Loading…

Back to home

Data Processing Agreement (DPA)

Last updated: August 11, 2026

This Data Processing Agreement ("DPA") forms part of the Real-Lenses Terms of Service and applies to customers who process personal data through our Services (the "Controller" or "Customer"). Real-Lenses acts as a "Processor" on behalf of the Customer.

1. Definitions

  • Personal Data — any information relating to an identified or identifiable natural person
  • Processing — any operation performed on Personal Data
  • Controller — the entity that determines the purposes and means of processing
  • Processor — the entity that processes Personal Data on behalf of the Controller
  • Sub-processor — a third party engaged by the Processor to assist in processing

2. Roles and Scope

When a Customer uploads media or data containing Personal Data to Real-Lenses for forensic analysis, the Customer is the Controller and Real-Lenses is the Processor. We process Personal Data only on documented instructions from the Customer.

3. Processing Instructions

Real-Lenses will process Personal Data only for the purpose of providing forensic analysis, generating reports, and operating the Services as described in the Terms. We will not process Personal Data for our own purposes or use it for marketing without consent.

4. Sub-Processors

We engage the following categories of sub-processors:

  • Cloud hosting — infrastructure providers for data storage and compute
  • Payment processing — Stripe for billing
  • Email delivery — Resend for transactional emails
  • AI/ML providers — for forensic analysis model inference
  • Analytics — for usage tracking and product improvement

We ensure sub-processors are bound by written agreements providing equivalent data protection. We notify Customers of new sub-processors and allow objection.

5. Data Security

We implement appropriate technical and organizational measures including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Access controls and least-privilege permissions
  • Regular security assessments and vulnerability scanning
  • Incident response procedures
  • Employee training and confidentiality agreements
  • Data backup and disaster recovery

6. Data Breach Notification

In the event of a Personal Data breach, Real-Lenses will notify the Customer without undue delay (and in any case within 72 hours of becoming aware). We will provide information about the nature of the breach, measures taken, and recommendations for mitigation.

7. Data Subject Rights

Real-Lenses will assist the Customer in responding to data subject requests (access, rectification, erasure, portability) by providing the necessary data and tools within our Services. The Customer is responsible for responding directly to data subjects.

8. Data Return and Deletion

Upon termination, the Customer may export their data. Real-Lenses will delete all Personal Data within 30 days of termination, unless retention is required by law. The Customer can request earlier deletion via contact@real-lenses.com.

9. Audit Rights

The Customer may audit Real-Lenses' compliance with this DPA, subject to reasonable notice and confidentiality. We provide relevant documentation and cooperate with audits conducted by the Customer or their designated auditor.

10. International Transfers

For transfers outside the EEA/UK/Switzerland, we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission. A copy of the SCCs is available upon request.

11. Contact

For DPA-related inquiries, contact our Data Protection Officer at contact@real-lenses.com.

Questions about this policy? Contact us at contact@real-lenses.com