本数据保护文本解释了 Contrima 如何在摄影师账户、参与者和访问流程、画廊、通信、文件以及礼品、交换、销售和许可流程中处理个人数据,包括相关的支付和付款流程。它概述了数据主体的目的、流程、保护措施和权利。英文版本具有权威性,提供译文仅为便于理解。
f00fe99c5db7本隐私政策提供多种语言版本。 英文版本为权威版本。翻译版本仅为便于理解而提供。 数据主体通常居住地法律规定的强制性权利不受影响。
《通用数据保护条例》(GDPR)所指的数据控制者为:
Mark Reinhardt(个体经营者)
"Contrima"是由Mark Reinhardt
提供的服务
电子邮件:info@contrima.com
我们处理个人数据旨在从技术层面提供Contrima服务, 保障并进一步开发该服务,以及执行和记录与摄影师、画廊、审批、赠礼、交换、销售、 授权、购买、订阅、卖家及支付相关的流程。
这尤其包括来自网站运营、 用户账户和摄影师个人资料、 二维码及访问系统、索赔和画廊流程、 预览、发布、审批、同意、授权和购买流程、 通信,以及计费、支付处理、 卖家入驻、验证、款项支付、归档和记录保存的数据。
我们处理个人数据主要基于以下法律依据:
若我们基于同意处理数据,您可随时撤回同意,该撤回自撤回之日起生效。
Contrima作为独立的数据控制者处理特定数据, 特别是用于平台运营、安全、通信、计费、 卖家/款项支付流程、文档记录、验证及归档。 当Contrima代表相关摄影师履行特定职能时, 数据处理均在法律规定的框架内进行。
Contrima 运行于 AWS 爱尔兰(欧盟)区域。 访问网站或使用 平台时产生的数据将在我们的托管服务提供商系统上进行处理。
托管服务提供商(数据处理方):
Amazon Web Services EMEA SARL,地址:38 avenue John F. Kennedy, L-1855 Luxembourg(“AWS”)
针对图像数据、预览文件、图库内容、 校样文件及归档资料的存储,AWS 基础设施内可能使用多种存储及归档存储类, 包括非公开归档存储类(如 AWS S3 Glacier Deep Archive)。
每次访问网站或平台时,网络服务器都会自动处理所谓服务器日志文件中的信息。 这可能特别包括:
处理的目的在于确保网站和平台的技术运行、稳定性和安全性(例如错误分析、防御攻击、检测滥用行为以及对与安全相关的访问进行审计)。 法律依据是《通用数据保护条例》(GDPR)第6条第1款第f项。
日志文件仅在实现上述目的所需的时间内存储, 随后将被删除或匿名化,除非出于证据目的(例如发生安全事件时)需要进一步保留。
出于安全考虑,我们采用传输层加密(TLS/SSL)技术,以确保对传输内容提供最佳保护。 但请注意,通过互联网传输的数据仍可能存在安全漏洞。
我们的网站和平台可能会使用Cookie或类似技术。 我们区分以下两类:
技术上必要的 Cookie 是提供网站和平台服务所必需的。 在终端设备上存储/读取这些信息的法律依据是《电信数据保护法》(TDDDG)第25条第2款第2项; 后续的个人数据处理依据是 《通用数据保护条例》(GDPR)第6条第1款第f项,或 《通用数据保护条例》(GDPR)第6条第1款第b项, 前提是该功能对于履行合同或执行特定工作流程是必要的。
若未来使用分析、营销或其他需要征得同意的工具, 我们将修订本隐私政策,并在必要时, 事先征得您的同意。
当我们提供创建用户账户或登录选项时, 我们会处理为此目的所需的数据 (例如电子邮件地址、登录凭据、技术会话数据、语言设置、 时区、个人资料数据及安全信息), 以便提供用户账户、启用登录功能、 管理个人资料并确保系统安全。
对于摄影师个人资料,若提供或启用了相关功能,我们还可能处理额外的个人资料、作品集、展示、 开票、卖家、税务、订阅、存储及定价数据。
法律依据通常为《通用数据保护条例》(GDPR)第6条第1款第(b)项, 以及《通用数据保护条例》(GDPR)第6条第1款第(f)项 (安全利益、防止滥用、系统稳定性)。
注:密码不会以明文形式存储, 通常以哈希值形式存储(技术安全措施)。
Contrima 还会处理被拍摄者、接受者、买家及其他数据主体的个人数据,这些处理与上传、图库任务、访问流程、预览、发布、审批、同意、授权、购买以及特定案例的记录相关。
此类数据可能直接来源于数据主体, (例如当其开启访问入口、提供电子邮件地址、 选择语言、作出声明或进行购买时), 或通过摄影师或其他相关方间接传送至我们; (例如通过上传图像文件、委托数据、联系方式、 二维码卡片、图库引用或案例信息)。
根据具体情况,主要处理以下数据:图像文件、 委托及案例信息、联系方式、 语言和设备环境、状态数据、声明和合同数据, 以及验证和审计信息。
在涉及未成年人和其代表的情况下,若工作流程确有必要,我们还可能处理角色详情、授权及代理确认信息、未成年人与授权成年人之间的委托关系、时间戳、通信数据、验证数据,以及关于购买、支付、激活或交付的状态信息。
若个人数据并非直接从数据主体处收集, 我们将依法履行《通用数据保护条例》(GDPR)第14条规定的告知义务。 拍摄照片及初始上传的法律许可性 取决于具体个案情况及摄影者的责任。
Contrima 可能会提供二维码、公共访问码、个人访问链接、 访问令牌、语言环境及类似的访问系统, 以便被拍摄者、接收方、购买者或其他相关方 访问参与者页面、图库、预览、审批、 同意或购买流程。
在此过程中,我们特别处理公共或个人代码、 令牌值、首选语言、时间戳、申领状态、 重发事件、会话或浏览器标记、 安全信息以及在相应流程中提供的电子邮件地址。
当未成年人使用个人访问权限或进行申领、授权、许可或购买流程时,未成年人自身的参与情况以及父母、监护人或其他授权成年人所需的授权可能被单独记录。
此处理旨在安全地提供访问权限, 分配特定案例,防止滥用, 提供个性化链接,确保语言适配的显示, 并执行相应工作流的技术和组织方面。 法律依据为《通用数据保护条例》(GDPR)第6条第1款(b)项和第6条第1款(f)项。
在中立的重复查看中,我们可能会以遮蔽形式显示联系信息,且出于安全原因,无法再次披露直接访问权限。
在图库和许可的背景下,我们特别处理以下信息: 案例、图库、参与者分配、图像变体、 预览、水印、发布级别、 激活、购买、审批、授权及同意状态,以及 针对特定案例所选的套餐或优惠。
出于记录和验证目的,我们还可能记录: 适用的套餐版本、显示的文本版本、 语言、时间戳、使用的电子邮件地址、 门户或访问令牌上下文,以及其他技术上必要的审计数据。 PDF 或类似的协议及验证文件可能会被生成、 存储并提供给相关方。
此处理旨在处理相关案例, 显示预览,在获得同意或完成支付后激活访问权限, 记录声明和合同, 核实权利范围,以及用于法律辩护。 根据具体情况,其法律依据为《通用数据保护条例》(GDPR)第6条第1款第(b)项、 第6条第1款第(f)项、 第6条第1款第(c)项, 以及在个别必要情况下,第6条第1款第(a)项。
如果您通过电子邮件联系我们,我们将处理您提供的数据 (例如姓名、电子邮件地址、邮件内容), 以便处理您的咨询。
法律依据为《通用数据保护条例》(GDPR)第6条第1款第(b)项; (涉及(预)合同沟通时) 或《通用数据保护条例》(GDPR)第6条第1款第(f)项; (一般咨询;高效沟通的合法利益)。
联系表单:若提供联系表单, 我们将仅为处理咨询之目的处理其中收集的数据。 本隐私政策将根据需要进行更新, 例如当实施垃圾邮件防护等额外服务时。
若未来我们提供电子通讯, 我们将修订本隐私政策, 并特别以透明方式披露邮件服务提供商、 双重确认订阅流程、任何性能指标, 以及退订选项。
我们使用亚马逊简单电子邮件服务(AWS SES)发送系统邮件和交易邮件; (例如:确认函、个人访问链接、重发邮件、 图库或预约通知、购买或支付信息、 发票或卖家/付款通知); 我们使用亚马逊简单电子邮件服务(AWS SES)。
具体而言,将处理电子邮件地址、 (如适用)姓名、语言环境以及电子邮件的技术元数据 (例如投递信息)。
法律依据为《通用数据保护条例》(GDPR)第 6(1)(b) 条、 《通用数据保护条例》(GDPR)第 6(1)(c) 条, 和/或《通用数据保护条例》(GDPR)第 6(1)(f) 条。
当使用付费服务、订阅、存储套餐、 图片或许可证购买、卖家账户或提现功能时, 我们会处理为此目的所需的计费、 交易及验证数据。
这可能特别包括:
针对支付处理、订阅、卖家入驻 及款项支付功能,我们主要使用 Stripe 和 Stripe Connect。 如果您在支付服务过程中提供个人数据, Stripe 将接收这些数据,并根据 Stripe 隐私政策进行处理。
此处理旨在实现支付处理、 履行合同、开具发票、 遵守法律义务、 防范欺诈和滥用、 卖家验证以及执行款项支付。 其法律依据为《通用数据保护条例》(GDPR)第6条第1款第(b)项、 《通用数据保护条例》(GDPR)第6条第1款第(c)项、 《通用数据保护条例》(GDPR)第6条第1款第(f)项,以及 在必要时,《通用数据保护条例》(GDPR)第6条第1款第(a)项。
若购买或支付流程由未成年人发起或涉及未成年人,我们还可能处理有关付款人、批准人或授权成年人的额外信息,以及与批准、授权、退款或拒付相关的状态和验证数据。
在立即提供数字图像或数字使用权的情况下,还可能处理关于服务立即开始、撤销权到期、代表性批准的相关确认,以及相关时间、文本版本、语言版本、技术证据和审计信息。
我们聘请服务提供商代表我们处理数据 (依据《通用数据保护条例》(GDPR)第28条进行的数据处理), 并向可能在相关情境中作为独立控制者行事的机构 传输数据。
其中包括:
在使用 AWS、AWS SES、Stripe 或其他所采用的服务过程中,若将个人数据传输至欧洲经济区(EEA)以外的国家,则仅在符合《通用数据保护条例》(GDPR)第 44 条及后续条款的要求下进行, 例如基于适当的保障措施(如标准合同条款) 和/或其他公认的保护机制。
我们仅在以下情况下处理和存储个人数据: 为实现相应目的所必需, 或适用法定保留义务。 此后,数据将被删除、匿名化, 或转移至与其状态和目的相符的归档状态。
以下规定特别适用于Contrima:
存储在 Deep Archive 存储类中的归档对象不可公开访问; 且通常无法实时访问; 若需重新访问,可能需要单独的恢复流程。
在法律要求的框架内,您特别享有以下权利:
您有权向数据保护监管机构提出投诉, 特别是向您惯常居住的成员国、 您的工作地点或涉嫌侵权行为发生地的监管机构提出投诉。 我们注册办事处的管辖机构为:
巴登-符腾堡州数据保护与信息自由专员(LfDI BW)
邮政信箱 10 29 32
70025 斯图加特
电子邮件:poststelle@lfdi.bwl.de
网站:baden-wuerttemberg.datenschutz.de
若法律环境、服务、支付服务、 存储及归档流程或数据处理实践发生变更, 我们可能会修订本隐私政策。 以本页面上发布的最新版本为准。
您通常无需仅因访问本网站获取信息而提供个人数据。 然而,若您: 使用访问点或图库, 提交声明、进行购买 或激活卖家/付款功能, 则需提供特定信息 以提供相关服务、 处理交易、办理支付、 进行付款或履行法律义务。
目前不进行全自动决策,包括《通用数据保护条例》(GDPR)第22条所指的个人画像分析。 然而,出于安全、防欺诈、风险管控或合规机制的考虑, 可能会暂时限制访问、上传、 发布、支付或提现操作,并随后进行人工核查。
f00fe99c5db7This privacy policy is provided in several languages. The English version is authoritative. Translations are provided solely for the sake of clarity. Mandatory rights under the law of the data subject’s usual place of residence remain unaffected.
The data controller within the meaning of the General Data Protection Regulation (GDPR) is:
Mark Reinhardt (sole trader)
"Contrima" is a service provided by Mark Reinhardt
Email: info@contrima.com
We process personal data in order to provide Contrima from a technical perspective, to secure and further develop the service, and to carry out and document processes relating to photographers, galleries, approvals, gifts, exchanges, sales, licensing, purchases, subscriptions, sellers and payments.
This includes, in particular, data from the operation of the website, from user accounts and photographer profiles, from QR and access systems, claiming and gallery processes, from preview, publication, approval, consent, licensing and purchase procedures, from communication, as well as from billing, payment processing, seller onboarding, verification, payouts, archiving and record-keeping.
We process personal data in particular on the following legal bases:
Where we process data on the basis of consent, you may withdraw your consent at any time with effect for the future.
Contrima processes certain data as a data controller in its own right, in particular for platform operation, security, communication, billing, seller/payout processes, documentation, verification and archiving. Where Contrima performs individual functions on behalf of the respective photographer, processing takes place within the framework provided for by law in each case.
Contrima is operated in the AWS Ireland (EU) region. Data generated when accessing the website or using the platform is processed on our hosting provider’s systems.
Hosting service provider (data processor):
Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855 Luxembourg (“AWS”)
For the storage of image data, preview files, gallery content, proof files and archive holdings, various storage and archive storage classes may be used within the AWS infrastructure, including non-public archive storage classes such as AWS S3 Glacier Deep Archive.
Each time the website or platform is accessed, the web server automatically processes information in so-called server log files. This may include, in particular:
The purpose of processing is the technical provision, stability and security of the website and platform (e.g. error analysis, defence against attacks, detection of misuse and auditing of security-related access). The legal basis is Article 6(1)(f) of the GDPR.
The log files are only stored for as long as is necessary for the purposes stated, and are subsequently deleted or anonymised, provided that no further retention is required for evidential purposes (e.g. in the event of security incidents).
For security reasons, we use transport encryption (TLS/SSL) to provide the best possible protection for transmitted content. Please note, however, that data transmission over the internet may still be subject to security vulnerabilities.
Our website and platform may use cookies or similar technologies. We distinguish between:
Technically necessary cookies are required to provide the website and platform. The legal basis for storing/reading these on end devices is Section 25(2)(2) of the TDDDG; the subsequent processing of personal data takes place on the basis of Art. 6(1)(f) GDPR or Art. 6(1)(b) GDPR, if the function is necessary for the performance of a contract or the execution of a specific workflow.
Insofar as analysis, marketing or other tools requiring consent are used in future, we will amend this privacy policy and – where necessary – obtain consent in advance.
Where we offer the option to create a user account or log in, we process the data required for this purpose (e.g. email address, login details, technical session data, language settings, time zone, profile data and security information), in order to provide the user account, enable login, manage the profile and ensure the security of the system.
For photographer profiles, additional profile, portfolio, showcase, invoicing, seller, tax, subscription, storage and pricing data may also be processed, insofar as these functions are offered or activated.
The legal basis is generally Article 6(1)(b) of the GDPR and Article 6(1)(f) of the GDPR (security interests, prevention of misuse, system stability).
Note: Passwords are not stored in plain text, but are generally stored as a hash value (technical security procedure).
Contrima also processes personal data of photographed persons, accepting persons, buyers and other data subjects in connection with uploads, gallery assignments, access processes, previews, publications, approvals, consents, licensing, purchases and the documentation of specific cases.
Such data may originate directly from the data subject (e.g. when they open an access point, provide an email address, select a language, make a declaration or make a purchase) or reach us indirectly via the photographer or other parties involved; (e.g. through the upload of image files, assignment data, contact details, QR cards, gallery references or case information).
Depending on the case, the following data in particular is processed: image files, assignment and case information, contact details, language and device contexts, status data, declaration and contract data, as well as verification and audit information.
In cases involving minors and representatives, additional role details, consent and representation confirmations, associations between the minor and the consenting adult, timestamps, communication data, verification data and status information regarding purchase, payment, activation or delivery may also be processed, insofar as this is necessary for the respective workflow.
Where personal data is not collected directly from the data subject, we fulfil the information obligations under Article 14 of the GDPR to the extent required by law. The legal permissibility of taking a photograph and the initial upload depends on the specific individual case and the responsibility of the photographer.
Contrima may provide QR codes, public access codes, personal access links, access tokens, language contexts and similar access systems, to enable photographed persons, recipients, buyers or other parties involved to access participant pages, galleries, previews, approval, consent or purchase processes.
In doing so, we process in particular public or personal codes, token values, preferred language, timestamps, claim status, resend events, session or browser markers, security information and the email address provided in the respective flow.
Where minors use personal access or a claiming, authorisation, licensing or purchase process, the minor’s own involvement and the required authorisation by a parent or guardian or other authorised adult may be documented separately.
This processing serves to securely provide access, to assign a specific case, to prevent misuse, to deliver personalised links, to ensure language-appropriate display, and to carry out the technical and organisational aspects of the respective workflow. The legal basis is Article 6(1)(b) GDPR and Article 6(1)(f) GDPR.
In neutral repeat views, we may display contact details in a masked form and, for security reasons, cannot disclose direct access again.
In the context of galleries and licences, we process, in particular, information regarding: cases, galleries, participant assignments, image variants, previews, watermarks, publication levels, activations, purchase, approval, authorisation and consent statuses, as well as the packages or offers selected for the specific case.
For documentation and verification purposes, we may also log the applicable package version, the displayed text version, the language, the timestamp, the email address used, the portal or access token context, and other technically necessary audit data. PDF or comparable agreement and verification documents may be generated, stored and made available to the parties involved.
This processing serves to handle the respective case, display previews, activate access following consent or payment, document declarations and contracts, verify the scope of rights, and defend legal interests. The legal basis, depending on the case, is Article 6(1)(b) of the GDPR, Article 6(1)(f) of the GDPR, Article 6(1)(c) of the GDPR and, where necessary in individual cases, Article 6(1)(a) of the GDPR.
If you contact us by email, we process the data you provide (e.g. name, email address, content of the message), in order to deal with your enquiry.
The legal basis is Article 6(1)(b) of the GDPR (insofar as this concerns (pre-)contractual communication) or Article 6(1)(f) of the GDPR (general enquiries; legitimate interest in efficient communication).
Contact form: Where a contact form is provided, we process the data collected there exclusively for the purpose of handling the enquiry. This privacy policy will be updated as necessary, e.g. if additional services such as spam protection are implemented.
Should we offer a newsletter in future, we will amend this privacy policy and, in particular, transparently disclose the mailing service provider, the double opt-in procedure, any performance metrics, and options for withdrawal.
For the sending of system and transactional emails, (e.g. confirmations, personal access links, resend messages, gallery or appointment notifications, purchase or payment information, invoice or seller/payout notifications) we use Amazon Simple Email Service (AWS SES).
In particular, the email address, where applicable, name, language context and technical metadata of the email (e.g. delivery information) are processed.
The legal basis is Article 6(1)(b) of the GDPR, Article 6(1)(c) of the GDPR, and/or Article 6(1)(f) of the GDPR.
When paid services, subscriptions, storage packages, image or licence purchases, seller accounts or payout functions are used, we process the billing, transaction and verification data required for this purpose.
This may include, in particular:
For payment processing, subscriptions, seller onboarding and payout functions, we use Stripe and Stripe Connect in particular. If you provide personal data in connection with payment services, Stripe receives this data and processes it in accordance with the Stripe Privacy Policy.
This processing serves the purposes of payment processing, contract performance, invoicing, compliance with legal obligations, prevention of fraud and misuse, seller verification and the execution of payouts. The legal basis is Article 6(1)(b) of the GDPR, Article 6(1)(c) of the GDPR, Article 6(1)(f) of the GDPR and, where necessary, Article 6(1)(a) of the GDPR.
In the case of purchases or payment processes initiated by or involving minors, additional information regarding the paying, approving or authorised adult, as well as status and verification data relating to approval, authorisation, refunds or chargebacks, may also be processed.
In the case of the immediate provision of digital images or digital rights of use, confirmations regarding the immediate start of provision, the expiry of a right of withdrawal, representative approval, as well as the associated times, text versions, language versions, technical evidence and audit information may also be processed.
We engage service providers who process data on our behalf (processing on behalf of the controller pursuant to Article 28 of the GDPR), and we also transfer data to bodies which may act as independent controllers in the relevant context.
These include, in particular:
Insofar as, in the context of the use of AWS, AWS SES, Stripe or other services employed, personal data is transferred to countries outside the European Economic Area (EEA), this is done only in compliance with the requirements of Articles 44 et seq. of the GDPR, e.g. on the basis of appropriate safeguards such as standard contractual clauses and/or other recognised protection mechanisms.
We process and store personal data only for as long as, it is necessary for the respective purposes or statutory retention obligations apply. Thereafter, the data is deleted, anonymised or transferred to an archive status appropriate to its status and purpose.
The following applies in particular to Contrima:
Archived objects in Deep Archive storage classes are not publicly accessible; and are generally not accessible in real time; a separate restore process may be required for re-access.
Within the framework of the legal requirements, you have the following rights in particular:
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement. The competent authority for our registered office is:
The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI BW)
PO Box 10 29 32
70025 Stuttgart
Email: poststelle@lfdi.bwl.de
Website: baden-wuerttemberg.datenschutz.de
We may amend this privacy policy, if the legal situation, services, payment services, storage and archiving procedures or data processing practices change. The version published on this page at any given time shall apply.
You are generally not obliged to provide personal data simply for visiting the website for information purposes. However, use an access point or a gallery, submit a declaration, make a purchase or activate seller/payout functions, certain details are required to provide the relevant service, process the transaction, handle payments, make payouts or fulfil legal obligations.
Fully automated decision-making, including profiling within the meaning of Article 22 of the GDPR, does not currently take place. However, security, fraud, risk or compliance mechanisms may result in access, uploads, publications, payments or withdrawals being temporarily restricted and subsequently checked manually.