In short
When HYPERTURE processes your team's photos and account data, your organization is the controller and we are the processor. This DPA sets out our obligations under Article 28 of the GDPR - instructions, confidentiality, security, sub-processors, transfers, breach notification, and deletion - with the specifics in Annexes A-C. It applies automatically alongside the Terms of Service; no signature is required unless you ask for a counter-signed copy.
01
Scope & relationship
This DPA applies where HYPERZ AI B.V. ("HYPERTURE", "Processor") processes personal data on behalf of a customer organization ("Customer", "Controller") in connection with the HYPERTURE service. It supplements and forms part of the agreement between the parties.
Where this DPA refers to the GDPR, it means Regulation (EU) 2016/679 and any national implementing laws, as well as equivalent data protection laws that apply to the processing.
02
Definitions
Terms such as "controller", "processor", "personal data", "processing", "data subject", "personal data breach", and "sub-processor" have the meanings given to them in the GDPR.
"Customer Personal Data" means personal data that HYPERTURE processes on behalf of the Customer under the agreement, as described in Annex A.
03
Roles & responsibilities
The Customer is the controller of Customer Personal Data and HYPERTURE is the processor. The Customer is responsible for the lawful basis of the processing, including obtaining and maintaining each individual's consent for their photos to be processed and for the resulting headshots to be used.
HYPERTURE will process Customer Personal Data only as a processor, in accordance with this DPA and the Customer's documented instructions.
04
Processing instructions
HYPERTURE processes Customer Personal Data only on the Customer's documented instructions, including those given through the service's configuration, the agreement, and this DPA. If we are required by law to process beyond those instructions, we will inform the Customer in advance unless the law prohibits it.
We will promptly inform the Customer if, in our opinion, an instruction infringes applicable data protection law. We are not obliged to monitor the Customer's compliance with the law.
05
Confidentiality
HYPERTURE ensures that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and are trained on their data protection responsibilities. Access is granted on a need-to-know, least-privilege basis.
06
Security measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, and risks of the processing, HYPERTURE implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex B.
Given that Customer Personal Data includes facial images, we apply heightened controls to the storage, access, and deletion of source photos and per-person models.
07
Sub-processors
The Customer provides general authorization for HYPERTURE to engage sub-processors to support the service. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. A current list is set out in Annex C.
We will give the Customer prior notice of any intended addition or replacement of a sub-processor, allowing the Customer to object on reasonable data protection grounds.
08
Data subject requests
Taking into account the nature of the processing, HYPERTURE assists the Customer with appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights under the GDPR. Where a data subject contacts us directly about Customer Personal Data, we will promptly refer them to the Customer.
09
Personal data breaches
HYPERTURE notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provides the information reasonably available to assist the Customer in meeting its own notification obligations. We will take reasonable steps to mitigate the effects and to minimize any damage.
10
DPIA & prior consultation
HYPERTURE provides reasonable assistance to the Customer with any data protection impact assessment and any prior consultation with a supervisory authority that the Customer is required to carry out, in each case in relation to the processing under this DPA and taking into account the information available to us.
11
International transfers
HYPERTURE hosts Customer Personal Data on infrastructure in the European Union. Where any transfer of Customer Personal Data outside the European Economic Area takes place, it is carried out under an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses, which are incorporated by reference, together with any supplementary measures required.
12
Return & deletion
On termination of the service, or on the Customer's request, HYPERTURE deletes or returns Customer Personal Data and deletes existing copies, unless retention is required by law. Source photos and per-person models are deleted within 30 days of generating a set in the ordinary course, and on request at any time.
13
Audits
HYPERTURE makes available to the Customer information reasonably necessary to demonstrate compliance with Article 28 of the GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates. Audits are subject to reasonable notice, confidentiality, and frequency limits, and may be satisfied through up-to-date certifications or third-party reports where available.
14
Liability & precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the agreement. In the event of a conflict between this DPA and the agreement on the subject of data protection, this DPA prevails. Where Standard Contractual Clauses apply, they prevail over this DPA to the extent of any conflict.
This DPA remains in effect for as long as HYPERTURE processes Customer Personal Data.
Annex A
Details of processing
Annex B
Security measures
HYPERTURE maintains technical and organizational measures including, at a minimum:
- Encryption of personal data in transit (TLS) and at rest.
- Role-based access controls, multi-factor authentication for internal access, and least-privilege provisioning.
- Audit logging of access to source photos and generated sets.
- Network segmentation, hardened infrastructure, and regular patching.
- Secure software development practices and dependency monitoring.
- Backup, resilience, and tested restoration procedures.
- Personnel confidentiality obligations and data protection training.
- Defined retention and secure deletion of source photos and per-person models.
- An incident response process for detecting, reporting, and handling personal data breaches.
Annex C
Sub-processors
HYPERTURE engages the following categories of sub-processor to deliver the service. The current named list is available on request at privacy@hyperture.ai.