Legal
Data Processing Agreement (DPA)
Effective Date: July 1, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Conditions between the User ("Controller") and ApprovePictures ("Processor") and applies whenever the Processor processes personal data on behalf of the Controller in the course of providing the Service. It is entered into pursuant to Article 28 of the EU General Data Protection Regulation (GDPR).
1. Parties
Processor: Christian Nikita Valsvik (sole proprietorship), organization number 836 259 882, Ustedalen 84, 3580 Geilo, Norway. Contact: support@approvepictures.com.
Controller: The registered account holder (photographer, studio, or agency) using the Service to collect proofing feedback and deliver assets to their own end-customers. By creating an account or uploading images through the Service, the Controller accepts this DPA.
2. Scope & Subject Matter
The Processor processes personal data solely to (a) host and display the Controller's galleries, (b) receive and store end-customer feedback (stars, comments, markings), (c) route optional payment flows through Stripe, and (d) deliver notifications and asset downloads as configured by the Controller. Duration of processing follows the lifetime of the Controller's account and each gallery's expiration policy.
3. Categories of Data and Data Subjects
- Data subjects: Controller's end-customers and any individuals identifiable from the uploaded imagery.
- Personal data: Photographic imagery, gallery feedback (stars, comments, markings), email addresses used to invite end-customers, IP-hash based rate-limiting identifiers, and payment reference tokens.
4. Processor Instructions
The Processor will process personal data only on documented instructions from the Controller, including with regard to transfers to a third country, unless required to do so by EU or Member State law. Use of the Service through its interfaces constitutes such documented instructions.
5. Confidentiality
The Processor ensures that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
6. Security Measures
The Processor implements appropriate technical and organisational measures under GDPR Article 32, including: encryption in transit (TLS) and at rest, unguessable 20-character share tokens, brute-force rate-limiting on password-protected galleries, isolated support-audit tokens, row-level security in the database, and least-privilege access to the production environment.
7. Sub-processors
The Controller grants general authorisation for the Processor to engage the sub-processors listed below. The Processor will announce intended additions or replacements at least 30 days in advance via email or in-app notice; the Controller may object on reasonable grounds.
- Supabase (database, storage, authentication) — EU region
- Lovable Cloud (application hosting, deployment) — EU region
- Cloudflare (edge network, transport security) — global CDN under SCCs
- Stripe (payments processing) — EU / global under SCCs
- Google Identity (OAuth sign-in) — global
- Lovable Email (transactional email delivery) — EU region
- Sentry (Functional Software, Inc.) — error and crash monitoring for the browser (consent-gated) and the server runtime (legitimate interest); EU region, with PII scrubbing applied before transmission
8. International Transfers
Personal data is processed primarily within the European Union. Where a sub-processor operates outside the EEA, transfers are protected by the European Commission's Standard Contractual Clauses (2021/914) or an adequacy decision.
9. Data Subject Rights & Assistance
Taking into account the nature of the processing, the Processor provides tools that allow the Controller to fulfil requests from data subjects to exercise their rights under GDPR Chapter III, including access, rectification, restriction, portability and erasure. Additional assistance beyond built-in Service capabilities may be requested in writing at support@approvepictures.com.
10. Personal Data Breaches
The Processor will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach, providing the information required under GDPR Article 33(3) to the extent then available.
11. Termination & Return / Deletion
On termination of the Controller's account, the Processor will delete or return (at the Controller's choice) all personal data processed on behalf of the Controller, and delete existing copies unless retention is required by EU or Member State law. Anonymous galleries are automatically purged 7 days after creation; registered galleries are deleted on the schedule chosen by the Controller and no later than 30 days after archival.
12. Audits
The Processor will make available to the Controller all information necessary to demonstrate compliance with GDPR Article 28 obligations. Where more detailed audits are required, the Controller may request a written audit summary once per calendar year at no cost, or arrange an inspection at the Controller's expense with reasonable prior notice.
13. Governing Law
This DPA is governed by the laws of Norway. Disputes are subject to the exclusive jurisdiction of the Norwegian courts, with venue in Geilo. The rights and obligations of the parties under the GDPR remain unaffected.
