This Data Processing Agreement ("DPA") is incorporated into and forms part of the Terms of Service between LumiCodex and the customer identified in the applicable Account ("Customer"). It applies automatically to all plans, without signature, whenever LumiCodex processes personal data contained in Customer Content as a processor on the Customer's behalf (see Section 1 of the Privacy Policy). Corporate customers who require a countersigned copy can request one at support [at] lumicodex [dot] com.
1. Definitions
"GDPR" means Regulation (EU) 2016/679. "Personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings given in the GDPR. "Customer Data" means personal data contained in Content that the Customer uploads to or processes through the Service. Capitalized terms not defined here have the meanings given in the Terms of Service.
2. Roles and scope
For Customer Data, the Customer is the controller (or, where the Customer acts for another controller, a processor — in which case LumiCodex is a sub-processor) and LumiCodex is the processor. This DPA does not apply to personal data that LumiCodex processes as a controller for its own purposes (account, billing, support, security), which is described in the Privacy Policy. The details of the processing are set out in Annex A.
3. Processing on documented instructions
LumiCodex processes Customer Data only on the Customer's documented instructions, including with regard to transfers to third countries, unless required to do otherwise by EU or member state law (in which case LumiCodex informs the Customer of that legal requirement before processing, unless the law prohibits it). The Customer's complete instructions are: the Terms of Service, this DPA, and the Customer's configuration and use of the Service (uploading, organizing, publishing, sharing, and deleting Content). LumiCodex will inform the Customer if, in its opinion, an instruction infringes the GDPR.
4. Confidentiality
LumiCodex ensures that persons authorized to process Customer Data are bound by contractual or statutory obligations of confidentiality.
5. Security
LumiCodex implements appropriate technical and organizational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing (GDPR Art. 32). The current measures are summarized in Annex B.
6. Sub-processors
The Customer gives LumiCodex general written authorization to engage sub-processors for the processing of Customer Data. The current list of sub-processors is published in Section 5 of the Privacy Policy. LumiCodex will update that list at least 15 days before a new sub-processor processes Customer Data. If the Customer objects on reasonable data-protection grounds and LumiCodex cannot offer a workaround, the Customer may terminate the affected subscription as its sole remedy; termination takes effect at the end of the current paid period unless mandatory law requires otherwise. LumiCodex imposes data-protection obligations on each sub-processor that are materially equivalent to this DPA and remains liable for its sub-processors' performance.
7. Assistance with data subject rights
Taking into account the nature of the processing, LumiCodex assists the Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). If a data subject contacts LumiCodex directly about Customer Data, LumiCodex will refer them to the Customer without responding on the merits, except where required by law.
8. Personal data breach
LumiCodex notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and provides information reasonably available to LumiCodex to help the Customer meet its own notification obligations under GDPR Arts. 33 and 34.
9. DPIA assistance
Taking into account the nature of the processing and the information available to it, LumiCodex provides reasonable assistance to the Customer with data protection impact assessments and prior consultations under GDPR Arts. 35 and 36, where they relate to the Service.
10. Deletion and return
The Customer can export Content while the Account is active. Upon termination of the Account, LumiCodex deletes Customer Data in accordance with the Terms of Service and the Privacy Policy, subject to routine backup cycles and any retention required by law. Backup copies are deleted on the normal backup expiry schedule.
11. Audits and information
LumiCodex makes available the information reasonably necessary to demonstrate compliance with GDPR Art. 28, primarily by responding in writing to reasonable security and compliance questionnaires (at most once per 12-month period, at the Customer's expense where the effort is material). On-site or remote technical audits are available only where required by applicable law or a supervisory authority, with at least 30 days' notice, during business hours, at the Customer's cost, under confidentiality, and without access to other customers' data or to information that would compromise the security of the Service.
12. International transfers
Customer Data may be processed in the countries described in Section 6 of the Privacy Policy. Where processing involves a transfer outside the EEA to a country without an adequacy decision, LumiCodex relies on appropriate safeguards, in particular the EU Standard Contractual Clauses (as incorporated into its agreements with the relevant sub-processors) and supplementary measures where appropriate.
13. Liability
The liability of each party under this DPA is subject to the limitations and exclusions of liability in the Terms of Service, to the extent permitted by law. Nothing in this DPA limits a data subject's rights under the GDPR.
14. Term, precedence, and governing law
This DPA takes effect when the Customer first uses the Service and remains in force for as long as LumiCodex processes Customer Data. If this DPA conflicts with the Terms of Service regarding the processing of Customer Data, this DPA prevails. This DPA is governed by French law, and disputes follow the jurisdiction clause of the Terms of Service.
Annex A — Details of processing
- Subject matter: hosting, processing, and delivery of the Customer's photographic Content through the Service.
- Duration: the term of the Account, plus the deletion period described in Section 10.
- Nature and purposes: storage, encoding/transcoding, tiling, color management, caching, CDN delivery, backup, and — to keep the platform safe and provide features — automated analysis such as content moderation, detection of illegal content, categorization, and tagging (see Section 4 of the Privacy Policy). Customer Data is not sold and is not used to train third-party AI models, to the extent contractually available from providers.
- Categories of data subjects: persons depicted in or identifiable from the Customer's photographs and files; the Customer's own end users and clients where their data appears in Content or metadata.
- Categories of personal data: images of individuals; metadata embedded in files (e.g. EXIF data, which may include capture location, timestamps, device identifiers); captions, titles, and other descriptive text supplied by the Customer. The Service is not intended for special categories of data (GDPR Art. 9); the Customer must not upload such data except where images incidentally reveal it (e.g. photographs of people).
Annex B — Technical and organizational measures
- Encryption of data in transit (TLS) and encryption at rest for stored Content;
- access controls and authentication for administrative and customer access; scoped, token-based access for shared/private media delivery;
- cloud key management (AWS KMS) for cryptographic material;
- logical separation of customer data; least-privilege access to production systems;
- logging and monitoring of access and system events;
- redundant storage and routine backups with defined expiry;
- vendor selection limited to established providers under GDPR-compliant data processing terms (see the sub-processor list).
Company
LumiCodex — SIRET 981 087 513 00017 — Annemasse (74100), France. Email: support [at] lumicodex [dot] com. See also the mentions légales.