Legal

Data Processing Agreement (DPA)

This Data Processing Agreement ("DPA") forms an integral part of the AIMARKER Terms of Service and is concluded upon accepting the Terms. It governs the processing of personal data that the Customer entrusts to the Provider in connection with the Service, in accordance with Art. 28 of Regulation (EU) 2016/679 (GDPR). This English text is a convenience translation; the Polish version prevails.

§ 1. Parties

  • Controller (Customer): the business using the Service under the Terms. Where the Customer itself acts as a processor for its own client, the Provider acts as a sub-processor and this DPA applies accordingly.
  • Processor (Provider): DEV-PAGE spółka z ograniczoną odpowiedzialnością, ul. Dygasińskiego 68, 26-020 Chmielnik, Poland, KRS 0001079913, NIP 6572984911, REGON 527401969.

§ 2. Subject matter, nature and purpose

The Controller entrusts the processing of personal data contained in Content entered into the Service solely for providing the Services described in the Terms.

Processing includes collection (upload or entry), storage, organisation, viewing, modifying file metadata (C2PA, IPTC), publishing on the transparency page and via the snippet at the Controller's instruction, backups and deletion.

§ 3. Types of data and data subjects

Depending on Content, data may include: identification and contact data (e.g. names of authors or approvers, agency name, Users' emails); likeness and other data visible in uploaded images; data in texts, page addresses and file metadata; audit-log data.

Data subjects: the Controller's staff and contractors, its clients, and persons whose data or likeness appears in Content.

The Controller does not entrust special categories (Art. 9) or criminal-offence data (Art. 10) unless necessary and lawful, in which case it is responsible for the legal basis.

§ 4. Duration

For the term of the service contract and, after termination, until deletion under § 11.

§ 5. Processor obligations

The Processor: processes data only on documented instructions (use of the Service's features, the Terms and this DPA) and informs the Controller if an instruction infringes the law; ensures confidentiality of authorised persons; applies Art. 32 security measures (§ 8); complies with sub-processor rules (§ 7); assists with data-subject requests and with Arts. 32–36 obligations; deletes or returns data at the end (§ 11); and makes available information and allows audits (§ 10).

The Processor does not use entrusted data for its own purposes, in particular not for training AI models, marketing or profiling.

§ 6. Controller obligations

The Controller warrants it processes data lawfully, has a legal basis to entrust it and has informed data subjects (including about likeness in uploaded images). It is responsible for its instructions, the data it enters and its configuration of the Service.

§ 7. Sub-processors

The Controller gives general authorisation for sub-processors listed in Annex 1. The Processor will give at least 14 days' notice of additions or replacements; the Controller may object on reasonable grounds and, failing agreement, terminate with immediate effect. The Processor imposes equivalent obligations on sub-processors and remains liable for them.

§ 8. Security

The Processor applies the technical and organisational measures in Annex 2 and may update them without lowering the level of protection.

§ 9. Personal data breaches

The Processor notifies the Controller of a breach without undue delay and no later than 36 hours after becoming aware of it, to the Organisation owner's email, including where possible the nature of the breach, categories and approximate numbers of data subjects and records, likely consequences and measures taken or proposed.

§ 10. Audits

The Controller may verify compliance, primarily by requesting information and documentation (answered within 14 days). On-site audits are possible with at least 14 days' notice, during business hours, at most once a year unless there has been a breach or a supervisory authority requires it, at the Controller's cost.

§ 11. Deletion after termination

Before termination the Controller can download its files and reports. After termination the Processor deletes entrusted data within 30 days, and from backups within 90 days, unless EU or Member State law requires retention.

§ 12. Transfers outside the EEA

The Processor does not transfer entrusted data to third countries or international organisations. Any future transfer would require prior notice under § 7 and Chapter V GDPR safeguards.

§ 13. Liability and final provisions

Liability is governed by Art. 82 GDPR and the Terms. Matters not covered are governed by the Terms, the GDPR and Polish law; in data-protection matters this DPA prevails.

A signed copy can be requested at kontakt@aimarker.pl.

Effective from 2026-10-09 (version 1.0).

Annex 1. Sub-processors

  • Contabo GmbH, Welfenstraße 22, 81541 Munich, Germany: server hosting (VPS), data and backup storage; data location: EU (Germany).

Annex 2. Technical and organisational measures

  • Encryption in transit (HTTPS/TLS, Let's Encrypt certificates).
  • User passwords and API keys stored only as cryptographic hashes.
  • Organisation-level data separation; the public API exposes only data meant for publication.
  • Organisation roles (owner, admin, member) and an audit log of user actions.
  • Labelling-mode tokens limited in time (4 hours) and to the client site's domains.
  • Containerised infrastructure with an isolated database network not reachable from the Internet; server admin access only via SSH keys.
  • Regular software updates and data backups.
  • Access limited to authorised persons bound by confidentiality.

DEV-PAGE spółka z ograniczoną odpowiedzialnością · ul. Dygasińskiego 68, 26-020 Chmielnik · NIP 6572984911 · KRS 0001079913 · kontakt@aimarker.pl