Data Processing Agreement (DPA)
Agreement for the processing of personal data pursuant to Art. 28 GDPR.
This DPA only applies when using TattooMate as a hosted SaaS solution.
1. Subject matter and duration
This Data Processing Agreement governs the processing of personal data by FutureMate as processor on behalf of the controller in the context of using TattooMate as a SaaS solution. The duration of processing is governed by the term of the underlying contract.
2. Nature and purpose of processing
Processing takes place for the purpose of providing and using the TattooMate software. This includes in particular the storage, organisation, display and processing of client data, consents, health details, signatures, images and documents captured by the studio.
3. Categories of data subjects
Data subjects are in particular: - Clients of the studio - Parents/guardians (in U18 processes) - Staff and artists of the studio
4. Types of personal data
The following are processed in particular: - Master data (e.g. name, date of birth) - Contact data - Health details - Consents and signatures - Image and document data (e.g. IDs, treatment images)
5. Place of processing
Processing of personal data generally takes place within the European Union or the European Economic Area. Insofar as service providers with a registered office or server location outside the EU/EEA are used in the course of providing the service (e.g. for content delivery or security services), this only occurs if an adequate level of data protection is ensured, for example through EU Commission standard contractual clauses or an adequacy decision. A current overview of service providers processing data outside the EU/EEA can be provided upon request.
6. Responsibility
The controller is responsible for the lawfulness of data collection and processing. The processor processes data exclusively on documented instructions from the controller, unless required to do otherwise by European Union or member state law. If the processor considers an instruction to be unlawful, it will inform the controller without delay.
7. Confidentiality
The processor commits all persons authorized to process personal data to confidentiality or subjects them to an appropriate statutory duty of confidentiality. This obligation continues to apply even after the respective activity has ended.
8. Obligations of the processor
The processor undertakes to: - treat personal data confidentially - implement appropriate technical and organisational measures (TOMs) - only involve authorised personnel in processing - support the controller with data protection enquiries
9. Technical and organisational measures
Measures include in particular: - Access restrictions and role/permission systems - Encrypted connections (TLS) - Separate instances per studio - Protection against unauthorised access A detailed overview of the TOMs can be provided on request.
10. Notification of data breaches
The processor will inform the controller without undue delay, and no later than within 48 hours of becoming aware, of any breach of the protection of personal data within the meaning of Art. 33 GDPR that occurred in the context of the processing. The notification will include, to the extent known at that time, in particular the nature of the breach, the categories and approximate number of data subjects and records affected, and the measures already taken or proposed. The processor supports the controller in fulfilling its notification and communication obligations towards the supervisory authority and data subjects (Art. 33, 34 GDPR).
11. Support with data protection impact assessments
The processor supports the controller, to the extent technically possible and reasonable, in preparing data protection impact assessments (Art. 35 GDPR) as well as any prior consultations with the supervisory authority (Art. 36 GDPR), insofar as the processing under this agreement is relevant to this.
12. Sub-processors
Sub-processors (e.g. hosting or infrastructure service providers) are only used if they are contractually obliged to comply with the GDPR. The controller will be informed of the engagement of new sub-processors and of significant changes and may object within a reasonable period if a compelling reason exists.
13. Rights of data subjects
The processor supports the controller in upholding the rights of data subjects (e.g. access, deletion, rectification, data portability) where technically possible. If a data subject contacts the processor directly with a relevant request, the processor forwards the request to the controller without delay, unless independent handling has been agreed.
14. Verification and audit rights
The processor provides the controller, upon request, with all information necessary to demonstrate compliance with the obligations set out in Art. 28 GDPR. The controller is entitled to satisfy itself of compliance with these obligations to a reasonable extent and with reasonable prior notice, for example by obtaining self-disclosures or evidence from the processor. More extensive on-site inspections take place by prior arrangement and with due regard to the processor's legitimate interests, in particular the protection of other customers' data.
15. Termination of processing
After termination of the contract, personal data will be deleted or made available for handover at the controller's choice, provided there is no legal retention obligation.
16. Liability
The liability provisions of the main contract apply. Liability is governed by the statutory provisions of the GDPR.
17. Final provisions
The law of the Federal Republic of Germany applies. Should individual provisions of this DPA be invalid, the validity of the remaining provisions shall remain unaffected.