Legal

Data Processing Agreement (DPA) under Art. 28 GDPR

Status: 11 August 2026 · All legal documents

Only the German version is legally binding. Switch the site language to Deutsch to read it.

Translation for information purposes. Only the German version is legally binding.


When this agreement applies

This agreement applies exclusively to business events — booked by a business, public authority, association or other organisation in the course of its activity. It becomes part of the contract automatically upon conclusion and does not need to be signed separately; a signed counterpart is available on request at privacy@snapories.com.

It does not apply to private events (wedding, birthday, family celebration). There, the booking person is as a rule outside the scope of the GDPR (household exemption, Art. 2(2)(c) GDPR) and we are an independent controller — there is no processing on behalf in that constellation.

Parties

Controllerthe booking organisation (the "Organiser")
ProcessorMatthias Anderer GmbH, Abt-Kaspar-Str. 19, 83607 Holzkirchen, Germany

§ 1 Subject matter, duration and binding instructions

1.1 The subject matter is the processing of personal data that we carry out on behalf of the Organiser when providing the services described in the Terms. The nature, purpose, scope, categories of data and data subjects are set out in Annex 1.

1.2 The agreement runs for the duration of the main contract, at the longest until all data processed on behalf has been deleted under § 9.

1.3 We process the data exclusively on the documented instructions of the Organiser. Instructions are given in text form to privacy@snapories.com; the settings provided in the product (event period, data region, visibility, downloads, blocking of images and guests, languages, deletion requests) constitute instructions.

1.4 If we consider an instruction to be unlawful, we will inform the Organiser without undue delay. We may suspend execution until confirmation or amendment (Art. 28(3) subpara. 2 GDPR).

1.5 Processing for our own purposes — contract performance and billing, operational and IT security, abuse prevention, aggregated metrics without personal reference, compliance with legal obligations — is not the subject of this agreement. To that extent we are an independent controller; the Privacy Policy applies.


§ 2 Place of processing

2.1 Processing takes place in the data region chosen at booking: European Union (Frankfurt am Main) or United States (Northern Virginia). Personal data is not mirrored between the regions. Storage, processing and deletion take place exclusively in that region; for the delivery of images they are, while the event is running, also cached transiently at edge locations outside the chosen region (Annex 3, section 1.1).

2.2 By way of exception, generation in the AI photobooth takes place at the AI provider used, including outside the EEA (Annex 3). The Organiser acknowledges this; if they disable the photobooth for their event, this transfer does not occur.

2.3 Transfers to third countries take place exclusively on the basis of an adequacy decision or the standard contractual clauses (Implementing Decision (EU) 2021/914) together with a transfer impact assessment.


§ 3 Confidentiality

3.1 We use only persons who are bound to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR).

3.2 The persons used are familiar with the relevant data-protection requirements and are instructed regularly.


§ 4 Technical and organisational measures

4.1 We implement the measures under Art. 32 GDPR described in Annex 2 and maintain them for the duration of the contract.

4.2 Measures may be developed further as long as the level of protection is not reduced. We document material changes and communicate them on request.


§ 5 Sub-processors

5.1 The Organiser grants general written authorisation for the engagement of sub-processors (Art. 28(2) sentence 2 GDPR). The sub-processors engaged as at the date of this agreement are listed by name in Annex 3.

5.2 Where we intend to engage a further sub-processor or replace an existing one, we will inform the Organiser at least 30 days in advance in text form. The Organiser may object within that period for an important, data-protection-related reason. If they object, we may adjust the affected service or terminate the contract by ordinary notice with effect from the planned change and refund the pro-rata fee.

5.3 We bind sub-processors to data-protection obligations that materially correspond to those agreed here, and we are liable for their conduct as for our own.


§ 6 Assistance to the Organiser

6.1 Data subject rights. Where data subjects approach us directly, we forward the request to the Organiser without undue delay and do not answer it ourselves in so far as it concerns the subject matter of the processing. We assist the Organiser by appropriate technical and organisational measures in fulfilling the rights under Art. 12–22 GDPR, in particular access, rectification, erasure, restriction and release of an event's images.

6.2 Obligations under Art. 32–36 GDPR. We assist the Organiser in ensuring the security of processing, in notifying personal data breaches and in carrying out a data protection impact assessment, in each case taking into account the nature of processing and the information available to us.

6.3 Effort. Assistance within the usual and reasonable scope is free of charge. For assistance going beyond what is legally owed and causing significant effort we may charge a reasonable fee; we will point this out in advance.


§ 7 Notification of personal data breaches

7.1 We inform the Organiser without undue delay after becoming aware of a personal data breach within the scope of the processing — as a rule within 24 hours.

7.2 The notification contains, to the extent available: a description of the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken and proposed, and a contact point.

7.3 Notification to the supervisory authority (Art. 33 GDPR) and communication to data subjects (Art. 34 GDPR) are the responsibility of the Organiser; we assist them.


§ 8 Evidence and audits

8.1 On request we make available to the Organiser all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR — primarily through documentation, Annex 2 and, where available, certificates and audit reports of our sub-processors.

8.2 Where that evidence is insufficient in an individual case, we allow for and contribute to audits, including inspections. These must be announced with reasonable notice (at least 14 days), must not unreasonably disrupt operations, and take place at most once a year — unless there is specific cause. Third-party auditors must not be competitors and must be bound to confidentiality.


§ 9 Deletion and return

9.1 After the end of processing we delete the data processed on behalf or return it, at the Organiser's choice. The Organiser can download an event's images from the dashboard at any time.

9.2 Absent a differing instruction, deletion takes place upon expiry of the storage period agreed in the Terms. On request we delete earlier.

9.3 Excluded from deletion is data subject to a statutory retention obligation; it is blocked from further use.

9.4 Deletion is confirmed in text form on request.


§ 10 Liability

Liability is governed by Art. 82 GDPR and the provisions of the main contract; the liability limitations of the main contract do not apply to claims of data subjects under Art. 82 GDPR.


§ 11 Relationship to the main contract

In the event of contradictions between this agreement and the main contract, this agreement prevails with respect to the processing of personal data.


§ 12 Final provisions

12.1 Amendments require text form. 12.2 German law applies. 12.3 Should a provision be invalid, the validity of the remainder is unaffected. 12.4 Binding language version.

Only the German version of this agreement is legally binding. Versions in other languages are provided for information purposes only. In the event of any discrepancy, the German version prevails.


Annex 1 — Subject matter of the processing

Nature and purpose. Collection, storage, structuring, display, provision and deletion of images and associated data for the purpose of operating a closed event gallery including an AI photobooth, on behalf of and on the instructions of the Organiser.

Data subjects

  • guests who join the event
  • persons depicted in contributed or generated images
  • employees of the Organiser who use the dashboard

Categories of data

CategoryContent
Image datafilm-roll photos, AI photobooth shots, generated images, thumbnails
Image metadatacapture time, dimensions, attribution to guest and event, block status, share flag
Participation dataself-chosen display name, role, quotas and their consumption, join time
Identity data (account-free)server-issued identifier and access token; no device fingerprint
Event dataevent name, period, join code, settings, languages, data region
Communication dataemail addresses of dashboard users, one-time codes
Text inputdescriptive text guests enter in the AI photobooth

No special categories. No biometric data for unique identification is created and no data under Art. 9 GDPR is processed intentionally. Images may by their nature reveal sensitive information; the Organiser assesses on their own responsibility whether their event requires particular precautions in that respect.


Annex 2 — Technical and organisational measures (Art. 32 GDPR)

Confidentiality

  • Physical access: exclusively data centres of certified providers (ISO 27001, SOC 2); we operate no hardware of our own.
  • System access: access to production systems only for named persons, via personalised accounts with two-factor authentication; access to the internal console via an explicitly configured address list.
  • Data access: role- and scope-bound tokens (event, host, partner, referral, staff); image files only via signed, short-lived retrieval links.
  • Separation: complete separation of the data regions (own databases, own storage areas, no cross-region mirroring); separation of the six surfaces onto their own domains with no shared browser storage; separation of test and production data.
  • Pseudonymisation: account-free identity via server-issued identifiers; IP addresses in the abuse counters are truncated and hashed, never stored in clear text.

Integrity

  • Transfer: TLS for all connections; no embedding of third-party scripts, fonts or analytics tools; payment data flows directly to the payment service provider.
  • Input: server-side validation of all input against a central, typed contract schema; logging of administrative operations; quota and cost counters using atomic operations to prevent double counting.

Availability and resilience

  • managed, redundant storage and database services with encryption at rest; automatic scaling of the application layer; hard cost ceilings for AI calls; abuse protection against automated bulk requests.

Procedures for review

  • automated test runs before every release (functional end-to-end tests, validation of the infrastructure description, automated reconciliation of every browser storage entry against a central registry);
  • documented receipt of instructions via a named address;
  • control of sub-processors under § 5 of this agreement.

Annex 3 — Sub-processors

The current Sub-processor list applies and forms part of this agreement. Changes are notified under § 5.2.