Legal
Data Processing Agreement
If there is a person in the material you send us, we are processing personal data that is yours — and the GDPR then requires us to have an agreement about it. This is that agreement.
1. Two roles, and the difference matters
A single order has us processing two kinds of data, and the GDPR gives us a different role for each. That sounds like paperwork and is not: it decides who makes the call, who reports a breach to the regulator, and who a data subject should turn to.
- Your own data — your name, your company details, your email address, your VAT number, your messages. For those we are the controller: we decide why we need them and how long we keep them. That is covered by our Privacy Policy, not by this document.
- The material you supply, to the extent there are people in it — in practice mostly the worn shot we ask for so the fit is right. The person in that photo is your data subject: you took the photo, you have the arrangement with them, you decide what the image is for. We process it solely on your instruction. For that we are the processor and you are the controller — and that is what this document is about.
This agreement applies automatically as soon as you place an order, as an inseparable part of our Terms of Service. There is nothing to sign. If you need a signed copy for your own records, email hello@visuails.com and you will get one.
2. The parties
Processor: VISUAILS, trading name of Lucas Snuverink, Vaarwerkhorst 17, 7531 HK Enschede, the Netherlands. KVK 99742993 · VAT NL005407575B96 · hello@visuails.com. This is a registered and postal address, not a visiting address.
Controller: you — the business placing the order, as identified at checkout.
3. Subject matter, nature, purpose and duration
Subject matter and purpose. Producing product visuals and video from the material you supply, and delivering them to you. There is no other purpose. We do not use your material for our own portfolio, for advertising, or to learn anything from it, unless you give us separate and demonstrable permission per order.
Nature of the processing. Receiving, storing, passing to the sub-processors in §8, being looked at and reviewed by a person, and deleting. Nothing is profiled and nothing is decided automatically.
Duration. This agreement starts with your first order and ends once the last piece of data it covers has been deleted — see §12. It therefore outlives the order itself, and that is deliberate.
4. Type of personal data and categories of data subjects
Type of personal data. Images of natural persons in the material you supply, plus whatever is visible in it or sits in its file metadata — a face, a body, sometimes a name on a label or a location in the EXIF data.
Categories of data subjects. The people appearing in that material: usually a model, an employee, or you.
What does not belong in it. We never ask for special categories of personal data within the meaning of Art. 9 GDPR, and never for images of children. If you supply material that contains them anyway, we do not process it under this agreement and we will contact you. Note that a face in a photograph is not automatically biometric data: it becomes that only through processing aimed at unique identification, and we do not do that.
5. We process only on your instruction
We process the personal data solely on your documented instruction and not for our own purposes. Your order — the form, the brief, and the correspondence about it — is that instruction. There is no other.
That includes transfers outside the European Economic Area: we transfer nothing beyond what §8 and §11 set out, unless you instruct us to or Union or Dutch law requires it of us. If the law requires something that departs from this, we tell you before we do it, unless that law forbids us from telling you.
If we believe an instruction of yours infringes the GDPR, we say so and we do not carry it out until it is resolved. That is not us refusing to work; it is the last paragraph of Art. 28(3).
6. Confidentiality
VISUAILS is a sole trader. In practice that means one person has access, and that person is Lucas Snuverink. If we ever bring someone in — an employee, a freelancer for retouching — it happens only after that person has committed to confidentiality in writing, and that commitment survives the end of the engagement. We keep material confidential without being asked and without a separate NDA.
7. Security
What follows is what actually exists, and nothing more. We are not ISO certified, no penetration test has been carried out, and there is no information security management system. A security clause that promises more than is there is the clause that gets used against us when something happens.
- Encrypted in transit and at rest. All traffic runs over TLS. Material sits in Cloudflare R2 and order data in Cloudflare D1, both encrypted at rest.
- Addresses that cannot be guessed. Supplied material sits under a key with a random component; there is no sequential numbering anyone could walk to reach someone else’s files.
- Access behind its own lock. The admin portal uses a hashed password and session tokens that are themselves stored hashed. Your own portal uses a single-use sign-in link or code, with cookies that are
HttpOnlyandSecureand scoped to your dashboard path. - An ownership check on every file. Every download passes a check tied to the order rather than to the URL. It is built that way on purpose and it is tested on every change by a test that deliberately tries to weaken the check.
- Rate limits on ordering, uploading, signing in and fetching files, so a script cannot keep trying.
- No raw IP addresses. Where we have to count traffic we store a salted hash, not the address.
- The retention periods are executed, not just promised. A nightly task deletes what has expired, from storage and from the database, and records on the order’s timeline what went. That is the difference between a period in a document and a period in reality.
- A weekly copy of the database on a disk we control ourselves, so losing the platform does not mean losing your order. That copy contains personal data. It does not go to a cloud service, it does not sit in a shared folder, and it is not committed to the source code history. A nightly task checks that this copy is no older than ten days and warns us if it is — a backup nobody notices has stopped is not a backup.
We reassess these measures whenever something material changes in what we process, and in any case once a year.
8. Sub-processors
We use other parties. You hereby give us a general written authorisation for that, within the meaning of Art. 28(2) GDPR, on three conditions: this list is current, we announce an addition or replacement at least 30 days in advance by email, and you may object during that period. If you do, we find an alternative or you may end the engagement free of charge for the part not yet performed.
With each party below we have a processor agreement that passes on the same obligations we owe you (Art. 28(4)). We remain liable to you for what they do.
| Who | Where | For what | Transfer basis |
|---|---|---|---|
| Freepik Company, S.L.U. | Málaga, Spain (EU) | generating the visuals from your material | inside the EU; no transfer at this level |
| Cloudflare, Inc. | United States, with storage in the EU | storing the material you supply and the visuals we deliver, and running the site | processor agreement with Standard Contractual Clauses (SCCs) |
| Resend | United States | email; the order notice to the studio carries the supplied material as an attachment | processor agreement with Standard Contractual Clauses (SCCs) |
About the generation itself. Freepik offers a large number of models on its platform, from different makers. Which one we use at a given moment changes — we work with whatever gives the best result at the time, and that is part of how we do our job. The party that receives your material stays the same and is named above; that is what this clause has to fix. Freepik states expressly in its own terms: "Under no circumstances will we use your images or voices, or those of third parties that you upload to our platform, to train or improve our artificial intelligence models or those of third-party providers", and that supplied images are deleted immediately after generation. For transfers to model providers outside the EEA, Freepik concludes Standard Contractual Clauses (Art. 46(2)(c) GDPR).
Retouching happens on our own machine. Retouching and editing are done in Photoshop and in DaVinci Resolve, locally. Those programs do not send your material to a cloud service: the file sits on the disk, is edited there, and leaves there under the periods in §3. Adobe and Blackmagic Design are therefore not on the list above — they do not receive your material. Adobe writes about locally stored material in its own terms: "For Content stored locally on your device, we do not scan or review your Content." Software running on our machine processes nothing on our behalf; a service that receives the file does. That distinction decides who belongs on the list. If we ever move to a cloud service for retouching — Adobe’s own cloud storage included — that is an addition to the list, with the 30 days' notice set out above.
What is not on this list, and why. Our payment provider and the review platforms are absent. They do not touch your material; they only process data for which we are ourselves the controller. Those are covered in the Privacy Policy.
9. Data subject rights
If the person in the image comes to us with a request — access, erasure, objection — we do not answer it ourselves. That request belongs with you, because you are the controller. We forward it to you within three working days and then help with whatever it takes technically: we find where the image is, hand it over or delete it, and confirm in writing what happened. That help is free within normal use of the service.
10. Personal data breaches
If we discover a security breach affecting your personal data, we report it to you and not to the Dutch DPA. That is not a choice: as a processor that is exactly our role (Art. 33(2) GDPR). You then decide whether a report is due — and the 72-hour clock for your report starts running the moment we put it in front of you. So we put it there quickly: within 24 hours of knowing, even if the picture is not yet complete.
What that report contains: what happened, when, which kinds of data and which data subjects it likely affects, what we have already done to limit it, and what we do not yet know. That last part is in there too. We add to it as we learn more, and we keep our own record of every incident — including the ones that do not need reporting.
We help you further with what Art. 32 to 36 GDPR asks of you, including a data protection impact assessment if your use needs one.
11. Transfers outside the European Economic Area
The generation happens with a party in Spain, so inside the EU. Where a sub-processor in §8 is established outside the EEA, the transfer rests on the European Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR). We do not transfer personal data to a country or party outside that list without informing you first.
One thing we write down more plainly than is customary: when the visuals are made, material is placed into the sub-processor’s tool by a person, from our environment. So it is not an automatic integration but an act, and it falls under the same arrangements as the rest of this agreement.
12. Return and deletion
The periods below are the same ones as in §7 of the Terms and §6 of the Privacy Policy. They are executed by a nightly task, not by hand.
- The material you supply: 90 days after the order, then deleted.
- The visuals we deliver: 90 days in VISUAILS Studio, so you can fetch them again in that time; a copy may remain in our own archive without guarantee.
Want it gone sooner? Email us and we delete it — unless a statutory retention duty stands in the way, and then we say which one. At the end of this agreement we delete everything it covers, copies included, or return it to you if you prefer. Anything that has to stay for that reason stays only for that reason and is not used again.
The data we hold as controller — your invoice, your company details — is not covered here. Those carry the seven-year Dutch tax retention duty, and that is set out in the Privacy Policy.
13. Audit, liability and closing
Audit. Once a year, and additionally after a breach affecting your data, you may request what you need to establish that we keep to this agreement. We answer within two weeks. If you want an inspection by an independent expert we will cooperate; the cost is yours, unless it turns up something we should have fixed.
Liability. For damage arising from processing in breach of the GDPR, Art. 82 GDPR applies. The liability cap in §11 of the Terms does not apply to GDPR fines or damages attributable to us. That is a deliberate choice: a privacy clause that caps its own liability at the order value is not an agreement but an exit.
Closing. Where this agreement differs from the Terms of Service, this agreement prevails, but only for the processing of personal data. Dutch law applies; the Overijssel District Court has jurisdiction. If the GDPR changes or binding rules are added, we amend this text and announce it the same way we announce a change to §8.
14. Questions
About this agreement, about a data subject request, or to get a signed copy: hello@visuails.com. One person reads that inbox, and it is the same person who carries out the processing.
This page was drafted against the text of Article 28 GDPR and covers points (a) to (h) of paragraph 3. It has not yet been reviewed by a lawyer. For your own situation — certainly if you sit in a chain with more than one controller — have your own adviser check it.