Version 2 · 26.07.2026
Zwischen
dem Auftragsverarbeiter
Contrima GmbH, vertreten durch ihren Geschäftsführer Herrn Mark Reinhardt, Enzianweg 29, 71384 Weinstadt
(nachfolgend „CONTRIMA“)
und
dem Verantwortlichen
{photographer_name}
{photographer_address}
{photographer_email}
(nachfolgend „Du“)
CONTRIMA erbringt Dir gegenüber Leistungen zur Bereitstellung einer Infrastruktur für die Übermittlung von Fotografien an abgebildete Personen sowie für das Bildlizenzvertragsmanagement (im Folgenden: „Hauptvertrag“). Teil der Durchführung des Hauptvertrags ist die Verarbeitung von personenbezogenen Daten der Abgebildeten, die Du an CONTRIMA übermittelst. Zur Erfüllung der Anforderungen der DSGVO an derartige Konstellationen schließt Du als Verantwortlicher im Sinne des Datenschutzrechts mit CONTRIMA den nachfolgenden Vertrag zur Auftragsdatenverarbeitung.
1.1 Die Zusammenarbeit der Parteien nach Maßgabe des Hauptvertrages bringt es mit sich, dass CONTRIMA Zugriff auf von Dir bereitgestellte personenbezogene Daten (im Folgenden „Auftragsdaten“) erhält und diese ausschließlich in Deinem Auftrag und nach Deiner Weisung im Sinne von Art. 4 Nr. 8 und Art. 28 DSGVO verarbeitet.
1.2 Von der Verarbeitung können die folgenden Auftragsdaten betroffen sein:
| Betroffene Personen (Kategorien) | Art der Daten |
|---|---|
| Abgebildete Personen |
|
| Erziehungsberechtigte Personen der abgebildeten Personen |
|
| Ansprechpartner von Behörden (z. B. Steuerbehörden) |
|
1.3 Die Art und der Umfang der Verarbeitung der Auftragsdaten richtet sich nach den Zwecken des Hauptvertrages und ist hierauf beschränkt. Die Dauer der Verarbeitung entspricht der Laufzeit des Hauptvertrages.
1.4 CONTRIMA ist eine abweichende oder über die Festlegungen in der Anlage 1 sowie Ziff. 1.2 hinausgehende Verarbeitung von Auftragsdaten untersagt. Dies gilt auch für die Verwendung anonymisierter Daten.
1.5 Die Verarbeitung der Auftragsdaten findet ausschließlich im Gebiet der Bundesrepublik Deutschland, in einem Mitgliedsstaat der Europäischen Union oder in einem anderen Vertragsstaat des Abkommens über den Europäischen Wirtschaftsraum statt. Jede Verlagerung in ein Drittland bedarf der vorherigen schriftlichen Zustimmung des Auftraggebers und darf nur erfolgen, wenn die besonderen Voraussetzungen der Art. 44 bis 49 DSGVO erfüllt sind.
1.6 Die Bestimmungen dieses Vertrages finden Anwendung auf alle Tätigkeiten, die mit dem Hauptvertrag in Zusammenhang stehen und bei denen CONTRIMA und seine Beschäftigten oder durch CONTRIMA Beauftragte mit personenbezogenen Daten in Berührung kommen, die von Dir stammen oder für Dich erhoben wurden.
2.1 CONTRIMA verarbeitet die Auftragsdaten nur im Rahmen der Beauftragung und ausschließlich in Deinem Auftrag und nach Deiner Weisung iSv Art. 28 DSGVO (Auftragsverarbeitung), dies gilt insbesondere in Bezug auf die Übermittlung personenbezogener Daten in ein Drittland. Du hast das alleinige Recht, Weisungen über Art, Umfang und Methode der Verarbeitungstätigkeiten zu erteilen (nachfolgend auch „Weisungsrecht“). Wird CONTRIMA durch das Recht der Europäischen Union oder der Mitgliedstaaten, dem er unterliegt, zu weiteren Verarbeitungen verpflichtet, teilt CONTRIMA Dir diese rechtlichen Anforderungen vor der Verarbeitung mit.
2.2 Weisungen an CONTRIMA werden von Dir grundsätzlich schriftlich erteilt (Mailadresse: info@contrima.com).
2.3 Ist CONTRIMA der Ansicht, dass eine Deiner Weisungen gegen datenschutzrechtliche Bestimmungen verstößt, hat CONTRIMA Dich unverzüglich darauf hinzuweisen. CONTRIMA ist berechtigt, die Durchführung der betreffenden Weisung so lange auszusetzen, bis diese durch den Auftraggeber bestätigt oder geändert wird.
3.1 CONTRIMA ist verpflichtet, die gesetzlichen Bestimmungen über den Datenschutz zu beachten und die von Dir erlangten Informationen nicht an Dritte weiterzugeben oder deren Zugriff auszusetzen. Daten sind gegen die Kenntnisnahme durch Unbefugte unter Berücksichtigung des Stands der Technik zu sichern.
3.2 Ferner wird CONTRIMA alle Personen, die von CONTRIMA mit der Bearbeitung und der Erfüllung dieses Vertrages betraut werden (im Folgenden „Mitarbeiter“ genannt), in Schriftform zur Vertraulichkeit verpflichten (Verpflichtung zur Vertraulichkeit, Art. 28 Abs. 3 lit. b DSGVO) und die Einhaltung dieser Verpflichtung mit der gebotenen Sorgfalt sicherstellen. Dies wird CONTRIMA Dir auf Verlangen nachweisen.
3.3 CONTRIMA wird die innerbetriebliche Organisation so gestalten, dass sie den besonderen Anforderungen des Datenschutzes gerecht wird. CONTRIMA verpflichtet sich, alle geeigneten technischen und organisatorischen Maßnahmen zum angemessenen Schutz der Auftragsdaten gem. Art. 32 DSGVO, insbesondere die in Anlage 1 zu diesem Vertrag aufgeführten Maßnahmen, zu ergreifen und diese für die Dauer der Verarbeitung der Auftragsdaten aufrecht zu erhalten.
3.4 Eine Änderung der getroffenen technischen und organisatorischen Maßnahmen bleibt CONTRIMA vorbehalten, wobei CONTRIMA sicherstellt, dass das vertraglich vereinbarte Schutzniveau nicht unterschritten wird. CONTRIMA hat Dich unverzüglich schriftlich zu informieren, wenn Grund zu der Annahme besteht, dass die Maßnahmen gemäß Anlage 1 nicht mehr ausreichend sind und wird sich mit Dir hinsichtlich weiterer technischer und organisatorischer Maßnahmen abstimmen.
3.5 Auf Verlangen von Dir wird CONTRIMA die Einhaltung der in Anlage 1 bestimmten technischen und organisatorischen Maßnahmen durch geeignete Nachweise nachweisen.
4.1 Bei Störungen, Verdacht auf Datenschutzverletzungen oder Verletzungen vertraglicher Verpflichtungen CONTRIMAs, Verdacht auf sicherheitsrelevante Vorfälle oder andere Unregelmäßigkeiten bei der Verarbeitung der Auftragsdaten, bei CONTRIMA im Rahmen des Auftrags durch beschäftigte Personen oder durch Dritte, wird CONTRIMA Dich unverzüglich, spätestens aber innerhalb von 24 Stunden in Schriftform oder elektronischer Form informieren. Dasselbe gilt für Prüfungen CONTRIMAs durch die Datenschutz-Aufsichtsbehörde. Die Meldungen gemäß § 4 Abs. 1 S. 1 enthalten jeweils zumindest die in Art. 33 Absatz 3 DSGVO genannten Angaben.
4.2 CONTRIMA wird Dich im Falle des § 4.1 bei der Erfüllung seiner diesbezüglichen Aufklärungs-, Abhilfe- und Informationsmaßnahmen im Rahmen des Zumutbaren unterstützen. CONTRIMA wird insbesondere unverzüglich die erforderlichen Maßnahmen zur Sicherung der Daten und zur Minderung möglicher nachteiliger Folgen der Betroffenen durchführen und Dich informieren.
4.3 CONTRIMA verpflichtet sich, Dir auf Deine mündliche oder schriftliche Anforderung innerhalb einer angemessenen Frist alle Auskünfte und Nachweise zur Verfügung zu stellen, die zur Durchführung einer Kontrolle gemäß § 7.1 dieses Vertrages erforderlich sind. Ferner wird CONTRIMA Dir auf Deinen Wunsch ein umfassendes und aktuelles Datenschutz- und Sicherheitskonzept für die Auftragsverarbeitung sowie über zugriffsberechtigte Personen zur Verfügung stellen.
5.1 CONTRIMA ist verpflichtet, ein Verzeichnis zu allen Kategorien von in Deinem Auftrag durchgeführten Tätigkeiten der Verarbeitung gem. Art. 30 Abs. 2 DSGVO zu führen. Das Verzeichnis ist Dir auf Verlangen zur Verfügung zu stellen.
5.2 Sollten die Auftragsdaten bei CONTRIMA durch Pfändung oder Beschlagnahme, durch ein Insolvenz- oder Vergleichsverfahren oder durch sonstige Ereignisse oder Maßnahmen Dritter gefährdet werden, so hat CONTRIMA Dich unverzüglich darüber zu informieren, sofern dies nicht durch gerichtliche oder behördliche Anordnung untersagt ist. CONTRIMA wird in diesem Zusammenhang alle zuständigen Stellen unverzüglich darüber informieren, dass die Entscheidungshoheit über die Daten ausschließlich beim Auftraggeber als „Verantwortlichem“ im Sinne der DSGVO liegt.
6.1 Die vertraglich vereinbarten Leistungen werden unter Einschaltung der in Anlage 2 genannten Subunternehmer durchgeführt. CONTRIMA ist im Rahmen seiner vertraglichen Verpflichtungen zur Begründung von Unterauftragsverhältnissen mit Subunternehmern („Subunternehmerverhältnis“) befugt. Vor der Begründung von weiteren Unterauftragsverhältnissen informiert CONTRIMA Dich schriftlich bzw. dokumentiert elektronisch im Sinne des Art. 28 Abs. 2 DSGVO mit einer Frist von vier Wochen. Du kannst gegen die Änderung Einspruch innerhalb von zwei Wochen nach Erhalt der vorstehenden Mitteilung erheben.
6.2 Ein Subunternehmerverhältnis im Sinne dieser Bestimmungen liegt nicht vor, wenn CONTRIMA Dritte mit Dienstleistungen beauftragt, die als reine Nebenleistungen anzusehen sind. Dazu gehören z.B. Post- oder Telekommunikationsleistungen ohne konkreten Bezug zu Leistungen, die CONTRIMA für Dich erbringt sowie sonstige Maßnahmen zur Sicherstellung der Vertraulichkeit, Verfügbarkeit, Integrität und Belastbarkeit der Hard- und Software von Datenverarbeitungsanlagen.
7.1 Du bist berechtigt, Dich regelmäßig von der Einhaltung der Regelungen dieses Vertrages, insbesondere der Umsetzung und Einhaltung der technischen und organisatorischen Maßnahmen gemäß § 3.3 dieser Vereinbarung, zu überzeugen. Hierfür kannst Du z.B. Auskünfte einholen oder Dir Zertifizierungen oder interne Prüfungen vorlegen lassen oder die technischen und organisatorischen Maßnahmen von CONTRIMA zu den üblichen Geschäftszeiten selbst persönlich bzw. durch einen sachkundigen Dritten prüfen lassen, sofern dieser nicht in einem Wettbewerbsverhältnis zu CONTRIMA steht.
7.2 Du wirst Kontrollen nur im erforderlichen Umfang durchführen und angemessene Rücksicht auf die Betriebsabläufe von CONTRIMA nehmen. Über den Zeitpunkt sowie die Art der Prüfung verständigen sich die Parteien rechtzeitig.
7.3 Du dokumentierst das Kontrollergebnis und teilst es CONTRIMA mit. Bei Fehlern oder Unregelmäßigkeiten, die Du insbesondere bei der Prüfung von Auftragsergebnissen feststellst, informierst Du CONTRIMA unverzüglich.
8.1 CONTRIMA unterstützt Dich nach Möglichkeit mit geeigneten technischen und organisatorischen Maßnahmen bei der Erfüllung Deiner Pflichten nach Art. 12 bis 22 sowie Art. 32 bis 36 DSGVO. CONTRIMA wird Dir unverzüglich, spätestens aber innerhalb von 7 Werktagen, die gewünschte Auskunft über Auftragsdaten geben, sofern Du nicht selbst über die entsprechenden Informationen verfügst.
8.2 Macht der Betroffene seine Rechte gemäß Art. 16 bis 18 DSGVO geltend, ist CONTRIMA dazu verpflichtet, die Auftragsdaten auf Deine Weisung hin unverzüglich, spätestens binnen einer Frist von 7 Werktagen zu berichtigen, zu löschen oder einzuschränken. CONTRIMA wird Dir die Löschung, Berichtigung bzw. Einschränkung der Daten auf Verlangen schriftlich nachweisen.
8.3 Macht ein Betroffener Rechte, etwa auf Auskunftserteilung, Berichtigung oder Löschung hinsichtlich seiner Daten, unmittelbar gegenüber CONTRIMA geltend, wird CONTRIMA dieses Ersuchen unverzüglich an Dich weiterleiten und wartet Deine Weisungen ab. Ohne entsprechende Einzelweisung wird CONTRIMA nicht mit der betroffenen Person in Kontakt treten.
9.1 Die Laufzeit dieses Vertrags entspricht der Laufzeit des Hauptvertrags. Im Zweifel gilt eine Kündigung des Hauptvertrags auch als Kündigung dieses Vertrags und eine Kündigung dieses Vertrages als Kündigung des Hauptvertrages.
9.2 Du bist jederzeit zu einer außerordentlichen Kündigung dieses Vertrages aus wichtigem Grund berechtigt. Ein wichtiger Grund liegt vor, wenn CONTRIMA seinen Pflichten aus diesem Vertrag nicht nachkommt, Bestimmungen der DSGVO vorsätzlich oder grob fahrlässig verletzt oder eine Weisung nicht ausführen kann oder will. Bei einfachen – also weder vorsätzlichen noch grob fahrlässigen – Verstößen setzt Du CONTRIMA zunächst eine angemessene Frist, innerhalb welcher CONTRIMA den Verstoß abstellen kann. Nach fruchtlosem Ablauf dieser Frist steht Dir sodann das Recht zur außerordentlichen Kündigung zu.
10.1 CONTRIMA wird Dir nach Beendigung des Hauptvertrags oder jederzeit auf Verlangen alle an CONTRIMA überlassenen Daten zurückgeben oder auf Wunsch, sofern nicht eine gesetzliche Aufbewahrungsfrist besteht, vollständig und unwiderruflich löschen. Dies gilt auch für Vervielfältigungen der Auftragsdaten bei CONTRIMA, wie etwa Datensicherungen, nicht aber für Dokumentationen, die dem Nachweis der auftrags- und ordnungsgemäßen Verarbeitung der Auftragsdaten dienen. Solche Dokumentationen sind von CONTRIMA für die Dauer der gesetzlichen Aufbewahrungsfristen aufzubewahren.
10.2 Du hast das Recht, die vollständige und vertragsgerechte Rückgabe bzw. Löschung der Daten bei CONTRIMA in geeigneter Weise zu kontrollieren.
10.3 CONTRIMA ist verpflichtet, auch über das Ende des Hauptvertrags hinaus die ihm im Zusammenhang mit dem Hauptvertrag bekannt gewordenen Daten vertraulich zu behandeln.
11.1 Die Haftung der Parteien richtet sich nach Art. 82 DSGVO. Eine Haftung von CONTRIMA Dir gegenüber wegen Verletzung von Pflichten aus diesem Vertrag oder dem Hauptvertrag bleibt hiervon unberührt.
11.2 Die Parteien stellen sich jeweils von der Haftung frei, wenn eine Partei nachweist, dass sie in keinerlei Hinsicht für den Umstand, durch den der Schaden bei einem Betroffenen eingetreten ist, verantwortlich ist. § 11 Abs. 2 S. 1 gilt im Falle einer gegen eine Partei verhängten Geldbuße entsprechend, wobei die Freistellung in dem Umfang erfolgt, in dem die jeweils andere Partei Anteil an der Verantwortung für den durch die Geldbuße sanktionierten Verstoß trägt.
12.1 Änderungen und Ergänzungen dieser Vereinbarung bedürfen der Schriftform im Sinne des Art. 28 Abs. 9 DSGVO. Dies gilt auch für den Verzicht auf dieses Formerfordernis.
12.2 Die Regelungen dieses Vertrags gehen im Zweifel den Regelungen des Hauptvertrags vor. Sollten sich einzelne Bestimmungen dieser Vereinbarung ganz oder teilweise als unwirksam oder undurchführbar erweisen oder infolge Änderungen einer Gesetzgebung nach Vertragsabschluss unwirksam oder undurchführbar werden, wird dadurch die Wirksamkeit der übrigen Bestimmungen nicht berührt. An die Stelle der unwirksamen oder undurchführbaren Bestimmung soll die wirksame und durchführbare Bestimmung treten, die dem Sinn und Zweck der nichtigen Bestimmung möglichst nahekommt.
12.3 Dieser Vertrag unterliegt dem Recht der Bundesrepublik Deutschland. CONTRIMA stellt diese Bedingungen zur besseren Verständlichkeit in einer Vielzahl von Sprachversionen zur Verfügung. Bei Diskrepanzen ist die englische Sprachversion dieses Auftragsdatenverarbeitungsvertrags maßgeblich.
CONTRIMA ist verpflichtet, geeignete technische und organisatorische Maßnahmen so durchzuführen, dass die Verarbeitung der Auftragsdaten im Einklang mit den gesetzlichen Anforderungen erfolgt und der Schutz der Rechte der betroffenen Person in angemessener Form gewährleistet ist.
CONTRIMA wird ihre innerbetriebliche Organisation so gestalten, dass sie den besonderen Anforderungen des Datenschutzes gerecht wird. Dabei sind insbesondere Maßnahmen zu treffen, die je nach der Art der zu schützenden Daten oder Datenkategorien geeignet sind.
Im Einzelnen werden folgende Maßnahmen bestimmt, die der Umsetzung der Vorgaben des Art. 32 DSGVO dienen:
| Nr. | Maßnahme | Umsetzung der Maßnahme |
|---|---|---|
| 1 | Zutrittskontrolle | Die produktive Datenverarbeitung findet ausschließlich in der AWS-Cloud statt; die physischen Datenverarbeitungsanlagen werden dort durch AWS gesichert (vgl. AVV und Zertifizierungen von AWS). Die Verwaltung erfolgt von einem zugangsgeschützten Arbeitsplatz in abschließbaren, nicht öffentlich zugänglichen Räumen hinter einer Firewall. Es bestehen kein Publikumsverkehr und keine eigenen Serverräume. |
| 2 | Zugangskontrolle | Systemzugriff nur über persönliche Anmeldung mit Benutzername und Passwort. Administrations- und AWS-Zugänge sind durch starke Passwörter und Zwei-Faktor-Authentifizierung geschützt. Endgeräte sind durch Betriebssystem-Login, Firewall und Festplattenverschlüsselung abgesichert. |
| 3 | Zugriffskontrolle | Rollen- und Berechtigungskonzept in der Anwendung mit zentraler Berechtigungsprüfung, serverseitige Prüfung auf allen datenverändernden Endpunkten, Schutz gegen CSRF sowie ausschließlich parametrisierte Datenbankzugriffe. Auf Infrastrukturebene minimale Zahl an Administratoren (Ein-Personen-Betrieb) und Rechtevergabe nach dem Least-Privilege-Prinzip. |
| 4 | Trennungskontrolle | Mandantenfähige logische Trennung aller Daten je Fotograf über eine eindeutige Eigentümerzuordnung; getrennte Produktivumgebung. Eine logische Trennung ist ausreichend. |
| 5 | Pseudonymisierung / Datenminimierung | Zugang externer Personen über zufällige, nicht erratbare Token (Permanentlink). Es werden nur die für den jeweiligen Zweck erforderlichen Daten erhoben (im Kern die E-Mail-Adresse); Wiedererkennungsnotizen werden bewusst kurz und neutral gehalten. |
| 6 | Weitergabekontrolle | Übertragung ausschließlich über verschlüsselte Verbindungen (TLS/HTTPS). Speicherung der Bild- und Vertragsdaten auf verschlüsseltem Objektspeicher (S3 Server-Side Encryption). Übermittlung an Subunternehmer nur im erforderlichen Umfang auf Grundlage von AVV bzw. EU-Standardvertragsklauseln. |
| 7 | Eingabekontrolle | Protokollierung nachweisrelevanter Vorgänge auf Anwendungsebene, insbesondere Vereinbarungs- und Zustimmungsannahmen mit Zeitstempel, IP-Adresse, Geräteinformation und Versions-Hash sowie Zahlungs-Events. Durch den Ein-Personen-Betrieb ist jede Eingabe, Änderung und Löschung einer einzigen handelnden Person zuzuordnen. |
| 8 | Verfügbarkeit und Belastbarkeit | Datenbank redundant über mehrere AWS-Zonen bzw. -Regionen innerhalb der EU bzw. des EWR; automatisierte Datenbank-Snapshots als Sicherung; Code- und Server-Sicherungen sowie ein vorgehaltenes Server-Abbild (AMI) zur raschen Wiederherstellung; zusätzliches lokales Backup-System; dokumentierter Notfall- und Wiederanlaufplan. |
| 9 | Datenschutz-Management | Verantwortlich ist der Geschäftsführer der CONTRIMA GmbH. Es ist kein Datenschutzbeauftragter bestellt, da keine gesetzliche Bestellpflicht besteht. Erfüllung der Informationspflichten nach Art. 13 DSGVO im Aktivierungsablauf, vorhandener Prozess zur Bearbeitung von Betroffenenanfragen sowie geführtes Verzeichnis von Verarbeitungstätigkeiten nach Art. 30 DSGVO. |
| 10 | Incident-Response-Management | Firewall mit regelmäßiger Aktualisierung; dokumentierter Prozess zur Erkennung und Meldung von Datenschutzverletzungen nach Art. 33 und 34 DSGVO einschließlich unverzüglicher Information des Auftraggebers. |
| 11 | Datenschutzfreundliche Voreinstellungen | Privacy by default: keine Erhebung über das Erforderliche hinaus, Bildvorschauen nur mit Wasserzeichen und Bereitstellung der Originale erst nach erteilter Berechtigung sowie einfache Ausübung des Widerrufsrechts über die Oberfläche. |
| 12 | Auftragskontrolle (Unterauftragsverarbeiter) | Sorgfältige Auswahl; Abschluss von AVV bzw. EU-Standardvertragsklauseln (Modul 3) mit allen Unterauftragsverarbeitern, bei Drittlandbezug mit geeigneten Garantien; Information des Auftraggebers vor Hinzuziehung oder Ersetzung; Sicherstellung der Datenlöschung nach Auftragsende. Derzeit eingesetzt: Stripe (Zahlungsabwicklung), Amazon Web Services (Hosting/Speicherung), DeepL (Übersetzung von Anzeigetexten). |
Nach Ziffer 6.1 der Vereinbarung einbezogene Unterauftragnehmer, deren Einsatz Du zustimmst:
| Subunternehmen (Name, Anschrift bzw. Sitz) |
Leistungsgegenstand im Rahmen der Auftragsverarbeitung |
|---|---|
| Stripe Payments Europe, Ltd. 1 Grand Canal Street Lower, Grand Canal Dock Dublin, D02 H210, Irland („Stripe“) |
Zahlungsabwicklung; im Verkaufsfall Zahlungs-, Identitäts- und Transaktionsdaten des Käufers. (s. hierzu auch 6. aus Allgemeine Datenschutzhinweise) |
| Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxemburg („AWS“) |
Web- und Datenbank-Hosting Speicherung und Verarbeitung der Bilddaten (Originale, Varianten, Archiv, Exporte) inkl. EXIF-Metadaten. E-Mail-Services (s. hierzu auch 6. aus Allgemeine Datenschutzhinweise) |
| DeepL SE Maarweg 165 50825 Köln („DeepL“) |
Ggf. Übersetzung der Wiedererkennungsnotiz und ggf. des Kollektionsnamens in die Sprache des Permanentlinks. (s. hierzu auch 6. aus Allgemeine Datenschutzhinweise) |
Version 2 · 26.07.2026
Between
the data processor
Contrima GmbH, represented by its managing director Mr Mark Reinhardt, Enzianweg 29, 71384 Weinstadt
(hereinafter ‘CONTRIMA’)
and
the Data Controller
{photographer_name}
{photographer_address}
{photographer_email}
(hereinafter “you”)
CONTRIMA provides services to you for the provision of an infrastructure for the transmission of photographs to the persons depicted therein, as well as for the management of image licence agreements (hereinafter: “Main Contract”). Part of the performance of the Main Contract involves the processing of personal data relating to the persons depicted, which you transmit to CONTRIMA. In order to comply with the requirements of the GDPR in such circumstances, you, as the data controller within the meaning of data protection law, enter into the following data processing agreement with CONTRIMA.
1.1 The cooperation between the parties in accordance with the Main Contract entails that CONTRIMA will have access to personal data provided by you (hereinafter ‘Processed Data’) and that it processes this data exclusively on your behalf and in accordance with your instructions within the meaning of Article 4(8) and Article 28 of the GDPR.
1.2 The following data subject categories may be affected by the processing:
| Data subjects (categories) | Type of data |
|---|---|
| Persons depicted |
|
| Legal guardians of the persons depicted |
|
| Contact persons at public authorities (e.g. tax authorities) |
|
1.3 The nature and scope of the processing of order data are determined by the purposes of the main contract and are limited to these. The duration of the processing corresponds to the term of the main contract.
1.4 CONTRIMA is prohibited from processing contract data in any manner that deviates from or goes beyond the provisions set out in Annex 1 and clause 1.2. This also applies to the use of anonymised data.
1.5 The processing of order data shall take place exclusively within the territory of the Federal Republic of Germany, in a Member State of the European Union or in another State party to the Agreement on the European Economic Area. Any transfer to a third country requires the prior written consent of the client and may only take place if the specific conditions set out in Articles 44 to 49 of the GDPR are met.
1.6 The provisions of this contract apply to all activities related to the main contract in which CONTRIMA and its employees or persons commissioned by CONTRIMA come into contact with personal data originating from you or collected on your behalf.
2.1 CONTRIMA shall process the contract data only within the scope of the contract and exclusively on your behalf and in accordance with your instructions within the meaning of Article 28 of the GDPR (processing on behalf of a controller); this applies in particular to the transfer of personal data to a third country. You have the sole right to issue instructions regarding the nature, scope and method of the processing activities (hereinafter also referred to as the ‘right to issue instructions’). If CONTRIMA is obliged to carry out further processing under the law of the European Union or the Member States to which it is subject, CONTRIMA shall inform you of these legal requirements prior to processing.
2.2 Instructions to CONTRIMA must, as a general rule, be given by you in writing (email address: info@contrima.com).
2.3 If CONTRIMA considers that one of your instructions contravenes data protection regulations, CONTRIMA must inform you of this without delay. CONTRIMA is entitled to suspend the implementation of the instruction in question until it is confirmed or amended by the client.
3.1 CONTRIMA is obliged to comply with the statutory provisions on data protection and not to disclose the information obtained from you to third parties or to prevent them from accessing it. Data must be secured against unauthorised access, taking into account the state of the art.
3.2 Furthermore, CONTRIMA shall require all persons entrusted by CONTRIMA with the processing and performance of this contract (hereinafter referred to as ‘employees’) to undertake in writing to maintain confidentiality (Obligation of confidentiality, Article 28(3)(b) of the GDPR) and shall ensure compliance with this obligation with due care. CONTRIMA shall provide you with evidence of this upon request.
3.3 CONTRIMA shall organise its internal operations in such a way as to meet the specific requirements of data protection. CONTRIMA undertakes to implement all appropriate technical and organisational measures to ensure the adequate protection of the commissioned data in accordance with Article 32 of the GDPR, in particular the measures set out in Annex 1 to this contract, and to maintain these for the duration of the processing of the commissioned data.
3.4 CONTRIMA reserves the right to amend the technical and organisational measures put in place, whilst ensuring that the level of protection agreed in the contract is not compromised. CONTRIMA must inform you in writing without delay if there is reason to believe that the measures set out in Annex 1 are no longer sufficient, and will consult with you regarding further technical and organisational measures.
3.5 At your request, CONTRIMA shall demonstrate compliance with the technical and organisational measures set out in Annex 1 by providing appropriate evidence.
4.1 In the event of disruptions, suspected data breaches or breaches of CONTRIMA’s contractual obligations, suspected security incidents or other irregularities in the processing of the contract data, whether by persons employed by CONTRIMA in the context of the contract or by third parties, CONTRIMA shall inform you without delay, but at the latest within 24 hours, in writing or by electronic means. The same applies to inspections of CONTRIMA by the data protection supervisory authority. Notifications pursuant to Section 4(1), first sentence, shall in each case contain at least the information specified in Article 33(3) of the GDPR.
4.2 In the event referred to in Section 4.1, CONTRIMA shall assist you, to the extent reasonably practicable, in fulfilling its relevant obligations to provide information, take remedial action and keep you informed. In particular, CONTRIMA shall immediately implement the necessary measures to secure the data and to mitigate any potential adverse consequences for the data subjects, and shall inform you accordingly.
4.3 CONTRIMA undertakes to provide you, upon your verbal or written request and within a reasonable period, with all information and evidence necessary to carry out an audit in accordance with § 7.1 of this contract. Furthermore, at your request, CONTRIMA will provide you with a comprehensive and up-to-date data protection and security policy for the processing of personal data, as well as a list of authorised access holders.
5.1 CONTRIMA is obliged to maintain a record of all categories of processing activities carried out on your behalf in accordance with Article 30(2) of the GDPR. This record must be made available to you upon request.
5.2 Should the data processed on your behalf at CONTRIMA be at risk due to attachment or seizure, insolvency or composition proceedings, or other events or measures taken by third parties, CONTRIMA must inform you of this without delay, provided this is not prohibited by a court or official order. In this context, CONTRIMA shall immediately inform all relevant authorities that decision-making authority over the data lies exclusively with the client as the ‘controller’ within the meaning of the GDPR.
6.1 The contractually agreed services shall be performed with the involvement of the subcontractors listed in Annex 2. CONTRIMA is authorised, within the scope of its contractual obligations, to enter into subcontracting relationships with subcontractors (‘subcontracting relationship’). Before entering into any further subcontracting relationships, CONTRIMA shall inform you in writing or by electronic means in accordance with Article 28(2) of the GDPR, giving four weeks’ notice. You may object to the change within two weeks of receiving the aforementioned notification.
6.2 A subcontracting relationship within the meaning of these provisions does not exist if CONTRIMA commissions third parties to provide services that are to be regarded as purely ancillary services. These include, for example, postal or telecommunications services with no specific connection to the services CONTRIMA provides for you, as well as other measures to ensure the confidentiality, availability, integrity and resilience of the hardware and software of data processing systems.
7.1 You are entitled to verify, on a regular basis, compliance with the provisions of this contract, in particular the implementation of and compliance with the technical and organisational measures set out in clause 3.3 of this agreement. To this end, you may, for example, request information, ask to be provided with certifications or internal audit reports, or have CONTRIMA’s technical and organisational measures inspected yourself during normal business hours or by a competent third party, provided that such third party is not in competition with CONTRIMA.
7.2 You shall carry out inspections only to the extent necessary and shall take due account of CONTRIMA’s operational processes. The parties shall agree in good time on the timing and nature of the inspection.
7.3 You shall document the results of the audit and notify CONTRIMA thereof. In the event of errors or irregularities which you identify, in particular when auditing the results of orders, you shall inform CONTRIMA without delay.
8.1 CONTRIMA shall, where possible, support you with appropriate technical and organisational measures in fulfilling your obligations under Articles 12 to 22 and Articles 32 to 36 of the GDPR. CONTRIMA shall provide you with the requested information regarding processing data without delay, but no later than within 7 working days, unless you already have the relevant information yourself.
8.2 If a data subject exercises their rights under Articles 16 to 18 of the GDPR, CONTRIMA is obliged, on your instructions, to rectify, erase or restrict the processing of the data without undue delay, and at the latest within 7 working days. CONTRIMA will provide you with written confirmation of the erasure, rectification or restriction of the data upon request.
8.3 If a data subject exercises rights – such as the right to access, rectification or erasure of their data – directly against CONTRIMA, CONTRIMA shall forward this request to you without delay and await your instructions. CONTRIMA shall not contact the data subject without specific instructions to do so.
9.1 The term of this contract corresponds to the term of the main contract. In case of doubt, termination of the main contract shall also be deemed to be termination of this contract, and termination of this contract shall be deemed to be termination of the main contract.
9.2 You are entitled at any time to terminate this contract extraordinarily for good cause. Good cause shall be deemed to exist if CONTRIMA fails to fulfil its obligations under this contract, breaches provisions of the GDPR intentionally or through gross negligence, or is unable or unwilling to carry out an instruction. In the case of minor breaches – i.e. those that are neither intentional nor due to gross negligence – you shall first set CONTRIMA a reasonable period within which CONTRIMA may remedy the breach. Once this period has expired without result, you shall then be entitled to terminate this contract without notice.
10.1 Upon termination of the main contract or at any time upon request, CONTRIMA shall return to you all data provided to CONTRIMA or, upon request, delete it completely and irrevocably, provided that no statutory retention period applies. This also applies to copies of the order data held by CONTRIMA, such as data backups, but not to documentation serving as evidence of the proper and compliant processing of the order data. Such documentation must be retained by CONTRIMA for the duration of the statutory retention periods.
10.2 You have the right to verify, in an appropriate manner, that the data has been returned or deleted by CONTRIMA in full and in accordance with the contract.
10.3 CONTRIMA is obliged to treat as confidential any data that has come to its knowledge in connection with the main contract, even after the main contract has ended.
11.1 The liability of the parties is governed by Article 82 of the GDPR. This does not affect CONTRIMA’s liability towards you for any breach of obligations arising from this contract or the main contract.
11.2 Each party shall be exempt from liability if it proves that it is in no way responsible for the circumstance that caused the damage to a data subject. Section 11(2), first sentence, shall apply mutatis mutandis in the event of a fine being imposed on a party, whereby the indemnification shall apply to the extent that the other party bears a share of the responsibility for the infringement sanctioned by the fine.
12.1 Any amendments or additions to this agreement must be made in writing in accordance with Article 28(9) of the GDPR. This also applies to any waiver of this formal requirement.
12.2 In the event of any doubt, the provisions of this Agreement shall take precedence over those of the main contract. Should any individual provisions of this Agreement prove to be wholly or partially invalid or unenforceable, or should they become invalid or unenforceable as a result of legislative changes following the conclusion of the Agreement, this shall not affect the validity of the remaining provisions. The invalid or unenforceable provision shall be replaced by a valid and enforceable provision that comes as close as possible to the meaning and purpose of the invalid provision.
12.3 This contract is governed by the law of the Federal Republic of Germany. CONTRIMA provides these terms and conditions in a variety of language versions for the sake of clarity. In the event of any discrepancies, the English version of this Data Processing Agreement shall prevail.
CONTRIMA is obliged to implement appropriate technical and organisational measures to ensure that the processing of the commissioned data is carried out in accordance with the statutory requirements and that the rights of the data subject are adequately safeguarded.
CONTRIMA shall structure its internal organisation in such a way as to meet the specific requirements of data protection. In particular, measures must be taken that are appropriate to the nature of the data or categories of data to be protected.
Specifically, the following measures are set out to implement the requirements of Article 32 of the GDPR:
| No. | Measure | Implementation of the measure |
|---|---|---|
| 1 | Access control | Productive data processing takes place exclusively in the AWS cloud; the physical data processing facilities there are secured by AWS (see AWS Terms of Service and certifications). Administration is carried out from an access-controlled workstation in lockable, non-publicly accessible rooms behind a firewall. There is no public access and no dedicated server rooms. |
| 2 | Access Control | System access is granted only via personal login with a username and password. Administrative and AWS accesses are protected by strong passwords and two-factor authentication. End devices are secured by operating system login, a firewall and disk encryption. |
| 3 | Access control | Role- and authorisation-based concept within the application, featuring centralised authorisation checks, server-side validation on all endpoints that modify data, protection against CSRF, and exclusively parameterised database access. At the infrastructure level, a minimum number of administrators (single-person operation) and the granting of rights in accordance with the principle of least privilege. |
| 4 | Segregation of duties | Multi-tenant logical separation of all data for each photographer via a unique owner assignment; separate production environment. Logical separation is sufficient. |
| 5 | Pseudonymisation / Data minimisation | Access for external parties via random, non-guessable tokens (permanent link). Only the data necessary for the respective purpose is collected (essentially the email address); identifying notes are deliberately kept brief and neutral. |
| 6 | Control of data disclosure | Transmission takes place exclusively via encrypted connections (TLS/HTTPS). Image and contract data are stored on encrypted object storage (S3 Server-Side Encryption). Data is transferred to subcontractors only to the extent necessary, on the basis of the Data Processing Agreement (DPA) or EU Standard Contractual Clauses. |
| 7 | Input control | Logging of audit-relevant operations at application level, in particular the acceptance of agreements and consents, including timestamps, IP addresses, device information and version hashes, as well as payment events. As the service is operated by a single person, every entry, modification and deletion can be traced back to a single individual. |
| 8 | Availability and Resilience | Database redundancy across multiple AWS zones or regions within the EU or the EEA; automated database snapshots as backups; code and server backups, as well as a pre-configured server image (AMI) for rapid recovery; additional local backup system; documented emergency and recovery plan. |
| 9 | Data Protection Management | The Managing Director of CONTRIMA GmbH is responsible. No data protection officer has been appointed, as there is no legal obligation to do so. Compliance with the information obligations under Article 13 of the GDPR during the activation process; an existing process for handling data subjects’ enquiries; and a register of processing activities maintained in accordance with Article 30 of the GDPR. |
| 10 | Incident Response Management | Firewall updated regularly; documented process for detecting and reporting data breaches in accordance with Articles 33 and 34 of the GDPR, including the immediate notification of the client. |
| 11 | Privacy-friendly default settings | Privacy by default: no data collected beyond what is necessary; image previews only with watermarks; original files provided only after authorisation has been granted; and the right to withdraw consent can be exercised easily via the user interface. |
| 12 | Contract management (sub-processors) | Careful selection; conclusion of data processing agreements or EU Standard Contractual Clauses (Module 3) with all sub-processors, with appropriate safeguards where third countries are involved; notification of the client prior to engaging or replacing sub-processors; ensuring data erasure upon termination of the contract. Currently used: Stripe (payment processing), Amazon Web Services (hosting/storage), DeepL (translation of advert copy). |
Sub-processors included under clause 6.1 of the agreement, to the use of whom you consent:
| Subcontractor (name, address or registered office) |
Scope of services within the framework of data processing |
|---|---|
| Stripe Payments Europe, Ltd. 1 Grand Canal Street Lower, Grand Canal Dock , Dublin, D02 H210, Ireland (“Stripe”) |
Payment processing; in the event of a sale, the purchaser’s payment, identity and transaction data (see also clause 6 of Privacy Policy) |
| Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg (“AWS”) |
Web and database hosting ; storage and processing of image data (originals, variants, archive, exports), including EXIF metadata. Email services (see also section 6 of Privacy Policy) |
| DeepL SE , Maarweg 165 , 50825 Cologne (“DeepL”) |
Where applicable, translation of the recognition note and, where applicable, the collection name into the language of the permanent link (see also 6. from Privacy Policy) |