Login
Kostenlos startenStart
DesignsPreiseBlog

Legal

Auftragsverarbeitungsvertrag

Last updated: August 11, 2026

The Article 28 terms that govern Framebird’s processing of customer personal data.

On this page

  1. 01Scope and roles
  2. 02Processing details
  3. 03Instructions and confidentiality
  4. 04Technical and organizational measures
  5. 05Subprocessors
  6. 06Assistance and personal-data breaches
  7. 07Return, deletion, and audits
  8. 08International transfers
  9. 09Liability, order of precedence, and termination
01

Scope and roles

This Data Processing Addendum (“DPA”) forms part of the Framebird Terms where a customer uses the Services to process personal data for which that customer is a controller or processor. The customer is the controller or processor, as applicable; Framebird is its processor or subprocessor.

The customer's use of Framebird after accepting the Terms constitutes written acceptance of this DPA. The customer identity and contact details are those in its Framebird account or order; Framebird's identity and address are Framebird UG (haftungsbeschränkt), Eberswalder Str. 29, 10437 Berlin, Germany. Conflicting customer instructions require a separately signed agreement. Contact legal@framebird.io for a countersigned copy or documented instructions that cannot be expressed through the Services.

02

Processing details

Subject matter
Hosting, organizing, transforming, presenting, sharing, collaborating on, and securing Customer Content.
Duration
The account or subscription term plus the documented deletion and backup lifecycle.
Data subjects
Customer users, clients, guests, collaborators, content subjects, and people represented in metadata.
Personal data
Account and contact data, uploaded media and metadata, comments, annotations, review choices, guest data, access logs, device data, and other personal data selected by the customer.
Purpose
Providing, securing, supporting, maintaining, and improving the customer-configured Services.
03

Instructions and confidentiality

Framebird processes customer personal data only on documented instructions expressed through the Terms, this DPA, product configuration, and lawful support requests. We inform the customer if an instruction appears to infringe applicable data-protection law, unless prohibited from doing so.

Personnel authorized to process customer personal data are subject to confidentiality obligations and receive access only where needed for their role.

04

Technical and organizational measures

  • encrypted transport, provider-managed encryption at rest, and controlled production credentials;
  • role-based access, least privilege, session controls, and production access logging;
  • tenant authorization checks and separation of public Share access from private account access;
  • backups, recoverable trash where offered, availability monitoring, and incident recovery procedures;
  • dependency, vulnerability, patch, logging, error-monitoring, and change-review processes;
  • vendor due diligence, written data-protection terms, and transfer safeguards where required;
  • data minimization, retention controls, secure deletion workflows, and staff confidentiality.
  • incident response, business continuity, and periodic review of the effectiveness of safeguards.
05

Subprocessors

The customer gives general authorization for the subprocessors on the Subprocessors page. Framebird remains responsible for imposing materially equivalent data-protection obligations on each subprocessor.

We provide at least 30 days' advance notice by account email before adding or replacing a production subprocessor that materially affects customer personal data. A customer may object on reasonable data-protection grounds during that period. We will work in good faith on an alternative; if none is reasonably available, either party may terminate the affected Service.

06

Assistance and personal-data breaches

Taking account of the nature of processing and information available to us, Framebird assists with data subject requests, security obligations, breach notifications, impact assessments, and regulator consultations. The customer remains responsible for responding as controller.

Framebird notifies the customer without undue delay after becoming aware of a confirmed personal-data breach affecting customer personal data and supplies available information needed for the customer's assessment and notification duties. Notice is not an admission of fault.

07

Return, deletion, and audits

Customers should export required data before account termination. On request or termination, Framebird deletes or returns customer personal data from active systems according to the documented retention schedule and, for a verified account-deletion request, aims to complete active-system deletion within 30 days, unless law requires retention. Isolated backup copies remain protected from ordinary use and expire through the applicable backup cycle. If restored for disaster recovery, the deletion instruction is reapplied.

Framebird provides information reasonably necessary to demonstrate compliance. Subject to confidentiality, security, and reasonable advance notice, a customer may conduct one proportionate audit per year, with additional audits following a qualifying incident or regulator request. The customer first uses current independent reports and remote documentation where they reasonably satisfy the request. On-site work must avoid exposing another customer's data and may be charged at reasonable cost unless the audit identifies a material Framebird breach.

08

International transfers

Where a transfer of Customer Personal Data from the EEA to Framebird or a subprocessor requires safeguards and no adequacy decision applies, the parties incorporate the European Commission Standard Contractual Clauses in Decision (EU) 2021/914: Module Two for controller-to-processor transfers or Module Three for processor-to-processor transfers. Docking applies; optional independent dispute resolution does not apply; and the governing law and courts are Germany. The competent supervisory authority is determined under Clause 13, ordinarily the Berlin Commissioner for Data Protection and Freedom of Information for Framebird.

Annex I is completed by the party identities and processing details in this DPA and the customer's account; transfers occur continuously as needed to provide the Services for the contract duration. Annex II consists of the technical and organizational measures above. Annex III is the current Subprocessors page. Framebird assesses transfer risks and applies supplementary technical, contractual, or organizational measures where appropriate.

09

Liability, order of precedence, and termination

The liability provisions in the Terms apply to this DPA to the extent permitted by data-protection law. This DPA prevails over conflicting Terms on processing Customer Personal Data; the Standard Contractual Clauses prevail where they conflict with this DPA. The DPA ends after Framebird has completed processing and deletion obligations, while confidentiality, audit, transfer, and liability provisions survive as needed for their purpose.

Produkt

  • Preise
  • Hilfe
  • Changelog
  • Designs
  • Affiliate Programm
  • Studentenrabatt

Unternehmen

  • Blog
  • About
  • Marke
  • Support

Tools

  • Bildkonverter
  • Bildkompressor
  • Bild-Wasserzeichen
  • Bild-Vorschau
  • EXIF-Daten auslesen

Vergleich

  • vs Shootproof
  • vs Pixieset
  • vs PicDrop
  • vs SmugMug

Kontakt

  • Kontaktiere uns
  • X (Twitter)
  • Instagram
Alle Systeme betriebsbereit
ImpressumDatenschutzNutzungsbedingungenRückerstattungen
Verträge hier kündigenVertrag widerrufen
©2026 Framebird
- built in berlin