Last updated: October 4, 2026 · Version: 2026-10-04
This Data Processing Agreement ("DPA") under Article 28 of the General Data Protection Regulation ("GDPR") supplements the Exportlab Terms of Service and applies to the extent that Exportlab processes personal data on behalf of a customer in the course of providing the Service.
Controller is the customer using an Exportlab account or workspace ("Customer").
Processor is Exportlab, Adelgundenstrasse 1, 80538 Munich, Germany, email: hey@exportlab.io ("Exportlab").
This DPA takes effect when a Customer subject to the GDPR or comparable data protection laws accepts the Terms of Service or uses the Service. No separate signature is required. A countersigned copy is available on request (hey@exportlab.io).
1. Subject matter and duration
- The subject matter is the provision of the Exportlab Service (storing, managing, editing, sharing and delivering media and related data, and workflow features such as galleries, client portal, guest uploads, asset collections, public profiles, proposals, invoices, contracts, model releases, group shoots, review and team communication).
- Processing lasts for the term of the underlying agreement for use of the Service, plus the deletion and return periods in section 10.
2. Nature, purpose and scope of processing
- Nature: collection, storage, organisation, adaptation, retrieval, consultation, use, disclosure by making available, alignment, restriction, erasure.
- Purpose: solely the provision of the Service under the Terms of Service and the Customer's documented instructions.
- Types of personal data: photos and videos of people; names, email addresses, phone numbers, postal addresses and other contact data; contents of messages, comments, forms, proposals, invoices and contracts; signature and consent data (e.g. model releases); upload, access and usage data on pages provided by the Customer; where enabled by the Customer: facial features derived from images (biometric data, Art. 9 GDPR) and AI-generated descriptions and keywords.
- Categories of data subjects: the Customer's clients, people photographed or filmed, models, guests and participants uploading content, visitors to the Customer's public pages, signatories, the Customer's staff and team members.
3. Instructions
- Exportlab processes personal data only on documented instructions from the Customer, including with regard to transfers to third countries, unless required to do so by Union or Member State law; in that case Exportlab informs the Customer of that legal requirement before processing, unless that law prohibits it.
- Instructions are given by the Terms of Service, this DPA, and the Customer's settings and actions in the Service (e.g. uploading, sharing, enabling features such as face recognition, deleting).
- If Exportlab considers that an instruction infringes data protection law, it informs the Customer without undue delay.
4. Confidentiality
Exportlab ensures that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and receive access on a need-to-know basis only.
5. Technical and organisational measures (Art. 32 GDPR)
Exportlab implements in particular the following measures and develops them in line with the state of the art:
- Hosting and location: operation on Amazon Web Services in region eu-central-1 (Frankfurt am Main, Germany).
- Encryption: TLS for all transmissions; encryption at rest by the infrastructure provider; access PINs additionally encrypted with our own keys (AWS KMS).
- Access control: sign-in via AWS Cognito, optional two-factor authentication; role-based permissions within a workspace; strict separation of different customers' data (tenant isolation), checked server-side on every access.
- Sharing: media delivered through time-limited signed URLs; PIN protection for galleries and links at the Customer's choice.
- Logging: per-workspace audit log of security-relevant events; monitoring and alerting.
- Availability and resilience: redundant storage at the infrastructure provider, backups, recovery procedures.
- Secrets management: credentials and keys kept exclusively in a secrets management system, never in source code.
- Development and operations: separate development, test and production environments; automated tests before release; vulnerabilities remediated according to risk.
- Data minimisation in product analytics: product analytics only with consent, without session recording and without transmitting email addresses.
6. Sub-processors
- The Customer grants general authorisation for the engagement of sub-processors. At the date of this version they include in particular:
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, storage, databases, delivery (CDN), sign-in (Cognito), email delivery (SES), optional face recognition (Rekognition) | EU (Frankfurt); CDN worldwide |
| Stripe Payments Europe, Ltd. | Payment processing for purchases in the Service | EU / USA |
| OpenAI, L.L.C. / OpenAI Ireland Ltd. | AI features (e.g. image descriptions, assistant), where enabled | USA / EU |
| Anthropic, PBC | AI assistant features, where enabled | USA |
| Functional Software, Inc. (Sentry) | Error monitoring | USA / EU |
| PostHog Inc. | Product analytics, only with consent | EU |
| Sendinblue SAS (Brevo) | Newsletter delivery | EU |
- Exportlab informs the Customer with reasonable notice (usually 30 days) before adding or replacing a sub-processor, by updating this list and notifying the account email address. The Customer may object on reasonable data protection grounds; if no solution can be found, the Customer may terminate the affected part of the agreement.
- Exportlab binds each sub-processor contractually to data protection obligations substantially equivalent to those in this DPA and remains liable for their compliance.
7. International transfers
Where personal data is processed outside the EEA, this happens only on the basis of an adequacy decision (including the EU-U.S. Data Privacy Framework where the recipient is certified) or appropriate safeguards, in particular the EU Standard Contractual Clauses.
8. Assistance
- Exportlab assists the Customer with appropriate technical and organisational measures in responding to data subject requests (access, rectification, erasure, restriction, portability, objection). Many of these actions the Customer can take directly in the Service. Requests that reach Exportlab directly are forwarded to the Customer.
- Exportlab assists the Customer with data protection impact assessments and prior consultations insofar as they concern processing by Exportlab.
9. Personal data breaches
Exportlab notifies the Customer of a personal data breach affecting the Customer's data without undue delay, where possible within 48 hours of becoming aware of it, via the account email address. The notification includes, as far as known, the nature of the breach, the categories and approximate number concerned, the likely consequences and the measures taken or proposed.
10. Deletion and return
- The Customer can download and delete content in the Service at any time.
- After termination of the agreement or deletion of the account, Exportlab deletes the Customer's personal data unless a statutory retention obligation applies (e.g. for invoice data). Copies in backups are deleted as part of the regular backup rotation.
- Biometric data (facial features) is deleted as soon as the Customer disables the feature, deletes the related content or closes the account.
11. Demonstrating compliance and audits
On request, Exportlab makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR and allows for audits by the Customer or an auditor mandated by it and bound to confidentiality, with reasonable prior notice, during normal business hours and without disrupting operations. Compliance is demonstrated primarily through written information and documentation.
12. Customer obligations
The Customer is responsible for the lawfulness of the processing, in particular for having the necessary legal bases, information and consents of data subjects — for example for recordings of people, for uploading its clients' contact data and, if enabled, for face recognition (Art. 9 GDPR).
13. Final provisions
- In the event of conflict between this DPA and the Terms of Service, this DPA prevails with respect to data protection.
- Exportlab may amend this DPA where required by changes in law or sub-processors; the level of protection will not be reduced. Material changes are communicated to the Customer.
- This DPA is governed by the laws of the Federal Republic of Germany.