10.3 CONTRIMA is verplicht om de gegevens die het in verband met de hoofdovereenkomst ter kennis zijn gekomen, ook na beëindiging van de hoofdovereenkomst vertrouwelijk te behandelen.
11.1 De aansprakelijkheid van de partijen is geregeld in artikel 82 van de AVG. Dit laat de aansprakelijkheid van CONTRIMA jegens jou wegens schending van verplichtingen uit hoofde van deze overeenkomst of de hoofdovereenkomst onverlet.
11.2 De partijen stellen elkaar vrij van aansprakelijkheid indien een partij aantoont dat zij in geen enkel opzicht verantwoordelijk is voor de omstandigheid waardoor de schade bij een betrokkene is ontstaan. § 11, lid 2, zin 1 is van overeenkomstige toepassing in het geval van een aan een partij opgelegde geldboete, waarbij de vrijstelling plaatsvindt in de mate waarin de andere partij medeverantwoordelijk is voor de overtreding die met de geldboete is bestraft.
12.1 Wijzigingen en aanvullingen op deze overeenkomst moeten schriftelijk worden vastgelegd in de zin van artikel 28, lid 9, AVG. Dit geldt ook voor het afzien van deze vormvereiste.
12.2 In geval van twijfel hebben de bepalingen van deze overeenkomst voorrang boven de bepalingen van de hoofdovereenkomst. Indien afzonderlijke bepalingen van deze overeenkomst geheel of gedeeltelijk ongeldig of onuitvoerbaar blijken te zijn of als gevolg van wetswijzigingen na het sluiten van de overeenkomst ongeldig of onuitvoerbaar worden, laat dit de geldigheid van de overige bepalingen onverlet. De ongeldige of onuitvoerbare bepaling wordt vervangen door een geldige en uitvoerbare bepaling die zo dicht mogelijk aansluit bij de strekking en het doel van de ongeldige bepaling.
12.3 Deze overeenkomst is onderworpen aan het recht van de Bondsrepubliek Duitsland. CONTRIMA stelt deze voorwaarden ter wille van een betere begrijpelijkheid in verschillende taalversies ter beschikking. In geval van discrepanties is de Engelse taalversie van deze overeenkomst inzake gegevensverwerking doorslaggevend.
CONTRIMA is verplicht passende technische en organisatorische maatregelen te nemen, zodat de verwerking van de opdrachtgegevens in overeenstemming met de wettelijke vereisten plaatsvindt en de bescherming van de rechten van de betrokkene op passende wijze wordt gewaarborgd.
CONTRIMA zal haar interne organisatie zodanig inrichten dat deze voldoet aan de specifieke eisen op het gebied van gegevensbescherming. Daarbij moeten met name maatregelen worden genomen die geschikt zijn voor de aard van de te beschermen gegevens of gegevenscategorieën.
In het bijzonder worden de volgende maatregelen vastgesteld, die dienen ter uitvoering van de voorschriften van art. 32 AVG:
| Nr. | Maatregel | Uitvoering van de maatregel |
|---|---|---|
| 1 | Toegangscontrole | De productieve gegevensverwerking vindt uitsluitend plaats in de AWS-cloud; de fysieke gegevensverwerkingsinstallaties worden daar door AWS beveiligd (zie AVV en certificeringen van AWS). Het beheer vindt plaats vanaf een met een toegangscode beveiligde werkplek in afsluitbare, voor het publiek niet-toegankelijke ruimtes achter een firewall. Er is geen publiekstoegang en er zijn geen eigen serverruimtes. |
| 2 | Toegangscontrole | Toegang tot het systeem is alleen mogelijk via persoonlijke aanmelding met gebruikersnaam en wachtwoord. Beheerders- en AWS-toegangen worden beveiligd door sterke wachtwoorden en tweefactorauthenticatie. Eindapparaten worden beveiligd door aanmelding via het besturingssysteem, een firewall en schijfversleuteling. |
| 3 | Toegangscontrole | Rollen- en machtigingsconcept in de applicatie met centrale machtigingscontrole, serverzijde controle op alle eindpunten die gegevens wijzigen, bescherming tegen CSRF en uitsluitend geparametriseerde databasetoegang. Op infrastructuurniveau een minimaal aantal beheerders (beheer door één persoon) en toekenning van rechten volgens het ‘least privilege’-principe. |
| 4 | Scheidingcontrole | Logische scheiding van alle gegevens per fotograaf via een unieke eigendomstoewijzing; afzonderlijke productieomgeving. Een logische scheiding is voldoende. |
| 5 | Pseudonimisering / gegevensminimalisering | Toegang voor externe personen via willekeurige, niet te raden tokens (permanente link). Er worden alleen de gegevens verzameld die voor het betreffende doel noodzakelijk zijn (in wezen het e-mailadres); herkenningsnotities worden bewust kort en neutraal gehouden. |
| 6 | Controle op doorgifte | Overdracht uitsluitend via versleutelde verbindingen (TLS/HTTPS). Opslag van beeld- en contractgegevens op versleutelde objectopslag (S3 Server-Side Encryption). Doorgifte aan onderaannemers alleen voor zover noodzakelijk op basis van een verwerkersovereenkomst of EU-modelcontractbepalingen. |
| 7 | Controle op invoer | Logboekregistratie van voor bewijsvoering relevante handelingen op applicatieniveau, in het bijzonder het aangaan van overeenkomsten en het verlenen van toestemming met tijdstempel, IP-adres, apparaatinformatie en versie-hash, evenals betalingsgebeurtenissen. Door de eenpersoonsbediening kan elke invoer, wijziging en verwijdering aan één enkele handelende persoon worden toegewezen. |
| 8 | Beschikbaarheid en veerkracht | Database redundant verdeeld over meerdere AWS-zones of -regio’s binnen de EU of de EER; geautomatiseerde databasesnapshots als back-up; code- en serverback-ups en een opgeslagen serverimage (AMI) voor snel herstel; aanvullend lokaal back-upsysteem; gedocumenteerd nood- en herstelplan. |
| 9 | Gegevensbeschermingsbeheer | De verantwoordelijke is de directeur van CONTRIMA GmbH. Er is geen functionaris voor gegevensbescherming aangesteld, aangezien er geen wettelijke verplichting tot aanstelling bestaat. Naleving van de informatieverplichtingen overeenkomstig art. 13 AVG tijdens het activeringsproces, een bestaand proces voor de afhandeling van verzoeken van betrokkenen en een bijgehouden register van verwerkingsactiviteiten overeenkomstig art. 30 AVG. |
| 10 | Incidentresponsbeheer | Firewall die regelmatig wordt bijgewerkt; gedocumenteerd proces voor het opsporen en melden van inbreuken op de gegevensbescherming overeenkomstig art. 33 en 34 AVG, inclusief onmiddellijke kennisgeving aan de opdrachtgever. |
| 11 | Privacyvriendelijke standaardinstellingen | Privacy by default: geen gegevensverzameling die verder gaat dan het noodzakelijke, afbeeldingsvoorbeelden alleen met watermerk en verstrekking van de originelen pas na toestemming, evenals eenvoudige uitoefening van het herroepingsrecht via de gebruikersinterface. |
| 12 | Controle op opdrachten (subverwerkers) | Zorgvuldige selectie; het sluiten van verwerkersovereenkomsten of EU-modelcontractbepalingen (module 3) met alle onderverwerkers, met passende waarborgen bij verwerking in derde landen; informatieverstrekking aan de opdrachtgever vóór het inschakelen of vervangen van onderverwerkers; waarborging van gegevensverwijdering na beëindiging van de opdracht. Momenteel in gebruik: Stripe (betalingsverwerking), Amazon Web Services (hosting/opslag), DeepL (vertaling van advertentieteksten). |
Subverwerkers die overeenkomstig paragraaf 6.1 van de overeenkomst zijn betrokken en waarmee je instemt:
| Onderaannemer (naam, adres of vestigingsplaats) |
Omvang van de dienstverlening in het kader van de gegevensverwerking |
|---|---|
| Stripe Payments Europe, Ltd. 1 Grand Canal Street Lower, Grand Canal Dock Dublin, D02 H210, Ierland („Stripe“) |
Betalingsverwerking; in geval van verkoop: betalings-, identiteits- en transactiegegevens van de koper (zie hiervoor ook 6. uit Privacybeleid) |
| Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxemburg („AWS“) |
Web- en databasehosting ; opslag en verwerking van beeldgegevens (originelen, varianten, archief, exporten), inclusief EXIF-metadata. E-maildiensten (zie hiervoor ook 6. uit Privacybeleid) |
| DeepL SE Maarweg 165 50825 Keulen („DeepL“) |
Eventueel vertaling van de herkenningsnotitie en eventueel de collectienaam naar de taal van de permanente link (zie hiervoor ook 6. uit Privacybeleid) |
Versie 2 · 26 jul 2026
Between
the data processor
Contrima GmbH, represented by its managing director Mr Mark Reinhardt, Enzianweg 29, 71384 Weinstadt
(hereinafter ‘CONTRIMA’)
and
the Data Controller
{photographer_name}
{photographer_address}
{photographer_email}
(hereinafter “you”)
CONTRIMA provides services to you for the provision of an infrastructure for the transmission of photographs to the persons depicted therein, as well as for the management of image licence agreements (hereinafter: “Main Contract”). Part of the performance of the Main Contract involves the processing of personal data relating to the persons depicted, which you transmit to CONTRIMA. In order to comply with the requirements of the GDPR in such circumstances, you, as the data controller within the meaning of data protection law, enter into the following data processing agreement with CONTRIMA.
1.1 The cooperation between the parties in accordance with the Main Contract entails that CONTRIMA will have access to personal data provided by you (hereinafter ‘Processed Data’) and that it processes this data exclusively on your behalf and in accordance with your instructions within the meaning of Article 4(8) and Article 28 of the GDPR.
1.2 The following data subject categories may be affected by the processing:
| Data subjects (categories) | Type of data |
|---|---|
| Persons depicted |
|
| Legal guardians of the persons depicted |
|
| Contact persons at public authorities (e.g. tax authorities) |
|
1.3 The nature and scope of the processing of order data are determined by the purposes of the main contract and are limited to these. The duration of the processing corresponds to the term of the main contract.
1.4 CONTRIMA is prohibited from processing contract data in any manner that deviates from or goes beyond the provisions set out in Annex 1 and clause 1.2. This also applies to the use of anonymised data.
1.5 The processing of order data shall take place exclusively within the territory of the Federal Republic of Germany, in a Member State of the European Union or in another State party to the Agreement on the European Economic Area. Any transfer to a third country requires the prior written consent of the client and may only take place if the specific conditions set out in Articles 44 to 49 of the GDPR are met.
1.6 The provisions of this contract apply to all activities related to the main contract in which CONTRIMA and its employees or persons commissioned by CONTRIMA come into contact with personal data originating from you or collected on your behalf.
2.1 CONTRIMA shall process the contract data only within the scope of the contract and exclusively on your behalf and in accordance with your instructions within the meaning of Article 28 of the GDPR (processing on behalf of a controller); this applies in particular to the transfer of personal data to a third country. You have the sole right to issue instructions regarding the nature, scope and method of the processing activities (hereinafter also referred to as the ‘right to issue instructions’). If CONTRIMA is obliged to carry out further processing under the law of the European Union or the Member States to which it is subject, CONTRIMA shall inform you of these legal requirements prior to processing.
2.2 Instructions to CONTRIMA must, as a general rule, be given by you in writing (email address: info@contrima.com).
2.3 If CONTRIMA considers that one of your instructions contravenes data protection regulations, CONTRIMA must inform you of this without delay. CONTRIMA is entitled to suspend the implementation of the instruction in question until it is confirmed or amended by the client.
3.1 CONTRIMA is obliged to comply with the statutory provisions on data protection and not to disclose the information obtained from you to third parties or to prevent them from accessing it. Data must be secured against unauthorised access, taking into account the state of the art.
3.2 Furthermore, CONTRIMA shall require all persons entrusted by CONTRIMA with the processing and performance of this contract (hereinafter referred to as ‘employees’) to undertake in writing to maintain confidentiality (Obligation of confidentiality, Article 28(3)(b) of the GDPR) and shall ensure compliance with this obligation with due care. CONTRIMA shall provide you with evidence of this upon request.
3.3 CONTRIMA shall organise its internal operations in such a way as to meet the specific requirements of data protection. CONTRIMA undertakes to implement all appropriate technical and organisational measures to ensure the adequate protection of the commissioned data in accordance with Article 32 of the GDPR, in particular the measures set out in Annex 1 to this contract, and to maintain these for the duration of the processing of the commissioned data.
3.4 CONTRIMA reserves the right to amend the technical and organisational measures put in place, whilst ensuring that the level of protection agreed in the contract is not compromised. CONTRIMA must inform you in writing without delay if there is reason to believe that the measures set out in Annex 1 are no longer sufficient, and will consult with you regarding further technical and organisational measures.
3.5 At your request, CONTRIMA shall demonstrate compliance with the technical and organisational measures set out in Annex 1 by providing appropriate evidence.
4.1 In the event of disruptions, suspected data breaches or breaches of CONTRIMA’s contractual obligations, suspected security incidents or other irregularities in the processing of the contract data, whether by persons employed by CONTRIMA in the context of the contract or by third parties, CONTRIMA shall inform you without delay, but at the latest within 24 hours, in writing or by electronic means. The same applies to inspections of CONTRIMA by the data protection supervisory authority. Notifications pursuant to Section 4(1), first sentence, shall in each case contain at least the information specified in Article 33(3) of the GDPR.
4.2 In the event referred to in Section 4.1, CONTRIMA shall assist you, to the extent reasonably practicable, in fulfilling its relevant obligations to provide information, take remedial action and keep you informed. In particular, CONTRIMA shall immediately implement the necessary measures to secure the data and to mitigate any potential adverse consequences for the data subjects, and shall inform you accordingly.
4.3 CONTRIMA undertakes to provide you, upon your verbal or written request and within a reasonable period, with all information and evidence necessary to carry out an audit in accordance with § 7.1 of this contract. Furthermore, at your request, CONTRIMA will provide you with a comprehensive and up-to-date data protection and security policy for the processing of personal data, as well as a list of authorised access holders.
5.1 CONTRIMA is obliged to maintain a record of all categories of processing activities carried out on your behalf in accordance with Article 30(2) of the GDPR. This record must be made available to you upon request.
5.2 Should the data processed on your behalf at CONTRIMA be at risk due to attachment or seizure, insolvency or composition proceedings, or other events or measures taken by third parties, CONTRIMA must inform you of this without delay, provided this is not prohibited by a court or official order. In this context, CONTRIMA shall immediately inform all relevant authorities that decision-making authority over the data lies exclusively with the client as the ‘controller’ within the meaning of the GDPR.
6.1 The contractually agreed services shall be performed with the involvement of the subcontractors listed in Annex 2. CONTRIMA is authorised, within the scope of its contractual obligations, to enter into subcontracting relationships with subcontractors (‘subcontracting relationship’). Before entering into any further subcontracting relationships, CONTRIMA shall inform you in writing or by electronic means in accordance with Article 28(2) of the GDPR, giving four weeks’ notice. You may object to the change within two weeks of receiving the aforementioned notification.
6.2 A subcontracting relationship within the meaning of these provisions does not exist if CONTRIMA commissions third parties to provide services that are to be regarded as purely ancillary services. These include, for example, postal or telecommunications services with no specific connection to the services CONTRIMA provides for you, as well as other measures to ensure the confidentiality, availability, integrity and resilience of the hardware and software of data processing systems.
7.1 You are entitled to verify, on a regular basis, compliance with the provisions of this contract, in particular the implementation of and compliance with the technical and organisational measures set out in clause 3.3 of this agreement. To this end, you may, for example, request information, ask to be provided with certifications or internal audit reports, or have CONTRIMA’s technical and organisational measures inspected yourself during normal business hours or by a competent third party, provided that such third party is not in competition with CONTRIMA.
7.2 You shall carry out inspections only to the extent necessary and shall take due account of CONTRIMA’s operational processes. The parties shall agree in good time on the timing and nature of the inspection.
7.3 You shall document the results of the audit and notify CONTRIMA thereof. In the event of errors or irregularities which you identify, in particular when auditing the results of orders, you shall inform CONTRIMA without delay.
8.1 CONTRIMA shall, where possible, support you with appropriate technical and organisational measures in fulfilling your obligations under Articles 12 to 22 and Articles 32 to 36 of the GDPR. CONTRIMA shall provide you with the requested information regarding processing data without delay, but no later than within 7 working days, unless you already have the relevant information yourself.
8.2 If a data subject exercises their rights under Articles 16 to 18 of the GDPR, CONTRIMA is obliged, on your instructions, to rectify, erase or restrict the processing of the data without undue delay, and at the latest within 7 working days. CONTRIMA will provide you with written confirmation of the erasure, rectification or restriction of the data upon request.
8.3 If a data subject exercises rights – such as the right to access, rectification or erasure of their data – directly against CONTRIMA, CONTRIMA shall forward this request to you without delay and await your instructions. CONTRIMA shall not contact the data subject without specific instructions to do so.
9.1 The term of this contract corresponds to the term of the main contract. In case of doubt, termination of the main contract shall also be deemed to be termination of this contract, and termination of this contract shall be deemed to be termination of the main contract.
9.2 You are entitled at any time to terminate this contract extraordinarily for good cause. Good cause shall be deemed to exist if CONTRIMA fails to fulfil its obligations under this contract, breaches provisions of the GDPR intentionally or through gross negligence, or is unable or unwilling to carry out an instruction. In the case of minor breaches – i.e. those that are neither intentional nor due to gross negligence – you shall first set CONTRIMA a reasonable period within which CONTRIMA may remedy the breach. Once this period has expired without result, you shall then be entitled to terminate this contract without notice.
10.1 Upon termination of the main contract or at any time upon request, CONTRIMA shall return to you all data provided to CONTRIMA or, upon request, delete it completely and irrevocably, provided that no statutory retention period applies. This also applies to copies of the order data held by CONTRIMA, such as data backups, but not to documentation serving as evidence of the proper and compliant processing of the order data. Such documentation must be retained by CONTRIMA for the duration of the statutory retention periods.
10.2 You have the right to verify, in an appropriate manner, that the data has been returned or deleted by CONTRIMA in full and in accordance with the contract.
10.3 CONTRIMA is obliged to treat as confidential any data that has come to its knowledge in connection with the main contract, even after the main contract has ended.
11.1 The liability of the parties is governed by Article 82 of the GDPR. This does not affect CONTRIMA’s liability towards you for any breach of obligations arising from this contract or the main contract.
11.2 Each party shall be exempt from liability if it proves that it is in no way responsible for the circumstance that caused the damage to a data subject. Section 11(2), first sentence, shall apply mutatis mutandis in the event of a fine being imposed on a party, whereby the indemnification shall apply to the extent that the other party bears a share of the responsibility for the infringement sanctioned by the fine.
12.1 Any amendments or additions to this agreement must be made in writing in accordance with Article 28(9) of the GDPR. This also applies to any waiver of this formal requirement.
12.2 In the event of any doubt, the provisions of this Agreement shall take precedence over those of the main contract. Should any individual provisions of this Agreement prove to be wholly or partially invalid or unenforceable, or should they become invalid or unenforceable as a result of legislative changes following the conclusion of the Agreement, this shall not affect the validity of the remaining provisions. The invalid or unenforceable provision shall be replaced by a valid and enforceable provision that comes as close as possible to the meaning and purpose of the invalid provision.
12.3 This contract is governed by the law of the Federal Republic of Germany. CONTRIMA provides these terms and conditions in a variety of language versions for the sake of clarity. In the event of any discrepancies, the English version of this Data Processing Agreement shall prevail.
CONTRIMA is obliged to implement appropriate technical and organisational measures to ensure that the processing of the commissioned data is carried out in accordance with the statutory requirements and that the rights of the data subject are adequately safeguarded.
CONTRIMA shall structure its internal organisation in such a way as to meet the specific requirements of data protection. In particular, measures must be taken that are appropriate to the nature of the data or categories of data to be protected.
Specifically, the following measures are set out to implement the requirements of Article 32 of the GDPR:
| No. | Measure | Implementation of the measure |
|---|---|---|
| 1 | Access control | Productive data processing takes place exclusively in the AWS cloud; the physical data processing facilities there are secured by AWS (see AWS Terms of Service and certifications). Administration is carried out from an access-controlled workstation in lockable, non-publicly accessible rooms behind a firewall. There is no public access and no dedicated server rooms. |
| 2 | Access Control | System access is granted only via personal login with a username and password. Administrative and AWS accesses are protected by strong passwords and two-factor authentication. End devices are secured by operating system login, a firewall and disk encryption. |
| 3 | Access control | Role- and authorisation-based concept within the application, featuring centralised authorisation checks, server-side validation on all endpoints that modify data, protection against CSRF, and exclusively parameterised database access. At the infrastructure level, a minimum number of administrators (single-person operation) and the granting of rights in accordance with the principle of least privilege. |
| 4 | Segregation of duties | Multi-tenant logical separation of all data for each photographer via a unique owner assignment; separate production environment. Logical separation is sufficient. |
| 5 | Pseudonymisation / Data minimisation | Access for external parties via random, non-guessable tokens (permanent link). Only the data necessary for the respective purpose is collected (essentially the email address); identifying notes are deliberately kept brief and neutral. |
| 6 | Control of data disclosure | Transmission takes place exclusively via encrypted connections (TLS/HTTPS). Image and contract data are stored on encrypted object storage (S3 Server-Side Encryption). Data is transferred to subcontractors only to the extent necessary, on the basis of the Data Processing Agreement (DPA) or EU Standard Contractual Clauses. |
| 7 | Input control | Logging of audit-relevant operations at application level, in particular the acceptance of agreements and consents, including timestamps, IP addresses, device information and version hashes, as well as payment events. As the service is operated by a single person, every entry, modification and deletion can be traced back to a single individual. |
| 8 | Availability and Resilience | Database redundancy across multiple AWS zones or regions within the EU or the EEA; automated database snapshots as backups; code and server backups, as well as a pre-configured server image (AMI) for rapid recovery; additional local backup system; documented emergency and recovery plan. |
| 9 | Data Protection Management | The Managing Director of CONTRIMA GmbH is responsible. No data protection officer has been appointed, as there is no legal obligation to do so. Compliance with the information obligations under Article 13 of the GDPR during the activation process; an existing process for handling data subjects’ enquiries; and a register of processing activities maintained in accordance with Article 30 of the GDPR. |
| 10 | Incident Response Management | Firewall updated regularly; documented process for detecting and reporting data breaches in accordance with Articles 33 and 34 of the GDPR, including the immediate notification of the client. |
| 11 | Privacy-friendly default settings | Privacy by default: no data collected beyond what is necessary; image previews only with watermarks; original files provided only after authorisation has been granted; and the right to withdraw consent can be exercised easily via the user interface. |
| 12 | Contract management (sub-processors) | Careful selection; conclusion of data processing agreements or EU Standard Contractual Clauses (Module 3) with all sub-processors, with appropriate safeguards where third countries are involved; notification of the client prior to engaging or replacing sub-processors; ensuring data erasure upon termination of the contract. Currently used: Stripe (payment processing), Amazon Web Services (hosting/storage), DeepL (translation of advert copy). |
Sub-processors included under clause 6.1 of the agreement, to the use of whom you consent:
| Subcontractor (name, address or registered office) |
Scope of services within the framework of data processing |
|---|---|
| Stripe Payments Europe, Ltd. 1 Grand Canal Street Lower, Grand Canal Dock , Dublin, D02 H210, Ireland (“Stripe”) |
Payment processing; in the event of a sale, the purchaser’s payment, identity and transaction data (see also clause 6 of Privacy Policy) |
| Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg (“AWS”) |
Web and database hosting ; storage and processing of image data (originals, variants, archive, exports), including EXIF metadata. Email services (see also section 6 of Privacy Policy) |
| DeepL SE , Maarweg 165 , 50825 Cologne (“DeepL”) |
Where applicable, translation of the recognition note and, where applicable, the collection name into the language of the permanent link (see also 6. from Privacy Policy) |