APPENDIX I: Data Processing Agreement
This Data Processing Agreement governs how IMGFILETOOLS processes personal data on behalf of the Controller in accordance with Regulation (EU) 2016/679 (GDPR).
Last revision: September 8, 2026
Introduction
This data processing agreement (the "Data Processing Agreement" or "Processing Agreement") applies to the processing of personal data that IMGFILETOOLS ("IMGFILETOOLS" or the "processor"), operated by IMGFILETOOLS (operator of imgfiletools.com), carries out on your behalf in relation to personal data contained in files you upload when using our services.
The use of these services requires access to and processing by IMGFILETOOLS, as a processor, of certain personal data for which you act as a controller (the "controller").
This Processing Agreement forms part of the IMGFILETOOLS Terms & Conditions and applies upon acceptance of those Terms. In the event of conflict, this Processing Agreement prevails over the Terms & Conditions.
Related: Privacy Policy · Appendix II — SCC Module 4
Clause 1 — Purpose and scope
The purpose of this Processing Agreement is to ensure compliance with Article 28(3) and (4) of the GDPR. It applies to the processing of personal data specified in Annex I. Annexes I and II form part of this Agreement. These terms do not by themselves ensure compliance with Chapter V GDPR obligations related to international transfers.
Clause 2 — Interpretation
Terms defined in the GDPR have the same meaning here. This Agreement shall be read in light of the GDPR and shall not be interpreted in a way that conflicts with GDPR rights and obligations or prejudices fundamental rights of data subjects.
Clause 3 — Hierarchy
In the event of a contradiction between this Processing Agreement and related agreements between the Parties, this Processing Agreement shall prevail.
Clause 4 — Description of processing(s)
Annex I specifies the details of the processing operations, including categories of personal data and purposes for which personal data is processed on behalf of the controller.
Clause 5 — Obligations of the Parties
5.1 Instructions
The processor shall process personal data only on documented instructions from the controller, unless required otherwise by Union or Member State law. The processor shall inform the controller if, in its opinion, an instruction infringes the GDPR or applicable data protection law.
5.2 Purpose limitation
The processor shall process personal data only for the specific purpose(s) set out in Annex I, unless it receives further instructions from the controller.
5.3 Duration
Processing shall only take place for the duration specified in Annex I.
5.4 Security of processing
The processor shall implement at least the technical and organisational measures in Annex II to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Access is limited to personnel who need it and who are under confidentiality obligations.
5.5 Sensitive data
If processing involves special categories of data or data relating to criminal convictions, the processor shall apply additional restrictions and/or safeguards as appropriate.
5.6 Documentation and compliance
The Parties shall be able to demonstrate compliance. The processor shall deal promptly with controller inquiries and, upon request, make available information necessary to demonstrate compliance and contribute to audits. Audits are limited to what is strictly necessary, generally to a maximum of one (1) audit per year, with at least one (1) month prior notice, and are carried out at the controller's expense unless otherwise agreed.
5.7 Use of sub-processors
The processor has the controller's general authorisation to engage sub-processors. The processor shall impose substantively equivalent data protection obligations on sub-processors and remains responsible to the controller for their performance.
5.8 International transfers
Transfers to a third country or international organisation will be carried out in accordance with Chapter V of the GDPR, including adequacy decisions or Standard Contractual Clauses. Where a transfer from the processor to the controller requires Module 4 SCCs, see Appendix II.
Clause 6 — Assistance to the controller
The processor shall promptly notify the controller of any data subject request it receives and shall not respond itself unless authorised. The processor shall assist the controller, taking into account the nature of processing, with DPIAs, prior consultation, accuracy, and Article 32 GDPR security obligations as set out in Annex II.
Clause 7 — Notification of personal data breach
In the event of a personal data breach concerning data processed on behalf of the controller, the processor shall notify the controller without undue delay after becoming aware of it, including a description of the nature of the breach, a contact point, likely consequences, and measures taken or proposed.
ANNEX I — Description of the processing
Categories of data subjects
Those whose data is contained in files the controller uploads when using IMGFILETOOLS services (for example employees, customers, suppliers).
Categories of personal data
Those categories of personal data included in files uploaded when using the services.
Sensitive data
Special categories of personal data will be processed only to the extent such data appears in uploaded files. Appropriate purpose limitation and access restrictions apply.
Nature of the processing
Actions necessary to provide the services (for example conversion, editing, compression, rendering, or document generation related to uploaded content).
Purpose(s)
To provide the requested IMGFILETOOLS services on behalf of the controller.
Duration
To the extent strictly necessary to provide the services. Uploaded Content is generally deleted within 2 hours after processing.
Sub-processors
IMGFILETOOLS uses third-party providers (for example cloud hosting, object storage, email, and payment processors where applicable) acting as sub-processors under our instructions with appropriate technical and organisational measures. For an up-to-date list, contact [email protected].
ANNEX II — Technical and organisational measures
- Measures to protect against interception, unauthorized copying, modification, and destruction of transferred information.
- Procedures and policies to detect, protect against, and mitigate malware.
- Protection of sensitive information when transmitted as attachments or over the network.
- Acceptable-use policies for communication and system resources.
- Organisational accountability for staff and third parties with authorised access.
- Cryptographic techniques to protect confidentiality, integrity, and authenticity where appropriate.
- Retention and disposal guidelines aligned with applicable law and product retention windows.
- Staff confidentiality expectations and secure-handling practices for sensitive information.
Version control: September 8, 2026