버전 2 · 2026. 7. 26.
다음과 같은 당사자 간
위탁 처리자
Contrima GmbH(대표이사 Mark Reinhardt, Enzianweg 29, 71384 Weinstadt
, 이하 “CONTRIMA”)
및
개인정보 처리자
{photographer_name}
{photographer_address}
{photographer_email}
(이하 “귀하”)
CONTRIMA는 귀하에게 사진에 등장하는 인물들에게 사진을 전송하기 위한 인프라를 제공하고, 이미지 라이선스 계약 관리를 위한 서비스를 제공합니다(이하 “주계약”). 본 계약의 이행 과정의 일환으로, 귀하가 CONTRIMA에 전송하는 사진 속 인물의 개인정보가 처리됩니다. 이러한 상황에 대한 GDPR의 요건을 충족하기 위해, 귀하는 개인정보 보호법상 책임자로서 CONTRIMA와 다음과 같은 위탁 처리 계약을 체결합니다.
1.1 본 계약에 따른 당사자 간의 협력으로 인해, CONTRIMA는 귀하가 제공한 개인정보 (이하 “위탁 데이터”)에 접근하게 되며, CONTRIMA는 GDPR 제4조 제8호 및 제28조에 따라 전적으로 귀하의 위탁에 따라 귀하의 지시에만 따라 이를 처리합니다.
1.2 처리 대상에는 다음의 위탁 데이터가 포함될 수 있습니다:
| 관련 개인(범주) | 데이터 유형 |
|---|---|
| 사진에 찍힌 인물 |
|
| 사진에 등장하는 인물의 법정 대리인 |
|
| 관할 기관(예: 세무 당국)의 담당자 |
|
1.3 주문 데이터의 처리 방식 및 범위는 주계약의 목적에 따라 결정되며, 이에 국한됩니다. 처리 기간은 주계약의 유효 기간과 동일합니다.
1.4 CONTRIMA는 부속서 1 및 제1.2항에 명시된 내용과 상이하거나 이를 초과하는 방식으로 주문 데이터를 처리하는 것이 금지됩니다. 이는 익명화된 데이터의 사용에도 적용됩니다.
1.5 수탁 데이터의 처리는 오로지 독일 연방공화국 영토 내, 유럽연합(EU) 회원국 또는 유럽경제지역(EEA) 협정의 다른 당사국에서만 이루어집니다. 제3국으로의 이전은 의뢰인의 사전 서면 동의를 받아야 하며, GDPR 제44조부터 제49조까지의 특별 요건을 충족하는 경우에만 이루어질 수 있습니다.
1.6 본 계약의 규정은 주계약과 관련이 있으며, CONTRIMA 및 그 직원 또는 CONTRIMA가 위임한 자가 귀하로부터 제공되었거나 귀하를 위해 수집된 개인정보를 취급하는 모든 활동에 적용됩니다.
2.1 CONTRIMA는 위탁의 범위 내에서, 그리고 전적으로 귀하의 의뢰에 따라 및 GDPR 제28조(위탁 처리)의 의미에 따른 귀하의 지시에 의해서만 위탁 데이터를 처리하며, 이는 특히 제3국으로의 개인정보 전송과 관련하여 적용됩니다. 귀하께서는 처리 활동의 유형, 범위 및 방법에 대한 지시를 내릴 독점적인 권한(이하 “지시권”)을 가집니다. CONTRIMA가 적용받는 유럽연합 또는 회원국의 법률에 따라 추가 처리가 의무화되는 경우, CONTRIMA는 처리 전에 귀하에게 해당 법적 요건을 통지합니다.
2.2 CONTRIMA에 대한 지시는 원칙적으로 귀하가 서면으로 제공해야 합니다(이메일 주소: info@contrima.com).
2.3 CONTRIMA가 귀하의 지시 중 일부가 개인정보 보호법규를 위반한다고 판단하는 경우, CONTRIMA는 귀하에게 이를 지체 없이 통지해야 합니다. CONTRIMA는 해당 지시가 의뢰인에 의해 확인되거나 수정될 때까지 해당 지시의 이행을 보류할 권한이 있습니다.
3.1 CONTRIMA는 개인정보 보호에 관한 법적 규정을 준수할 의무가 있으며, 귀하로부터 입수한 정보를 제3자에게 제공하지 않거나 제3자의 접근을 차단해야 합니다. 데이터는 최신 기술 수준을 고려하여 권한이 없는 자의 열람으로부터 보호되어야 합니다.
3.2 또한 CONTRIMA는 본 계약의 처리 및 이행을 위해 CONTRIMA가 위임한 모든 자(이하 “직원”이라 함)에게 서면으로 기밀 유지 의무를 부과할 것이며 (기밀 유지 의무, GDPR 제28조 제3항 b호) 이 의무를 준수하도록 필요한 주의를 기울여야 합니다. CONTRIMA는 귀하의 요청 시 이를 입증할 것입니다.
3.3 CONTRIMA는 데이터 보호의 특별한 요구 사항을 충족할 수 있도록 사내 조직 체계를 구축할 것입니다. CONTRIMA는 GDPR 제32조에 따라 위탁 데이터를 적절히 보호하기 위한 모든 적절한 기술적 및 조직적 조치, 특히 본 계약의 부속서 1에 명시된 조치를 취하고, 위탁 데이터 처리 기간 동안 이를 유지할 것을 약속합니다.
3.4 CONTRIMA는 취해진 기술적 및 조직적 조치를 변경할 권리를 보유하며, 이 경우 계약상 합의된 보호 수준이 저하되지 않도록 보장합니다. CONTRIMA는 부속서 1에 따른 조치가 더 이상 충분하지 않다고 판단할 만한 사유가 있는 경우, 지체 없이 귀하에게 서면으로 통지해야 하며, 추가적인 기술적 및 조직적 조치에 대해 귀하와 협의할 것입니다.
3.5 귀하의 요청이 있을 경우, CONTRIMA는 부속서 1에 명시된 기술적 및 조직적 조치의 준수를 적절한 증빙 자료를 통해 입증해야 합니다.
4.1 장애 발생, 개인정보 침해 의심 또는 CONTRIMA의 계약상 의무 위반, 보안 관련 사고의 의심 또는 위탁 데이터 처리 과정에서 발생하는 기타 부정행위, CONTRIMA가 위탁 계약의 범위 내에서 고용된 자나 제3자를 통해 처리하는 과정에서 발생하는 경우, CONTRIMA는 귀하에게 지체 없이, 늦어도 24시간 이내에 서면 또는 전자적 형태로 통지합니다. 이는 개인정보 보호 감독 당국이 CONTRIMA를 대상으로 실시하는 조사에 대해서도 동일하게 적용됩니다. 제4조 제1항 제1문에 따른 통지에는 각각 적어도 GDPR 제33조 제3항에 명시된 내용이 포함되어야 합니다.
4.2 CONTRIMA는 제4.1항에 해당하는 상황이 발생할 경우, 합리적으로 기대할 수 있는 범위 내에서 관련 설명, 시정 및 정보 제공 조치를 이행하는 데 있어 귀하를 지원할 것입니다. 특히 CONTRIMA는 데이터 보안을 확보하고 당사자에게 발생할 수 있는 불리한 결과를 최소화하기 위해 필요한 조치를 지체 없이 이행하고 귀하에게 이를 통지할 것입니다.
4.3 CONTRIMA는 귀하의 구두 또는 서면 요청에 따라, 본 계약 제7.1조에 따른 점검 수행에 필요한 모든 정보 및 증빙 자료를 적정한 기한 내에 귀하에게 제공할 것을 약속합니다. 또한 CONTRIMA는 귀하의 요청에 따라 위탁 처리에 관한 포괄적이고 최신의 개인정보 보호 및 보안 방침과 접근 권한이 있는 인원에 대한 정보를 귀하에게 제공할 것입니다.
5.1 CONTRIMA는 GDPR 제30조 제2항에 따라 귀하의 의뢰에 따라 수행되는 모든 처리 활동 범주에 대한 목록을 작성할 의무가 있습니다. 해당 목록은 귀하의 요청 시 제공되어야 합니다.
5.2 CONTRIMA에 보관된 위탁 데이터가 압류 또는 몰수, 파산 또는 화해 절차, 또는 제3자의 기타 사건이나 조치로 인해 위험에 처하게 되는 경우, 법원이나 관할 당국의 명령에 의해 금지되지 않는 한 CONTRIMA는 귀하에게 이를 지체 없이 통지해야 합니다. 이와 관련하여 CONTRIMA는 데이터에 대한 결정 권한이 전적으로 GDPR상 “책임자”인 의뢰인에게 있음을 모든 관련 기관에 지체 없이 통지할 것입니다.
6.1 계약상 합의된 서비스는 부속서 2에 명시된 하도급업체를 통해 수행됩니다. CONTRIMA는 계약상 의무의 범위 내에서 하도급업체와 하도급 관계를 체결할 권한이 있습니다. 추가적인 하도급 관계를 체결하기 전에, CONTRIMA는 GDPR 제28조 제2항에 따라 4주 전까지 서면 또는 전자 문서로 귀하에게 통지합니다. 귀하는 상기 통지를 수령한 날로부터 2주 이내에 해당 변경에 대해 이의를 제기할 수 있습니다.
6.2 CONTRIMA가 순수한 부수적 서비스로 간주되는 서비스를 제3자에게 위탁하는 경우에는 본 규정에 따른 하도급 관계가 성립되지 않습니다. 여기에는 예를 들어, CONTRIMA가 귀하를 위해 제공하는 서비스와 구체적인 관련성이 없는 우편 또는 통신 서비스, 그리고 데이터 처리 설비의 하드웨어 및 소프트웨어에 대한 기밀성, 가용성, 무결성 및 내구성을 보장하기 위한 기타 조치 등이 포함됩니다.
7.1 귀하는 본 계약의 규정, 특히 본 계약 제3.3조에 따른 기술적 및 조직적 조치의 이행 및 준수를 정기적으로 확인할 권리가 있습니다. 이를 위해 귀하는 예를 들어 관련 정보를 요청하거나, 인증서 또는 내부 감사 결과를 제출받거나, 통상적인 업무 시간 내에 CONTRIMA의 기술적 및 조직적 조치를 직접 또는 CONTRIMA와 경쟁 관계에 있지 않은 전문 지식을 갖춘 제3자를 통해 점검할 수 있습니다.
7.2 귀사는 필요한 범위 내에서만 점검을 수행하며, CONTRIMA의 업무 운영에 적절한 배려를 해야 합니다. 점검 시기 및 방식에 대해서는 당사자들이 적시에 합의합니다.
7.3 귀하는 점검 결과를 문서화하여 CONTRIMA에 통보해야 합니다. 특히 의뢰 결과 점검 시 오류나 부정규 사항을 발견한 경우, 귀하는 지체 없이 CONTRIMA에 이를 알려야 합니다.
8.1 CONTRIMA는 가능한 한 적절한 기술적 및 조직적 조치를 통해 귀하가 GDPR 제12조부터 제22조 및 제32조부터 제36조에 따른 의무를 이행할 수 있도록 지원합니다. 귀하가 해당 정보를 직접 보유하고 있지 않은 경우, CONTRIMA는 귀하가 요청한 위탁 데이터에 대한 정보를 지체 없이, 늦어도 7영업일 이내에 제공할 것입니다.
8.2 데이터 주체가 GDPR 제16조부터 제18조에 따른 권리를 행사하는 경우, CONTRIMA는 귀하의 지시에 따라 지체 없이, 늦어도 7영업일 이내에 위탁 데이터를 정정, 삭제 또는 처리 제한할 의무가 있습니다. CONTRIMA는 귀하의 요청에 따라 데이터의 삭제, 정정 또는 처리 제한 사실을 서면으로 증명해 드립니다.
8.3 정보 주체가 자신의 데이터와 관련하여 정보 제공, 정정 또는 삭제 등의 권리를 CONTRIMA에 직접 행사하는 경우, CONTRIMA는 해당 요청을 지체 없이 귀하에게 전달하고 귀하의 지시를 기다립니다. 별도의 구체적인 지시가 없는 한, CONTRIMA는 해당 정보 주체와 직접 연락하지 않습니다.
9.1 본 계약의 기간은 주계약의 기간과 동일합니다. 의문이 있는 경우, 주계약의 해지는 본 계약의 해지로 간주되며, 본 계약의 해지는 주계약의 해지로 간주됩니다.
9.2 귀하는 중대한 사유가 있는 경우 언제든지 본 계약을 특별 해지할 권리가 있습니다. 중대한 사유란 CONTRIMA가 본 계약에 따른 의무를 이행하지 않거나, GDPR 규정을 고의 또는 중대한 과실로 위반하거나, 지시를 이행할 수 없거나 이행할 의사가 없는 경우를 말합니다. 단순한 위반(즉, 고의나 중대한 과실이 아닌 경우)의 경우, 귀하는 우선 CONTRIMA가 위반 사항을 시정할 수 있는 합리적인 기한을 부여해야 합니다. 해당 기한이 무위로 경과한 후, 귀하에게는 특별 해지권이 발생합니다.
10.1 CONTRIMA는 본 계약 종료 후 또는 귀하의 요청이 있을 경우 언제든지 CONTRIMA에 제공된 모든 데이터를 귀하에게 반환하거나, 법적 보존 기간이 없는 한 귀하의 요청에 따라 해당 데이터를 완전하고 철회할 수 없게 삭제합니다. 이는 데이터 백업과 같이 CONTRIMA에 보관된 주문 데이터의 복제본에도 적용되나, 주문 데이터가 적법하고 규정에 따라 처리되었음을 입증하는 데 사용되는 문서에는 적용되지 않습니다. 이러한 문서는 CONTRIMA가 법정 보존 기간 동안 보관해야 합니다.
10.2 귀하는 CONTRIMA가 데이터를 완전하고 계약에 따라 반환하거나 삭제하는 과정을 적절한 방식으로 확인할 권리가 있습니다.
10.3 CONTRIMA는 주계약 종료 후에도 주계약과 관련하여 알게 된 데이터를 기밀로 취급할 의무가 있습니다.
11.1 당사자들의 책임은 GDPR 제82조에 따릅니다. 본 계약 또는 주계약상 의무 위반으로 인해 CONTRIMA가 귀하에게 부담하는 책임은 이에 영향을 받지 않습니다.
11.2 당사자 중 한 쪽이 데이터 주체의 손해 발생 사정에 대해 어떠한 면에서도 책임이 없음을 입증하는 경우, 양 당사자는 서로에 대한 책임을 면제받습니다. § 11 제2항 제1문은 당사자 중 한 쪽에 과태료가 부과된 경우에도 준용되며, 이 경우 면책은 과태료로 제재된 위반 행위에 대해 상대방 당사자가 책임의 일부를 지는 범위 내에서 이루어집니다.
12.1 본 계약의 변경 및 추가 조항은 GDPR 제28조 제9항에 따른 서면 형식을 준수해야 한다. 이는 해당 형식 요건에 대한 포기에도 적용된다.
12.2 의문이 있는 경우, 본 계약의 규정이 주계약의 규정보다 우선한다. 본 계약의 개별 조항이 전부 또는 일부 무효이거나 이행 불가능한 것으로 판명되거나, 계약 체결 후 법률 개정으로 인해 무효 또는 이행 불가능하게 되는 경우, 이로 인해 나머지 조항의 유효성에는 영향을 미치지 않습니다. 무효이거나 이행 불가능한 조항의 자리에는, 해당 무효 조항의 취지와 목적에 최대한 근접하는 유효하고 이행 가능한 조항이 대신 적용됩니다.
12.3 본 계약은 독일 연방공화국의 법률에 따릅니다. CONTRIMA는 이해의 편의를 위해 본 약관을 다양한 언어로 제공합니다. 내용에 차이가 있을 경우, 본 위탁 데이터 처리 계약의 영어 버전이 우선합니다.
CONTRIMA는 위탁 데이터의 처리가 법적 요건에 부합하고, 관련 당사자의 권리 보호가 적절한 형태로 보장되도록 적절한 기술적 및 조직적 조치를 이행할 의무가 있습니다.
CONTRIMA는 개인정보 보호의 특별한 요건을 충족할 수 있도록 내부 조직 체계를 구축할 것입니다. 이때 특히 보호 대상 데이터의 종류나 데이터 범주에 따라 적합한 조치를 취해야 합니다.
구체적으로, GDPR 제32조의 요건을 이행하기 위해 다음과 같은 조치가 정해집니다:
| 번호 | 조치 | 조치 이행 |
|---|---|---|
| 1 | 접근 통제 | 실제 데이터 처리는 전적으로 AWS 클라우드에서 이루어지며, 물리적 데이터 처리 장비는 AWS에 의해 해당 클라우드 내에서 보안이 유지됩니다(AVV 및 AWS 인증 참조). 관리는 방화벽 뒤에 위치한, 잠글 수 있고 일반인이 접근할 수 없는 공간 내의 접근 권한이 제한된 작업 공간에서 이루어집니다. 일반인의 출입이 허용되지 않으며 별도의 서버실도 없습니다. |
| 2 | 접근 제어 | 시스템 접근은 사용자 이름과 비밀번호를 통한 개인 로그인을 통해서만 가능합니다. 관리자 및 AWS 접근 권한은 강력한 비밀번호와 2단계 인증으로 보호됩니다. 단말기는 운영 체제 로그인, 방화벽 및 하드 디스크 암호화를 통해 보호됩니다. |
| 3 | 접근 제어 | 애플리케이션 내 역할 및 권한 체계 적용: 중앙 집중식 권한 검증, 데이터를 변경하는 모든 엔드포인트에 대한 서버 측 검증, CSRF 방지, 그리고 매개변수화된 데이터베이스 접근만 허용. 인프라 수준에서는 관리자 수를 최소화(1인 운영)하고, 최소 권한 원칙에 따라 권한을 부여합니다. |
| 4 | 분리 제어 | 고유한 소유자 할당을 통해 사진작가별로 모든 데이터를 다중 테넌트 방식으로 논리적으로 분리하며, 별도의 운영 환경을 운영합니다. 논리적 분리만으로도 충분합니다. |
| 5 | 가명화 / 데이터 최소화 | 무작위적이고 추측 불가능한 토큰(영구 링크)을 통해 외부 사용자의 접근을 허용합니다. 해당 목적에 필요한 데이터(기본적으로 이메일 주소)만 수집하며, 식별 가능한 메모는 의도적으로 간결하고 중립적으로 작성됩니다. |
| 6 | 전달 통제 | 전송은 오로지 암호화된 연결(TLS/HTTPS)을 통해서만 이루어집니다. 이미지 및 계약 데이터는 암호화된 객체 저장소(S3 서버 측 암호화)에 저장됩니다. 하도급업체로의 전송은 AVV 또는 EU 표준 계약 조항에 근거하여 필요한 범위 내에서만 이루어집니다. |
| 7 | 입력 통제 | 애플리케이션 수준에서 증거로 활용 가능한 작업에 대한 기록, 특히 타임스탬프, IP 주소, 기기 정보 및 버전 해시가 포함된 약정 및 동의 수락 내역과 결제 이벤트. 1인 운영 체제이므로 모든 입력, 변경 및 삭제는 단일 담당자에게 귀속됩니다. |
| 8 | 가용성 및 내구성 | EU 및 EEA 내 여러 AWS 존 또는 리전에 걸쳐 데이터베이스를 중복 구성; 백업용 자동화된 데이터베이스 스냅샷; 신속한 복구를 위한 코드 및 서버 백업과 사전 준비된 서버 이미지(AMI); 추가적인 로컬 백업 시스템; 문서화된 비상 및 복구 계획. |
| 9 | 개인정보 보호 관리 | 책임자는 CONTRIMA GmbH의 대표이사입니다. 법적 지정 의무가 없으므로 개인정보 보호 책임자는 지정되지 않았습니다. GDPR 제13조에 따른 정보 제공 의무를 활성화 절차에서 이행하며, 데이터 주체의 요청 처리를 위한 기존 프로세스 및 GDPR 제30조에 따른 처리 활동 목록을 관리하고 있습니다. |
| 10 | 사고 대응 관리 | 정기적으로 업데이트되는 방화벽; GDPR 제33조 및 제34조에 따른 개인정보 침해 탐지 및 보고 절차가 문서화되어 있으며, 여기에는 의뢰인에 대한 즉각적인 통지가 포함됩니다. |
| 11 | 개인정보 보호 친화적 기본 설정 | 기본 개인정보 보호(Privacy by default): 필요한 범위를 초과하여 정보를 수집하지 않으며, 이미지 미리보기는 워터마크가 적용된 형태로만 제공되고, 원본은 권한이 부여된 후에만 제공되며, 사용자 인터페이스를 통해 철회권을 간편하게 행사할 수 있습니다. |
| 12 | 위탁 관리 (하도급 처리자) | 신중한 선정; 모든 하도급 처리자와 데이터 처리 계약(AVV) 또는 EU 표준 계약 조항(모듈 3) 체결, 제3국 관련 시 적절한 보증 조치 적용; 하도급 처리자 추가 또는 교체 전 의뢰인에게 사전 통보; 계약 종료 후 데이터 삭제 보장. 현재 사용 중인 업체: Stripe(결제 처리), Amazon Web Services(호스팅/저장), DeepL(광고 문구 번역). |
본 협약 제6.1조에 따라 포함된 하도급업체로서, 귀하가 그 이용에 동의하는 업체:
| 하도급업체 (명칭, 주소 또는 본사 소재지) |
위탁 처리 범위 내의 서비스 내용 |
|---|---|
| Stripe Payments Europe, Ltd. 1 Grand Canal Street Lower, Grand Canal Dock Dublin, D02 H210, 아일랜드 (“Stripe”) |
결제 처리; 판매 시 구매자의 결제, 신원 및 거래 데이터. (이에 대해서는 개인정보 처리방침의 6항도 참조) |
| Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 룩셈부르크 (“AWS”) |
웹 및 데이터베이스 호스팅, 이미지 데이터(원본, 변형본, 아카이브, 내보내기) 및 EXIF 메타데이터의 저장 및 처리. 이메일 서비스 (이에 대해서는 개인정보 처리방침의 6항도 참조) |
| DeepL SE , Maarweg 165 , 50825 쾰른 (“DeepL”) |
필요한 경우 인식 메모 및 컬렉션 이름을 영구 링크의 언어로 번역함. (이에 대해서는 개인정보 처리방침의 6항 참조) |
버전 2 · 2026. 7. 26.
Between
the data processor
Contrima GmbH, represented by its managing director Mr Mark Reinhardt, Enzianweg 29, 71384 Weinstadt
(hereinafter ‘CONTRIMA’)
and
the Data Controller
{photographer_name}
{photographer_address}
{photographer_email}
(hereinafter “you”)
CONTRIMA provides services to you for the provision of an infrastructure for the transmission of photographs to the persons depicted therein, as well as for the management of image licence agreements (hereinafter: “Main Contract”). Part of the performance of the Main Contract involves the processing of personal data relating to the persons depicted, which you transmit to CONTRIMA. In order to comply with the requirements of the GDPR in such circumstances, you, as the data controller within the meaning of data protection law, enter into the following data processing agreement with CONTRIMA.
1.1 The cooperation between the parties in accordance with the Main Contract entails that CONTRIMA will have access to personal data provided by you (hereinafter ‘Processed Data’) and that it processes this data exclusively on your behalf and in accordance with your instructions within the meaning of Article 4(8) and Article 28 of the GDPR.
1.2 The following data subject categories may be affected by the processing:
| Data subjects (categories) | Type of data |
|---|---|
| Persons depicted |
|
| Legal guardians of the persons depicted |
|
| Contact persons at public authorities (e.g. tax authorities) |
|
1.3 The nature and scope of the processing of order data are determined by the purposes of the main contract and are limited to these. The duration of the processing corresponds to the term of the main contract.
1.4 CONTRIMA is prohibited from processing contract data in any manner that deviates from or goes beyond the provisions set out in Annex 1 and clause 1.2. This also applies to the use of anonymised data.
1.5 The processing of order data shall take place exclusively within the territory of the Federal Republic of Germany, in a Member State of the European Union or in another State party to the Agreement on the European Economic Area. Any transfer to a third country requires the prior written consent of the client and may only take place if the specific conditions set out in Articles 44 to 49 of the GDPR are met.
1.6 The provisions of this contract apply to all activities related to the main contract in which CONTRIMA and its employees or persons commissioned by CONTRIMA come into contact with personal data originating from you or collected on your behalf.
2.1 CONTRIMA shall process the contract data only within the scope of the contract and exclusively on your behalf and in accordance with your instructions within the meaning of Article 28 of the GDPR (processing on behalf of a controller); this applies in particular to the transfer of personal data to a third country. You have the sole right to issue instructions regarding the nature, scope and method of the processing activities (hereinafter also referred to as the ‘right to issue instructions’). If CONTRIMA is obliged to carry out further processing under the law of the European Union or the Member States to which it is subject, CONTRIMA shall inform you of these legal requirements prior to processing.
2.2 Instructions to CONTRIMA must, as a general rule, be given by you in writing (email address: info@contrima.com).
2.3 If CONTRIMA considers that one of your instructions contravenes data protection regulations, CONTRIMA must inform you of this without delay. CONTRIMA is entitled to suspend the implementation of the instruction in question until it is confirmed or amended by the client.
3.1 CONTRIMA is obliged to comply with the statutory provisions on data protection and not to disclose the information obtained from you to third parties or to prevent them from accessing it. Data must be secured against unauthorised access, taking into account the state of the art.
3.2 Furthermore, CONTRIMA shall require all persons entrusted by CONTRIMA with the processing and performance of this contract (hereinafter referred to as ‘employees’) to undertake in writing to maintain confidentiality (Obligation of confidentiality, Article 28(3)(b) of the GDPR) and shall ensure compliance with this obligation with due care. CONTRIMA shall provide you with evidence of this upon request.
3.3 CONTRIMA shall organise its internal operations in such a way as to meet the specific requirements of data protection. CONTRIMA undertakes to implement all appropriate technical and organisational measures to ensure the adequate protection of the commissioned data in accordance with Article 32 of the GDPR, in particular the measures set out in Annex 1 to this contract, and to maintain these for the duration of the processing of the commissioned data.
3.4 CONTRIMA reserves the right to amend the technical and organisational measures put in place, whilst ensuring that the level of protection agreed in the contract is not compromised. CONTRIMA must inform you in writing without delay if there is reason to believe that the measures set out in Annex 1 are no longer sufficient, and will consult with you regarding further technical and organisational measures.
3.5 At your request, CONTRIMA shall demonstrate compliance with the technical and organisational measures set out in Annex 1 by providing appropriate evidence.
4.1 In the event of disruptions, suspected data breaches or breaches of CONTRIMA’s contractual obligations, suspected security incidents or other irregularities in the processing of the contract data, whether by persons employed by CONTRIMA in the context of the contract or by third parties, CONTRIMA shall inform you without delay, but at the latest within 24 hours, in writing or by electronic means. The same applies to inspections of CONTRIMA by the data protection supervisory authority. Notifications pursuant to Section 4(1), first sentence, shall in each case contain at least the information specified in Article 33(3) of the GDPR.
4.2 In the event referred to in Section 4.1, CONTRIMA shall assist you, to the extent reasonably practicable, in fulfilling its relevant obligations to provide information, take remedial action and keep you informed. In particular, CONTRIMA shall immediately implement the necessary measures to secure the data and to mitigate any potential adverse consequences for the data subjects, and shall inform you accordingly.
4.3 CONTRIMA undertakes to provide you, upon your verbal or written request and within a reasonable period, with all information and evidence necessary to carry out an audit in accordance with § 7.1 of this contract. Furthermore, at your request, CONTRIMA will provide you with a comprehensive and up-to-date data protection and security policy for the processing of personal data, as well as a list of authorised access holders.
5.1 CONTRIMA is obliged to maintain a record of all categories of processing activities carried out on your behalf in accordance with Article 30(2) of the GDPR. This record must be made available to you upon request.
5.2 Should the data processed on your behalf at CONTRIMA be at risk due to attachment or seizure, insolvency or composition proceedings, or other events or measures taken by third parties, CONTRIMA must inform you of this without delay, provided this is not prohibited by a court or official order. In this context, CONTRIMA shall immediately inform all relevant authorities that decision-making authority over the data lies exclusively with the client as the ‘controller’ within the meaning of the GDPR.
6.1 The contractually agreed services shall be performed with the involvement of the subcontractors listed in Annex 2. CONTRIMA is authorised, within the scope of its contractual obligations, to enter into subcontracting relationships with subcontractors (‘subcontracting relationship’). Before entering into any further subcontracting relationships, CONTRIMA shall inform you in writing or by electronic means in accordance with Article 28(2) of the GDPR, giving four weeks’ notice. You may object to the change within two weeks of receiving the aforementioned notification.
6.2 A subcontracting relationship within the meaning of these provisions does not exist if CONTRIMA commissions third parties to provide services that are to be regarded as purely ancillary services. These include, for example, postal or telecommunications services with no specific connection to the services CONTRIMA provides for you, as well as other measures to ensure the confidentiality, availability, integrity and resilience of the hardware and software of data processing systems.
7.1 You are entitled to verify, on a regular basis, compliance with the provisions of this contract, in particular the implementation of and compliance with the technical and organisational measures set out in clause 3.3 of this agreement. To this end, you may, for example, request information, ask to be provided with certifications or internal audit reports, or have CONTRIMA’s technical and organisational measures inspected yourself during normal business hours or by a competent third party, provided that such third party is not in competition with CONTRIMA.
7.2 You shall carry out inspections only to the extent necessary and shall take due account of CONTRIMA’s operational processes. The parties shall agree in good time on the timing and nature of the inspection.
7.3 You shall document the results of the audit and notify CONTRIMA thereof. In the event of errors or irregularities which you identify, in particular when auditing the results of orders, you shall inform CONTRIMA without delay.
8.1 CONTRIMA shall, where possible, support you with appropriate technical and organisational measures in fulfilling your obligations under Articles 12 to 22 and Articles 32 to 36 of the GDPR. CONTRIMA shall provide you with the requested information regarding processing data without delay, but no later than within 7 working days, unless you already have the relevant information yourself.
8.2 If a data subject exercises their rights under Articles 16 to 18 of the GDPR, CONTRIMA is obliged, on your instructions, to rectify, erase or restrict the processing of the data without undue delay, and at the latest within 7 working days. CONTRIMA will provide you with written confirmation of the erasure, rectification or restriction of the data upon request.
8.3 If a data subject exercises rights – such as the right to access, rectification or erasure of their data – directly against CONTRIMA, CONTRIMA shall forward this request to you without delay and await your instructions. CONTRIMA shall not contact the data subject without specific instructions to do so.
9.1 The term of this contract corresponds to the term of the main contract. In case of doubt, termination of the main contract shall also be deemed to be termination of this contract, and termination of this contract shall be deemed to be termination of the main contract.
9.2 You are entitled at any time to terminate this contract extraordinarily for good cause. Good cause shall be deemed to exist if CONTRIMA fails to fulfil its obligations under this contract, breaches provisions of the GDPR intentionally or through gross negligence, or is unable or unwilling to carry out an instruction. In the case of minor breaches – i.e. those that are neither intentional nor due to gross negligence – you shall first set CONTRIMA a reasonable period within which CONTRIMA may remedy the breach. Once this period has expired without result, you shall then be entitled to terminate this contract without notice.
10.1 Upon termination of the main contract or at any time upon request, CONTRIMA shall return to you all data provided to CONTRIMA or, upon request, delete it completely and irrevocably, provided that no statutory retention period applies. This also applies to copies of the order data held by CONTRIMA, such as data backups, but not to documentation serving as evidence of the proper and compliant processing of the order data. Such documentation must be retained by CONTRIMA for the duration of the statutory retention periods.
10.2 You have the right to verify, in an appropriate manner, that the data has been returned or deleted by CONTRIMA in full and in accordance with the contract.
10.3 CONTRIMA is obliged to treat as confidential any data that has come to its knowledge in connection with the main contract, even after the main contract has ended.
11.1 The liability of the parties is governed by Article 82 of the GDPR. This does not affect CONTRIMA’s liability towards you for any breach of obligations arising from this contract or the main contract.
11.2 Each party shall be exempt from liability if it proves that it is in no way responsible for the circumstance that caused the damage to a data subject. Section 11(2), first sentence, shall apply mutatis mutandis in the event of a fine being imposed on a party, whereby the indemnification shall apply to the extent that the other party bears a share of the responsibility for the infringement sanctioned by the fine.
12.1 Any amendments or additions to this agreement must be made in writing in accordance with Article 28(9) of the GDPR. This also applies to any waiver of this formal requirement.
12.2 In the event of any doubt, the provisions of this Agreement shall take precedence over those of the main contract. Should any individual provisions of this Agreement prove to be wholly or partially invalid or unenforceable, or should they become invalid or unenforceable as a result of legislative changes following the conclusion of the Agreement, this shall not affect the validity of the remaining provisions. The invalid or unenforceable provision shall be replaced by a valid and enforceable provision that comes as close as possible to the meaning and purpose of the invalid provision.
12.3 This contract is governed by the law of the Federal Republic of Germany. CONTRIMA provides these terms and conditions in a variety of language versions for the sake of clarity. In the event of any discrepancies, the English version of this Data Processing Agreement shall prevail.
CONTRIMA is obliged to implement appropriate technical and organisational measures to ensure that the processing of the commissioned data is carried out in accordance with the statutory requirements and that the rights of the data subject are adequately safeguarded.
CONTRIMA shall structure its internal organisation in such a way as to meet the specific requirements of data protection. In particular, measures must be taken that are appropriate to the nature of the data or categories of data to be protected.
Specifically, the following measures are set out to implement the requirements of Article 32 of the GDPR:
| No. | Measure | Implementation of the measure |
|---|---|---|
| 1 | Access control | Productive data processing takes place exclusively in the AWS cloud; the physical data processing facilities there are secured by AWS (see AWS Terms of Service and certifications). Administration is carried out from an access-controlled workstation in lockable, non-publicly accessible rooms behind a firewall. There is no public access and no dedicated server rooms. |
| 2 | Access Control | System access is granted only via personal login with a username and password. Administrative and AWS accesses are protected by strong passwords and two-factor authentication. End devices are secured by operating system login, a firewall and disk encryption. |
| 3 | Access control | Role- and authorisation-based concept within the application, featuring centralised authorisation checks, server-side validation on all endpoints that modify data, protection against CSRF, and exclusively parameterised database access. At the infrastructure level, a minimum number of administrators (single-person operation) and the granting of rights in accordance with the principle of least privilege. |
| 4 | Segregation of duties | Multi-tenant logical separation of all data for each photographer via a unique owner assignment; separate production environment. Logical separation is sufficient. |
| 5 | Pseudonymisation / Data minimisation | Access for external parties via random, non-guessable tokens (permanent link). Only the data necessary for the respective purpose is collected (essentially the email address); identifying notes are deliberately kept brief and neutral. |
| 6 | Control of data disclosure | Transmission takes place exclusively via encrypted connections (TLS/HTTPS). Image and contract data are stored on encrypted object storage (S3 Server-Side Encryption). Data is transferred to subcontractors only to the extent necessary, on the basis of the Data Processing Agreement (DPA) or EU Standard Contractual Clauses. |
| 7 | Input control | Logging of audit-relevant operations at application level, in particular the acceptance of agreements and consents, including timestamps, IP addresses, device information and version hashes, as well as payment events. As the service is operated by a single person, every entry, modification and deletion can be traced back to a single individual. |
| 8 | Availability and Resilience | Database redundancy across multiple AWS zones or regions within the EU or the EEA; automated database snapshots as backups; code and server backups, as well as a pre-configured server image (AMI) for rapid recovery; additional local backup system; documented emergency and recovery plan. |
| 9 | Data Protection Management | The Managing Director of CONTRIMA GmbH is responsible. No data protection officer has been appointed, as there is no legal obligation to do so. Compliance with the information obligations under Article 13 of the GDPR during the activation process; an existing process for handling data subjects’ enquiries; and a register of processing activities maintained in accordance with Article 30 of the GDPR. |
| 10 | Incident Response Management | Firewall updated regularly; documented process for detecting and reporting data breaches in accordance with Articles 33 and 34 of the GDPR, including the immediate notification of the client. |
| 11 | Privacy-friendly default settings | Privacy by default: no data collected beyond what is necessary; image previews only with watermarks; original files provided only after authorisation has been granted; and the right to withdraw consent can be exercised easily via the user interface. |
| 12 | Contract management (sub-processors) | Careful selection; conclusion of data processing agreements or EU Standard Contractual Clauses (Module 3) with all sub-processors, with appropriate safeguards where third countries are involved; notification of the client prior to engaging or replacing sub-processors; ensuring data erasure upon termination of the contract. Currently used: Stripe (payment processing), Amazon Web Services (hosting/storage), DeepL (translation of advert copy). |
Sub-processors included under clause 6.1 of the agreement, to the use of whom you consent:
| Subcontractor (name, address or registered office) |
Scope of services within the framework of data processing |
|---|---|
| Stripe Payments Europe, Ltd. 1 Grand Canal Street Lower, Grand Canal Dock , Dublin, D02 H210, Ireland (“Stripe”) |
Payment processing; in the event of a sale, the purchaser’s payment, identity and transaction data (see also clause 6 of Privacy Policy) |
| Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg (“AWS”) |
Web and database hosting ; storage and processing of image data (originals, variants, archive, exports), including EXIF metadata. Email services (see also section 6 of Privacy Policy) |
| DeepL SE , Maarweg 165 , 50825 Cologne (“DeepL”) |
Where applicable, translation of the recognition note and, where applicable, the collection name into the language of the permanent link (see also 6. from Privacy Policy) |