Právní dokumenty
Data Processing Agreement (DPA)
Part of the contract with every host who uses Pixelka or Pozýva in the course of business or any activity that is not purely personal (company, agency, school, association, public body). Concluded electronically by accepting the Terms of Service; on request we also sign it on paper. This is a translation; in case of doubt the Slovak version prevails.
- Parties
- Subject matter, nature and purpose of processing
- Categories of data subjects and personal data
- Duration of processing
- Controller’s instructions
- Processor’s obligations
- Sub-processors
- Security measures
- Deletion and return of data
- Audit and demonstrating compliance
- Liability and final provisions
1. Parties
| Controller | the gallery host — the person identified by the e-mail and billing details given when creating the gallery (“the controller”) |
|---|---|
| Processor | VitaCore s. r. o., Matúšova 8027/54, Bratislava – mestská časť Staré Mesto, 811 04, Slovakia, company ID 56 093 667, tax ID 2122201774, Commercial Register of the Municipal Court Bratislava III, Section: Sro, Insert No.: 176563/B, e-mail info@eventpixel.eu (“the processor”) |
This agreement is concluded under Art. 28(3) of Regulation (EU) 2016/679 (GDPR) and prevails over the Terms of Service in matters of personal data processing.
2. Subject matter, nature and purpose of processing
The processor provides the controller with a hosting service: an event photo gallery to which guests upload photos, videos and voice messages, and related features (slideshow, guest book, digital invitation with RSVP, sending personal links to guests, statistics, optional face search, notifications). Processing consists of storing, displaying, generating previews, transcoding, backing up, making available according to the controller’s settings, and deleting.
The purpose is determined by the controller: documenting and sharing event photos among participants, organising the event (invitations, RSVP) and any further purposes the controller communicates to guests (for example internal or marketing communication — the consent-before-upload feature serves this).
3. Categories of data subjects and personal data
| Data subjects | guests and event participants, people captured in photos and videos, co-hosts, the controller’s contact persons |
|---|---|
| Ordinary personal data | likenesses and voices in recordings, file metadata, names and nicknames in the guest book and RSVP, number of people, meal choice, notes, guests’ e-mail and phone (if the controller collects them or sends personal links), time the invitation was opened, time and text of consent given, pseudonymous visit identifiers |
| Special category (only if the controller enables face search) | biometric face vectors from photos in the gallery; a guest’s selfie is processed only transiently for comparison and is not stored |
The controller does not store in the gallery data it has no legal basis to process, and does not enable face search without informing guests and obtaining their consent where required.
4. Duration of processing
For the life of the gallery under the chosen plan (retention period of 12 or 24 months after the event, or as extended by buying a plan) or until deleted by the controller, whichever comes first. Afterwards the processor deletes the data under section 9.
5. Controller’s instructions
The processor processes personal data only on the controller’s documented instructions. Instructions are: this agreement, the Terms of Service, the gallery settings (password, approval, visibility, downloads, contact collection, consent before upload, face search, co-hosts), the chosen plan and actions taken through the manager link (deletion, download, export), as well as written instructions sent by e-mail.
If the processor considers an instruction to infringe the GDPR or other law, it informs the controller without delay. The processor does not transfer data to a third country unless required by Union or member-state law; in that case it informs the controller in advance unless the law prohibits it.
6. Processor’s obligations
- ensures that persons authorised to process personal data are bound by confidentiality; accesses gallery content only for technical administration and for support at the controller’s request, and can evidence such access
- implements the technical and organisational measures in section 8 and Art. 32 GDPR
- respects the conditions for engaging another processor in section 7
- assists the controller with appropriate measures in responding to data-subject requests (access, erasure, portability etc.): a request received by the processor is forwarded to the controller within 3 business days and, on the controller’s instruction, the processor performs the erasure or export
- assists the controller in meeting its obligations under Art. 32–36 GDPR (security, breach notification, impact assessment), taking into account the nature of processing and the information available
- notifies the controller of a personal data breach without undue delay and at the latest within 48 hours of becoming aware, describing the nature of the breach, likely consequences and measures taken
- deletes the data after the end of the service under section 9
- makes available to the controller the information necessary to demonstrate compliance with Art. 28 GDPR and allows audits under section 10
- keeps records of categories of processing activities under Art. 30(2) GDPR
7. Sub-processors
The controller gives general authorisation to engage the following sub-processors:
| Websupport, s. r. o., Slovakia | web hosting, database, mail server, storage of encrypted backups |
|---|---|
| Contabo GmbH, Germany | server for photos, videos and voice messages |
| Amazon Web Services EMEA SARL, Luxembourg (region eu-central-1, Frankfurt) | face search (Amazon Rekognition) — only if enabled by the controller |
| Stripe Payments Europe, Ltd., Ireland | card payments for the plan — processes the controller’s data as payer, not guests’ data |
| Browser push service providers (Google LLC, Mozilla Corporation, Apple Inc.) | delivery of notifications to the controller; content encrypted, the provider sees only the fact of delivery |
The processor informs the controller by e-mail at least 14 days before an intended change (addition or replacement) of a sub-processor. The controller may object within that period; if the parties do not agree, the controller may terminate this agreement and delete the gallery, receiving a proportionate refund for the unused part of a paid plan. The processor imposes on every sub-processor, by contract, the same data-protection obligations it has itself and remains liable for the sub-processor’s performance.
All sub-processors process data in the European Union; Stripe and push service providers may process some data in the USA under a Commission adequacy decision (EU-US Data Privacy Framework) or standard contractual clauses.
8. Security measures
- transport encryption (TLS 1.2+) for all service addresses and outgoing e-mail (TLS, DKIM, SPF, DMARC)
- separate storage for each gallery, content accessible only via long random tokens; manager links that can be regenerated; gallery and account passwords stored as hashes
- gallery content not indexed by search engines (noindex) and addresses that cannot be derived
- servers in the EU (Germany, Slovakia), access exclusively via SSH keys, patched systems, firewall, isolated containers
- keys to external services encrypted in the database; secrets outside the public directory
- daily off-server backup, AES-256 encrypted, kept 14 days; the backup key is not held by the storage provider
- availability and error monitoring from an independent point; error logging without photo content
- IP addresses in statistics and rate limits pseudonymised with an HMAC hash and secret key
- on deletion of a photo, immediate removal of the original, previews and face vectors; backups catch up within 14 days
- authorised persons of the processor: the managing director and administrators authorised by them, bound by confidentiality
9. Deletion and return of data
During the agreement the controller can download the entire gallery content in original quality (ZIP archive) and export collected contacts (CSV) in gallery management; the list of RSVP replies is available in gallery management and on request we provide it in a machine-readable format.
After the retention period ends or the gallery is deleted, the processor erases all personal data from primary storage immediately and from backups within 14 days, unless Union or member-state law requires retention (e.g. the controller’s accounting documents as a customer). The processor notifies the controller by e-mail 30 and 7 days before retention ends.
10. Audit and demonstrating compliance
On request the processor provides the controller with a description of security measures, the list of sub-processors, records of access to its gallery and other information needed to demonstrate compliance. An on-site audit, or one through an independent auditor bound by confidentiality, is possible at most once a year, on written notice of at least 30 days, during business hours and in a way that does not disrupt the service or the security of other controllers’ data; the controller bears the audit costs unless the audit finds a material breach.
11. Liability and final provisions
Each party is liable for damage under Art. 82 GDPR. The processor’s liability towards the controller for damage arising from breach of this agreement is limited to the price paid for the affected gallery, but not less than €500; the limitation does not apply in cases of intent or gross negligence.
This agreement takes effect when the controller creates the gallery and lasts until the data is deleted under section 9. It is governed by the law of the Slovak Republic. The processor notifies changes by e-mail at least 14 days in advance; if the controller disagrees, it may terminate as for a change of sub-processor. A signed and stamped paper copy is available on request at info@eventpixel.eu. Effective from 2026-09-13.



