Data Processing Addendum
Recommended controller/processor terms for photographer client data and outsourced image processing.
1. Controller / processor roles
For client photographs and related production data, the photographer typically determines why and how the images are collected and is therefore the controller/business. Pixeldotedit should process those files only to deliver the contracted editing services and related support.
2. Documented instructions
Orders, editing profiles, support messages and signed service agreements form the photographer’s documented instructions. Pixeldotedit should not materially repurpose client images for unrelated goals without a separate legal basis and authorization.
3. Confidentiality
People authorized to process client data should be bound by confidentiality obligations appropriate to their role.
4. Security measures
Maintain reasonable technical and organizational safeguards appropriate to the risk, including access controls, secure credential practices, reputable storage/transfer providers, auditability and incident-response procedures.
5. Subprocessors
Maintain a list of providers that may process personal data for hosting, storage, file transfer, payments, support or other production functions. Contractual privacy/security obligations should flow down to those subprocessors.
6. International transfers
Where applicable, use lawful transfer mechanisms for personal data moved between India and client jurisdictions such as the EEA, UK, United States, Canada or Australia.
7. Data subject assistance
When a photographer receives a lawful privacy request from their client, Pixeldotedit should reasonably assist with locating, exporting, correcting or deleting processor-held data where technically feasible and legally required.
8. Deletion or return
At the end of the service relationship, return or delete production data according to the retention policy, subject to backup cycles and legal obligations.
9. Incident assistance
If Pixeldotedit becomes aware of a qualifying security incident involving a photographer’s client data, it should notify the photographer without undue delay consistent with applicable law and the facts available.
10. Audit information
Provide reasonable information about relevant privacy/security controls where required by contract. Any on-site or extensive audit rights should be defined in a signed enterprise agreement.