Sürüm 2 · 26 Tem 2026
Aşağıdaki taraflar arasında
Veri İşleyen
Contrima GmbH, Genel Müdürü Bay Mark Reinhardt tarafından temsil edilen, Enzianweg 29, 71384 Weinstadt
(bundan sonra “CONTRIMA” olarak anılacaktır)
ile
Veri Sorumlusu
{photographer_name}
{photographer_address}
{photographer_email}
(bundan sonra “Sen” olarak anılacaktır)
CONTRIMA, fotoğraflarda yer alan kişilere fotoğrafların iletilmesi ve görsel lisans sözleşmesi yönetimi için bir altyapı sağlamak üzere Sana hizmet sunmaktadır (bundan sonra “Ana Sözleşme” olarak anılacaktır). Ana Sözleşmenin yerine getirilmesinin bir parçası olarak, senin CONTRIMA’ya ilettiğin fotoğraflarda yer alan kişilerin kişisel verileri işlenmektedir. Bu tür durumlara ilişkin GDPR gerekliliklerini yerine getirmek amacıyla, veri koruma hukuku anlamında veri sorumlusu olarak sen, CONTRIMA ile aşağıdaki Veri İşleme Sözleşmesini imzalarsın.
1.1 Ana Sözleşme hükümlerine göre taraflar arasındaki işbirliği, CONTRIMA’nın sizin tarafınızdan sağlanan kişisel verilere (bundan sonra “İşleme Verileri” olarak anılacaktır) erişim hakkına sahip olur ve bu verileri yalnızca sizin adınıza ve talimatınız doğrultusunda GDPR’nin 4. maddesinin 8. fıkrası ile 28. maddesi uyarınca işler.
1.2 İşleme, aşağıdaki işleme verileri dahil olabilir:
| İlgili Kişiler (Kategoriler) | Veri türü |
|---|---|
| Fotoğrafında yer alan kişiler |
|
| Resimlerde yer alan kişilerin yasal vasileri |
|
| Resmi kurumların irtibat kişileri (örn. vergi daireleri) |
|
1.3 Sipariş verilerinin işlenme türü ve kapsamı, ana sözleşmenin amaçlarına göre belirlenir ve bu amaçlarla sınırlıdır. İşleme süresi, ana sözleşmenin süresine karşılık gelir.
1.4 CONTRIMA’nın, Ek 1’de ve Madde 1.2’de belirtilenlerin dışında veya bu hükümlerin ötesinde sipariş verilerini işlemesi yasaktır. Bu, anonimleştirilmiş verilerin kullanımı için de geçerlidir.
1.5 Sipariş verilerinin işlenmesi, münhasıran Federal Almanya Cumhuriyeti topraklarında, bir Avrupa Birliği üye devletinde veya Avrupa Ekonomik Alanı Anlaşması’na taraf olan başka bir ülkede gerçekleştirilir. Üçüncü bir ülkeye herhangi bir aktarım, işverenin önceden yazılı onayı gerektirir ve yalnızca GDPR’nin 44 ila 49. maddelerinde belirtilen özel koşullar yerine getirildiğinde gerçekleştirilebilir.
1.6 Bu sözleşmenin hükümleri, ana sözleşmeyle ilgili olan ve CONTRIMA ile çalışanlarının veya CONTRIMA tarafından görevlendirilen kişilerin, sizden kaynaklanan veya sizin adınıza toplanan kişisel verilerle temas kurduğu tüm faaliyetler için geçerlidir.
2.1 CONTRIMA, işleme verilerini yalnızca görev kapsamında ve münhasıran sizin adınıza ve GDPR’nin 28. maddesi (İşleme Görevi) anlamı dahilinde talimatınız doğrultusunda işler; bu durum, özellikle kişisel verilerin üçüncü bir ülkeye aktarılmasıyla ilgili olarak geçerlidir. İşleme faaliyetlerinin türü, kapsamı ve yöntemi hakkında talimat verme hakkı yalnızca size aittir (bundan sonra “talimat verme hakkı” olarak da anılacaktır). CONTRIMA’nın tabi olduğu Avrupa Birliği veya üye devletlerin mevzuatı uyarınca ek işleme yükümlülükleri olması durumunda, CONTRIMA işleme başlamadan önce bu yasal gereklilikleri size bildirecektir.
2.2 CONTRIMA’ya verilecek talimatlar, ilke olarak tarafınızca yazılı olarak verilir (e-posta adresi: info@contrima.com).
2.3 CONTRIMA, talimatlarınızdan birinin veri koruma mevzuatına aykırı olduğunu düşünürse, bunu size derhal bildirmekle yükümlüdür. CONTRIMA, söz konusu talimatın müşteri tarafından onaylanana veya değiştirilene kadar uygulanmasını askıya alma hakkına sahiptir.
3.1 CONTRIMA, veri koruma ile ilgili yasal hükümlere uymakla ve sizden elde ettiği bilgileri üçüncü şahıslara aktarmamak veya bu kişilerin erişimini engellemekle yükümlüdür. Veriler, teknik imkanlar dahilinde yetkisiz kişilerin erişimine karşı korunmalıdır.
3.2 Ayrıca CONTRIMA, bu sözleşmenin işlenmesi ve yerine getirilmesi ile görevlendirilen tüm kişileri (bundan sonra “Çalışanlar” olarak anılacaktır) yazılı olarak gizlilik yükümlülüğüne tabi tutacak (Gizlilik Yükümlülüğü, GDPR Madde 28, Paragraf 3, b bendi) ve bu yükümlülüğün gerekli özenle yerine getirilmesini sağlayacaktır. CONTRIMA, talebiniz üzerine bunu size kanıtlayacaktır.
3.3 CONTRIMA, şirket içi organizasyonunu veri korumanın özel gerekliliklerini karşılayacak şekilde düzenleyecektir. CONTRIMA, GDPR’nin 32. maddesi uyarınca iş verilerinin uygun şekilde korunması için tüm uygun teknik ve organizasyonel önlemleri, özellikle de bu sözleşmenin 1. Ekinde belirtilen önlemleri almayı ve iş verilerinin işlendiği süre boyunca bunları sürdürmeyi taahhüt eder.
3.4 CONTRIMA, alınan teknik ve organizasyonel önlemlerde değişiklik yapma hakkını saklı tutar; ancak CONTRIMA, sözleşmede kararlaştırılan koruma seviyesinin altına düşülmemesini garanti eder. CONTRIMA, Ek 1’deki önlemlerin artık yeterli olmadığına dair bir gerekçe olması durumunda seni derhal yazılı olarak bilgilendirecek ve ilave teknik ve organizasyonel önlemler konusunda seninle mutabık kalacaktır.
3.5 Talebiniz üzerine CONTRIMA, Ek 1’de belirtilen teknik ve organizasyonel önlemlere uyulduğunu uygun kanıtlarla ispat edecektir.
4.1 Arızalar, veri koruma ihlali şüphesi veya CONTRIMA’nın sözleşme yükümlülüklerini ihlal etmesi durumunda, güvenlikle ilgili olay şüphesi veya sipariş verilerinin işlenmesinde, CONTRIMA’nın sipariş kapsamında istihdam ettiği kişiler veya üçüncü taraflar tarafından gerçekleştirilen diğer usulsüzlükler söz konusu olduğunda, CONTRIMA sizi derhal, en geç 24 saat içinde yazılı veya elektronik olarak bilgilendirecektir. Aynı durum, Veri Koruma Denetim Kurumu tarafından CONTRIMA’ya yönelik denetimler için de geçerlidir. § 4, fıkra 1, cümle 1 uyarınca yapılacak bildirimler, her durumda en azından GDPR’nin 33. maddesinin 3. fıkrasında belirtilen bilgileri içerecektir.
4.2 CONTRIMA, § 4.1’de belirtilen durumlarda, bu konudaki bilgilendirme, düzeltme ve bilgilendirme tedbirlerini yerine getirirken makul ölçüler dahilinde size destek verecektir. CONTRIMA, özellikle verilerin güvenliğini sağlamak ve ilgili kişilerin maruz kalabileceği olası olumsuz sonuçları en aza indirmek için gerekli önlemleri derhal alacak ve sizi bilgilendirecektir.
4.3 CONTRIMA, sözlü veya yazılı talebiniz üzerine, bu Sözleşmenin § 7.1'ine göre bir denetimin gerçekleştirilmesi için gerekli olan tüm bilgileri ve kanıtları makul bir süre içinde size sunmayı taahhüt eder. Ayrıca CONTRIMA, talebiniz üzerine, işleme faaliyetleri için kapsamlı ve güncel bir veri koruma ve güvenlik konseptini ve erişim yetkisi olan kişilere ilişkin bilgileri size sunacaktır.
5.1 CONTRIMA, GDPR Madde 30, Paragraf 2 uyarınca, sizin adınıza gerçekleştirilen tüm işleme faaliyetlerinin kategorilerini içeren bir kayıt tutmakla yükümlüdür. Bu kayıt, talebiniz üzerine size sunulmalıdır.
5.2 CONTRIMA’daki iş verileri, haciz veya el koyma, iflas veya uzlaşma işlemleri ya da üçüncü şahısların diğer olayları veya tedbirleri nedeniyle tehlikeye girerse, CONTRIMA, bunun mahkeme veya resmi makam kararıyla yasaklanmadığı sürece, sizi bu durum hakkında derhal bilgilendirmekle yükümlüdür. CONTRIMA bu bağlamda, veriler üzerindeki karar yetkisinin münhasıran GDPR anlamında “Veri Sorumlusu” olarak işverene ait olduğunu tüm yetkili makamlara derhal bildirecektir.
6.1 Sözleşmede kararlaştırılan hizmetler, Ek 2’de belirtilen alt yüklenicilerin katılımıyla gerçekleştirilecektir. CONTRIMA, sözleşmesel yükümlülükleri kapsamında alt yüklenicilerle alt yüklenici ilişkileri (“alt yüklenici ilişkisi”) kurma yetkisine sahiptir. CONTRIMA, yeni alt yüklenici ilişkileri kurmadan önce, GDPR’nin 28. maddesinin 2. fıkrası uyarınca, dört haftalık bir süre tanıyarak size yazılı olarak veya elektronik ortamda bildirimde bulunur. Yukarıdaki bildirimi aldıktan sonra iki hafta içinde bu değişikliğe itiraz edebilirsiniz.
6.2 CONTRIMA’nın, tamamen yan hizmetler olarak kabul edilebilecek hizmetler için üçüncü taraflara görev vermesi durumunda, bu hükümler kapsamında bir alt yüklenici ilişkisi söz konusu değildir. Bunlara, örneğin, CONTRIMA’nın sizin için sunduğu hizmetlerle somut bir bağlantısı olmayan posta veya telekomünikasyon hizmetleri ile veri işleme sistemlerinin donanım ve yazılımlarının gizliliğini, kullanılabilirliğini, bütünlüğünü ve dayanıklılığını sağlamak için alınan diğer önlemler dahildir.
7.1 Bu sözleşmenin hükümlerine, özellikle de bu anlaşmanın 3.3. maddesine göre teknik ve organizasyonel önlemlerin uygulanmasına ve bunlara uyulmasına ilişkin durumları düzenli olarak kontrol etme hakkına sahipsiniz. Bunun için örneğin bilgi alabilir, sertifikaların veya iç denetim raporlarının size sunulmasını talep edebilir ya da CONTRIMA’nın teknik ve organizasyonel önlemlerini normal çalışma saatleri içinde şahsen veya CONTRIMA ile rekabet ilişkisi içinde olmayan uzman bir üçüncü taraf aracılığıyla denetletebilirsiniz.
7.2 Denetimleri yalnızca gerekli ölçüde gerçekleştirecek ve CONTRIMA’nın iş akışlarına uygun şekilde özen göstereceksiniz. Denetimin zamanı ve şekli konusunda taraflar zamanında mutabık kalacaktır.
7.3 Denetim sonucunu belgelendirecek ve CONTRIMA’ya bildireceksiniz. Özellikle iş sonuçlarının denetimi sırasında tespit ettiğiniz hatalar veya usulsüzlükler konusunda CONTRIMA’yı derhal bilgilendireceksiniz.
8.1 CONTRIMA, mümkün olduğunca uygun teknik ve organizasyonel önlemler alarak, GDPR’nin 12 ila 22. maddeleri ile 32 ila 36. maddeleri uyarınca yükümlülüklerinizi yerine getirmenize destek olacaktır. CONTRIMA, ilgili bilgilere kendiniz sahip değilseniz, iş verileriyle ilgili talep ettiğiniz bilgileri derhal, en geç 7 iş günü içinde size sağlayacaktır.
8.2 İlgili kişi, GDPR’nin 16 ila 18. maddeleri uyarınca haklarını kullanırsa, CONTRIMA, talimatınız doğrultusunda iş verilerini derhal, en geç 7 iş günü içinde düzeltmek, silmek veya kısıtlamakla yükümlüdür. CONTRIMA, talep üzerine verilerin silinmesi, düzeltilmesi veya kısıtlanmasını size yazılı olarak teyit edecektir.
8.3 Bir veri sahibi, verileriyle ilgili bilgi verme, düzeltme veya silme gibi haklarını doğrudan CONTRIMA’ya karşı kullanırsa, CONTRIMA bu talebi derhal size iletecek ve talimatlarınızı bekleyecektir. İlgili özel talimat verilmedikçe, CONTRIMA veri sahibi ile iletişime geçmeyecektir.
9.1 Bu sözleşmenin süresi, ana sözleşmenin süresine karşılık gelir. Şüphe durumunda, ana sözleşmenin feshi bu sözleşmenin feshi olarak, bu sözleşmenin feshi ise ana sözleşmenin feshi olarak kabul edilir.
9.2 Önemli bir neden olması halinde, bu sözleşmeyi her zaman olağanüstü olarak feshetme hakkına sahipsiniz. Önemli bir neden, CONTRIMA’nın bu sözleşmeden doğan yükümlülüklerini yerine getirmemesi, GDPR hükümlerini kasten veya ağır ihmal sonucu ihlal etmesi ya da bir talimatı yerine getirememesi veya getirmek istememesi durumlarında mevcuttur. Basit – yani kasıtlı veya ağır ihmalden kaynaklanmayan – ihlallerde, öncelikle CONTRIMA’ya ihlali gidermesi için makul bir süre tanıyacaksınız. Bu sürenin sonuçsuz olarak dolmasının ardından, olağanüstü fesih hakkına sahip olacaksınız.
10.1 CONTRIMA, ana sözleşmenin sona ermesinden sonra veya talep üzerine her zaman, CONTRIMA’ya devredilen tüm verileri size iade edecek veya yasal bir saklama süresi bulunmadığı sürece, talebiniz üzerine bu verileri tamamen ve geri alınamaz şekilde silecektir. Bu durum, CONTRIMA’da bulunan sipariş verilerinin kopyaları (örneğin yedeklemeler) için de geçerlidir; ancak sipariş verilerinin kurallara uygun şekilde işlendiğini kanıtlamaya yarayan belgeler için geçerli değildir. Bu tür belgeler, yasal saklama süreleri boyunca CONTRIMA tarafından saklanmalıdır.
10.2 CONTRIMA’daki verilerin tam ve sözleşmeye uygun şekilde iade edilmesini veya silinmesini uygun bir şekilde denetleme hakkına sahipsiniz.
10.3 CONTRIMA, ana sözleşmenin sona ermesinden sonra da ana sözleşme kapsamında kendisine ulaşan verileri gizli tutmakla yükümlüdür.
11.1 Tarafların sorumluluğu, GDPR’nin 82. maddesine tabidir. CONTRIMA’nın, bu sözleşmeden veya ana sözleşmeden kaynaklanan yükümlülüklerin ihlali nedeniyle size karşı sorumluluğu bundan etkilenmez.
11.2 Taraflardan biri, bir veri sahibinde meydana gelen zarara yol açan durumdan hiçbir şekilde sorumlu olmadığını kanıtladığı takdirde, her iki taraf da sorumluluktan muaf tutulur. § 11, 2. fıkra, 1. cümle, bir tarafa para cezası verilmesi durumunda da aynı şekilde geçerlidir; bu durumda, muafiyet, para cezası ile yaptırım uygulanan ihlalin sorumluluğunda diğer tarafın payı ölçüsünde geçerlidir.
12.1 Bu anlaşmadaki değişiklikler ve eklemeler, GDPR Madde 28, Paragraf 9 uyarınca yazılı olarak yapılmalıdır. Bu hüküm, bu şekil şartından feragat edilmesi için de geçerlidir.
12.2 Şüphe durumunda, bu sözleşmedeki hükümler ana sözleşmedeki hükümlere göre önceliklidir. Bu sözleşmenin münferit hükümlerinin tamamen veya kısmen geçersiz veya uygulanamaz olduğu ortaya çıkarsa veya sözleşmenin imzalanmasından sonra mevzuatta yapılan değişiklikler neticesinde geçersiz veya uygulanamaz hale gelirse, bu durum diğer hükümlerin geçerliliğini etkilemez. Geçersiz veya uygulanamaz hükmün yerine, geçersiz hükmün anlam ve amacına mümkün olduğunca yakın olan geçerli ve uygulanabilir bir hüküm ikame edilecektir.
12.3 Bu sözleşme, Federal Almanya Cumhuriyeti hukukuna tabidir. CONTRIMA, daha iyi anlaşılabilirlik amacıyla bu şartları çeşitli dil versiyonlarında sunmaktadır. Herhangi bir tutarsızlık durumunda, bu Veri İşleme Sözleşmesi’nin İngilizce versiyonu esas alınacaktır.
CONTRIMA, işlenecek verilerin yasal gerekliliklere uygun şekilde işlenmesini ve ilgili kişinin haklarının uygun bir şekilde korunmasını sağlamak üzere uygun teknik ve organizasyonel önlemleri almakla yükümlüdür.
CONTRIMA, kurum içi organizasyonunu veri korumanın özel gerekliliklerini karşılayacak şekilde düzenleyecektir. Bu bağlamda, özellikle korunacak verilerin veya veri kategorilerinin türüne göre uygun önlemler alınmalıdır.
GDPR’nin 32. maddesindeki hükümlerin uygulanmasına yönelik olarak, ayrıntılı olarak aşağıdaki önlemler belirlenmiştir:
| No. | Tedbir | Önlemin Uygulanması |
|---|---|---|
| 1 | Erişim Kontrolü | Üretim amaçlı veri işleme faaliyetleri münhasıran AWS bulutunda gerçekleştirilmektedir; fiziksel veri işleme tesisleri burada AWS tarafından güvence altına alınmaktadır (bkz. AVV ve AWS sertifikaları). Yönetim, erişim korumalı bir iş istasyonundan, kilitlenebilir, halka açık olmayan odalarda ve bir güvenlik duvarı arkasında gerçekleştirilir. Halka açık alanlar ve kurumun kendi sunucu odaları bulunmamaktadır. |
| 2 | Erişim Kontrolü | Sisteme erişim, yalnızca kullanıcı adı ve şifre ile kişisel oturum açma yoluyla mümkündür. Yönetim ve AWS erişimleri, güçlü şifreler ve iki faktörlü kimlik doğrulama ile korunmaktadır. Son kullanıcı cihazları, işletim sistemi oturum açma, güvenlik duvarı ve sabit disk şifreleme ile korunmaktadır. |
| 3 | Erişim Kontrolü | Uygulamada merkezi yetki denetimi, verileri değiştiren tüm uç noktalarda sunucu tarafında denetim, CSRF'ye karşı koruma ve yalnızca parametreli veritabanı erişimlerini içeren rol ve yetki konsepti. Altyapı düzeyinde minimum sayıda yönetici (tek kişilik işletim) ve en az ayrıcalık ilkesine göre hak tahsisi. |
| 4 | Ayırma Kontrolü | Her fotoğrafçı için tüm verilerin, benzersiz bir sahiplik ataması yoluyla çoklu müşteri desteğine uygun mantıksal olarak ayrılması; ayrı üretim ortamı. Mantıksal bir ayrım yeterlidir. |
| 5 | Takma Adlandırma / Veri Asgari Düzeye İndirme | Dışarıdan gelen kişilerin erişimi, rastgele ve tahmin edilemeyen tokenlar (kalıcı bağlantı) aracılığıyla sağlanır. Yalnızca ilgili amaç için gerekli olan veriler toplanır (temel olarak e-posta adresi); tanımlayıcı notlar kasıtlı olarak kısa ve tarafsız tutulur. |
| 6 | Aktarım Kontrolü | Aktarım yalnızca şifreli bağlantılar üzerinden gerçekleştirilir (TLS/HTTPS). Görüntü ve sözleşme verilerinin şifreli nesne depolama alanında saklanması (S3 Sunucu Tarafı Şifreleme). Alt yüklenicilere aktarım, yalnızca gerekli ölçüde ve AVV veya AB Standart Sözleşme Maddeleri temelinde yapılır. |
| 7 | Giriş Kontrolü | Uygulama düzeyinde kanıtlama açısından önemli işlemlerin günlüğe kaydedilmesi; özellikle zaman damgası, IP adresi, cihaz bilgileri ve sürüm hash'i ile birlikte anlaşma ve onay kabulleri ile ödeme olayları. Tek kişilik işletme yapısı sayesinde, her türlü giriş, değişiklik ve silme işlemi tek bir sorumlu kişiye atfedilebilir. |
| 8 | Kullanılabilirlik ve Dayanıklılık | Veritabanı, AB veya AEA içindeki birden fazla AWS bölgesi veya bölgesi üzerinden yedeklenmiştir; yedekleme amacıyla otomatik veritabanı anlık görüntüleri; hızlı geri yükleme için kod ve sunucu yedeklemeleri ile önceden hazırlanmış bir sunucu görüntüsü (AMI); ek yerel yedekleme sistemi; belgelenmiş acil durum ve yeniden başlatma planı. |
| 9 | Veri Koruma Yönetimi | Sorumlu kişi, CONTRIMA GmbH'nin genel müdürüdür. Yasal bir atama yükümlülüğü bulunmadığından veri koruma görevlisi atanmamıştır. GDPR’nin 13. maddesine göre aktivasyon sürecinde bilgilendirme yükümlülüklerinin yerine getirilmesi, veri sahiplerinin taleplerini işleme yönelik mevcut süreç ve GDPR’nin 30. maddesine göre işleme faaliyetlerinin kayıt altına alınması. |
| 10 | Olay Müdahale Yönetimi | Düzenli olarak güncellenen güvenlik duvarı; GDPR’nin 33. ve 34. maddeleri uyarınca veri koruma ihlallerinin tespit edilmesi ve bildirilmesine ilişkin belgelenmiş süreç, buna müşterinin derhal bilgilendirilmesi de dahildir. |
| 11 | Veri Koruma Dostu Varsayılan Ayarlar | Varsayılan olarak gizlilik: Gerekenden fazlasının toplanmaması, resim önizlemelerinin yalnızca filigranlı olarak sunulması ve orijinallerin ancak izin verildikten sonra sağlanması; ayrıca arayüz üzerinden iptal hakkının kolayca kullanılması. |
| 12 | İşveren Kontrolü (Alt İşlemciler) | Titiz seçim; tüm alt işleyicilerle AVV veya AB Standart Sözleşme Maddeleri (Modül 3) imzalanması, üçüncü ülkelerden hizmet alınması durumunda uygun garantilerin sağlanması; alt işleyicinin devreye alınmasından veya değiştirilmesinden önce işverenin bilgilendirilmesi; işin sona ermesinden sonra verilerin silinmesinin sağlanması. Şu anda kullanılanlar: Stripe (ödeme işlemleri), Amazon Web Services (barındırma/depolama), DeepL (reklam metinlerinin çevirisi). |
Sözleşmenin 6.1. maddesi uyarınca dahil edilen ve kullanımına onay verdiğin alt yükleniciler:
| Alt yüklenici (Adı, adresi veya merkezi) |
Sipariş işleme kapsamında sunulan hizmet |
|---|---|
| Stripe Payments Europe, Ltd. 1 Grand Canal Street Lower, Grand Canal Dock Dublin, D02 H210, İrlanda (“Stripe”) |
Ödeme işlemleri; satış durumunda alıcının ödeme, kimlik ve işlem verileri. (Bu konuda ayrıca bkz. Gizlilik Politikası'daki 6. madde) |
| Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Lüksemburg (“AWS”) |
Web ve veritabanı barındırma ; EXIF meta verileri dahil olmak üzere görüntü verilerinin (orijinaller, varyantlar, arşiv, dışa aktarımlar) depolanması ve işlenmesi. E-posta hizmetleri (bu konuda ayrıca bkz. Gizlilik Politikası'deki 6. madde) |
| DeepL SE , Maarweg 165 , 50825 Köln (“DeepL”) |
Gerekirse, tanıma notunun ve gerekirse koleksiyon adının kalıcı bağlantının diline çevirisi. (Bu konuda ayrıca bkz. Gizlilik Politikası'deki 6. madde) |
Sürüm 2 · 26 Tem 2026
Between
the data processor
Contrima GmbH, represented by its managing director Mr Mark Reinhardt, Enzianweg 29, 71384 Weinstadt
(hereinafter ‘CONTRIMA’)
and
the Data Controller
{photographer_name}
{photographer_address}
{photographer_email}
(hereinafter “you”)
CONTRIMA provides services to you for the provision of an infrastructure for the transmission of photographs to the persons depicted therein, as well as for the management of image licence agreements (hereinafter: “Main Contract”). Part of the performance of the Main Contract involves the processing of personal data relating to the persons depicted, which you transmit to CONTRIMA. In order to comply with the requirements of the GDPR in such circumstances, you, as the data controller within the meaning of data protection law, enter into the following data processing agreement with CONTRIMA.
1.1 The cooperation between the parties in accordance with the Main Contract entails that CONTRIMA will have access to personal data provided by you (hereinafter ‘Processed Data’) and that it processes this data exclusively on your behalf and in accordance with your instructions within the meaning of Article 4(8) and Article 28 of the GDPR.
1.2 The following data subject categories may be affected by the processing:
| Data subjects (categories) | Type of data |
|---|---|
| Persons depicted |
|
| Legal guardians of the persons depicted |
|
| Contact persons at public authorities (e.g. tax authorities) |
|
1.3 The nature and scope of the processing of order data are determined by the purposes of the main contract and are limited to these. The duration of the processing corresponds to the term of the main contract.
1.4 CONTRIMA is prohibited from processing contract data in any manner that deviates from or goes beyond the provisions set out in Annex 1 and clause 1.2. This also applies to the use of anonymised data.
1.5 The processing of order data shall take place exclusively within the territory of the Federal Republic of Germany, in a Member State of the European Union or in another State party to the Agreement on the European Economic Area. Any transfer to a third country requires the prior written consent of the client and may only take place if the specific conditions set out in Articles 44 to 49 of the GDPR are met.
1.6 The provisions of this contract apply to all activities related to the main contract in which CONTRIMA and its employees or persons commissioned by CONTRIMA come into contact with personal data originating from you or collected on your behalf.
2.1 CONTRIMA shall process the contract data only within the scope of the contract and exclusively on your behalf and in accordance with your instructions within the meaning of Article 28 of the GDPR (processing on behalf of a controller); this applies in particular to the transfer of personal data to a third country. You have the sole right to issue instructions regarding the nature, scope and method of the processing activities (hereinafter also referred to as the ‘right to issue instructions’). If CONTRIMA is obliged to carry out further processing under the law of the European Union or the Member States to which it is subject, CONTRIMA shall inform you of these legal requirements prior to processing.
2.2 Instructions to CONTRIMA must, as a general rule, be given by you in writing (email address: info@contrima.com).
2.3 If CONTRIMA considers that one of your instructions contravenes data protection regulations, CONTRIMA must inform you of this without delay. CONTRIMA is entitled to suspend the implementation of the instruction in question until it is confirmed or amended by the client.
3.1 CONTRIMA is obliged to comply with the statutory provisions on data protection and not to disclose the information obtained from you to third parties or to prevent them from accessing it. Data must be secured against unauthorised access, taking into account the state of the art.
3.2 Furthermore, CONTRIMA shall require all persons entrusted by CONTRIMA with the processing and performance of this contract (hereinafter referred to as ‘employees’) to undertake in writing to maintain confidentiality (Obligation of confidentiality, Article 28(3)(b) of the GDPR) and shall ensure compliance with this obligation with due care. CONTRIMA shall provide you with evidence of this upon request.
3.3 CONTRIMA shall organise its internal operations in such a way as to meet the specific requirements of data protection. CONTRIMA undertakes to implement all appropriate technical and organisational measures to ensure the adequate protection of the commissioned data in accordance with Article 32 of the GDPR, in particular the measures set out in Annex 1 to this contract, and to maintain these for the duration of the processing of the commissioned data.
3.4 CONTRIMA reserves the right to amend the technical and organisational measures put in place, whilst ensuring that the level of protection agreed in the contract is not compromised. CONTRIMA must inform you in writing without delay if there is reason to believe that the measures set out in Annex 1 are no longer sufficient, and will consult with you regarding further technical and organisational measures.
3.5 At your request, CONTRIMA shall demonstrate compliance with the technical and organisational measures set out in Annex 1 by providing appropriate evidence.
4.1 In the event of disruptions, suspected data breaches or breaches of CONTRIMA’s contractual obligations, suspected security incidents or other irregularities in the processing of the contract data, whether by persons employed by CONTRIMA in the context of the contract or by third parties, CONTRIMA shall inform you without delay, but at the latest within 24 hours, in writing or by electronic means. The same applies to inspections of CONTRIMA by the data protection supervisory authority. Notifications pursuant to Section 4(1), first sentence, shall in each case contain at least the information specified in Article 33(3) of the GDPR.
4.2 In the event referred to in Section 4.1, CONTRIMA shall assist you, to the extent reasonably practicable, in fulfilling its relevant obligations to provide information, take remedial action and keep you informed. In particular, CONTRIMA shall immediately implement the necessary measures to secure the data and to mitigate any potential adverse consequences for the data subjects, and shall inform you accordingly.
4.3 CONTRIMA undertakes to provide you, upon your verbal or written request and within a reasonable period, with all information and evidence necessary to carry out an audit in accordance with § 7.1 of this contract. Furthermore, at your request, CONTRIMA will provide you with a comprehensive and up-to-date data protection and security policy for the processing of personal data, as well as a list of authorised access holders.
5.1 CONTRIMA is obliged to maintain a record of all categories of processing activities carried out on your behalf in accordance with Article 30(2) of the GDPR. This record must be made available to you upon request.
5.2 Should the data processed on your behalf at CONTRIMA be at risk due to attachment or seizure, insolvency or composition proceedings, or other events or measures taken by third parties, CONTRIMA must inform you of this without delay, provided this is not prohibited by a court or official order. In this context, CONTRIMA shall immediately inform all relevant authorities that decision-making authority over the data lies exclusively with the client as the ‘controller’ within the meaning of the GDPR.
6.1 The contractually agreed services shall be performed with the involvement of the subcontractors listed in Annex 2. CONTRIMA is authorised, within the scope of its contractual obligations, to enter into subcontracting relationships with subcontractors (‘subcontracting relationship’). Before entering into any further subcontracting relationships, CONTRIMA shall inform you in writing or by electronic means in accordance with Article 28(2) of the GDPR, giving four weeks’ notice. You may object to the change within two weeks of receiving the aforementioned notification.
6.2 A subcontracting relationship within the meaning of these provisions does not exist if CONTRIMA commissions third parties to provide services that are to be regarded as purely ancillary services. These include, for example, postal or telecommunications services with no specific connection to the services CONTRIMA provides for you, as well as other measures to ensure the confidentiality, availability, integrity and resilience of the hardware and software of data processing systems.
7.1 You are entitled to verify, on a regular basis, compliance with the provisions of this contract, in particular the implementation of and compliance with the technical and organisational measures set out in clause 3.3 of this agreement. To this end, you may, for example, request information, ask to be provided with certifications or internal audit reports, or have CONTRIMA’s technical and organisational measures inspected yourself during normal business hours or by a competent third party, provided that such third party is not in competition with CONTRIMA.
7.2 You shall carry out inspections only to the extent necessary and shall take due account of CONTRIMA’s operational processes. The parties shall agree in good time on the timing and nature of the inspection.
7.3 You shall document the results of the audit and notify CONTRIMA thereof. In the event of errors or irregularities which you identify, in particular when auditing the results of orders, you shall inform CONTRIMA without delay.
8.1 CONTRIMA shall, where possible, support you with appropriate technical and organisational measures in fulfilling your obligations under Articles 12 to 22 and Articles 32 to 36 of the GDPR. CONTRIMA shall provide you with the requested information regarding processing data without delay, but no later than within 7 working days, unless you already have the relevant information yourself.
8.2 If a data subject exercises their rights under Articles 16 to 18 of the GDPR, CONTRIMA is obliged, on your instructions, to rectify, erase or restrict the processing of the data without undue delay, and at the latest within 7 working days. CONTRIMA will provide you with written confirmation of the erasure, rectification or restriction of the data upon request.
8.3 If a data subject exercises rights – such as the right to access, rectification or erasure of their data – directly against CONTRIMA, CONTRIMA shall forward this request to you without delay and await your instructions. CONTRIMA shall not contact the data subject without specific instructions to do so.
9.1 The term of this contract corresponds to the term of the main contract. In case of doubt, termination of the main contract shall also be deemed to be termination of this contract, and termination of this contract shall be deemed to be termination of the main contract.
9.2 You are entitled at any time to terminate this contract extraordinarily for good cause. Good cause shall be deemed to exist if CONTRIMA fails to fulfil its obligations under this contract, breaches provisions of the GDPR intentionally or through gross negligence, or is unable or unwilling to carry out an instruction. In the case of minor breaches – i.e. those that are neither intentional nor due to gross negligence – you shall first set CONTRIMA a reasonable period within which CONTRIMA may remedy the breach. Once this period has expired without result, you shall then be entitled to terminate this contract without notice.
10.1 Upon termination of the main contract or at any time upon request, CONTRIMA shall return to you all data provided to CONTRIMA or, upon request, delete it completely and irrevocably, provided that no statutory retention period applies. This also applies to copies of the order data held by CONTRIMA, such as data backups, but not to documentation serving as evidence of the proper and compliant processing of the order data. Such documentation must be retained by CONTRIMA for the duration of the statutory retention periods.
10.2 You have the right to verify, in an appropriate manner, that the data has been returned or deleted by CONTRIMA in full and in accordance with the contract.
10.3 CONTRIMA is obliged to treat as confidential any data that has come to its knowledge in connection with the main contract, even after the main contract has ended.
11.1 The liability of the parties is governed by Article 82 of the GDPR. This does not affect CONTRIMA’s liability towards you for any breach of obligations arising from this contract or the main contract.
11.2 Each party shall be exempt from liability if it proves that it is in no way responsible for the circumstance that caused the damage to a data subject. Section 11(2), first sentence, shall apply mutatis mutandis in the event of a fine being imposed on a party, whereby the indemnification shall apply to the extent that the other party bears a share of the responsibility for the infringement sanctioned by the fine.
12.1 Any amendments or additions to this agreement must be made in writing in accordance with Article 28(9) of the GDPR. This also applies to any waiver of this formal requirement.
12.2 In the event of any doubt, the provisions of this Agreement shall take precedence over those of the main contract. Should any individual provisions of this Agreement prove to be wholly or partially invalid or unenforceable, or should they become invalid or unenforceable as a result of legislative changes following the conclusion of the Agreement, this shall not affect the validity of the remaining provisions. The invalid or unenforceable provision shall be replaced by a valid and enforceable provision that comes as close as possible to the meaning and purpose of the invalid provision.
12.3 This contract is governed by the law of the Federal Republic of Germany. CONTRIMA provides these terms and conditions in a variety of language versions for the sake of clarity. In the event of any discrepancies, the English version of this Data Processing Agreement shall prevail.
CONTRIMA is obliged to implement appropriate technical and organisational measures to ensure that the processing of the commissioned data is carried out in accordance with the statutory requirements and that the rights of the data subject are adequately safeguarded.
CONTRIMA shall structure its internal organisation in such a way as to meet the specific requirements of data protection. In particular, measures must be taken that are appropriate to the nature of the data or categories of data to be protected.
Specifically, the following measures are set out to implement the requirements of Article 32 of the GDPR:
| No. | Measure | Implementation of the measure |
|---|---|---|
| 1 | Access control | Productive data processing takes place exclusively in the AWS cloud; the physical data processing facilities there are secured by AWS (see AWS Terms of Service and certifications). Administration is carried out from an access-controlled workstation in lockable, non-publicly accessible rooms behind a firewall. There is no public access and no dedicated server rooms. |
| 2 | Access Control | System access is granted only via personal login with a username and password. Administrative and AWS accesses are protected by strong passwords and two-factor authentication. End devices are secured by operating system login, a firewall and disk encryption. |
| 3 | Access control | Role- and authorisation-based concept within the application, featuring centralised authorisation checks, server-side validation on all endpoints that modify data, protection against CSRF, and exclusively parameterised database access. At the infrastructure level, a minimum number of administrators (single-person operation) and the granting of rights in accordance with the principle of least privilege. |
| 4 | Segregation of duties | Multi-tenant logical separation of all data for each photographer via a unique owner assignment; separate production environment. Logical separation is sufficient. |
| 5 | Pseudonymisation / Data minimisation | Access for external parties via random, non-guessable tokens (permanent link). Only the data necessary for the respective purpose is collected (essentially the email address); identifying notes are deliberately kept brief and neutral. |
| 6 | Control of data disclosure | Transmission takes place exclusively via encrypted connections (TLS/HTTPS). Image and contract data are stored on encrypted object storage (S3 Server-Side Encryption). Data is transferred to subcontractors only to the extent necessary, on the basis of the Data Processing Agreement (DPA) or EU Standard Contractual Clauses. |
| 7 | Input control | Logging of audit-relevant operations at application level, in particular the acceptance of agreements and consents, including timestamps, IP addresses, device information and version hashes, as well as payment events. As the service is operated by a single person, every entry, modification and deletion can be traced back to a single individual. |
| 8 | Availability and Resilience | Database redundancy across multiple AWS zones or regions within the EU or the EEA; automated database snapshots as backups; code and server backups, as well as a pre-configured server image (AMI) for rapid recovery; additional local backup system; documented emergency and recovery plan. |
| 9 | Data Protection Management | The Managing Director of CONTRIMA GmbH is responsible. No data protection officer has been appointed, as there is no legal obligation to do so. Compliance with the information obligations under Article 13 of the GDPR during the activation process; an existing process for handling data subjects’ enquiries; and a register of processing activities maintained in accordance with Article 30 of the GDPR. |
| 10 | Incident Response Management | Firewall updated regularly; documented process for detecting and reporting data breaches in accordance with Articles 33 and 34 of the GDPR, including the immediate notification of the client. |
| 11 | Privacy-friendly default settings | Privacy by default: no data collected beyond what is necessary; image previews only with watermarks; original files provided only after authorisation has been granted; and the right to withdraw consent can be exercised easily via the user interface. |
| 12 | Contract management (sub-processors) | Careful selection; conclusion of data processing agreements or EU Standard Contractual Clauses (Module 3) with all sub-processors, with appropriate safeguards where third countries are involved; notification of the client prior to engaging or replacing sub-processors; ensuring data erasure upon termination of the contract. Currently used: Stripe (payment processing), Amazon Web Services (hosting/storage), DeepL (translation of advert copy). |
Sub-processors included under clause 6.1 of the agreement, to the use of whom you consent:
| Subcontractor (name, address or registered office) |
Scope of services within the framework of data processing |
|---|---|
| Stripe Payments Europe, Ltd. 1 Grand Canal Street Lower, Grand Canal Dock , Dublin, D02 H210, Ireland (“Stripe”) |
Payment processing; in the event of a sale, the purchaser’s payment, identity and transaction data (see also clause 6 of Privacy Policy) |
| Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg (“AWS”) |
Web and database hosting ; storage and processing of image data (originals, variants, archive, exports), including EXIF metadata. Email services (see also section 6 of Privacy Policy) |
| DeepL SE , Maarweg 165 , 50825 Cologne (“DeepL”) |
Where applicable, translation of the recognition note and, where applicable, the collection name into the language of the permanent link (see also 6. from Privacy Policy) |