Data Processing Addendum (United States)
Welche Fassung gilt für Sie? Die Fassung des Landes, in dem Ihr Unternehmen seinen Sitz hat. Sie wird bei der Registrierung festgelegt.
Für alle Fassungen gilt deutsches Recht, Gerichtsstand Duisburg.
Service provider terms under the CCPA/CPRA and comparable state privacy laws · Effective: September 7, 2026 · Version 1.0 (US)
This Data Processing Addendum (DPA) is accepted electronically at registration on Pixalo (checkbox, timestamp, IP address, version). It forms part of the Terms of Service (US). In the event of conflict regarding the processing of personal data, this DPA prevails.
1. Parties and roles
The Customer is the business registered on Pixalo (photographer or company) established in the United States that uses the platform to process personal information. Pixalo (Cloudox, business division Pixalo, Oststrasse 181, 47057 Duisburg, Germany; contracting party Erol Demirkoparan, doing business as Cloudox) provides the Service.
For personal information the Customer uploads to or collects through the Service, the Customer is the "business" or "controller" and Pixalo is the "service provider" or "processor" within the meaning of the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, the Texas Data Privacy and Security Act and comparable US state privacy laws (together, State Privacy Laws). Where the Customer acts as a service provider for a school or other organization, Pixalo acts as its subcontractor.
2. Description of the processing
Subject matter: provision of the Pixalo platform for organizing photo days, matching photos to children by QR photo card, publishing access-code protected galleries and client galleries, operating the Customer's online store and processing orders, invoices, credit notes, lab exports, appointment bookings and customer communication.
Duration: the term of the Terms of Service (US). Nature and purpose: hosting, storage, organization, adaptation (resizing, watermarking), retrieval, transmission, restriction and deletion by automated means, solely to provide the Service to the Customer. Details are set out in Annex 1.
3. Categories of personal information and individuals
- Photographs of children and adults, including group photos, and photo card data (QR codes, names or identifiers used for matching)
- Student and class information (first name, last name, class or group, school) imported from class lists
- Customer data: names, email addresses, postal addresses, phone numbers, order and payment status, invoice data, download and access logs
- Contacts at schools and other client organizations; appointment bookings
- Technical data: IP addresses, device and browser information, security logs
- Individuals: photographed persons including children, parents and guardians, store customers, school contacts, persons who book appointments, and the Customer's staff
4. Service provider obligations
Pixalo will:
- process personal information only on behalf of the Customer and for the specific business purpose of providing the Service as described in this DPA and the Terms, and not for any other purpose
- not sell or share personal information (as those terms are defined in the CCPA), and not use it for cross-context behavioral advertising
- not retain, use or disclose personal information outside the direct business relationship with the Customer, or for any purpose other than the business purposes specified, except as permitted by State Privacy Laws
- not combine personal information received from the Customer with personal information received from other customers or collected from its own interactions with individuals, except as permitted by State Privacy Laws (for example to detect security incidents or to improve the Service without building profiles)
- comply with applicable State Privacy Laws and provide the same level of privacy protection as they require; notify the Customer if it determines that it can no longer meet its obligations under State Privacy Laws
- allow the Customer to take reasonable and appropriate steps to ensure that Pixalo uses personal information consistently with the Customer's obligations, and to stop and remediate unauthorized use, including by providing information on request and allowing reasonable assessments no more than once a year
- assist the Customer, through appropriate technical and organizational measures and the functions of the dashboard, in responding to verifiable consumer requests (access, deletion, correction, portability, opt-out) and in conducting data protection assessments where required
- impose written obligations at least as protective as those in this DPA on subcontractors listed in Annex 2 and notify the Customer of any new subcontractor at least 30 days in advance, giving the Customer the opportunity to object
- implement reasonable security procedures and practices appropriate to the nature of the information (Annex 3) and notify the Customer of a security breach affecting the Customer's personal information without undue delay and no later than 48 hours after becoming aware of it, with the information available at that time, so that the Customer can meet its notification duties under state breach notification laws
- at the end of the Service, delete or return all personal information at the Customer's choice, unless retention is required by law, and delete existing copies
- certify that it understands the restrictions in this Section and will comply with them
- if Pixalo receives a request from a consumer or a third party concerning the Customer's personal information, not respond on the Customer's behalf unless required by law or instructed by the Customer, and forward the request to the Customer without undue delay where the Customer can be identified from the request
5. Customer obligations
- The Customer is responsible for the lawfulness of the collection and use of personal information, including obtaining the consents and releases required to photograph children and other persons and to publish and sell their images, for notices to consumers (privacy policy for parents and customers), and for the accuracy of the data it uploads.
- The Customer is responsible for the settings it selects in the dashboard (download period, gallery expiry, retention, access codes) and for informing its customers about them.
- The Customer will use the Service in compliance with school and district policies, State Privacy Laws and, where applicable, student privacy laws.
- The Customer will promptly inform Pixalo of any consumer request that requires Pixalo's assistance and of any errors or irregularities it identifies in the processing.
6. Children's information
Pixalo's Service is directed to photographers and to parents and guardians, not to children, and Pixalo does not knowingly collect personal information directly from children under 13. Photographs and names of children are provided by the Customer or by schools and are processed solely on the Customer's behalf. To the extent the Children's Online Privacy Protection Act (COPPA) applies to the Customer's activities, the Customer is responsible for obtaining verifiable parental consent, and Pixalo processes such information only as the Customer's service provider for internal operations. Store accounts are created by adults; children are not permitted to create accounts.
7. Data location and transfers
Pixalo processes and stores personal information in the European Union (AWS region Frankfurt, Germany). Personal information originating in the United States is transferred to the European Union for processing. No US federal law restricts such transfers; the Customer acknowledges that data is hosted outside the United States and that Pixalo is subject to the laws of Germany and the European Union, including the GDPR, which provide a high level of protection. Limited technical data is processed by content delivery and security providers on a global network (Annex 2).
8. Liability and term
Liability is governed by the Terms of Service (US). This DPA applies for as long as Pixalo processes personal information on behalf of the Customer; obligations that by their nature continue after termination (confidentiality, deletion, assistance with pending consumer requests) survive. Material changes to this DPA require the Customer's express acceptance in the dashboard.
This DPA is governed by the laws of the Federal Republic of Germany with exclusive jurisdiction of the courts of Duisburg, Germany, as set out in the Terms of Service (US). The obligations under applicable State Privacy Laws apply regardless of this choice of law.
Annex 1: Description of the processing
Processing activities
- Upload, storage and organization of photos; generation of watermarked previews
- Matching photos to children via QR photo cards; import of class lists (including AI-assisted text recognition of list photos in the EU)
- Publication of access-code protected galleries and client galleries; delivery of previews and originals
- Order processing, invoicing, credit notes, refunds, lab export files
- Customer accounts, downloads, email notifications (access codes, order confirmations, reminders)
- Appointment bookings and reminders
- Statistics and security logging
Retention and deletion
- Galleries and photos: retained for the term of the agreement and deleted by the Customer's settings and deletion functions; unassigned photos are cleaned up automatically after the quarantine period
- Download links: valid for the period set by the Customer (7 to 90 days from the order, default 7 days); generated ZIP archives are deleted automatically after expiry
- Customer and order data: for the term of the agreement plus statutory retention periods for invoices and accounting records
- Database backups: rolling, currently seven days
- After termination: deletion or return in accordance with Section 4
Annex 2: Subcontractors (sub-processors)
| Service | Provider | Location |
|---|---|---|
| Cloud hosting (operation of the platform on Amazon EC2, including infrastructure monitoring) | Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg | EU, Frankfurt region (eu-central-1) |
| Object storage for media files (Amazon S3) | Amazon Web Services EMEA SARL, Luxembourg | EU, Frankfurt region (eu-central-1) |
| Database and daily backups (Amazon RDS) | Amazon Web Services EMEA SARL, Luxembourg | EU, Frankfurt region (eu-central-1) |
| Content delivery (Amazon CloudFront) | Amazon Web Services EMEA SARL, Luxembourg | Worldwide edge locations, including the United States |
| Email dispatch (Amazon SES): transactional and notification emails | Amazon Web Services EMEA SARL, Luxembourg | EU, Frankfurt region (eu-central-1) |
| AI-assisted text recognition for class lists (Amazon Bedrock, Anthropic models) | Amazon Web Services EMEA SARL, Luxembourg | EU inference only (Frankfurt region); inputs and outputs are not used to train models |
| DNS, reverse proxy/CDN, TLS termination and DDoS protection for all Pixalo domains | Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA | Global network; IP addresses, request metadata and security logs |
| Subscription billing for the Customer's Pixalo subscription (not for the Customer's own store payments) | Stripe, Inc., 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA, and Stripe Payments Europe, Ltd. | United States / EU |
Annex 3: Security measures (summary)
- Hosting in ISO 27001 certified data centers in Frankfurt; no physical access by Pixalo staff
- Multi-factor authentication for administrative access; role-based access; least privilege; logged administrative actions
- Tenant isolation at database level (row level security); access-code protected galleries; signed download links with expiry; watermarked previews
- TLS encryption for all connections; encryption at rest for databases, storage and backups
- Audit logs for orders, consents and administrative changes; consent records with timestamp, IP address and document version
- Daily automated backups with rolling retention; redundant infrastructure; DDoS protection; monitoring and alerting
- Logical separation of tenants; separate test and production environments
- Deletion functions in the dashboard; automated clean-up of expired archives and unassigned photos; deletion at the end of the agreement
- Change control: source code under version control; changes reach production only through a versioned deployment with automated type, security and consistency checks; no credentials in source code, secrets held in an encrypted store
- Recovery: documented backup and restore procedure; restore tests from backups at regular intervals
- Subcontractor control: written data processing agreements with all subcontractors; EU Standard Contractual Clauses or equivalent transfer mechanisms where data leaves the EU
- Security testing: automated security and consistency checks before every deployment; internal adversarial review of changed areas; findings are fixed before release