France & EU compliance
Data Processing Addendum (DPA)
The Article 28 GDPR terms for customers using PhotoChapter as a processor.
Last updated: 26 August 2026
Roles and scope
Where a customer determines the purposes and means of processing event personal data, the customer is the controller and PhotoChapter is the processor. We process only the personal data necessary to provide, secure, support, and improve the contracted service, on the customer’s documented instructions.
Processor commitments
PhotoChapter will ensure confidentiality, implement appropriate technical and organisational safeguards, assist with data-subject requests and security obligations where applicable, notify the customer without undue delay of a personal-data breach affecting customer data, and delete or return customer data at the end of the service subject to legal retention duties.
Subprocessors and transfers
The customer gives general written authorisation for the subprocessors on the published list. We will provide notice of material additions or replacements and allow a reasonable, documented objection. International transfers require an adequate legal mechanism, such as an adequacy decision or Standard Contractual Clauses where applicable.
Audit and precedence
On reasonable written notice, PhotoChapter will make available information necessary to demonstrate compliance and support proportionate audits without compromising other customers’ security. This DPA must be reviewed, completed, and signed by the legal entity before use in production.