Data Processing Agreement
This DPA is an inseparable annex to the Terms of Service and sets out, in accordance with Article 28(3) GDPR, how the platform operator (processor) processes the personal data of customers and the children depicted, on behalf of the Photographer (controller).
Effective from 1 August 2026
This is an informational translation provided for convenience. In case of any discrepancy, the Hungarian version prevails.
1. Parties
- Controller: the Photographer registered on the Platform — they decide the purposes and means of processing customer and child data.
- Processor: Imre Dobó, sole proprietor (Hajnal utca 14. 2/13., 4029 Debrecen, Hungary; tax number: 53669401-1-29; email: doboimre86@gmail.com) — operator of the Képesbolt platform.
The DPA enters into force together with the acceptance of the Terms of Service and remains in force for the duration of the service contract and until deletion of the data. Processing where the platform acts as controller is described in the Privacy Policy.
2. Subject matter, duration, nature and purpose
| Element | Content |
|---|---|
| Subject matter | processing of personal data related to photo orders placed in the Photographer's galleries |
| Duration | the term of the service contract + a 30-day grace period after termination |
| Nature | storage, organisation, display, transmission (to payment, invoicing and email providers), automated order processing, deletion |
| Purpose | receiving, fulfilling and keeping records of photo orders; serving gallery customers |
3. Data subjects and data categories
- Data subjects: visitors and customers of the Photographer's galleries (typically parents and family members) and the persons depicted — including children.
- Data categories: customer name, email, phone, billing and delivery details; order contents and comments; gallery access data (email gate, visit log: IP address, user agent); and photographs containing children's likeness.
4. Processing on documented instructions
The processor processes personal data only on the controller's documented instructions (Art. 28(3)(a)): the Terms, this DPA and the settings made by the Photographer in the admin interface. The processor informs the controller if an instruction appears to infringe the law, does not use the data for its own purposes and discloses it to no one except the sub-processors listed below, unless required by EU or Member State law.
5. Confidentiality
Persons authorised to access the data are bound by contractual or statutory confidentiality (Art. 28(3)(b)); access is limited to what is strictly necessary.
6. Security measures (Art. 32)
- TLS/HTTPS on every interface and API connection;
- provider keys and tokens stored encrypted (AES-256-GCM);
- bcrypt-hashed passwords; gallery access cookies contain no passwords;
- tenant-level access separation — each Photographer's data is isolated;
- tokenised, time-limited downloads (unique links valid for 30 days);
- gallery protection tools: password, email gate, scheduled access, watermark, search engine exclusion;
- logging and regular backups [TO BE VERIFIED — backup schedule].
7. Sub-processors
The controller gives general authorisation for the sub-processors below (Art. 28(2)). The processor imposes equivalent data protection obligations on them and notifies the controller of intended changes in advance; the controller may object.
| Sub-processor | Task | Location / safeguard |
|---|---|---|
| Hostinger International Ltd. | server infrastructure, storage | Cyprus (EU); EU data centre [TO BE VERIFIED] |
| Google Ireland Ltd. | photo storage for the Platform storage option | Ireland (EU); US transfers: EU-US DPF + SCC |
| SMTP2GO Ltd. | transactional emails (order confirmations, download links) | New Zealand — EU adequacy decision |
| Cloudflare, Inc. | CDN and network protection | USA — EU-US Data Privacy Framework |
8. Personal data breach notification
The processor notifies the controller of any personal data breach without undue delay — at the latest within 48 hours of becoming aware of it (Art. 33(2)) — describing its nature, the estimated scope of affected data and subjects, the likely consequences and the measures taken. Notifying the supervisory authority (72 hours) and the data subjects is the controller's obligation, in which the processor fully assists.
9. Assistance
Taking into account the nature of the processing, the processor assists the controller in responding to data subject requests (Art. 28(3)(e)) and in complying with Articles 32-36 (security, breach handling, data protection impact assessments; Art. 28(3)(f)). Requests received directly from data subjects are forwarded to the controller without delay.
10. Deletion and return at the end of the contract
On termination, at the controller's choice, the processor returns the data (via the export available in the interface) and/or deletes it (Art. 28(3)(g)). After a 30-day grace period all processed personal data is deleted or anonymised, unless EU or Member State law requires storage (e.g. accounting documents — 8 years, Act C of 2000, Section 169).
11. Audit
The processor makes available all information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits conducted by the controller or an auditor mandated by the controller (Art. 28(3)(h)) — at most once a year, with at least 15 days' prior written notice, protecting trade secrets and other customers' data.
12. Final provisions
This DPA is effective from 1 August 2026 (v1.0) and is amended together with the Terms of Service. In matters not regulated here, the GDPR, Hungarian Act CXII of 2011 and the Terms apply.
This document is an informational template — legal review is in progress.