Data Processing Agreement (United Kingdom)
Welche Fassung gilt für Sie? Die Fassung des Landes, in dem Ihr Unternehmen seinen Sitz hat. Sie wird bei der Registrierung festgelegt.
Für alle Fassungen gilt deutsches Recht, Gerichtsstand Duisburg.
Under Article 28 UK GDPR and the Data Protection Act 2018 · Effective: 7 September 2026 · Version 1.0 (UK)
This Data Processing Agreement (DPA) is concluded electronically at registration on Pixalo (checkbox, timestamp, IP address, version). It forms part of the Terms of Service (UK). In the event of conflict regarding the processing of personal data, this DPA prevails.
1. Parties and roles
1.1 Client
The Client is the customer registered on Pixalo (photographer or company) established in the United Kingdom who uses the platform to process personal data. The Client is the controller of the personal data it uploads and collects through the Service, or, where the Client itself acts as processor for a school, nursery or other organisation, the Client's customer is the controller and the Client engages Pixalo as sub-processor with that controller's authorisation.
1.2 Processor
Cloudox, business division Pixalo, Oststrasse 181, 47057 Duisburg, Germany (contracting party: Erol Demirkoparan, trading as Cloudox), email [email protected] (Pixalo, the Processor). Pixalo is established in Germany and is a processor within the meaning of Article 4(8) UK GDPR.
1.3 UK representative
Pixalo has no establishment in the United Kingdom. Where Article 27 UK GDPR requires it, Pixalo appoints a representative in the United Kingdom; the representative's details are published in the Privacy Notice (UK addendum) and updated there.
2. Subject matter, duration, nature and purpose
Subject matter: provision of the Pixalo platform for organising photo days, matching photos to children by QR photo card, publishing access-code protected galleries and client galleries, operating the Client's online shop and processing orders, invoices, credit notes, lab exports, appointment bookings and customer communication.
Duration: for the term of the Terms of Service (UK). Nature: storage, organisation, adaptation (resizing, watermarking), retrieval, transmission, restriction and erasure by automated means. Purpose: performance of the contract between Pixalo and the Client and, through the Client, between the Client and its customers.
Details are set out in Annex 1.
3. Categories of data and data subjects
- Photographs of children and adults, including group photos, and photo card data (QR codes, names or identifiers used for matching)
- Master data of children and classes (first name, surname, class or group, school or nursery) imported from class lists
- Customer data: names, email addresses, postal addresses, telephone numbers, order and payment status, invoice data, download and access logs
- Contact persons of schools, nurseries and other clients
- Appointment bookings and related contact data
- Technical data: IP addresses, device and browser information, security logs
- Data subjects: photographed persons including children, parents and guardians, customers of the online shop, contact persons of institutions, persons who book appointments, and the Client's staff
4. Obligations of the Processor (Article 28(3) UK GDPR)
- (a) Instructions: Pixalo processes personal data only on the Client's documented instructions, including with regard to transfers to a third country, unless required to do so by domestic law; in that case Pixalo informs the Client before processing unless the law prohibits it. Use of the platform functions and the settings the Client selects (for example the download period, gallery visibility, retention settings) constitute documented instructions. Pixalo will inform the Client if, in its opinion, an instruction infringes the UK GDPR.
- (b) Confidentiality: persons authorised to process personal data are bound by confidentiality obligations.
- (c) Security: Pixalo implements the technical and organisational measures required by Article 32 UK GDPR, summarised in Annex 3, and reviews them regularly.
- (d) Sub-processors: the Client gives general authorisation for the sub-processors listed in Annex 2. Pixalo informs the Client of intended additions or replacements at least 30 days in advance by email or in the dashboard; the Client may object on reasonable data protection grounds within that period. If no solution is found, the Client may terminate the affected service. Pixalo imposes the same data protection obligations on sub-processors by contract and remains fully liable to the Client for their performance.
- (e) Data subject rights: taking into account the nature of the processing, Pixalo assists the Client with appropriate technical and organisational measures in responding to requests to exercise data subject rights (access, rectification, erasure, restriction, portability, objection), in particular through export and deletion functions in the dashboard.
- (f) Assistance: Pixalo assists the Client in ensuring compliance with Articles 32 to 36 UK GDPR (security, personal data breach notification, data protection impact assessments, prior consultation), taking into account the nature of the processing and the information available to Pixalo. Pixalo notifies the Client of a personal data breach affecting the Client's data without undue delay and no later than 48 hours after becoming aware of it, with the information available at that time.
- (g) Deletion or return: at the end of the provision of services Pixalo deletes all personal data or returns it to the Client, at the Client's choice, and deletes existing copies, unless domestic law requires storage. Media files and galleries are deleted according to the retention mechanisms described in Annex 1; invoice and accounting records subject to statutory retention are archived in blocked form for the statutory period.
- (h) Information and audits: Pixalo makes available all information necessary to demonstrate compliance with Article 28 UK GDPR and allows for and contributes to audits, including inspections, conducted by the Client or an auditor mandated by the Client, with reasonable notice and during business hours, no more than once a year unless a supervisory authority requires otherwise or a breach has occurred. Pixalo may first satisfy audit requests by providing current certifications and reports of its sub-processors.
- (i) Requests received directly: if Pixalo receives a request from a data subject or a third party concerning the Client's data, Pixalo does not respond on the Client's behalf unless required by law or instructed by the Client. Pixalo forwards the request to the Client without undue delay where the Client can be identified from the request.
5. Obligations of the Client
- The Client is responsible for the lawfulness of the processing, in particular for a lawful basis to photograph children and other persons and to publish and sell the images, for information to data subjects (privacy notice for parents and customers), and for the accuracy of the data it uploads.
- The Client informs Pixalo without undue delay if it identifies errors or irregularities in the processing.
- The Client is responsible for the settings it selects in the dashboard (download period, gallery expiry, retention, access codes) and for informing its customers about them.
- The Client is responsible for registering with the Information Commissioner's Office (ICO) and paying the data protection fee where required.
6. International transfers
Pixalo processes and stores personal data in the European Union (AWS region Frankfurt). Transfers from the United Kingdom to the European Union are permitted under the UK adequacy regulations for the EU and EEA. Transfers from the European Union to the United Kingdom (for example returning data to the Client) are covered by the European Commission's adequacy decision for the United Kingdom.
Where a sub-processor processes limited technical data outside the UK and the EU (content delivery and security services, see Annex 2), the transfer is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses or an equivalent transfer mechanism in the sub-processor's data processing terms, and by additional safeguards (encryption in transit, minimisation).
7. Liability and term
Liability is governed by the Terms of Service (UK) and by Article 82 UK GDPR. This DPA applies for as long as Pixalo processes personal data on behalf of the Client. Obligations that by their nature continue after termination (confidentiality, deletion, assistance with data subject requests relating to the term) survive termination.
Amendments to this DPA follow the change procedure of the Terms of Service (UK). Material changes to this DPA require the Client's express acceptance in the dashboard.
This DPA is governed by the laws of the Federal Republic of Germany with exclusive jurisdiction of the courts of Duisburg, Germany, as set out in the Terms of Service (UK). The obligations under the UK GDPR and the Data Protection Act 2018 apply regardless of this choice of law.
Annex 1: Description of the processing
Processing activities
- Upload, storage and organisation of photos; generation of watermarked previews
- Matching photos to children via QR photo cards; import of class lists (including AI-assisted text recognition of list photos in the EU)
- Publication of access-code protected galleries and client galleries; delivery of previews and originals
- Order processing, invoicing, credit notes, refunds, lab export files
- Customer accounts, downloads, email notifications (access codes, order confirmations, reminders)
- Appointment bookings and reminders
- Statistics and security logging
Retention and deletion
- Galleries and photos: retained for the term of the contract and deleted by the Client's settings and deletion functions; unassigned photos are cleaned up automatically after the quarantine period
- Download links: valid for the period set by the Client (7 to 90 days from the order, default 7 days); generated ZIP archives are deleted automatically after expiry
- Customer and order data: for the term of the contract plus statutory retention periods for invoices and accounting records
- Database backups: rolling, currently seven days; media files follow the retention mechanisms above
- After termination: deletion or return in accordance with Section 4(g)
Annex 2: Sub-processors
| Service | Provider | Region / transfer basis |
|---|---|---|
| Cloud hosting (operation of the platform on Amazon EC2, including infrastructure monitoring) | Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg | EU, Frankfurt region (eu-central-1) |
| Object storage for media files (Amazon S3) | Amazon Web Services EMEA SARL, Luxembourg | EU, Frankfurt region (eu-central-1) |
| Database and daily backups (Amazon RDS) | Amazon Web Services EMEA SARL, Luxembourg | EU, Frankfurt region (eu-central-1) |
| Content delivery (Amazon CloudFront) | Amazon Web Services EMEA SARL, Luxembourg | Worldwide edge locations; AWS data processing addendum with UK Addendum to the EU Standard Contractual Clauses |
| Email dispatch (Amazon SES): transactional and notification emails | Amazon Web Services EMEA SARL, Luxembourg | EU, Frankfurt region (eu-central-1) |
| AI-assisted text recognition for class lists (Amazon Bedrock, Anthropic models) | Amazon Web Services EMEA SARL, Luxembourg | EU inference only (Frankfurt region); inputs and outputs are not used to train models |
| DNS, reverse proxy/CDN, TLS termination and DDoS protection for all Pixalo domains | Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA | Global network; IP addresses, request metadata and security logs; Cloudflare DPA with UK Addendum to the EU Standard Contractual Clauses |
| Subscription billing for the Client's Pixalo subscription (not for the Client's own shop payments) | Stripe Payments Europe, Ltd., Dublin, Ireland | EU / UK; Stripe data processing terms |
Annex 3: Technical and organisational measures (summary)
- Access control: hosting in ISO 27001 certified data centres in Frankfurt; no physical access by Pixalo staff
- System access control: multi-factor authentication for administrative access; role-based access; least privilege; logged administrative actions
- Data access control: tenant isolation at database level (row level security); access-code protected galleries; signed download links with expiry; watermarked previews
- Transmission control: TLS encryption for all connections; encryption at rest for databases, storage and backups
- Input control: audit logs for orders, consents and administrative changes; consent records with timestamp, IP address and document version
- Availability control: daily automated backups with rolling retention; redundant infrastructure; DDoS protection; monitoring and alerting
- Separation control: logical separation of tenants; separate test and production environments
- Deletion: deletion functions in the dashboard; automated clean-up of expired archives and unassigned photos; deletion at the end of the contract
- Change control: source code under version control; changes reach production only through a versioned deployment with automated type, security and consistency checks; no credentials in source code, secrets held in an encrypted store
- Recovery: documented backup and restore procedure; restore tests from backups at regular intervals
- Sub-processor control: data processing agreements with all sub-processors; EU Standard Contractual Clauses or the UK Addendum where data leaves the UK and the EU
- Security testing: automated security and consistency checks before every deployment; internal adversarial review of changed areas; findings are fixed before release