Data Processing Agreement
Version 2026-09-15. This agreement applies only where you use Pictomemo as a business, association or other organisation and the photos you upload contain personal data of people for whom you are the controller. For personal use, the Privacy Policy is the applicable document.
1. Parties and roles
This Data Processing Agreement ("DPA") is between you, the customer ("Controller"), and A. Alae, trading as Pictomemo, Tangier, Morocco ("Processor"). It forms part of the Terms of Service. Where you upload photos containing personal data of employees, members, clients or other people in the course of your activity, you act as Controller and Pictomemo processes that data on your behalf as Processor. For your own account data, Pictomemo remains an independent controller under the Privacy Policy.
2. Subject matter, duration, nature and purpose
Processing of photographs and related data supplied by the Controller, for the purpose of producing a memory book (digital and printed) as described in the Terms, for as long as the Controller keeps a book or an account with Pictomemo, and for the retention periods in the Privacy Policy afterwards. Categories of data subjects: the people shown in the photos. Categories of data: images, dates and places of photos, names given by the Controller, and, where the Controller enables it, short-lived face signatures used to group photos of the same person within one book.
3. Controller's obligations
The Controller warrants that it has a lawful basis and, where required, the consent of the people shown (and of parents or guardians for children) to have their images processed for a memory book, that its instructions comply with applicable law, and that it will not upload special categories of data beyond what images incidentally reveal.
4. Processor's obligations
Pictomemo will: process the data only on the Controller's documented instructions, which are these Terms, the settings chosen in the Service and any written instruction sent to contact@pictomemo.com, unless the law requires otherwise, in which case it will inform the Controller before processing where the law allows; ensure that people authorised to process the data are bound by confidentiality; implement the technical and organisational measures described in section 10 of the Privacy Policy; assist the Controller, considering the nature of the processing, in responding to data subject requests, through the self-serve tools and the data request form; assist with security, breach notification, impact assessments and prior consultation where required; delete or return the data at the end of the service as described in section 7 of the Privacy Policy, unless the law requires retention; and make available the information necessary to demonstrate compliance, allowing audits by the Controller or an auditor mandated by it, on 30 days' notice, at most once a year, at the Controller's expense, under confidentiality.
5. Sub-processors
The Controller gives general authorisation to the sub-processors listed in section 8 of the Privacy Policy, who process data under written terms that impose obligations equivalent to this DPA. Pictomemo will notify the Controller of any intended change by updating that list and, for changes affecting the processing of the Controller's data, by email at least 14 days in advance; the Controller may object on reasonable grounds within that period, in which case the parties will look for a solution and, failing one, the Controller may terminate the affected service. Pictomemo remains liable to the Controller for the performance of its sub-processors.
6. International transfers
Data is hosted in the United States with the providers listed in the Privacy Policy. Transfers from the EEA, the United Kingdom and Switzerland rely on the standard contractual clauses adopted by the European Commission (and the UK and Swiss addenda), with supplementary measures where needed; transfers from Morocco comply with the requirements of the CNDP. Copies of the clauses are available on request.
7. Personal data breaches
Pictomemo will notify the Controller without undue delay, and at the latest 48 hours after becoming aware of a personal data breach affecting the Controller's data, with the information available at that time and further information as it becomes available.
8. Liability
Each party is liable for the damage it causes by processing that infringes applicable data protection law. Pictomemo's liability under this DPA is subject to the limitations in the Terms of Service, to the extent permitted by law.
9. Term and termination
This DPA lasts as long as Pictomemo processes personal data for the Controller. On termination, section 7 of the Privacy Policy governs deletion; the Controller can export its data at any time from the account page.
10. Governing law
This DPA is governed by the law that governs the Terms of Service, without prejudice to mandatory data protection law applicable to the Controller.
11. Contact
DPA enquiries and written instructions: contact@pictomemo.com.