バージョン 2 · 2026/07/26
以下に
データ処理委託者
Contrima GmbH(代表取締役:マーク・ラインハルト氏、所在地:Enzianweg 29, 71384 Weinstadt
、以下「CONTRIMA」という)
および
データ管理者
{photographer_name}
{photographer_address}
{photographer_email}
(以下「あなた」)
CONTRIMAは、写真に写っている人物への写真送信のためのインフラの提供、および画像ライセンス契約の管理に関するサービス(以下「本契約」という)をあなたに提供します。 本契約の履行の一環として、貴殿がCONTRIMAに提供した被写体の個人データの処理が行われます。このような状況におけるGDPRの要件を満たすため、貴殿は、データ保護法上のデータ管理者として、CONTRIMAと以下の委託データ処理契約を締結します。
1.1 本契約に基づく当事者間の協力に伴い、CONTRIMAは、貴社から提供された個人データ (以下「委託データ」という)にアクセスし、GDPR第4条第8項および第28条の趣旨に基づき、貴社の委託および指示のみに従って当該データを処理することになります。
1.2 処理の対象となる可能性のある委託データは以下の通りです:
| データ主体(カテゴリー) | データの種類 |
|---|---|
| 写り込んだ人物 |
|
| 画像に写っている人物の親権者 |
|
| 行政機関(例:税務当局)の担当者 |
|
1.3 受注データの処理の種類および範囲は、主契約の目的に基づき、これに限定される。処理期間は、主契約の有効期間に相当する。
1.4 CONTRIMAは、別紙1および第1.2項の規定と異なる、またはそれらを超える注文データの処理を行うことは禁じられています。これは、匿名化されたデータの使用についても同様です。
1.5 受託データの処理は、ドイツ連邦共和国の領土内、欧州連合(EU)加盟国、または欧州経済領域(EEA)協定の他の締約国においてのみ行われる。 第三国への移転は、委託者の事前の書面による同意を必要とし、GDPR第44条から第49条に定める特別な要件が満たされている場合にのみ行うことができる。
1.6 本契約の規定は、主契約に関連し、かつCONTRIMAおよびその従業員、またはCONTRIMAが委託した者が、お客様から提供された、またはお客様のために収集された個人データを取り扱うすべての活動に適用される。
2.1 CONTRIMAは、委託の範囲内においてのみ、かつGDPR第28条(委託処理)の定義に基づくあなたの委託および指示に従ってのみ、委託データを処理します。これは、特に第三国への個人データの移転に関して適用されます。 お客様には、処理活動の種類、範囲、および方法について指示を与える独占的な権利(以下、「指示権」ともいう)があります。 CONTRIMAが、その適用を受ける欧州連合または加盟国の法令により、さらなる処理を義務付けられる場合、CONTRIMAは処理に先立ち、これらの法的要件を貴社に通知します。
2.2 CONTRIMAに対する指示は、原則として書面(メールアドレス:info@contrima.com)により行われるものとします。
2.3 CONTRIMAが、貴殿からの指示のいずれかがデータ保護法規に違反すると判断した場合、CONTRIMAは直ちにその旨を貴殿に通知しなければなりません。CONTRIMAは、当該指示が依頼者によって確認または変更されるまで、当該指示の実施を一時停止する権利を有します。
3.1 CONTRIMAは、データ保護に関する法的規定を遵守し、お客様から取得した情報を第三者に開示せず、また第三者による当該情報へのアクセスを阻止する義務を負う。データは、技術的水準を考慮した上で、権限のない者による閲覧から保護されなければならない。
3.2 さらに、CONTRIMAは、本契約の処理および履行をCONTRIMAから委託されたすべての者(以下「従業員」という)に対し、書面により守秘義務を課すものとする (機密保持義務、GDPR第28条第3項b号)し、必要な注意を払って当該義務の遵守を確保する。CONTRIMAは、貴社の要求に応じて、これを証明する。
3.3 CONTRIMAは、データ保護の特別な要件を満たすよう、社内体制を整備するものとします。 CONTRIMAは、GDPR第32条に基づき、委託データを適切に保護するために必要なすべての適切な技術的および組織的措置、特に本契約の別紙1に記載された措置を講じ、委託データの処理期間中、これらを維持することを約束します。
3.4 CONTRIMAは、講じられた技術的および組織的措置を変更する権利を留保しますが、その際、契約で合意された保護水準を下回らないことを保証します。 CONTRIMAは、別紙1に定める措置がもはや十分でないと見なされる理由がある場合には、直ちに書面により貴社に通知し、さらなる技術的および組織的措置について貴社と協議するものとします。
3.5 貴社の要請があった場合、CONTRIMAは、適切な証拠資料を用いて、別紙1に規定された技術的および組織的措置が遵守されていることを証明するものとします。
4.1 障害、データ保護違反の疑い、またはCONTRIMAの契約上の義務違反が生じた場合、 セキュリティ関連のインシデントの疑い、または委託データの処理において、CONTRIMAが本委託契約の範囲内で従業員または第三者を通じて行った処理におけるその他の不備が生じた場合、CONTRIMAは直ちに、遅くとも24時間以内に、書面または電子形式で貴社に通知するものとします。 データ保護監督当局によるCONTRIMAへの検査についても同様とします。第4条第1項第1文に基づく通知には、それぞれ少なくともGDPR第33条第3項に規定される情報が含まれるものとします。
4.2 第4.1項に該当する場合、CONTRIMAは、当該事案に関する説明、是正措置および情報提供措置の履行にあたり、合理的な範囲内で貴社を支援するものとします。 特に、CONTRIMAは、データの保護および影響を受ける者への潜在的な悪影響を軽減するために必要な措置を直ちに講じ、貴社にその旨を通知する。
4.3 CONTRIMAは、貴社からの口頭または書面による要請に対し、本契約第7.1条に基づく監査の実施に必要なすべての情報および証拠を、合理的な期間内に提供する義務を負う。 さらに、CONTRIMAは、貴社の要望に応じて、委託処理に関する包括的かつ最新のデータ保護・セキュリティ方針、およびアクセス権限を有する者に関する情報を貴社に提供します。
5.1 CONTRIMAは、GDPR第30条第2項に基づき、貴社の委託により実施されるすべての処理活動のカテゴリーに関する目録を作成する義務を負う。当該目録は、貴社の要求に応じて提供されなければならない。
5.2 差押えや没収、破産手続きや和解手続き、あるいはその他の事象や第三者による措置により、CONTRIMAにおける委託データが危険にさらされる場合、裁判所または行政当局の命令により禁止されていない限り、CONTRIMAは直ちに貴社にその旨を通知しなければなりません。 この際、CONTRIMAは、データに関する決定権がGDPR上の「管理者」である発注者にのみ帰属することを、すべての関係当局に直ちに通知するものとします。
6.1 契約で合意されたサービスは、別紙2に記載された下請業者を活用して実施される。CONTRIMAは、契約上の義務の範囲内で、下請業者との下請契約関係(「下請関係」)を締結する権限を有する。 さらなる下請け関係を締結する前に、CONTRIMAは、GDPR第28条第2項の規定に基づき、4週間の事前通知期間を設けて、書面または電子文書によりお客様に通知します。お客様は、上記の通知を受領してから2週間以内に、当該変更に対して異議を申し立てることができます。
6.2 CONTRIMAが、純粋な付随的サービスとみなされる業務を第三者に委託する場合、本規定における下請け関係は成立しません。 これには、例えば、CONTRIMAがお客様に対して提供するサービスと具体的な関連性のない郵便サービスや通信サービス、およびデータ処理システムのハードウェア・ソフトウェアの機密性、可用性、完全性、耐障害性を確保するためのその他の措置などが含まれます。
7.1 お客様は、本契約の規定、特に本契約第3.3条に基づく技術的および組織的措置の実施および遵守状況について、定期的に確認する権利を有する。 このため、例えば、情報を照会したり、認証書や内部監査報告書の提示を求めたり、あるいは、通常の営業時間内に、CONTRIMAの技術的および組織的措置について、ご自身で直接、またはCONTRIMAと競合関係にない専門知識を有する第三者を通じて確認を行うことができます。
7.2 貴社は、必要な範囲内でのみ検査を実施し、CONTRIMAの業務運営に適切な配慮を払わなければならない。検査の時期および方法については、当事者間で適時に合意する。
7.3 貴社は、監査結果を文書化し、CONTRIMAに通知するものとします。特に受注成果物の監査において、誤りや不備を発見した場合は、直ちにCONTRIMAに報告するものとします。
8.1 CONTRIMAは、可能な限り、適切な技術的および組織的措置を講じることで、GDPR第12条から第22条および第32条から第36条に基づく貴社の義務の履行を支援する。 CONTRIMAは、貴社が当該情報を自ら保有していない場合、委託データに関する貴社の情報開示請求に対し、遅くとも7営業日以内に、速やかに回答するものとします。
8.2 データ主体がGDPR第16条から第18条に基づく権利を行使した場合、CONTRIMAは、貴社の指示に基づき、遅滞なく、遅くとも7営業日以内に、委託データを訂正、削除、または処理の制限を行う義務を負います。 CONTRIMAは、ご請求に応じて、データの削除、訂正、または処理の制限について、書面によりその事実を証明いたします。
8.3 データ主体が、自身のデータに関する情報開示、訂正、または削除などの権利をCONTRIMAに対して直接行使した場合、CONTRIMAは当該要請を直ちに貴社に転送し、貴社の指示を待ちます。個別の指示がない限り、CONTRIMAは当該データ主体と連絡を取らないものとします。
9.1 本契約の有効期間は、主契約の有効期間に準じます。疑義が生じた場合、主契約の解約は本契約の解約とみなされ、本契約の解約は主契約の解約とみなされます。
9.2 お客様は、正当な理由がある場合、いつでも本契約を特別に解約する権利を有します。正当な理由とは、CONTRIMAが本契約に基づく義務を履行しない場合、GDPRの規定に故意または重過失により違反した場合、あるいは指示を履行できない、または履行する意思がない場合を指します。 単なる違反(すなわち、故意または重過失によるものではない違反)の場合、貴社はまず、CONTRIMAが当該違反を是正できる適切な期間をCONTRIMAに設定するものとします。当該期間が経過しても是正がなされない場合、貴社は本契約を特別解約する権利を有します。
10.1 CONTRIMAは、主契約の終了後、またはいつでも貴社の要求に応じて、CONTRIMAに提供されたすべてのデータを返還するか、または法的保存期間が定められていない限り、貴社の要望に応じて、完全かつ取り消し不能な形で消去するものとします。 これは、データバックアップなど、CONTRIMAが保有する受注データの複製物にも適用されますが、受注データが契約に従い適正に処理されたことを証明するための文書には適用されません。かかる文書は、法定保存期間の満了までCONTRIMAが保管しなければなりません。
10.2 お客様には、CONTRIMAによるデータの完全かつ契約に則った返還または削除が適切に行われていることを、適切な方法で確認する権利があります。
10.3 CONTRIMAは、主契約の終了後も、主契約に関連して知り得たデータを機密情報として扱う義務を負う。
11.1 当事者の責任は、GDPR第82条に基づくものとする。本契約または主契約に基づく義務の違反に起因する、CONTRIMAがお客様に対して負う責任については、この限りではない。
11.2 当事者のいずれかが、データ主体に損害が生じた事由について、いかなる点においても責任を負わないことを立証した場合、当該当事者は責任を免除されるものとする。 第11条第2項第1文は、いずれかの当事者に課された罰金の場合にも準用されるものとし、その免責は、当該罰金によって制裁された違反に対する責任を、相手方がどの程度分担しているかに応じて行われるものとする。
12.1 本契約の変更および追加は、GDPR第28条第9項の定める書面によるものとする。この形式要件の放棄についても同様とする。
12.2 疑義が生じた場合、本契約の規定は主契約の規定に優先する。 本契約の個々の条項が、全部または一部が無効または履行不能であることが判明した場合、あるいは契約締結後の法改正により無効または履行不能となった場合でも、それによって残りの条項の有効性には影響を及ぼさないものとする。 無効または履行不能となった条項の代わりに、当該無効な条項の趣旨および目的に可能な限り近い、有効かつ履行可能な条項が適用されるものとする。
12.3 本契約は、ドイツ連邦共和国の法律に準拠する。CONTRIMAは、理解を容易にするため、本規約を多数の言語版で提供している。内容に相違がある場合は、本委託データ処理契約の英語版が優先される。
CONTRIMAは、委託データの処理が法的要件に準拠して行われ、かつデータ主体の権利が適切な形で保護されるよう、適切な技術的および組織的措置を講じる義務を負う。
CONTRIMAは、データ保護の特別な要件を満たすよう、社内組織体制を整備するものとします。その際、特に、保護すべきデータの種類またはデータカテゴリに応じて適切な措置を講じなければなりません。
具体的には、GDPR第32条の規定を実施するために、以下の措置を定める:
| 番号 | 措置 | 措置の実施 |
|---|---|---|
| 1 | アクセス制御 | 本番環境でのデータ処理は、すべてAWSクラウド内で行われます。物理的なデータ処理設備は、AWSによって同クラウド内で保護されています(AVVおよびAWSの認証を参照)。 管理業務は、ファイアウォールの内側にある、施錠可能で一般に公開されていない部屋内の、アクセス制限が施されたワークステーションから行われます。一般客の立ち入りはなく、専用のサーバールームも存在しません。 |
| 2 | アクセス制御 | システムへのアクセスは、ユーザー名とパスワードによる個人認証を介してのみ行われます。管理用およびAWSへのアクセスは、強固なパスワードと二要素認証によって保護されています。エンドポイントは、OSのログイン、ファイアウォール、およびハードディスクの暗号化によって保護されています。 |
| 3 | アクセス制御 | アプリケーションにおけるロールおよび権限管理コンセプトを採用し、一元的な権限チェック、データを変更するすべてのエンドポイントにおけるサーバー側での検証、CSRF対策、およびパラメータ化されたデータベースアクセスのみを徹底しています。 インフラストラクチャレベルでは、管理者の数を最小限に抑え(1名体制)、最小権限の原則に基づいて権限を付与しています。 |
| 4 | 分離管理 | 一意の所有者割り当てによる、写真家ごとのすべてのデータのマルチテナント対応の論理的分離;独立した本番環境。論理的な分離で十分です。 |
| 5 | 仮名化/データ最小化 | 外部関係者へのアクセスは、ランダムで推測不可能なトークン(パーマリンク)を介して行われます。収集されるデータは、それぞれの目的に必要なもの(基本的にはメールアドレス)に限られます。識別用のメモは、意図的に簡潔かつ中立的な表現に留められています。 |
| 6 | 情報開示の管理 | 通信は暗号化された接続(TLS/HTTPS)を介してのみ行われます。画像データおよび契約データは、暗号化されたオブジェクトストレージ(S3サーバーサイド暗号化)に保存されます。下請け業者へのデータ提供は、AVVまたはEU標準契約条項に基づき、必要な範囲に限定して行われます。 |
| 7 | 入力管理 | アプリケーションレベルでの証拠として重要な操作のログ記録。特に、タイムスタンプ、IPアドレス、デバイス情報、バージョンハッシュを伴う合意および同意の受諾、ならびに決済イベントを記録します。 1名体制による運用であるため、すべての入力、変更、削除は、単一の担当者によるものと特定できます。 |
| 8 | 可用性と耐障害性 | データベースは、EUおよびEEA内の複数のAWSゾーンまたはリージョンにまたがって冗長化されている。バックアップとして自動データベーススナップショットが作成される。 迅速な復旧のためのコードおよびサーバーのバックアップ、ならびにサーバーイメージ(AMI)の保持;追加のローカルバックアップシステム;文書化された緊急時対応および復旧計画。 |
| 9 | データ保護管理 | 責任者はCONTRIMA GmbHの代表取締役です。 法的任命義務がないため、データ保護責任者は任命されていません。GDPR第13条に基づく情報提供義務をアクティベーションプロセスにおいて履行しており、データ主体からの問い合わせに対応するためのプロセスが整備されているほか、GDPR第30条に基づく処理活動台帳も管理されています。 |
| 10 | インシデント対応管理 | 定期的に更新されるファイアウォール。GDPR第33条および第34条に基づくデータ保護侵害の検知および報告に関する文書化されたプロセス(発注者への直ちなる通知を含む)。 |
| 11 | プライバシーに配慮したデフォルト設定 | プライバシー・バイ・デフォルト:必要以上の情報収集を行わず、画像のプレビューには必ず透かしを入れ、許可が得られた後にのみオリジナル画像を提供するとともに、インターフェースを通じて撤回権を容易に行使できるようにする。 |
| 12 | 委託管理(再委託処理業者) | 慎重な選定;すべての再委託処理業者との間でデータ処理契約(AVV)またはEU標準契約条項(モジュール3)を締結し、第三国からの委託の場合は適切な保証措置を講じる;再委託または代替業者への切り替え前に委託者に通知;委託終了後のデータ消去を確実に行う。 現在利用中:Stripe(決済処理)、Amazon Web Services(ホスティング/保存)、DeepL(広告文の翻訳)。 |
本契約第6.1項に基づき、貴社がその利用に同意する下請け業者:
| 下請業者 (名称、住所または本店所在地) |
委託処理の範囲における業務内容 |
|---|---|
| Stripe Payments Europe, Ltd. 1 Grand Canal Street Lower, Grand Canal Dock Dublin, D02 H210, アイルランド (「Stripe」) |
決済処理;販売が発生した場合、購入者の決済データ、本人確認データ、および取引データ。 (これについてはプライバシーポリシーの6.も参照のこと) |
| Amazon Web Services EMEA SARL、38 Avenue John F. Kennedy、 L-1855 ルクセンブルク (「AWS」) |
Webおよびデータベースのホスティング 、画像データ(オリジナル、バリエーション、アーカイブ、エクスポート)の保存および処理(EXIFメタデータを含む)。 電子メールサービス (これについてはプライバシーポリシーの6.も参照) |
| DeepL SE Maarweg 165 50825 ケルン (「DeepL」) |
必要に応じて、認識メモおよびコレクション名(該当する場合)をパーマネントリンクの言語に翻訳する。 (これについてはプライバシーポリシーの6.も参照のこと) |
バージョン 2 · 2026/07/26
Between
the data processor
Contrima GmbH, represented by its managing director Mr Mark Reinhardt, Enzianweg 29, 71384 Weinstadt
(hereinafter ‘CONTRIMA’)
and
the Data Controller
{photographer_name}
{photographer_address}
{photographer_email}
(hereinafter “you”)
CONTRIMA provides services to you for the provision of an infrastructure for the transmission of photographs to the persons depicted therein, as well as for the management of image licence agreements (hereinafter: “Main Contract”). Part of the performance of the Main Contract involves the processing of personal data relating to the persons depicted, which you transmit to CONTRIMA. In order to comply with the requirements of the GDPR in such circumstances, you, as the data controller within the meaning of data protection law, enter into the following data processing agreement with CONTRIMA.
1.1 The cooperation between the parties in accordance with the Main Contract entails that CONTRIMA will have access to personal data provided by you (hereinafter ‘Processed Data’) and that it processes this data exclusively on your behalf and in accordance with your instructions within the meaning of Article 4(8) and Article 28 of the GDPR.
1.2 The following data subject categories may be affected by the processing:
| Data subjects (categories) | Type of data |
|---|---|
| Persons depicted |
|
| Legal guardians of the persons depicted |
|
| Contact persons at public authorities (e.g. tax authorities) |
|
1.3 The nature and scope of the processing of order data are determined by the purposes of the main contract and are limited to these. The duration of the processing corresponds to the term of the main contract.
1.4 CONTRIMA is prohibited from processing contract data in any manner that deviates from or goes beyond the provisions set out in Annex 1 and clause 1.2. This also applies to the use of anonymised data.
1.5 The processing of order data shall take place exclusively within the territory of the Federal Republic of Germany, in a Member State of the European Union or in another State party to the Agreement on the European Economic Area. Any transfer to a third country requires the prior written consent of the client and may only take place if the specific conditions set out in Articles 44 to 49 of the GDPR are met.
1.6 The provisions of this contract apply to all activities related to the main contract in which CONTRIMA and its employees or persons commissioned by CONTRIMA come into contact with personal data originating from you or collected on your behalf.
2.1 CONTRIMA shall process the contract data only within the scope of the contract and exclusively on your behalf and in accordance with your instructions within the meaning of Article 28 of the GDPR (processing on behalf of a controller); this applies in particular to the transfer of personal data to a third country. You have the sole right to issue instructions regarding the nature, scope and method of the processing activities (hereinafter also referred to as the ‘right to issue instructions’). If CONTRIMA is obliged to carry out further processing under the law of the European Union or the Member States to which it is subject, CONTRIMA shall inform you of these legal requirements prior to processing.
2.2 Instructions to CONTRIMA must, as a general rule, be given by you in writing (email address: info@contrima.com).
2.3 If CONTRIMA considers that one of your instructions contravenes data protection regulations, CONTRIMA must inform you of this without delay. CONTRIMA is entitled to suspend the implementation of the instruction in question until it is confirmed or amended by the client.
3.1 CONTRIMA is obliged to comply with the statutory provisions on data protection and not to disclose the information obtained from you to third parties or to prevent them from accessing it. Data must be secured against unauthorised access, taking into account the state of the art.
3.2 Furthermore, CONTRIMA shall require all persons entrusted by CONTRIMA with the processing and performance of this contract (hereinafter referred to as ‘employees’) to undertake in writing to maintain confidentiality (Obligation of confidentiality, Article 28(3)(b) of the GDPR) and shall ensure compliance with this obligation with due care. CONTRIMA shall provide you with evidence of this upon request.
3.3 CONTRIMA shall organise its internal operations in such a way as to meet the specific requirements of data protection. CONTRIMA undertakes to implement all appropriate technical and organisational measures to ensure the adequate protection of the commissioned data in accordance with Article 32 of the GDPR, in particular the measures set out in Annex 1 to this contract, and to maintain these for the duration of the processing of the commissioned data.
3.4 CONTRIMA reserves the right to amend the technical and organisational measures put in place, whilst ensuring that the level of protection agreed in the contract is not compromised. CONTRIMA must inform you in writing without delay if there is reason to believe that the measures set out in Annex 1 are no longer sufficient, and will consult with you regarding further technical and organisational measures.
3.5 At your request, CONTRIMA shall demonstrate compliance with the technical and organisational measures set out in Annex 1 by providing appropriate evidence.
4.1 In the event of disruptions, suspected data breaches or breaches of CONTRIMA’s contractual obligations, suspected security incidents or other irregularities in the processing of the contract data, whether by persons employed by CONTRIMA in the context of the contract or by third parties, CONTRIMA shall inform you without delay, but at the latest within 24 hours, in writing or by electronic means. The same applies to inspections of CONTRIMA by the data protection supervisory authority. Notifications pursuant to Section 4(1), first sentence, shall in each case contain at least the information specified in Article 33(3) of the GDPR.
4.2 In the event referred to in Section 4.1, CONTRIMA shall assist you, to the extent reasonably practicable, in fulfilling its relevant obligations to provide information, take remedial action and keep you informed. In particular, CONTRIMA shall immediately implement the necessary measures to secure the data and to mitigate any potential adverse consequences for the data subjects, and shall inform you accordingly.
4.3 CONTRIMA undertakes to provide you, upon your verbal or written request and within a reasonable period, with all information and evidence necessary to carry out an audit in accordance with § 7.1 of this contract. Furthermore, at your request, CONTRIMA will provide you with a comprehensive and up-to-date data protection and security policy for the processing of personal data, as well as a list of authorised access holders.
5.1 CONTRIMA is obliged to maintain a record of all categories of processing activities carried out on your behalf in accordance with Article 30(2) of the GDPR. This record must be made available to you upon request.
5.2 Should the data processed on your behalf at CONTRIMA be at risk due to attachment or seizure, insolvency or composition proceedings, or other events or measures taken by third parties, CONTRIMA must inform you of this without delay, provided this is not prohibited by a court or official order. In this context, CONTRIMA shall immediately inform all relevant authorities that decision-making authority over the data lies exclusively with the client as the ‘controller’ within the meaning of the GDPR.
6.1 The contractually agreed services shall be performed with the involvement of the subcontractors listed in Annex 2. CONTRIMA is authorised, within the scope of its contractual obligations, to enter into subcontracting relationships with subcontractors (‘subcontracting relationship’). Before entering into any further subcontracting relationships, CONTRIMA shall inform you in writing or by electronic means in accordance with Article 28(2) of the GDPR, giving four weeks’ notice. You may object to the change within two weeks of receiving the aforementioned notification.
6.2 A subcontracting relationship within the meaning of these provisions does not exist if CONTRIMA commissions third parties to provide services that are to be regarded as purely ancillary services. These include, for example, postal or telecommunications services with no specific connection to the services CONTRIMA provides for you, as well as other measures to ensure the confidentiality, availability, integrity and resilience of the hardware and software of data processing systems.
7.1 You are entitled to verify, on a regular basis, compliance with the provisions of this contract, in particular the implementation of and compliance with the technical and organisational measures set out in clause 3.3 of this agreement. To this end, you may, for example, request information, ask to be provided with certifications or internal audit reports, or have CONTRIMA’s technical and organisational measures inspected yourself during normal business hours or by a competent third party, provided that such third party is not in competition with CONTRIMA.
7.2 You shall carry out inspections only to the extent necessary and shall take due account of CONTRIMA’s operational processes. The parties shall agree in good time on the timing and nature of the inspection.
7.3 You shall document the results of the audit and notify CONTRIMA thereof. In the event of errors or irregularities which you identify, in particular when auditing the results of orders, you shall inform CONTRIMA without delay.
8.1 CONTRIMA shall, where possible, support you with appropriate technical and organisational measures in fulfilling your obligations under Articles 12 to 22 and Articles 32 to 36 of the GDPR. CONTRIMA shall provide you with the requested information regarding processing data without delay, but no later than within 7 working days, unless you already have the relevant information yourself.
8.2 If a data subject exercises their rights under Articles 16 to 18 of the GDPR, CONTRIMA is obliged, on your instructions, to rectify, erase or restrict the processing of the data without undue delay, and at the latest within 7 working days. CONTRIMA will provide you with written confirmation of the erasure, rectification or restriction of the data upon request.
8.3 If a data subject exercises rights – such as the right to access, rectification or erasure of their data – directly against CONTRIMA, CONTRIMA shall forward this request to you without delay and await your instructions. CONTRIMA shall not contact the data subject without specific instructions to do so.
9.1 The term of this contract corresponds to the term of the main contract. In case of doubt, termination of the main contract shall also be deemed to be termination of this contract, and termination of this contract shall be deemed to be termination of the main contract.
9.2 You are entitled at any time to terminate this contract extraordinarily for good cause. Good cause shall be deemed to exist if CONTRIMA fails to fulfil its obligations under this contract, breaches provisions of the GDPR intentionally or through gross negligence, or is unable or unwilling to carry out an instruction. In the case of minor breaches – i.e. those that are neither intentional nor due to gross negligence – you shall first set CONTRIMA a reasonable period within which CONTRIMA may remedy the breach. Once this period has expired without result, you shall then be entitled to terminate this contract without notice.
10.1 Upon termination of the main contract or at any time upon request, CONTRIMA shall return to you all data provided to CONTRIMA or, upon request, delete it completely and irrevocably, provided that no statutory retention period applies. This also applies to copies of the order data held by CONTRIMA, such as data backups, but not to documentation serving as evidence of the proper and compliant processing of the order data. Such documentation must be retained by CONTRIMA for the duration of the statutory retention periods.
10.2 You have the right to verify, in an appropriate manner, that the data has been returned or deleted by CONTRIMA in full and in accordance with the contract.
10.3 CONTRIMA is obliged to treat as confidential any data that has come to its knowledge in connection with the main contract, even after the main contract has ended.
11.1 The liability of the parties is governed by Article 82 of the GDPR. This does not affect CONTRIMA’s liability towards you for any breach of obligations arising from this contract or the main contract.
11.2 Each party shall be exempt from liability if it proves that it is in no way responsible for the circumstance that caused the damage to a data subject. Section 11(2), first sentence, shall apply mutatis mutandis in the event of a fine being imposed on a party, whereby the indemnification shall apply to the extent that the other party bears a share of the responsibility for the infringement sanctioned by the fine.
12.1 Any amendments or additions to this agreement must be made in writing in accordance with Article 28(9) of the GDPR. This also applies to any waiver of this formal requirement.
12.2 In the event of any doubt, the provisions of this Agreement shall take precedence over those of the main contract. Should any individual provisions of this Agreement prove to be wholly or partially invalid or unenforceable, or should they become invalid or unenforceable as a result of legislative changes following the conclusion of the Agreement, this shall not affect the validity of the remaining provisions. The invalid or unenforceable provision shall be replaced by a valid and enforceable provision that comes as close as possible to the meaning and purpose of the invalid provision.
12.3 This contract is governed by the law of the Federal Republic of Germany. CONTRIMA provides these terms and conditions in a variety of language versions for the sake of clarity. In the event of any discrepancies, the English version of this Data Processing Agreement shall prevail.
CONTRIMA is obliged to implement appropriate technical and organisational measures to ensure that the processing of the commissioned data is carried out in accordance with the statutory requirements and that the rights of the data subject are adequately safeguarded.
CONTRIMA shall structure its internal organisation in such a way as to meet the specific requirements of data protection. In particular, measures must be taken that are appropriate to the nature of the data or categories of data to be protected.
Specifically, the following measures are set out to implement the requirements of Article 32 of the GDPR:
| No. | Measure | Implementation of the measure |
|---|---|---|
| 1 | Access control | Productive data processing takes place exclusively in the AWS cloud; the physical data processing facilities there are secured by AWS (see AWS Terms of Service and certifications). Administration is carried out from an access-controlled workstation in lockable, non-publicly accessible rooms behind a firewall. There is no public access and no dedicated server rooms. |
| 2 | Access Control | System access is granted only via personal login with a username and password. Administrative and AWS accesses are protected by strong passwords and two-factor authentication. End devices are secured by operating system login, a firewall and disk encryption. |
| 3 | Access control | Role- and authorisation-based concept within the application, featuring centralised authorisation checks, server-side validation on all endpoints that modify data, protection against CSRF, and exclusively parameterised database access. At the infrastructure level, a minimum number of administrators (single-person operation) and the granting of rights in accordance with the principle of least privilege. |
| 4 | Segregation of duties | Multi-tenant logical separation of all data for each photographer via a unique owner assignment; separate production environment. Logical separation is sufficient. |
| 5 | Pseudonymisation / Data minimisation | Access for external parties via random, non-guessable tokens (permanent link). Only the data necessary for the respective purpose is collected (essentially the email address); identifying notes are deliberately kept brief and neutral. |
| 6 | Control of data disclosure | Transmission takes place exclusively via encrypted connections (TLS/HTTPS). Image and contract data are stored on encrypted object storage (S3 Server-Side Encryption). Data is transferred to subcontractors only to the extent necessary, on the basis of the Data Processing Agreement (DPA) or EU Standard Contractual Clauses. |
| 7 | Input control | Logging of audit-relevant operations at application level, in particular the acceptance of agreements and consents, including timestamps, IP addresses, device information and version hashes, as well as payment events. As the service is operated by a single person, every entry, modification and deletion can be traced back to a single individual. |
| 8 | Availability and Resilience | Database redundancy across multiple AWS zones or regions within the EU or the EEA; automated database snapshots as backups; code and server backups, as well as a pre-configured server image (AMI) for rapid recovery; additional local backup system; documented emergency and recovery plan. |
| 9 | Data Protection Management | The Managing Director of CONTRIMA GmbH is responsible. No data protection officer has been appointed, as there is no legal obligation to do so. Compliance with the information obligations under Article 13 of the GDPR during the activation process; an existing process for handling data subjects’ enquiries; and a register of processing activities maintained in accordance with Article 30 of the GDPR. |
| 10 | Incident Response Management | Firewall updated regularly; documented process for detecting and reporting data breaches in accordance with Articles 33 and 34 of the GDPR, including the immediate notification of the client. |
| 11 | Privacy-friendly default settings | Privacy by default: no data collected beyond what is necessary; image previews only with watermarks; original files provided only after authorisation has been granted; and the right to withdraw consent can be exercised easily via the user interface. |
| 12 | Contract management (sub-processors) | Careful selection; conclusion of data processing agreements or EU Standard Contractual Clauses (Module 3) with all sub-processors, with appropriate safeguards where third countries are involved; notification of the client prior to engaging or replacing sub-processors; ensuring data erasure upon termination of the contract. Currently used: Stripe (payment processing), Amazon Web Services (hosting/storage), DeepL (translation of advert copy). |
Sub-processors included under clause 6.1 of the agreement, to the use of whom you consent:
| Subcontractor (name, address or registered office) |
Scope of services within the framework of data processing |
|---|---|
| Stripe Payments Europe, Ltd. 1 Grand Canal Street Lower, Grand Canal Dock , Dublin, D02 H210, Ireland (“Stripe”) |
Payment processing; in the event of a sale, the purchaser’s payment, identity and transaction data (see also clause 6 of Privacy Policy) |
| Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg (“AWS”) |
Web and database hosting ; storage and processing of image data (originals, variants, archive, exports), including EXIF metadata. Email services (see also section 6 of Privacy Policy) |
| DeepL SE , Maarweg 165 , 50825 Cologne (“DeepL”) |
Where applicable, translation of the recognition note and, where applicable, the collection name into the language of the permanent link (see also 6. from Privacy Policy) |