Legal
LensDeliver Data Processing Agreement
Effective date: 2026-06-13
Customer / Controller: the business customer using LensDeliver.
Processor: LensDeliver, operated by Szymon Gruszczyński, NIP 5361958833, REGON 520718806, address: woj. ŁÓDZKIE, pow. rawski, gm. Sadkowice, miejsc. Kaleń, nr 89, lok. 3, 96-206, Poland.
Privacy contact: privacy@lens-deliver.com
1. Purpose
This DPA sets out the terms under which LensDeliver processes personal data on behalf of the customer in connection with the LensDeliver service.
2. Subject matter and nature of processing
LensDeliver may process personal data as necessary to provide the service, including:
hosting and delivering galleries,
storing files and metadata,
authenticating users and managing sessions,
sending operational or gallery-related emails triggered by the customer,
logging technical and security events,
maintaining infrastructure, limits, diagnostics, and safety controls,
supporting public galleries and internal previews.
3. Categories of data
Depending on the customer's use of the service, processing may include:
customer account and staff data,
end-client and recipient data,
gallery files and related metadata,
access control data such as PINs, sessions, and tokens,
technical event and security data,
email delivery and webhook event data,
operational account and billing data.
4. Categories of data subjects
Data subjects may include:
the customer and its staff,
the customer's own clients,
gallery recipients,
operational and contact persons associated with the account.
5. Processor obligations
LensDeliver will:
process personal data only on documented customer instructions or as necessary to provide the service,
apply appropriate technical and organizational security measures,
ensure confidentiality,
support the customer in responding to data subject requests where reasonably possible,
notify the customer of a personal data breach without undue delay after becoming aware of it,
not use customer data for unrelated marketing purposes.
6. Customer obligations
The customer remains responsible for:
the legal basis for processing client and recipient data,
the content and scope of data uploaded to the service,
avoiding unnecessary or unlawful data uploads,
communicating with data subjects where the customer acts as controller.
7. Subprocessors
LensDeliver may use subprocessors necessary to deliver the service, including providers such as:
Cloudflare,
Fly.io,
Neon,
Resend,
Google,
future monitoring or operational tooling where introduced.
An operational subprocessor register is maintained separately.
8. International transfers
LensDeliver aims to keep the main application infrastructure, database, and storage in Europe where reasonably available.
Some supporting providers may nevertheless process data outside the EEA.
In practice, this currently concerns mainly email delivery services and certain Google services used for authentication or analytics.
Where transfers outside the EEA occur, LensDeliver relies on appropriate contractual or legal safeguards under the relevant provider documentation.
9. Retention and deletion
Raw webhook payloads may be retained for a short operational period and then deleted or anonymized.
Technical logs, sessions, and operational records may be retained for security, diagnostics, accountability, backup, and dispute handling.
Gallery data follows the configured publish, deactivate, purge, and cleanup logic of the service.
Analytics data related to the landing page is processed only after consent and under the relevant analytics configuration.
After the service relationship ends, LensDeliver will delete or return data where applicable, unless longer retention is required by law or justified by legitimate operational necessity.
10. Security measures
LensDeliver applies measures including:
encrypted transport,
access control through roles and secrets,
session and request limiting,
tenant isolation,
security event logging,
backup and recovery procedures,
emergency protection mechanisms,
limiting logs and payload storage to what is operationally necessary.
11. Audits and information
On a reasonable request, LensDeliver may provide information necessary to demonstrate compliance with this DPA, subject to proportionality, confidentiality, and operational feasibility.
