Databehandleraftale
Last updated: 20 August 2026
This is a courtesy translation. The contractual language is German; in case of any discrepancy, the German version prevails.
This data processing agreement under Art. 28 GDPR supplements the Terms and Conditions and applies to every use of momentum.photo in which personal data of third parties, in particular of guests, is processed on behalf of the customer.
Parties
The controller is the customer running an event on momentum.photo, identified by the details stored in their account.
The processor is:
Marc Breuer
Am Altengraben 23
90768 Fürth
Germany
E-mail: [email protected]
Preamble
The controller uses momentum.photo to provide an album for an event to which their guests upload photos and videos. The controller alone determines the purposes and means of that processing and is the controller within the meaning of Art. 4(7) GDPR. The processor processes that data solely on documented instructions, as a processor within the meaning of Art. 4(8) GDPR.
This agreement does not cover data the processor processes for its own purposes, in particular the customer's own account, contract and billing data. In that respect the processor is its own controller and its privacy policy applies.
1. Subject matter and duration
1.1 The subject matter is the provision of the services described in the Terms and the plan overview, to the extent personal data is processed: operating the event album, storing and technically processing the uploaded media, delivering them to authorised viewers, sending the notifications provided for by the application, and providing the closing archive.
1.2 This agreement runs for the term of the respective event including the subsequent archive period. It ends, without notice being required, when the data is finally deleted under clause 9.
2. Nature and purpose of processing, categories of data and data subjects
2.1 Nature of processing: collection, storage, organisation, adaptation (technical conversion of image and video files, generation of previews, application of a photo look chosen by the controller), retrieval, use, transmission to the authorised viewers of the album, restriction and erasure.
2.2 Purpose: providing and operating the event album for the controller and their guests.
2.3 Categories of data:
- Photos and videos uploaded by guests, including the metadata they contain (EXIF), which depending on the recording device may include capture time and location data;
- the guest's name and, where the guest provides one, their e-mail address for notifications;
- the guest's language, the time of the consent they gave, and a technical access identifier (cookie);
- comments, likes and the assignment of media to photo tasks;
- name and e-mail address of invited co-hosts.
2.4 Categories of data subjects: guests of the event, people depicted in the media, and co-hosts invited by the controller.
2.5 The processor does not process this data for its own purposes. In particular it is not used for advertising and not to train artificial-intelligence systems.
3. Instructions
3.1 The processor processes the data solely on documented instructions from the controller. Those instructions arise from this agreement, the Terms, and the settings the controller makes in the dashboard; the latter constitute individual instructions in electronic form.
3.2 Further instructions are issued by the controller in text form to the address above. Oral instructions are to be confirmed in text form without undue delay.
3.3 If the processor considers an instruction unlawful, it informs the controller without undue delay. It may suspend execution until the controller confirms or amends the instruction.
3.4 Processing outside the instructions takes place only where the processor is required to do so by Union or Member State law; in that case it informs the controller of the legal requirement before processing, unless that law prohibits such information.
4. Obligations of the processor
4.1 The processor obliges the persons authorised to process the data to confidentiality, unless they are already under a statutory obligation of secrecy. That obligation survives the end of their activity.
4.2 The processor maintains a record of all categories of processing activities under Art. 30(2) GDPR.
4.3 The processor informs the controller without undue delay if a supervisory authority takes measures against it concerning the processing carried out on the controller's behalf.
4.4 The processor has not appointed a data protection officer; the conditions of Art. 37 GDPR and section 38 BDSG are not met. The contact point for all data protection matters is the address above.
5. Technical and organisational measures
5.1 The processor implements the measures described in Annex 1 under Art. 32 GDPR and maintains them for the duration of this agreement.
5.2 The measures may be adapted in the course of technical development as long as the level of protection is not reduced. Material changes are documented.
6. Sub-processors
6.1 The controller hereby grants general authorisation to engage further processors. The sub-processors engaged at the time this agreement is concluded are listed exhaustively in Annex 2 and are hereby expressly authorised.
6.2 If the processor intends to engage a further sub-processor or replace an existing one, it informs the controller in text form at least four weeks in advance. The controller may object to the change within two weeks for an important data protection reason. If they object, the processor may terminate the contract with ordinary notice as of the date of the intended change; fees already paid are refunded pro rata for the unused remainder of the term.
6.3 The processor imposes on every sub-processor data protection obligations equivalent to those of this agreement and remains responsible to the controller for their conduct.
6.4 Ancillary services the processor obtains from third parties without those third parties having access to the data processed on the controller's behalf do not constitute sub-processing within the meaning of this clause.
7. Assistance to the controller
7.1 The processor assists the controller by appropriate technical and organisational measures in responding to requests from data subjects for access, rectification, erasure, restriction, portability and objection. A substantial part of these capabilities is available to the controller directly in the dashboard: they can delete or hide individual media and comments, remove guests, and download all media as an archive.
7.2 If a data subject contacts the processor directly, the processor forwards the request to the controller without undue delay and does not answer it itself.
7.3 The processor assists the controller in complying with Art. 32 to 36 GDPR, in particular with the security of processing, notifications of breaches, and any data protection impact assessment, taking into account the nature of processing and the information available to it.
8. Personal data breaches
8.1 The processor notifies the controller in text form of any personal data breach concerning the controller's data that comes to its attention, without undue delay and as a rule within 24 hours of becoming aware of it.
8.2 The notification contains, where available, a description of the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
8.3 Notification to the supervisory authority and communication to the data subjects are the responsibility of the controller.
9. Erasure and return
9.1 When the term of the event expires, the processor makes all uploaded original files available to the controller as a ZIP archive via a personal link. The link is valid for four weeks; this satisfies the return obligation under Art. 28(3)(g) GDPR.
9.2 After those four weeks the processor permanently deletes all data processed on the controller's behalf, including all copies and derivatives. This covers the original files, all display sizes generated from them, the guest data and the archive itself.
9.3 An event that never went beyond the free trial and shows no activity for twelve months is likewise deleted in full. The processor announces this to the controller by e-mail two weeks in advance.
9.4 The processor may retain documentation serving as proof of proper processing, and data subject to a statutory retention obligation, beyond the end of this agreement.
10. Evidence and audits
10.1 On request the processor demonstrates compliance with its obligations under this agreement in an appropriate manner, in particular by providing information and the documentation of its technical and organisational measures.
10.2 The controller may satisfy themselves of compliance after prior notice, with reasonable lead time and during normal business hours. Audits are to be limited to what is necessary and must not disproportionately disrupt operations.
10.3 For audits going beyond simple information and not prompted by a specific cause, the processor may charge reasonable compensation for the effort involved.
11. Processing outside the European Union
Data processed on the controller's behalf is processed exclusively within the European Union. The object storage is operated with the "EU jurisdiction" storage location. Processing in a third country takes place only where the conditions of Art. 44 et seq. GDPR are met; the corresponding safeguards are named in Annex 2.
12. Liability
Art. 82 GDPR applies. Between the parties, the liability provisions of the Terms apply in addition.
13. Final provisions
13.1 Where this agreement and the Terms conflict, this agreement prevails for processing carried out on the controller's behalf.
13.2 The law of the Federal Republic of Germany applies.
13.3 Should any provision of this agreement be invalid, the validity of the remaining provisions is unaffected.
Annex 1: Technical and organisational measures (Art. 32 GDPR)
Confidentiality
- Physical access control: the servers are located in a data centre in Germany. Physical protection (access separation, video surveillance, logging) is provided by Hetzner Online GmbH as the operator of the data centre.
- System access control: access to the customer account is by username and password; passwords are stored only as a hash (bcrypt). Administrative server access is limited to the operator and secured by key-based authentication. Sign-in and upload operations are rate-limited.
- Data access control: the application separates the roles of operator, customer, co-host and guest; every request is checked against the caller's authorisation. Albums are reachable only via an unguessable access key (UUID). The media stores expose no directory listing.
- Separation control: data is stored separately per event and album and every query is scoped to the album concerned. Test and production systems use separate databases and separate file storage.
- Pseudonymisation: media files are stored under randomly generated file names; no conclusion about a person can be drawn from a file name.
Integrity
- Transfer control: every transmission is TLS-encrypted (HTTPS), including delivery via the content delivery network and transfer to the object storage. Archive download links are cryptographically signed and time-limited.
- Input control: uploads, changes and deletions are stored with a timestamp and the account or guest that caused them. Security-relevant operations are logged.
Availability and resilience
- Regular backup of server and database by the hosting provider.
- Redundant storage of media files in the object storage.
- Prompt installation of security updates for the operating system and the application.
- Monitoring of system load and background processing.
Procedures for review and evaluation
- Data protection by default: albums are not publicly discoverable and not indexable; guest data is collected only to the extent the respective function requires; providing an e-mail address is optional for guests.
- Automated deletion routines enforce the periods described in clause 9 without manual intervention.
- Control of processing on behalf: sub-processors are engaged only under an Art. 28 GDPR agreement; instructions are issued exclusively in text form.
Annex 2: Sub-processors
| Company | Service | Place of processing |
|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | Operation of the servers including database and backups | Germany |
| Cloudflare Germany GmbH, Rosental 7, 80331 München, Germany | "R2" object storage for media files, plus delivery of the website and the media files via the content delivery network, including protection against attacks | European Union ("EU jurisdiction"); additionally EU standard contractual clauses |
The payment service provider used for payment processing is not a sub-processor within the meaning of this agreement: it processes only the controller's payment data, as its own controller, and receives no access to the data processed on the controller's behalf.