Data Processing Agreement
Version 1.0 — June 2026
This Data Processing Agreement ("DPA") is entered into between the event organiser who has accepted the PartiPix Terms of Use ("Controller") and Devminds (BE 0688.824.615), Grote Veldstraat 140B, 8840 Staden, Belgium ("Processor"), collectively the "Parties".
This DPA is incorporated into and forms part of the PartiPix Terms of Use. By accepting the Terms of Use, the Controller agrees to the terms of this DPA. This DPA is required by Article 28 of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR").
Article 1 — Definitions
Terms not defined here have the meanings given in the GDPR.
- "Personal Data" means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller under this DPA — primarily photos uploaded by guests at events organised by the Controller, together with associated metadata.
- "Processing" means any operation or set of operations performed on Personal Data, including collection, storage, retrieval, use, disclosure, and erasure.
- "Sub-processor" means any third-party processor engaged by the Processor to carry out specific processing activities on behalf of the Controller.
- "Services" means the PartiPix live event photo sharing platform as described in the Terms of Use.
Article 2 — Subject matter, nature, and purpose of processing
- Subject matter: The Processor provides the Controller with a platform to collect, process, and display event photos contributed by guests.
- Nature: Storage, processing (format conversion, resizing, watermarking, moderation), real-time display, and deletion of photos and associated metadata.
- Purpose: Enabling the live slideshow feature and gallery functionality for events organised by the Controller.
- Duration: For the term of the Controller's active PartiPix subscription and until the applicable data retention period for each event expires.
Article 3 — Categories of data subjects and personal data
- Data subjects: Guests attending events organised by the Controller.
- Categories of personal data: Photographs (which may depict the physical appearance of data subjects), optional guest display names, upload timestamps, and IP addresses.
Article 4 — Obligations of the Processor
The Processor shall:
- Process Personal Data only on documented instructions from the Controller (as expressed through event configuration settings within the PartiPix platform) and not for any other purpose, unless required to do so by Union or Member State law.
- Ensure that persons authorised to process Personal Data are subject to a duty of confidentiality.
- Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption of data in transit and at rest, and access controls limiting data access to operational necessity.
- Not engage a sub-processor without prior general or specific authorisation from the Controller. The sub-processors listed in Annex 1 are hereby generally authorised. The Processor will notify the Controller of any intended changes to the sub-processor list, giving the Controller the opportunity to object.
- Assist the Controller in ensuring compliance with obligations under Articles 32–36 of the GDPR, including by providing information on implemented security measures.
- At the Controller's choice, delete or return all Personal Data after the end of the provision of Services, and delete existing copies unless required by law.
- Make available all information necessary to demonstrate compliance with this DPA, and allow and contribute to audits and inspections carried out by the Controller or a mandated auditor.
Article 5 — Data subject rights
The Processor shall assist the Controller in fulfilling requests from data subjects to exercise their rights under the GDPR (access, rectification, erasure, restriction, portability, objection). Where technically feasible, the Processor will provide the Controller with tools within the platform to manage data subject requests — in particular the ability to delete individual photos and to export event photo data.
Data subjects who wish to exercise their rights should contact the Controller (event organiser) in the first instance. The Processor provides a contact path at privacy@devminds.be for cases where the Controller is unreachable.
Article 6 — Security of processing
The Processor implements and maintains the following measures:
- TLS 1.2+ encryption for all data in transit
- Azure Storage service-side encryption for all data at rest
- Managed identity authentication (no hard-coded access keys)
- Role-based access control (RBAC) limiting personnel access to Personal Data
- Automated data retention policies with permanent deletion after the applicable retention period
- Application-level tenant isolation via EF Core global query filters
Article 7 — Sub-processors
The Controller grants general authorisation for the use of the following sub-processors (Annex 1):
| Sub-processor | Service | Location |
|---|---|---|
| Microsoft Azure | Cloud hosting — Container Apps, Azure SQL, Blob Storage, SignalR, App Insights | EU (Netherlands / Belgium) |
| Azure AI Content Safety (Microsoft) | Photo content moderation (when enabled by the Controller) | EU (Netherlands) |
| Azure Communication Services (Microsoft) | Transactional email delivery | EU |
Note: Stripe is used exclusively for payment processing of customer account fees and does not process guest Personal Data subject to this DPA.
Article 8 — International transfers
All Personal Data subject to this DPA is processed within the European Economic Area (EEA). The Processor will not transfer Personal Data to third countries without ensuring appropriate safeguards under Chapter V of the GDPR.
Article 9 — Data breach notification
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting Personal Data processed under this DPA. Notification will be made to the email address associated with the Controller's PartiPix account. The notification will include, to the extent available: the nature of the breach, the categories and approximate number of data subjects concerned, likely consequences, and measures taken or proposed.
Article 10 — Return and deletion of data
Upon termination of the Controller's account, the Processor will delete all Personal Data (event photos and associated metadata) associated with the Controller's events within 30 days, unless applicable law requires longer retention.
Article 11 — Governing law
This DPA is governed by Belgian law and the GDPR. Disputes arising from this DPA shall be subject to the jurisdiction of the courts of Bruges (West-Flanders), Belgium.
Article 12 — Acceptance
By accepting the PartiPix Terms of Use during registration or upon a DPA version update, the Controller confirms that they have read, understood, and agree to the terms of this DPA. The Controller's acceptance is recorded including the DPA version number, timestamp, and IP address as proof of consent.