Data processing agreement
The Article 28 GDPR terms that apply when Knipsmig processes photos on your behalf
Version 1.0 · Last updated: August 31, 2026
When your company or organisation runs an event on Knipsmig, you decide why and how the photos are collected. That makes you the data controller and Knipsmig the data processor, and Article 28 of the GDPR requires a written agreement between us. This page is that agreement. It is deliberately short and written so that it can be read without a lawyer, but it covers every point Article 28(3) requires.
It applies automatically to every Knipsmig account, incorporated by reference in the Terms of service, so nothing needs to be signed for it to be in force. If your procurement or legal team needs a countersigned copy, email support@knipsmig.com and I will return one. To keep a copy of this version, print this page or save it as a PDF from your browser.
Knipsmig is built and run by me, Peter Theill, through my company Commanigy, and "Knipsmig" in the clauses below means Commanigy.
1. Parties and definitions
Customer (the controller) is the person or organisation holding the Knipsmig account that owns the event, together with the organisation on whose behalf that account is used.
Knipsmig (the processor) is Commanigy, CVR no. 21288497, Amaliegade 36, 1256 København K, Denmark, represented by Peter Theill and reachable at support@knipsmig.com.
"GDPR" means Regulation (EU) 2016/679. "Personal Data", "processing", "data subject", "controller", "processor", "sub-processor", "supervisory authority" and "personal data breach" have the meanings given in the GDPR. "Customer Data" means all Personal Data that Knipsmig processes on the Customer's behalf under this agreement, described in Annex 1. "Service" means the Knipsmig event photo sharing service at knipsmig.com.
2. Scope and roles
This agreement governs Knipsmig's processing of Customer Data in the course of providing the Service. The Customer is the controller and Knipsmig is the processor of Customer Data. The Customer is responsible for having a lawful basis for collecting event photos, for informing the people photographed, and for the content that the Customer and its guests upload.
Knipsmig acts as an independent controller, not a processor, for a limited set of data that concerns its own relationship with the Customer: the account holder's sign-in details, billing records, support correspondence and aggregated usage statistics. That processing is described in the Privacy policy.
3. Processing on documented instructions
Knipsmig processes Customer Data only on the Customer's documented instructions. The Customer's instructions are: this agreement, the Terms of service, and the settings the Customer chooses in the Service (for example enabling host approval, locking uploads, turning off AI captioning, keeping an event beyond the free retention period, ordering prints, or connecting a Google account). Using a feature of the Service is an instruction to carry out the processing that feature requires.
Knipsmig will tell the Customer without delay if it believes an instruction infringes the GDPR or other EU or member state data protection law. Knipsmig will only process Customer Data outside the Customer's instructions where required by EU or member state law, and will in that case inform the Customer of the legal requirement before processing, unless the law prohibits it.
Knipsmig does not sell Customer Data, does not use it for advertising, does not use it to train artificial intelligence or machine learning models, and does not share it with anyone other than the sub-processors listed in Annex 2 and any recipient the Customer directs.
4. Confidentiality
Knipsmig is operated by a single person who is bound by this confidentiality obligation. Should Knipsmig engage staff or contractors with access to Customer Data, they will be bound by written confidentiality obligations before being granted access, and access will be limited to what their role requires.
5. Security
Knipsmig implements the technical and organisational measures described in Annex 3 and keeps them under review. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, these measures are designed to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. Knipsmig may update Annex 3 as the Service evolves, provided the overall level of security is not reduced.
6. Sub-processors
The Customer gives Knipsmig general written authorisation to engage the sub-processors listed in Annex 2. Knipsmig imposes data protection obligations on each sub-processor, by contract or by the sub-processor's published data processing terms, that are no less protective than those in this agreement, and remains fully liable to the Customer for the sub-processor's performance.
Knipsmig will update Annex 2 at least 14 days before adding or replacing a sub-processor that processes Customer Data. Customers who want to be notified directly can email support@knipsmig.com and ask to be added to the sub-processor notification list. If the Customer has reasonable data protection grounds to object to a new sub-processor, it may object in writing within those 14 days. If Knipsmig cannot accommodate the objection, the Customer may delete the affected event or terminate the Service without penalty.
Where a sub-processor is engaged only for an optional feature (marked as such in Annex 2), it receives Customer Data only when the Customer chooses to use that feature.
7. International transfers
Customer Data is stored at rest on infrastructure located in the European Economic Area: application servers and database in Germany, and media storage in the Netherlands, Germany and Ireland. Knipsmig will not move Customer Data at rest outside the EEA without updating this agreement and Annex 2 under clause 6.
Some sub-processors in Annex 2 are established outside the EEA or operate global infrastructure, and certain processing steps (content delivery, automated captioning, transactional email) may involve a transfer to a third country. Every such transfer is covered by an adequacy decision (including the EU-US Data Privacy Framework where the sub-processor is certified) or by the European Commission's Standard Contractual Clauses incorporated in the sub-processor's data processing terms, together with any supplementary measures the sub-processor documents. Annex 2 states the mechanism relied on for each sub-processor.
8. Assistance with data subject rights
The Service is built so that the Customer can handle most data subject requests directly: the event owner can view, download and delete any individual photo, video or voice message, delete a whole event, and export all event media as a zip file at any time. Removing an employee's photo in response to an erasure request takes seconds and needs no involvement from Knipsmig.
Where a request cannot be handled through the Service, Knipsmig will assist the Customer with appropriate technical and organisational measures, insofar as possible, within 10 working days of a request to support@knipsmig.com. If a data subject contacts Knipsmig directly about Customer Data, Knipsmig will not respond on the merits but will refer the person to the Customer and inform the Customer, unless the request concerns data for which Knipsmig is the controller.
9. Personal data breaches and other assistance
Knipsmig will notify the Customer without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting Customer Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information that is not yet available will follow as it becomes known. Notification is sent to the email address of the Customer's Knipsmig account.
Taking into account the nature of the processing and the information available to it, Knipsmig will assist the Customer in meeting its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), including by providing the information in this agreement and its annexes.
10. Deletion and return
The Customer can export all Customer Data for an event as a zip download at any time during the term, so return of data is available on demand and without assistance.
When the Customer deletes a photo, an event, or its account, or when a free event reaches the end of its retention period (about one month after the event date, with advance notice by email), Knipsmig deletes the corresponding Customer Data from the database and from primary media storage immediately. Cached copies at the content delivery network are reachable only through the original unguessable URL and expire from the cache thereafter; residual copies in short-lived operational logs are overwritten within 30 days.
Knipsmig will not retain Customer Data after the end of the Service except where EU or member state law requires storage, in which case only the data required will be kept, for only as long as the law requires.
11. Information and audits
Knipsmig makes available all information necessary to demonstrate compliance with Article 28 GDPR: this agreement, its annexes, the Privacy policy, and, on request, further written answers to reasonable questions from the Customer's data protection officer, auditor or supervisory authority.
Where written information is insufficient to satisfy a legal obligation of the Customer, Knipsmig will allow and contribute to an audit or inspection by the Customer or an independent auditor mandated by the Customer, on at least 30 days' written notice, no more than once per year unless a supervisory authority requires otherwise or a personal data breach has occurred, during normal business hours, and subject to reasonable confidentiality obligations. The Customer bears its own audit costs. Audits of sub-processor facilities are satisfied by the sub-processor's own certifications and audit reports.
12. Term, liability and governing law
This agreement takes effect when the Customer first uploads Customer Data to the Service and lasts for as long as Knipsmig processes Customer Data. Clauses 4, 10 and 11 survive termination for as long as Knipsmig holds any Customer Data.
Each party is liable for damage caused by processing that infringes the GDPR in accordance with Article 82 GDPR. Otherwise, the limitations of liability in the Terms of service apply to this agreement, to the extent permitted by data protection law.
In the event of conflict between this agreement and the Terms of service regarding the processing of Customer Data, this agreement prevails. Knipsmig may update this agreement to reflect changes in the Service or in the law; material changes are announced at least 30 days in advance on this page and to the Customer's account email, and the version number and date above identify the current text.
This agreement is governed by Danish law, without prejudice to the mandatory provisions of the GDPR, and the courts of Denmark have jurisdiction over any dispute arising from it.
Annex 1: Details of the processing
- Subject matter
- Collecting, storing, organising and making available photos, videos and optional voice messages from the Customer's events, and the related event administration.
- Duration
- From the first upload until the Customer deletes the event or account, or, for free events, until automatic deletion about one month after the event date. Events kept by the Customer are retained until the Customer deletes them.
- Nature and purpose
- Hosting and storage; generating thumbnails and web-sized versions; displaying media in the event gallery, slideshow and live wall; automated captioning and tagging of each image so the gallery can be searched and organised, and optional transcription of voice messages, both of which the Customer can turn off per event; zip export and download; sending the Customer transactional emails about the event; and, only when the Customer orders or enables them, print fulfilment, photobook and magazine production, and copying media to the Customer's own Google Drive or Google Photos.
- Categories of data subjects
- The Customer's event organisers and co-hosts; event guests who upload or view media (employees, attendees, family members); and any person who appears in uploaded media, including people who did not attend.
- Categories of personal data
- Photos, videos and voice messages, which may show identifiable people and, if the file carries it, the time and GPS location of capture; automatically generated captions, tags and transcripts derived from that media; an optional display name a guest chooses to attach to their uploads; event name, date and description; the co-host's email address if the Customer invites one; and technical data such as IP address, browser type and access timestamps in short-lived server logs. Guests do not create accounts, and no guest email address or profile is collected.
- Special categories of data
- None are requested or intended. The Customer acknowledges that photographs may incidentally reveal information such as ethnic origin, health, or religious belief, and that the Customer is responsible for the lawful basis for any such processing.
Annex 2: Sub-processors
Current as of the date at the top of this page. Rows marked "optional" receive Customer Data only when the Customer uses that feature.
| Sub-processor | Purpose | Data location | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH (Germany) | Application servers, database and object storage for media | Germany | EEA, no transfer |
| Backblaze, Inc. (United States) | Object storage for uploaded media | Netherlands (EU region) | Data at rest in the EEA; Standard Contractual Clauses for any support access |
| Amazon Web Services EMEA SARL (Luxembourg) | Object storage for media uploaded before Knipsmig's move to Hetzner and Backblaze | Ireland | EEA, no transfer |
| Cloudflare, Inc. (United States) | DNS, TLS termination, DDoS protection and content delivery cache for media | Global edge network; cached copies are transient | EU-US Data Privacy Framework and Standard Contractual Clauses |
| OpenAI (OpenAI Ireland Ltd / OpenAI, L.L.C.) | Automated caption and tag generation for each uploaded image; transcription of voice messages. The Customer can turn this off per event in the gallery settings. API data is not used to train OpenAI models. | United States, processed transiently and not retained beyond OpenAI's abuse-monitoring window | EU-US Data Privacy Framework and Standard Contractual Clauses |
| Resend, Inc. (United States) | Transactional email to the Customer and invited co-hosts (event notices, deletion warnings, zip links) | United States | Standard Contractual Clauses |
| Google LLC / Google Ireland Ltd | Google Tag Manager and Google Analytics for aggregated usage statistics; Google sign-in for the account holder. Optional: copying event media to the Customer's own Google Drive or Google Photos when the Customer connects an account | EU and United States | EU-US Data Privacy Framework and Standard Contractual Clauses |
| Ahrefs Pte. Ltd. (Singapore) | Cookieless, aggregated web analytics (page views, referrers, device type) | Singapore and EU | Standard Contractual Clauses |
| Stripe Payments Europe, Ltd. (Ireland) | Optional: payment processing for the account holder's purchases; receives billing details, not event media | EU and United States | EU-US Data Privacy Framework and Standard Contractual Clauses |
| Prodigi Group Ltd. (United Kingdom) | Optional: printing and shipping photo prints, photobooks and magazines; receives the ordered images and the delivery address | United Kingdom | EU adequacy decision for the United Kingdom |
Annex 3: Technical and organisational measures
- Encryption in transit. All connections between guests, the application, the content delivery network, storage providers and sub-processors use TLS. Plain HTTP is not served.
- EEA storage. Database and media are stored at rest on infrastructure in Germany, the Netherlands and Ireland. Storage credentials are held in encrypted Rails credentials, never in source code.
- Access to events. Each event has a long, randomly generated identifier that is not listed, indexed or linked anywhere. Owner functions require signing in through Google or Apple; Knipsmig stores no passwords. Co-hosts are invited explicitly by the owner.
- Customer controls. Host approval of uploads before they are visible to other guests, locking of further uploads, disabling guest downloads, turning off AI captioning and transcription, per-item and whole-event deletion, and zip export are available to the owner at any time.
- Data minimisation. Guests upload without accounts. Only an optional display name is collected from them. Free events are deleted automatically about one month after the event date, with a warning email beforehand.
- Encryption at rest of credentials. OAuth tokens for optional Google connections are encrypted at rest with application-level encryption.
- Infrastructure access. Production servers are reachable only over SSH with key authentication, by the operator alone. Provider consoles are protected by strong unique passwords and multi-factor authentication.
- Upload validation. Uploads are restricted to image, video and audio types; files are validated on ingest, and derived versions (thumbnails, web-sized images, transcoded video) are generated server-side for display.
- Logging. Application logs are short-lived and are used only for troubleshooting and abuse prevention. They are not exported to third-party log services.
- Deletion. Deleting a photo or event removes the record and purges the files from storage immediately.
- Sub-processor due diligence. Sub-processors are selected for EEA hosting where the function allows it, and each is bound by data processing terms including Standard Contractual Clauses or Data Privacy Framework certification for any third-country transfer.
- Software updates. The application and its dependencies are updated regularly; security advisories for the framework and libraries are monitored and patched promptly.
Questions
Questions about this agreement, requests for a countersigned copy, or requests to join the sub-processor notification list go to support@knipsmig.com.