Data Processing Agreement
Version: 1.3
Last updated: 24 September 2026
Effective date: 25 September 2026
This Data Processing Agreement ("DPA") forms part of the PhotoLuxie Terms of Service or any other agreement governing the Customer's use of PhotoLuxie (the "Agreement"). It applies where PhotoLuxie processes Personal Data on behalf of the Customer in connection with the Service.
1. Parties
1.1 Customer
The Customer identified through the applicable PhotoLuxie account, subscription or order. The Customer acts:
- as a Controller where it determines the purposes and means of processing Personal Data; or
- as a Processor where it uses PhotoLuxie on behalf of another Controller.
1.2 PhotoLuxie
Aikaterini Seirli
Sole proprietorship
Registered office: 2 Konitsis Street, 184 54 Nikaia, Attica, Greece
VAT number: 167935800
Tax office: KEFODE Attikis
Privacy contact: [email protected]
Where this DPA applies, PhotoLuxie acts as a Processor on behalf of the Customer, or as a Subprocessor where the Customer itself acts as a Processor. The Customer and PhotoLuxie are together the "Parties".
2. Definitions
"Applicable Data Protection Law" means the General Data Protection Regulation (EU) 2016/679 ("GDPR"), Greek Law 4624/2019 and any other applicable European Union or Member State data-protection legislation.
"Controller", "Processor", "Personal Data", "Processing", "Data Subject", "Personal Data Breach" and "Supervisory Authority" have the meanings given to them under the GDPR.
"Customer Personal Data" means Personal Data contained in, derived from or associated with Customer Content that PhotoLuxie processes on behalf of the Customer.
"Customer Content" has the meaning given in the PhotoLuxie Terms of Service.
"Subprocessor" means a third party engaged by PhotoLuxie to Process Customer Personal Data on behalf of the Customer.
"Service" means the PhotoLuxie service described in the Agreement.
3. Scope and Purpose
This DPA governs PhotoLuxie's Processing of Customer Personal Data on behalf of the Customer. It does not govern Personal Data that PhotoLuxie processes independently as a Controller, such as account administration, subscription administration, payments and billing records, fraud prevention, account and platform security, PhotoLuxie's own legal compliance, illegal-content reports, and direct communications between PhotoLuxie and its Customers. That Processing is described in the PhotoLuxie Privacy Policy.
4. Processing on Documented Instructions
PhotoLuxie will Process Customer Personal Data only:
- on documented instructions from the Customer;
- as necessary to provide the Service; or
- where Processing is required by applicable European Union or Member State law.
In case 3, PhotoLuxie informs the Customer of that specific legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
The Agreement, this DPA, Customer settings, configuration choices and instructions submitted through the Service constitute documented instructions.
PhotoLuxie will not:
- sell Customer Personal Data;
- use Customer Personal Data for advertising;
- use Customer Content to train artificial-intelligence or machine-learning models without separate express authorization from the Customer; or
- determine new independent purposes for Customer Personal Data except where required by law.
If PhotoLuxie reasonably believes that an instruction infringes Applicable Data Protection Law, it will inform the Customer without undue delay and may suspend execution of that instruction while the Parties clarify its lawfulness.
5. Details of Processing
The subject matter, duration, nature and purpose of the Processing, and the categories of Personal Data and Data Subjects, are described in Annex I. The categories actually processed depend on how the Customer uses the Service.
6. Customer Responsibilities
The Customer is responsible for:
- determining the purposes and lawful basis of the Processing for which it uses PhotoLuxie;
- ensuring its instructions comply with Applicable Data Protection Law;
- providing required privacy information to Data Subjects, including its own clients and the people it records as vendors;
- obtaining consent where consent is required;
- ensuring that Customer Personal Data is relevant and appropriate for its purpose;
- ensuring any Processing of special categories of Personal Data satisfies Article 9 GDPR;
- complying with requirements concerning children's Personal Data;
- the legal validity of contracts it concludes with its own clients through the Service, including electronically signed contracts; and
- having authority to instruct PhotoLuxie to Process Customer Personal Data.
Where the Customer acts as a Processor for another Controller, it confirms that it is authorized by that Controller to appoint PhotoLuxie as a Subprocessor, to give instructions to PhotoLuxie and, where necessary, to agree to this DPA on the Controller's behalf.
Nothing in this section limits obligations that Applicable Data Protection Law places directly on PhotoLuxie.
7. Confidentiality
PhotoLuxie will ensure that persons authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations, receive access only where necessary for their role, and are informed of their data-protection and security obligations.
Access to Customer Personal Data by PhotoLuxie personnel is limited to technical support requested by the Customer, security investigation, operation and maintenance of the infrastructure, investigation of abuse or legal reports, and other purposes necessary to provide the Service.
8. Security of Processing
PhotoLuxie will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, and other unlawful Processing, taking account of the state of the art, implementation costs, the nature, scope, context and purposes of Processing, and the risks to individuals.
The current measures are described in Annex II. PhotoLuxie may change individual controls provided that the overall level of protection is not materially reduced.
9. Access Control and Tenant Separation
PhotoLuxie maintains technical controls that prevent one Customer from accessing another Customer's private Customer Content, including account-level authorization, per-Customer ownership checks on every database query and stored file, private storage, protected client-gallery access codes, unguessable links for shared documents, and session controls.
Customers are responsible for choosing who receives their gallery links and access codes.
10. Subprocessors
The Customer gives PhotoLuxie general written authorization to engage Subprocessors where necessary to provide the Service. The current Subprocessors are listed in Annex III, and PhotoLuxie will publish and maintain that list at https://app.photoluxie.com/legal/en/services.
Before a Subprocessor Processes Customer Personal Data, PhotoLuxie will have a written agreement with it imposing data-protection obligations no less protective in substance than those in this DPA, to the extent relevant to its services. PhotoLuxie remains responsible for its Subprocessors as required by Applicable Data Protection Law.
11. Changes to Subprocessors
PhotoLuxie will give Customers at least 15 calendar days' notice, by email, before a new or replacement Subprocessor begins Processing Customer Personal Data.
A Customer may object during that period on reasonable, documented data-protection grounds. The Parties will work in good faith to find a solution. If none is available, PhotoLuxie may allow the Customer to stop using the affected feature or to terminate the affected part of the Service or the subscription. An objection may not be used solely to avoid unrelated payment obligations.
12. International Data Transfers
PhotoLuxie stores Customer Content and its database in the European Union (see Annex III). Requests to the Service pass through the Subprocessor's global network, and the Subprocessor is established in the United States. PhotoLuxie ensures that any such transfer is permitted by Applicable Data Protection Law, relying on the recipient's certification under the EU–US Data Privacy Framework and on the European Commission's Standard Contractual Clauses incorporated in the recipient's data processing agreement, or on another mechanism under Chapter V GDPR. More information is available on request.
13. Data Subject Requests
Taking into account the nature of the Processing, PhotoLuxie will reasonably assist the Customer in responding to requests from Data Subjects exercising their rights of access, rectification, erasure, restriction, portability and objection. Where the Service lets the Customer fulfil a request itself (for example by editing or deleting a gallery, photo, contract or client record), the Customer should use that functionality.
If PhotoLuxie receives a request relating to Customer Personal Data, it will not respond to the substance of the request unless legally required, and will forward the request to the relevant Customer where the Customer can reasonably be identified. PhotoLuxie may verify a request before disclosing Customer information.
14. Assistance With GDPR Compliance
Taking into account the nature of Processing and the information available to it, PhotoLuxie will reasonably assist the Customer with its obligations relating to security of Processing, Personal Data Breaches, Data Protection Impact Assessments, prior consultation with a Supervisory Authority, and Data Subject rights. Where assistance requires substantial bespoke work beyond normal Service functionality, PhotoLuxie may charge reasonable costs where legally permitted, without this preventing fulfilment of obligations imposed directly by the GDPR.
15. Personal Data Breach
PhotoLuxie will notify the Customer without undue delay, and where feasible within 48 hours, after becoming aware of a Personal Data Breach involving Customer Personal Data. The notification will include the information reasonably available to PhotoLuxie that helps the Customer meet its own obligations, such as the nature of the incident, the systems and categories of data affected, the categories and approximate number of Data Subjects and records affected where known, the likely consequences, the measures taken or proposed, and a contact point. Information may be provided in phases as the investigation progresses.
Notification of an incident is not an admission of fault or liability. Where the Customer acts as Controller, it remains responsible for deciding whether to notify a Supervisory Authority or affected Data Subjects.
16. Security Incident Cooperation
After a Personal Data Breach involving Customer Personal Data, PhotoLuxie will take reasonable steps to investigate, contain and mitigate it, preserve relevant evidence, fix identified vulnerabilities and give relevant information to the Customer. PhotoLuxie may withhold information where necessary to protect another Customer, confidential security details, law-enforcement investigations or the security of the Service, but not information the Customer reasonably needs to comply with Applicable Data Protection Law.
17. Special Categories of Personal Data
Professional photography may contain information from which sensitive characteristics can be inferred, including religious beliefs (for example baptisms and religious weddings), health, or racial or ethnic origin. PhotoLuxie does not determine whether Customer Content constitutes special-category data. The Customer is responsible for determining whether such Processing is permitted and which conditions apply. PhotoLuxie Processes such data only under the Customer's documented instructions and this DPA.
18. Photographs and Biometric Data
PhotoLuxie does not perform facial recognition or any other Processing designed to uniquely identify individuals from Customer Content. Any future feature of that kind would require a separate assessment, updated documentation and appropriate safeguards before it is offered.
19. Children's Data
The Service may be used for photography involving children, including family, wedding, event and baptism photography. PhotoLuxie Processes such data only as instructed by the Customer. The Customer is responsible for the legal requirements that apply to photographing minors, processing their Personal Data, providing notices, obtaining permissions and sharing galleries that contain children. PhotoLuxie will not use Personal Data relating to children for advertising or profiling.
20. Deletion and Return of Customer Personal Data
While the account is active, the Customer can access, download and delete its Customer Content through the Service. Deleting a gallery removes its photos, previews, thumbnails, prepared download archives and related database records, including its visit records.
Return or deletion, at the Customer's choice. When the Customer stops using the Service, it chooses whether Customer Personal Data is returned to it or deleted. For return, the Customer downloads its photographs, videos and documents from the Service itself, which is also possible during the suspension in Section 21; anything that cannot be downloaded from the Service is sent to the Customer by PhotoLuxie in a common electronic format if the Customer asks at [email protected] before deletion. For deletion, the Customer asks at [email protected], and PhotoLuxie deletes the account and all Customer Personal Data, together with existing copies as described below, unless European Union or Member State law requires them to be kept.
When an account is deleted for any reason, including under the payment and Free-plan lifecycles in Section 21, PhotoLuxie permanently deletes the Customer Content and Customer Personal Data of that account from its active systems. The Customer is responsible for downloading anything it wishes to keep before deletion.
After permanent deletion, database records may remain in the database provider's point-in-time recovery for up to 30 days before they expire, and in the database backups described in Annex II (item 9). There they are not available for normal use and are restored only for genuine disaster recovery, in which case the deletion is re-applied. PhotoLuxie does not keep a separate copy of photographs or other stored files. PhotoLuxie may retain Personal Data only where and for as long as the law requires.
21. Payment and Free-Plan Data Lifecycle
Unpaid subscription. Where a subscription payment fails, or where the Customer's files do not fit in the Free plan after a subscription ends, the process in the PhotoLuxie Terms of Service applies:
- days 1–3: grace period — the Service works normally and the Customer is notified by email;
- from day 4: suspension — client galleries are closed and the dashboard becomes read-only, so the Customer can see and download its content, or pay to reopen everything;
- on day 7: the Customer is notified again by email, and from the following day the account and all its Customer Content may be permanently deleted without further notice.
Free plan. A Free account has no time limit. If it has not been signed into for 180 days, PhotoLuxie may warn the Customer by email; if the Customer does not sign in within 30 days of that warning, the account and all its Customer Content may be permanently deleted.
These lifecycles do not apply where PhotoLuxie has agreed otherwise with a Customer in writing. Nothing in this section permits PhotoLuxie to retain Customer Personal Data beyond what Applicable Data Protection Law allows.
22. Audit and Demonstration of Compliance
PhotoLuxie will make available the information reasonably necessary to demonstrate its compliance with this DPA. Where that documentation is not sufficient, the Customer may request an audit of PhotoLuxie's Processing of Customer Personal Data.
Unless required because of a Personal Data Breach, a Supervisory Authority request, credible evidence of material non-compliance or another compelling legal reason, audits should occur no more than once in any twelve-month period, be requested with reasonable notice, take place during normal business hours, minimize disruption to PhotoLuxie and other Customers, and be subject to confidentiality and security requirements. PhotoLuxie may satisfy a request through documentation, its Subprocessors' audit reports and certifications, or a remote review where these reasonably address the Customer's concern.
The Customer bears its own audit costs and may be asked to reimburse reasonable costs of unusually burdensome audits, unless the audit finds material non-compliance by PhotoLuxie. Nothing in this section restricts the rights of Supervisory Authorities.
23. Supervisory Authorities
PhotoLuxie will cooperate with competent Supervisory Authorities as required by Applicable Data Protection Law. Where legally permitted, PhotoLuxie will inform the Customer of a binding request from a Supervisory Authority or other public authority concerning Customer Personal Data, and will not disclose Customer Personal Data to a public authority unless legally required, instructed by the Customer, or another lawful basis applies.
24. Government and Law-Enforcement Requests
Where PhotoLuxie receives a legally binding demand for Customer Personal Data, it will review the request's apparent validity, disclose only the data required, challenge or seek clarification where appropriate, and notify the affected Customer where legally permitted.
25. Records and Accountability
PhotoLuxie keeps a record of processing activities as required by Article 30(2) GDPR, and documentation of its Subprocessors, transfer mechanisms, security measures and incident-response procedures.
26. Processing Outside Customer Instructions
If PhotoLuxie determines the purposes and means of Processing outside the Customer's documented instructions, it acts as Controller for that separate Processing to the extent provided by Applicable Data Protection Law. PhotoLuxie will not recharacterize Processor activities as Controller activities to avoid its Processor obligations.
27. Liability
Each Party remains responsible for its own compliance with Applicable Data Protection Law. Liability under this DPA is subject to the liability provisions of the Agreement to the extent permitted by Applicable Data Protection Law. Nothing in the Agreement or this DPA limits the rights of Data Subjects, the powers of a Supervisory Authority, or liability that cannot legally be limited.
28. Duration
This DPA takes effect when the Customer accepts the Agreement or begins using the Service in a way that makes PhotoLuxie Process Customer Personal Data on its behalf, and remains in effect for as long as PhotoLuxie does so. Provisions on confidentiality, deletion, security, audit, liability and other obligations that by their nature survive termination remain in effect while any Customer Personal Data remains in PhotoLuxie's possession or control.
29. Conflict With Other Terms, Language
If this DPA conflicts with another provision of the Agreement regarding Processing of Customer Personal Data, this DPA prevails to the extent of the conflict. If mandatory Standard Contractual Clauses conflict with this DPA, those clauses prevail for the relevant transfer.
This DPA is available in Greek and English. If the two versions differ, the Greek version prevails.
30. Governing Law
This DPA is governed by the law governing the Agreement (Greek law), subject to the mandatory provisions of Applicable Data Protection Law.
Annex I — Details of Processing
A. Subject matter. Provision of the PhotoLuxie photography-gallery, client-delivery, storage and studio-workflow Service.
B. Duration. For as long as the Customer uses the Service, during the grace period and the suspension of Section 21 until the account is deleted, and for the limited recovery window described in Section 20.
C. Nature of Processing. Upload, storage, organization, display, generation of previews and thumbnails, generation of download archives (including the optional prepared full-gallery ZIP), generation of PDF files (contracts, day schedules), delivery to authorized recipients, access control, recording gallery visits, technical support, security analysis and deletion.
D. Purposes.
- hosting photography galleries and delivering photos and videos to the Customer's clients;
- controlling access to galleries;
- letting clients mark favorite photos, including their choice of photos for an album;
- client questionnaires, contracts with electronic signature, and day schedules;
- the Customer's own studio organization: shoots, locations, private notes, vendors and referrals, pricing guides, and income/expense and VAT entries;
- showing the Customer statistics on gallery visits and downloads;
- providing technical support and securing the Service.
E. Categories of Data Subjects. Depending on the Customer's use:
- the Customer's clients (for example couples, parents, families, event organizers);
- children and minors appearing in photographs or named in client information;
- guests, attendees and people appearing incidentally in photographs;
- visitors of client galleries;
- people completing questionnaires or signing contracts;
- the Customer's vendors and the people referred between them;
- counterparties in the Customer's income/expense and VAT entries;
- the Customer's staff and team members with access to the account.
F. Categories of Personal Data. Depending on the Customer's use:
- Identity and contact: names, email addresses, telephone numbers, Instagram handles, and relationship information.
- Photos and video: photographs, videos, previews, thumbnails, file names and image metadata.
- Event information: event type, date and time, locations, gallery names, and gallery sections.
- Client interaction: favorite photos, questionnaire answers, downloads, and gallery-access records.
- Contracts: contract text and terms, the signer's name, an image of the handwritten signature, and the date and status of signing.
- Studio workflow: private notes, day schedules (including PDF files), shoot preparation status, vendors and referrals, pricing guides (PDF files), and deposit and balance payment status.
- Bookkeeping: income and expense entries with description, counterparty name, amounts and VAT.
- Technical: IP addresses and browser/device information of gallery visitors and of failed access-code attempts, with timestamps. The IP address and device information in gallery visit records are erased automatically after 90 days; the visit itself (date, gallery, action) is kept for the Customer's statistics until the gallery is deleted. Records of failed login and access-code attempts are kept for at most one day.
G. Special categories. Depending on the Customer Content, data revealing religious beliefs, racial or ethnic origin, health or other Article 9 categories, as described in Section 17.
H. Frequency. Continuous, according to the Customer's use of the Service.
Annex II — Technical and Organizational Measures
- Encryption in transit. All connections to the Service use HTTPS/TLS. Login cookies are restricted to secure connections and cannot be read by page scripts.
- Storage. Files are stored in private object storage that is not publicly accessible. They are served only through the Service after an access check, except documents the Customer explicitly shares through an unguessable link.
- Account authentication. Account passwords are never stored in readable form: only a salted, iterated verifier is kept. Login and recovery attempts are rate-limited, sessions expire, and account recovery uses one-time recovery codes that are also stored only as hashes.
- Client gallery access codes. Gallery access codes are stored so that the Customer can view and resend them to its clients. Wrong-code attempts are rate-limited per visitor.
- Authorization and tenant isolation. Every database query and stored file is bound to the Customer account that owns it, and automated tests check that one account cannot read another account's data.
- Secrets. Production secrets are kept in the hosting provider's encrypted secret store, never in the source code or its repository.
- Logging. Gallery visits and downloads are recorded so the Customer can see them, and so that problems and abuse can be investigated. Retention is stated in Annex I.
- Infrastructure. The Service runs on the infrastructure of a major provider (Annex III), which includes network protection, DDoS mitigation and physical security. Dependencies are updated and identified vulnerabilities are fixed.
- Recovery and deletion. The database can be restored to any point in the last 30 days using the provider's point-in-time recovery. In addition, before changes to the system, the system operator keeps a temporary copy of the database (not of the photographs and other files) on an encrypted computer in Greece, to carry out the change safely and to recover if something goes wrong; the copy is not used for any other purpose and is deleted within 7 days. Deletion removes files, previews, thumbnails, archives and database records together.
- Personnel access. Access to production systems is limited to the operator, protected by account authentication, and reviewed when roles change.
- Incident response. PhotoLuxie follows a written procedure to identify, contain, investigate and recover from incidents, and to notify Customers as described in Section 15.
- Development. Changes are tried first on a separate test copy that uses fake data, and are checked with automated tests, including access-isolation tests, before they reach production. Test and production use separate credentials and data.
- Review. These measures are reassessed when the architecture, features or risks change.
Annex III — Subprocessors
| Provider | Purpose | Data | Location / transfer mechanism |
|---|---|---|---|
| Cloudflare, Inc. (and Cloudflare group entities) | Application hosting (Pages/Functions), database (D1), file storage (R2), content delivery and network security | All Customer Content and Customer Personal Data | Database stored under EU jurisdiction and files in the Eastern Europe (EEUR) storage region. Requests pass through Cloudflare's global network. EU–US Data Privacy Framework certification and Standard Contractual Clauses in Cloudflare's data processing agreement |
Other providers, which do not process Customer Personal Data. PhotoLuxie also uses Resend (Plus Five Five, Inc., USA) for the emails it sends to the Customer itself (sign-up codes, account and subscription notices) and for the confirmation of receipt sent to people who submit content reports, and Stripe (Stripe Payments Europe, Limited, Ireland) for subscription payments. The Service does not email the Customer's clients, and Stripe receives no Customer Content. That processing is carried out for PhotoLuxie itself and is described in the Privacy Policy. If either of them starts processing Customer Personal Data, it will be added here with the notice in Section 11.
Annex IV — Customer Instructions
Unless otherwise agreed in writing, the Customer instructs PhotoLuxie to:
- store Customer Content;
- process Customer Content technically as necessary to provide the features the Customer uses;
- make Customer Content available to the people the Customer authorizes through galleries, access codes and shared links;
- create previews, thumbnails, download archives and PDF files;
- record gallery visits and downloads and show them to the Customer;
- use the Subprocessors in Annex III;
- delete Customer Personal Data on the Customer's request and under the lifecycles in Section 21; and
- carry out any other Processing reasonably necessary to deliver the PhotoLuxie features the Customer uses.
Acceptance
This DPA forms part of the PhotoLuxie Agreement and does not require a handwritten signature: the Customer accepts it electronically together with the Terms of Service by ticking the box for them, and PhotoLuxie keeps a record of the version and time of acceptance.
Controller / Customer: the PhotoLuxie Customer identified by the relevant account.
Processor: Aikaterini Seirli, operating PhotoLuxie.
It takes effect when the Customer accepts the PhotoLuxie Terms of Service or another Agreement that incorporates this DPA.