Data Processing Agreement
For business event owners, this governs how Bloomsy processes personal data on your behalf.
1. Parties and scope
This Data Processing Agreement (the “DPA”) forms part of the contract between the business event owner (the “Controller”) and Codexio s.r.o. (the “Processor”, “we”) for the use of the Bloomsy service. It applies where, in providing the service, the Processor processes personal data on behalf of the Controller — in particular photos, videos and related metadata uploaded by event guests.
For its own purposes (account, order, payment, invoicing, service operation and security) the Processor acts as an independent controller; that processing is governed by the Privacy Policy, not by this DPA.
2. Subject matter, duration, nature and purpose
- Subject matter: processing of content and metadata uploaded to the Controller’s event.
- Duration: for the duration of the event and the retention period tied to the selected plan, after which content is deleted in accordance with the service terms; and thereafter only as required by law.
- Nature and purpose: storing, organising, generating previews of, making available and enabling download of the uploaded content, solely to provide the Bloomsy service as configured by the Controller.
- Types of personal data: images and audiovisual recordings of individuals; file metadata; uploader-provided names or labels where applicable; technical data (IP address, device/browser data) needed to operate the upload.
- Categories of data subjects: event guests and other individuals appearing in or identifiable from the uploaded content.
3. Instructions
The Processor processes the personal data only on the documented instructions of the Controller, including with regard to transfers, unless required to do otherwise by Union or Member State law; in that case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits it. The Controller’s instructions are given through the service settings and this DPA. The Processor informs the Controller if, in its opinion, an instruction infringes the GDPR or other data protection law.
4. Confidentiality
The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5. Security of processing
The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR, including as appropriate: encryption in transit and at rest, access controls and least-privilege, segregation of tenants’ content, logging and monitoring, backup and restore procedures, and regular review of the measures. A current summary of the measures is available from support@bloomsy.eu.
6. Sub-processors
The Controller gives general authorisation for the engagement of sub-processors. The Processor engages only sub-processors that provide sufficient guarantees under Article 28 GDPR and imposes on them, by contract, data protection obligations equivalent to those in this DPA. The current sub-processors are the infrastructure, storage, e-mail, payment, support and analytics providers listed in the Privacy Policy. The Processor informs the Controller of any intended addition or replacement of a sub-processor in reasonable time, giving the Controller the opportunity to object on reasonable data-protection grounds; if an objection cannot be resolved, the Controller may terminate the affected part of the service.
7. Assistance with data subject rights
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller’s obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR. Requests received by the Processor directly from a data subject are forwarded to the Controller without undue delay.
8. Assistance with the Controller’s wider obligations
The Processor assists the Controller in ensuring compliance with the obligations under Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to the Processor — in particular security of processing, notification of a personal data breach, communication of a breach to data subjects, data protection impact assessments and prior consultation.
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, with the information needed for the Controller to meet its own notification duties.
9. Deletion or return
At the Controller’s choice, the Processor deletes or returns all personal data to the Controller after the end of the provision of the services relating to processing, and deletes existing copies, unless Union or Member State law requires storage of the personal data. In the normal course, content is deleted according to the retention period of the selected plan.
10. Information and audits
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations in Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. Audits are carried out with reasonable prior notice, no more than once per year unless there is a specific data-protection concern, during business hours, and in a manner that does not disproportionately disrupt the Processor’s operations or compromise the security or confidentiality of other customers’ data. The Processor may satisfy audit requests by providing an up-to-date third-party report or certification where available.
11. International transfers
Where processing involves a transfer of personal data to a third country, the Processor ensures an appropriate transfer mechanism under Chapter V GDPR (an adequacy decision, or Standard Contractual Clauses with supplementary measures) and provides the Controller with the relevant information on request.
12. Controller responsibilities
The Controller is responsible for having a lawful basis for collecting and making available content within its event, for informing guests as required, for the configuration of the event (visibility, access, retention) and for the content it and its guests upload. The Controller must not instruct the Processor to process special categories of data as a distinct activity; such data may nonetheless appear in guest content, and the Controller remains responsible for its lawful handling.
13. Term and precedence
This DPA takes effect on acceptance at checkout and remains in force for as long as the Processor processes personal data on behalf of the Controller. In case of conflict between this DPA and the general Terms and Conditions on data protection matters, this DPA prevails. Questions about this DPA: support@bloomsy.eu.